Hacker News new | ask | show | jobs
by EagnaIonat 6 days ago
> Apple or whoever maintains that listof hashes from putting things other than child abuse on there, like dissident memes for example.

That's the common argument and it's wrong.

The hash database is regulated and used worldwide. To get the hashes of what you mention into the database requires numerous people signing off on it. It is also a 1:1 match, not a "dissident said X" type meme match.

> It also requires devices to run this spyware without a way to disable it.

All scanning is done on the cloud. Apple operating system has a nudity detector when posting images, but it only warns you the dangers of doing it before you hit send.

There is no spyware.

In fact when Apple tried to protect peoples data from those scans before everyone lost their mind. Forced Apple to remain keeping users data accessible on the cloud.

The truth is, if your government is determined to spy on its population there are much easier and less intrusive methods of doing so.

1 comments

> The hash database is regulated and used worldwide. To get the hashes of what you mention into the database requires numerous people signing off on it.

So, it's correct. What you're describing is a policy, not a technical limitation. The technical infrastructure allows exactly that. Policies can and will be changed and bypassed.

> It is also a 1:1 match, not a "dissident said X" type meme match.

So you can maintain a list of dissident memes just like you can maintain a list of CSAM. There is absolutely nothing technologically differentiating CSAM from images with dissenting political content. The database is an arbitrary list of material deemed hostile. Only putting CSAM on it is a pinky promise that will be broken.

> All scanning is done on the cloud.

Because there was so much backlash against putting spyware in devices, not because they didn't try.

> Forced Apple to remain keeping users data accessible on the cloud.

What are you talking about?

> The truth is, if your government is determined to spy on its population there are much easier and less intrusive methods of doing so.

Why is such a large political faction in the EU continuing to push for this surveillance in the form of Chat Control then? You are just stating this with no facts to back it up against all the evidence to the contrary.

> Policies can and will be changed and bypassed.

You should take the time to see how it works.

No singular country can put information in that wouldn't be picked up straight away by other countries. There are 70 countries signed up to it.

> So you can maintain a list of dissident memes just like you can maintain a list of CSAM.

Using hashes as a way to match doesn't scale in the way you describe. So it wouldn't be feasible to do that.

There are certainly approaches that can be taken, but CSAM isn't that.

> What are you talking about?

All major companies (for about 10 years) scan everyone's images/files for CSAM. That is happening now.

Apple came with an approach that would have the CSAM hashing checks on the device.

If your image/video passed then it was encrypted so that no one could decrypt it even on the cloud. If it failed, then it was business as usual and your file was uploaded as it has normally been and scanned.

It would have dramatically reduced server costs and meant that your files were 100% safe on the cloud from the government, instead of what they are now. Everyone lost their mind over it, but were taking news stories as facts when it didn't match the research paper.

> You are just stating this with no facts to back it up against all the evidence to the contrary.

To be fair, you started first and I've yet to see a link from you.

But here is a starting point.

https://www.interpol.int/en/Crimes/Crimes-against-children

> No singular country can put information in that wouldn't be picked up straight away by other countries. There are 70 countries signed up to it.

Once that is in place it's just a tiny change to switch to a national database. Granted, that's not a purely technological argument, but the main point is, you are not in control of what your images are scanned for and you cannot even verify it because it's hashes.

> Using hashes as a way to match doesn't scale in the way you describe. So it wouldn't be feasible to do that.

Why wouldn't it? If it scales for CSAM why wouldn't it scale for other types of content? If it doesn't scale for CSAM why are we even arguing about it? There is no technological difference between the two. It's all just images or videos.

> All major companies (for about 10 years) scan everyone's images/files for CSAM. That is happening now.

They scan the images on there servers. They do not scan my images, for example.

> It would have dramatically reduced server costs and meant that your files were 100% safe on the cloud from the government, instead of what they are now. Everyone lost their mind over it, but were taking news stories as facts when it didn't match the research paper.

It would have reduced server costs for Apple at the expense of energy costs and battery life for their customers. I fail to see how that is a win.

I don't care if my files are safe in "the cloud" when they are not safe on my device before being uploaded to the cloud. Also Apple introduced E2EE later anyway and there are other E2EE cloud storage options that have been available before. You are painting a false dilemma. We can have E2EE without surveillance scanning.

>>> if your government is determined to spy on its population there are much easier and less intrusive methods of doing so.

What are those methods? It is always about the children and terrorism when the government wants to extend mass surveillance.

Btw, when I follow your link I only get en error page stating "Access to this site was denied for security reasons. Please contact your network or system administrator."