Hacker News new | past | comments | ask | show | jobs | submit login

The concern is that Apple is handing governments a new tool to go “give me a list of all users that have this photo”. It could track down dissidents based on this and combined with metadata is probably sufficient to pinpoint who took a particular picture.

Think you shared that picture of police brutality anonymously? Think again.




But what im getting at. Is that this is exactly what Apple is trying to fight.

A government could already coerce Apple into handing over iCloud data.

The cryptography at play here, combined Private Set Intersection and Threshold Secret Sharing are clear steps to make it as hard as possible for any institution to body this for that reason.


Apple can already decrypt your iCloud photos, same with google etc. I don’t get this argument as they can already do that.


iCloud != iMessage


And this feature has nothing to do with iMessage.

Y'all are starting to make me more sympathetic to Apple. Their biggest misstep was making these announcements simultaneously without foreseeing how many people would (willingly or otherwise) conflate them.


iMessage data is getting scanned with a broader set of heuristics than iCloud data, while it’s supposed to have air tight privacy.


This is not true. There were multiple features announced. iMessage data is not being scanned by most phones. The ONLY CSAM detection that happens is on photos being uploaded to iCloud Photos.

The only phones where iMessage photo scanning happens are those for children under a certain age (maybe 13?) whose parents who have opted into child protection where the phone scans for nude photos and notifies the parents.

People are conflating these two _different_ but _related_ features and their goals and limits.


Unless they change the system, no notification would happen without multiple matches.

Also, dissidents can just turn off iCloud sync and no scanning will happen.


What would prevent governments from requiring Apple to scan regardless of iCloud state in order to do business within their borders?


How would Apple target the hash database to a specific phone without an iCloud connection?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: