46 comments

[ 1.6 ms ] story [ 32.9 ms ] thread
It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level.

Apple could easily not do this stuff and it may even be easier to not.

To me it is crazy people go out of their way to defend apple in this area.

They might be slightly better than some others (horray!) but given their ecosystem it is still the worst platform if you value any form of freedom. Depending on apple for your privacy is ignorance at best.

Their level is set where it best feeds their revenue. Their security plays equally as well into their walled garden.
the judge is indeed wise
The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections.

As sad as this is, end to end encryption means no CSAM scanning.

As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too.

This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me

The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen.

The criminal and disgusting tail end of this type of material deserves the worst of consequences for the perpetrators and all the support in the world for the victims, but these are mostly - you guessed it - poor and unprivileged children from far away places and they certainly can’t put this much pressure on apple

If these judges are so righteous, they should go further and mandate the OS to do mandatory scanning of personal hd.
IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.

Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.

“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)

I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are created, for their own good, of course.
I am not a lawyer.

There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example:

  * A: physical sexual abuse of children. B: possession or distribution of CSAM
  * A: drug trafficking or tax evasion. B: structured cash withdrawals
The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A.

It's my understanding that conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person: one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

It's my understanding that one can be convicted of structured withdrawals that are not driven by, linked to, or in any way related to anything nefarious.

IANAL but I thought the whole reason scanning worked was it wasn't required so there weren't fourth amendment issues.
Ah, the CSAM saga. Very poorly handled by Apple. Suspect it may have taken Hair Force One off the shortlist of CEO succession.
Seems like the kids miss their chance at justice because of section 230 allowing platforms the freedom to remove whatever they want but not be responsible for what they keep or amplify. That is the problem with 230. Censorship is permitted and punishing the censor isn't. Twitter and Tiktok are literally microblog platforms that get away with removing good stuff and leaving evil because they "are not a publisher" while the algorithm literally publishes a chosen set of articles to people. Facebook can remove religious freedom material and leave human trafficking groups. Section 230 gives the publishers the cake and the edict too.
Section 230 doesn't provide as much immunity as people think. A platform can still be liable for the choice to amplify something.
As the creator of mediaden.ca[1] I’ve thought about this. Client side scanning is maybe marginally better than server side scanning, but both paths lead to privacy rot.

Governments need to catch criminals, but they shouldn’t do it at everyone else’s expense.

1. https://mediaden.ca

sigh

Once again, someone (in this case, the judge of this case) asks if we can meet in the middle on whether or not private communications are actually private.

To be clear: this is not a limitation of nerds' imagination. This is a limitation of physics. A person is either party to a communication (and thus can decrypt it) or is not (and thus cannot). If you demand Apple scan encrypted photos for CSAM, what you are demanding is that Apple be party to every communication done with an iPhone. There is no middle ground on encryption, there will never be a middle ground on encryption, and I will hold this truth on my deathbed.

There is no "encrypted but crackable" - if the CIA can crack it at all, we're only a few years away from some kid's gaming rig doing the same thing. There is no "secure golden key" - if there was, you could buy it in the same section of Amazon that sells copies of the TSA master key that opens all luggage locks.

Personally, the next time a government demands decryption keys, I think Apple should just set all iCloud photo libraries in that country to public and say "Sorry, your politicians made private photos illegal, take it up with them". Obviously, telegraph this far in advance and give users time to actually delete their cloud-hosted photos first. But definitely do not pretend like you can keep a secret with a government bureaucracy of hundreds of thousands of people.

But then again, Apple also capitulated (good meaning) to the EU on third-party app distribution, so Apple has a lot less of a spine than they let on. At least Google actually stayed out of China.

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA.

For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has even extended to fictional CSAM such as AI generated stories and pictures. As an aside, if that gets extended to political speech or other non-CSAM materials that are determined to be undesirable, that's a big concern. I can imagine that a conservative state could pass a law banning all porn because they claim it could encourage illegal activities such as prostitution, rape, or CSA.

On the CSA side, you rarely hear about arrests (they happen but less than CSAM). There doesn't seem to be any real push for educating and protecting kids before it happens. Ironically, the groups doing the most to educate and implement protective strategies are the ones who have been involved in abuse scandals in the past (Churches, Scouts, etc). Even then, a lot of it is just getting clearances, which doesnt prevent people who where not caught or were first timers. Offenders get put on a list/map. This is sort of a half approach. If they are still a threat, they shouldn't be released. Yet if you comb the list and see some of the results, they don't all seem to fit with CSA. I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.

