Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?
If not, I'll happily stand corrected, but please share sources.
Addenda:
- Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...
- Paper breaking the hash: https://arxiv.org/abs/2111.06628
Edit: The second one is the wrong paper. I’ll find and link the correct one tomorrow. Keeping the link for transparency.
Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.
So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.
I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have
That box has been open for years now.
Big brother is already watching what you do on your Android device.
> A Dad Took Photos of His Naked Toddler for the Doctor. Google Flagged Him as a Criminal.
https://www.nytimes.com/2022/08/21/technology/google-surveil...
Google reported him to the police based on a single false positive.
To add insult to injury, even after the police contacted Google to tell them that they had cleared him of wrongdoing, Google refused to restore access to his account.
> The father uploaded photos of his son’s genitals, which were also backed up on his Google cloud, to the health care provider’s messaging system as requested.
(It is, granted, a bit pushy about it and will ask multiple times when you run it with an intrusive dialog.)
It's right there plain as day in the TOS. I don't know how people can use these products without understanding the contract they locked themselves into. /s
Very different than trying to narc out users to the authorities.
The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069
That's a new version. The one that as announced the same time as client side scanning to block uploading CSAM to iCloud worked like this.
1. It could be enabled on a child's device by the parents. It was not on be default.
2. If the child received a sexual image (not necessarily just CSAM...if an adult sends a dick pic to a child that is not CSAM but would have been flagged) the image is blocked, the child is notified, told their parents are worried the image may harm them, and asked if they still want to see it.
3. If the child says no, they do not want to see it, that is the end of the matter.
4. If the child says that they do want to see it and they are at least 13 they are shown the image and that is the end of the matter.
5. If the child says that they do want to see it and they are under 13, they are again told that they parents are concerned, and that if they view it their parents will be notified, and asked if they still want to view it.
6. If they say no that is the end of the matter.
7. If they say yes they see it but the parents also are notified and will be able to see it.
This should have been pretty uncontroversial, but there were objections on the grounds that if someone say sends their dick pic to your under 13 child and the child goes all the way through to step 7 and decides to view it, that is a violation of the sender's privacy because that message was only intended for the child.
Accidental false positives could lead to horrific outcomes up to and including oh look bob got shot by the cops for resisting.
It was possible to produce apparently matching innocuous images and then poison people's machines with them.Oops did you click on that picture of a tree have fun with the cops. Like an advanced form of swatting.
Although inspired by a desire to find CSAM Apple could be forced to scan for ANYTHING by repressive regimes including America and China.
Although initially targeting images client side scanning of messages is a pretty obvious next step. Again obvious good motivation exists and is completely justifiable who doesn't want to stop the next mass shooting or terrorist attack... and then we can basically use it to find people critical of the regime. Do remember we are presently prosecuting a political figure for a picture of sea shells and a guy in texas is rotting in prison for distributing political literature.
Including Europe. Europe is ruled by people who think 1984 was an instruction manual.
Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines:
"Apple says users can have up to 20 CSAM images on their phone before they'll tell police"
You might not like pictures that way but honestly I think more important in procescuting CSAM is to go after the large sources of CSAM generation. Its trafficing in East Asia, and in Europe. I think weirdly America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures. Abuse definitely happens in the US but making policy decisions like this produces bad policy.
Does iCloud rehost the photos to other people I don't really know because I use andriod tbh. If they are being rehosted (I assume to members of your contacts) that can be problematic but I think honestly the issue a lot more complex than just protect the children which the source of critic is a lot attacks against apples are coming from
The US has the largest pornography industry in the world by a massive margin, and the largest consumption of online pornography per capita
Meanwhile should we be surprised that CSAM production is higher in countries like the Philippines that have very weak digital policing, abject poverty, high numbers of street children etc?
Some TV shows rightfully take aim at this contradiction (recently: The Hunting Wives).
You can get married at 15 in Hawaii and Kansas.
You are "grandfathered" into sexual consent (not as in "marital rape" but "no longer statutory rape") when you do so.
So we may not want to be lording it too much on "international norms", particularly given that most of the marriages that happen at those ages are not "young couple got pregnant" but "older man in conservative/religious community".
In some countries it is as far as I’m aware
No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.
And therapists are legally mandated to report you if you told them you viewed or possessed CSAM.
I get it, actually. It's totally possible the picture in question was not known to authorities prior. That's called due diligence to look into it.
Adults not looking into things or following up on things are how the system fails children if you read some accounts of people who were abused by their guardians. Horrifying stuff.
Mandatory reporting makes sense for situations you are connected to. And even then there's presumably good reasons not everyone is a mandatory reporter. This goes way beyond that, mandatory reporting once removed for someone that doesn't know a single person involved.
Hell, reporting someone for that doesn't even guarantee the images get looked into! If they didn't save history they're probably not feeling like going back to the site to demonstrate. Similar if it was sent against their will and they deleted it right away.
Honestly shocked that anyone would even say this, but even giving you the benefit of the doubt here -- the one case where I could imagine this might not happen would be if you're a police officer investigating such cases. But they also have their own therapists dedicated/trained in police-specific issues.
But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.
A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something they've discovered is also used for CSAM.
You think it's a good thing for the therapist to be required to report this? Should they report that the patient admitted to viewing CSAM with no context so the whistleblower gets investigated and arrested, or should they provide the context -- that the patient is about to expose the corruption of the government receiving the report?
For that matter, consider what it does when someone is actually a pedophile. They find out that if they try to seek therapy to address their perverse attraction to kids, the therapist isn't allowed to keep their confidence and they'll be arrested, so instead of seeking professional help, they keep abusing kids. Is that the result we wanted? There is a reason doctor-patient confidentiality was a thing.
If its your license to practice on the line you know what choice you're going to make.
> Across most states, viewing CSEM alone is generally not a mandated-reporting trigger; reporting becomes obligatory when disclosures involve an identifiable child being abused or used to produce material.
> California’s CANRA imposes a distinct duty to report electronic access (download/stream) with identifying patient information, upheld against privacy challenges based on compelling state interest.
[0] https://www.psychiatrictimes.com/view/mandatory-reporting-ch...