He didn't get off to a good start in the interview - his initial explanation of hashes and safety vouchers was full of stuttering, and it's only through Joanna Stern's animations and explanations that you get what the intent is.
He tries to emphasize the distinction that this hash generation and comparison process only occurs when the file is about to be uploaded to iCloud, but I have to ask - who is manually choosing each individual photo that they want to upload to iCloud? Most people just toggle on the setting to automatically upload everything.
I would've liked to see questions in this interview about what type of security testing they have done regarding these features, both internally and in combination with NCMEC.
What I still don't get is why they do not allow the user to choose between this on-device hash generation and comparison, and the in-cloud scanning that other cloud providers are already doing.
He was desperately trying to reframe this away from “your iPhone” doing it and into “iCloud” doing it, but that requires a lot of mental gymnastics and nerdy terms.
And so that whole premise of Apple conflating multiple systems in one release is making it really hard for him to explain it away.
I’m waiting for next episode where they should try to explain “Synthetic Match Vouchers” and how they increase your CP count…
We hear a number for the threshold for the first time; from the video interview:
> Threshold of [matches], something on the order of 30 known child pornographic images
As I understood it, if around those number of matches are found on the device, then a scan happens on those matches in iCloud, and it’s the photos that match on iCloud that they then go on to report.
Apple are being useful idiots. Someone answered the call to nerd harder, and signed the order to sell out humanity. The consequence of such client side scanning will be felt for decades+. A so called rubicon moment in tech oppression.
One problem is, the CSAM database he talks about is from the US and not managed by Apple. What if another country requires to use a different database and requires to put in other in this country "legally compromising" images? Who audits this? Apple in the respective country? Who will even get notified about this?
Tank man and Winnie the Pooh, drawings of the prophet, copies of the bible (surely you can adapt this to text), wikileaked documents and video (or other embarrassing news), or just DMCA abuse. There are endless things governments will censor with this
In the interview he states Apple will promise to send the same database to all iPhones around the world and this database can be audited by 3rd parties so we can actually verify that Apple always send the same version to all iPhones.
There is of course the argument that Apple will backtrack on this promise but that applies to everything they do so I'm not sure how much weight to give it.
Which 3rd parties and how much auditing was there granted by NCMEC in the past?
I don't see the NCMEC call the CCC or EFF and ask them if they want to audit their database full of CSAM. (Or Apple or the other partners that weren't named.)
Too bad the meat of the problem was seemingly cut together into a 5s part before moving on to the iMessage stuff without any context or explanation. So there are multiple levels of auditability so you don‘t have to trust apple or countries even if Apple says „yes“ (which I guess means if Apple says yes to changing the database, but is not explained in the video). Would have been great if the main crux of the issue was not just glossed over.
> “So there are multiple levels of auditability so you don‘t have to trust apple or countries even if Apple says yes“- Apple
What auditability is he referring to? Who gets to audit the database and source code?
Earlier, he slips and says: “people can see…” then realizes he’s going off message. It seemed like he was going to state that users can somehow verify Apples claims about the db and or code.
The interview starts with a gross misrepresentation of the actual criticisms by the Apple CEO.
No there was no mixing up of two proposed technologies, that was not the issue at all. Noone with legitimate criticism was confused by that.
Basically what he communicated in the first sentences was 'we do not listen to what the critics say, we do not care how legitimate the criticism is, we will try to make it go away with manipulative rethoric and follow our plan'.
1:43: So to be clear, we are not looking for child pornography on iPhones, that's the first root of the misunderstanding
4:10: On your phone when photos are uploaded to the iCloud photo library - part of that upload pipeline- there is a.. what's called a neural hash... performed on the image and that neural hash is intersected with a database that's on your device...
I'm sorry but computing hashes on a device and comparing them against a set of hashes on a device is literally scanning for photos on the device. Pinky swear promises to "only do this on photos that you are uploading to iCloud" doesn't magically turn this into an iCloud feature.
This is on-device scanning for a set of hashes derived from a database of Photos that nobody can legally audit. The next instance of the FBI wanting to frame the next Martin Luther King Jr doesn't even have to go through the hassle of obtaining CP and inserting it into their target device. They can download completely innocent family photos from FB and upload them to the NMEC database and wait for the new hashes to be downloaded to their target's phone.
To make things worse, this is all just one little "oopsie, I wrote a bug" away from scanning every photo on device including on devices that have iCloud photos turned off and are in Airplane mode.