It seems like these laws are more about peddling to the publicist and lawmakers fantasy of incrementally extreme punishment rather than taking a appropriate, data driven, and level-headed approach that actually protects kids. Otherwise they will just keep pushing ham-fisted low-hanging "fixes" like required scanning and IDs to access the internet.

It's not about children. It was never about children. How many politicians have gotten caught in Epstein's island by now?

It's all about surveilling the masses and keeping them under control. Children are merely one of the political weapons they use to make the masses accept any proposed solution, no matter how Orwellian. You're not against protecting children from drug trafficking, money laundering, child molesting terrorists, are you?

I don't know how to say this and not sound like a CSAM or CSA offender but CSAM policing sounds too much thought policing to me, if you wanna police CSA just go and do it, don't police what people have in their mind.
The lowest of the low hanging political points scoring fruit will be picked.

I make this point on HN each time it comes up: Dealing with actual CSA requires actual people going to investigate actual reports of children's living conditions out in the real world, not "scanning digital files". Seems obvious when you say it like that, but the alternative seems to still score heavily on the political scale. Ironically, spending more money on "scanning digital files" takes away from resources that could prevent those digital files from being created in the first place, so all the additional time, money, and effort towards combatting CSAM is time, money, and effort specifically _not_ working against stopping CSA. It's categorically _not_ protecting the children.

Teachers, in Australia at least, have mandatory reporting where any kind of abuse is suspected. The heart-breaking irony is that the resources to investigate the reports are so scarce that they can only respond to reports where the child's life is in immediate danger.

Caveat: the above was true a few years ago, I genuinely don't know if it's still true. What I do know is that 'social work' isn't suddenly a high paying job, so I doubt resource availability has changed much.

There is no easy answer to this. It's entirely nuance.

It’s nothing to do with CSAM and all about surveilling who has which files and when, and who they send them to.

Even ADP in iCloud sends the hashes of the plaintext to Apple, non-e2ee. This allows them to see who has unique files, and when, and the networks of users to which they spread, and when.

Yeah DUH. its a trojan horse to eliminate any privacy in the populace, except for the government and elites, of course. They get privacy. You dont. How else are they going to maintain control over the populace?
Arresting for CSAM is easy and brings in a lot of money. It’s a slam dunk case for just possession. Investigating and prosecuting people for CSA takes a lot of manpower and time for single case and not nearly as profitable. As usual, follow the money.
It is not about CSAM, it's about scanning our data. If it were about kids safety there would be lots of people in jail
Theory besides what others have said: remove the supply and you affect the demand. That's the theory anyway, I'm not sure it works like that; to make a parallel, punishing drug users didn't affect dealers/supply networks.
My thought is that many different stakeholders have reasons to focus on CSAM:

- Prosecutors want to go after it because it is much easier to prove than CSA.

- Authoritarians want to go after it because it gives them a chance to get things like ID checks accepted by the public.

- People who genuinely want to prevent CSA focus on it because a large amount of CSAM is made by serial abusers - so capturing producers can prevent future abuse. Additionally, they believe (with good reasons) that CSAM consumption is a gateway to CSA and CSAM production for many people. Further, finding CSAM can be a way to identify and rescue children from abusive situations.

- CSA survivors may advocate for it often feel traumatized not just by the abuse, but by the fact that people might be continuously viewing that abuse.

- Going after it winds up creating digital forensics specialists and task forces, which creates a special interest group within police departments which wants to continue focusing on CSAM but is not set up to do anything about CSA.

I would recommend the podcast Hunting Warhead to anyone interested in learning more about this.

I'd like to know the link between availability of csam and CSA. There seems to be an assumption that the former causes the latter.

That's not to say it's acceptable if illegally produced.

We have issues in the UK. So far they've banned 'rape' porn. And now they're talking about 'barely legal'

None of this seems to be based on any statistics showing this is actually harmful in any way.

CSA doesn't neatly fit into a narrative.

If there's a person committing abuse against a child, usually a family member in their own household, there's no story there. They (hopefully) get arrested, get a minor mention in the media if that, and life moves on.

If, on the other hand, they send CSAM using a platform, device or protocol, then clearly the makers of that technology failed to uphold their sacred duty to protect the child. If most CSAM cases happen using a few major technologies (and they will, because societies tend to standardize on what technologies they use for communication), the technologies get blamed for the problem they supposedly enable.

If you dislike the technology for other reasons (the distrust of corporations from left-leaning politicians, censorship allegations on the right, a moral panic about the impact of smartphones on children's mental health), you can use people's misunderstanding of statistics to exaggerate the CSAM problem, blame the tech, and gain some notion of control over it in a way that is politically palatable to citizens.

It's worth saying explicitly that centralization doesn't have much to do with this. We've seen similar stories play out with bicycles, Walkmans, pagers, AI, heavy metal and Uber rapes. They were different moral panics, but the mechanic was roughly the same. I think the situation wouldn't change much if we all used PGP-encrypted email over personal mail servers to communicate.

An exception that proves the rule is the moral panic over CSA in primarily-catholic countries, notably relating to abuse committed by catholic priests, which are statistically no more likely to commit it than anybody else. As the influence of the Church on government policy is a hotly-debated topic in those countries, CSA is suddenly an issue that people can use to further their political causes.

First, I think it’s likely that you hear more about one than the other because you read websites like Hacker News and are not (I assume) an FBI agent or someone else who works on this stuff. A public defender I know would say that child abuse of all sorts is ever-present and relevant to their work, unfortunately.

Second, detecting CSAM leads to its producers who are by definition abusers. Here’s a nice article in Wired about the digital forensics of cracking down on a CSAM ring with some interesting details about the role played by crypto, and abusers’ misconceptions about it: https://www.wired.com/story/tracers-in-the-dark-welcome-to-v...

With that said, I agree that a lot of political concern for this is a smokescreen for a creating more surveillance. “think of the children!” has the flavor of a rhetorical trump card.

> yet almost nothing seems to be done to prevent CSA.

for the UK, there has been a massive shift to prevent this kind of stuff.

anyone who even volunteers with children or vulnerable adults needs to be screened. Charities are required to have policies for dealing with vulnerable people safely.

but to the point, Apple halfarse CSAM reporting.

Whatsapp which doesn't do "CSAM scanning" reports in one hour more CSAM than apple does in a year. From memory meta (instgram, facebook and whatsapp) reported millions of cases of CSAM for 2021, compared to apple's ~250 (not thousand, just 250)

for facebook its automated scanning, but for whatsapp, its just design. its really obvious how to report a message/image. in imessage, its impossible, there is no mechanism to long press/select/other a message.

Now, Facebook are bastards in virtually every way, but for whatsapp at least, they have made GUI changes that have real positive impact on CSAM protection.

Apple has not.

They made some noise about hashing, but thats invasive and ironically noisier than having user reports.

There is a pretty simple yet disappointing reason. CSAM is much easier to investigate and prosecute. You got evidence, you prosecute. Almost guaranteed conviction. You can even enforce big tech to implement proactive monitoring systems.

Compared to this, CSA is much harder. Every case is different. You have to do due diligence. And it is extremely hard to proactively detect them. Careful criminals will destroy all evidence. The number of case itself is smaller. And there is a good chance to lose in the court and for prosecutors this is a clearly risky move. Good ol' criminal investigation is expensive. There is a structural reason not to prioritize them.

The whole incentive structure is broken. The only thing to fix this is external pressure, but even it does not work these days. Exposing CSA is a rare event but media needs constant, sensitive headlines so they tend to treat CSA and CSAM like the same thing. Hence external pressures do not work, and even worse those work in a wrong way. This creates a bad feedback loop.

> This has even extended to fictional CSAM such as AI generated stories and pictures.

Peripheral to your comment, there is an argument against AI generated CSAM that no one seems to be making so allow me. AI will do the same for CSAM as it has already done for copyright laundering. That is, it will enable its distributors to train their models on real CSAM while obscuring the training material. A legal regime that permits unrestricted distribution of AI generated CSAM incentivizes actual abuse as a source of training material. If one opposes legal prohibitions on free speech grounds, then at a minimum there should be an audit requirement incumbent on AI generated CSAM distributors to document their process in sufficient detail as to establish that they haven't used actual CSAM for training, similarly to the way porn distributors are required to document that their models are of legal age.

>yet almost nothing seems to be done to prevent CSA.

>that many of the people actually arrested are arrested for CSAM and not CSA

So there are, or there aren't arrests?

Also you hear about CSA arrests all the damn time. If anything it's underplayed in the media somewhat when they're a specific people.

You wouldn't hold the postal service accountable for delivering CSAM or a bank for offering storing it a lock box would you? So why should cloud storage services be different? Stop clutching your pearls and welcoming big brother over imagined threats while a real rapist sits in the oval office!
If you're going to be committing a crime, why would you store it in a cloud service?
Because companies love turning things like this on by default.
A perfectly safe panopticon and freedom & privacy will always be at odds.

Don't let a classic "think of the children" appeal to emotion short circuit your reasoning.

A court should not quietly create a general duty to inspect everyone's private files because a provider could theoretically detect illegal content
I have to point out that the united states absolutely does not, under any context, care about the health and wellbeing of children. If they did they would have good, easy to access free healthcare and support for families including parental leave, as well as a good public school system that served every single child adequately.