Steve Jobs in 2010:
"Privacy means people know what they’re signing up for, in plain English, and repeatedly. That’s what it means. I’m an optimist, I believe people are smart. And some people want to share more data than other people do. Ask them. Ask them every time. Make them tell you to stop asking them if they get tired of your asking them. Let them know precisely what you’re going to do with their data. That’s what we think."
Interesting to see the "oh you must be confused" framing pop up everywhere. It's rampant as a defense of this in online discussions, Apple's defense, and Jon Gruber's take. Is there a name for this strategy?
> Paternalism: A serious fallacy of ethos, arbitrarily tut-tutting, dismissing or ignoring another's arguments or concerns as "childish" or "immature;" taking a condescending attitude of superiority toward opposing standpoints or toward opponents themselves.
Federighi is claiming we are confused and he's apologizing for confusing us. We are not confused. We understand the technologies and we object to them because they are dangerous and unnecessary. Do monitoring on the cloud platform, not on people's devices.
See Green and Stamos who explain in plain English.
25 comments
[ 19.0 ms ] story [ 675 ms ] threadHe tries to emphasize the distinction that this hash generation and comparison process only occurs when the file is about to be uploaded to iCloud, but I have to ask - who is manually choosing each individual photo that they want to upload to iCloud? Most people just toggle on the setting to automatically upload everything.
I would've liked to see questions in this interview about what type of security testing they have done regarding these features, both internally and in combination with NCMEC.
What I still don't get is why they do not allow the user to choose between this on-device hash generation and comparison, and the in-cloud scanning that other cloud providers are already doing.
And so that whole premise of Apple conflating multiple systems in one release is making it really hard for him to explain it away.
I’m waiting for next episode where they should try to explain “Synthetic Match Vouchers” and how they increase your CP count…
> Threshold of [matches], something on the order of 30 known child pornographic images
As I understood it, if around those number of matches are found on the device, then a scan happens on those matches in iCloud, and it’s the photos that match on iCloud that they then go on to report.
Fuck Apple for this. Dystopia grows deeper.
There is of course the argument that Apple will backtrack on this promise but that applies to everything they do so I'm not sure how much weight to give it.
Which 3rd parties and how much auditing was there granted by NCMEC in the past?
I don't see the NCMEC call the CCC or EFF and ask them if they want to audit their database full of CSAM. (Or Apple or the other partners that weren't named.)
Maybe they should try and Think Different(TM)?
> “So there are multiple levels of auditability so you don‘t have to trust apple or countries even if Apple says yes“- Apple
What auditability is he referring to? Who gets to audit the database and source code?
Earlier, he slips and says: “people can see…” then realizes he’s going off message. It seemed like he was going to state that users can somehow verify Apples claims about the db and or code.
This interview clarified nothing.
No there was no mixing up of two proposed technologies, that was not the issue at all. Noone with legitimate criticism was confused by that.
Basically what he communicated in the first sentences was 'we do not listen to what the critics say, we do not care how legitimate the criticism is, we will try to make it go away with manipulative rethoric and follow our plan'.
4:10: On your phone when photos are uploaded to the iCloud photo library - part of that upload pipeline- there is a.. what's called a neural hash... performed on the image and that neural hash is intersected with a database that's on your device...
I'm sorry but computing hashes on a device and comparing them against a set of hashes on a device is literally scanning for photos on the device. Pinky swear promises to "only do this on photos that you are uploading to iCloud" doesn't magically turn this into an iCloud feature.
This is on-device scanning for a set of hashes derived from a database of Photos that nobody can legally audit. The next instance of the FBI wanting to frame the next Martin Luther King Jr doesn't even have to go through the hassle of obtaining CP and inserting it into their target device. They can download completely innocent family photos from FB and upload them to the NMEC database and wait for the new hashes to be downloaded to their target's phone.
To make things worse, this is all just one little "oopsie, I wrote a bug" away from scanning every photo on device including on devices that have iCloud photos turned off and are in Airplane mode.
Interesting to see the "oh you must be confused" framing pop up everywhere. It's rampant as a defense of this in online discussions, Apple's defense, and Jon Gruber's take. Is there a name for this strategy?
Source: Master List of Logical Fallacies - http://utminers.utep.edu/omwilliamson/engl1311/fallacies.htm
See Green and Stamos who explain in plain English.
https://www.nytimes.com/2021/08/11/opinion/apple-iphones-pri...