Apple's bright idea for CSAM scanning could start 'persecution on a global basis' – 90+ civil rights groups
- Reference: 1629400930
- News link: https://www.theregister.co.uk/2021/08/19/apple_csam_condemned/
- Source link:
The US-based Center for Democracy and Technology organised the [1]open letter [PDF], which called on Apple to abandon its [2]approach to mass-scanning. Signatories include Liberty and Big Brother Watch in the UK, the Tor Project, and Privacy International.
The letter raises concerns about the accuracy of Apple's technology, arguing that these kinds of algorithms are "prone to mistakenly flag art, health information, educational resources, advocacy messages, and other imagery." And then there are the consequences of governments getting involved.
[3]
"Once this capability is built into Apple products, the company and its competitors will face enormous pressure – and potentially legal requirements – from governments around the world to scan photos not just for CSAM, but also for other images a government finds objectionable," the letter stated.
[4]
[5]
"Those images may be of human rights abuses, political protests, images companies have tagged as 'terrorist' or violent extremist content, or even unflattering images of the very politicians who will pressure the company to scan for them. That pressure could extend to all images stored on the device, not just those uploaded to iCloud. Thus, Apple will have laid the foundation for censorship, surveillance and persecution on a global basis."
[6]Apple didn't engage with the infosec world on CSAM scanning – so get used to a slow drip feed of revelations
[7]Apple says its CSAM scan code can be verified by researchers. Corellium starts throwing out dollar bills
[8]Apple responds to critics of CSAM scan plan with FAQs, says it'd block governments subverting its system
[9]Apple's iPhone computer vision has the potential to preserve privacy but also break it completely
Announced a fortnight ago, Apple's CSAM-probing technology looks for images that are uploaded from iPhones and iPads to iCloud backups; in other words, the vast majority of them. Billed as [10]a child safety initiative , the mass-scanning technology drew instant fury from civil rights advocates.
A closely related product being rolled out at the same time, known as "scan and alert," would tip off parents if their children's iThings received messages deemed explicit by an on-device machine-learning algorithm. The CDT [11]said in a statement: "The scan and alert feature in Messages could result in alerts that threaten the safety and wellbeing of some young people, and LGBTQ+ youths with unsympathetic parents are particularly at risk."
The CSAM-detecting system works by matching hashes of iCloud uploads with a secret database controlled by Apple, which is said to be populated by the US National Center for Missing and Exploited Children (NCMEC), an American equivalent of Britain's Child Exploitation and Online Protection (CEOP) police unit. Once a hash is matched, Apple says human moderators will review images before passing them to police.
[12]
Critics have said the hash-matching system is ripe for abuse by authoritarian governments looking to crack down on political dissidents sharing banned speech. Apple says it " [13]will refuse any such demands ." Adding fuel to the flames, NCMEC sent a memo to Apple, which was distributed among staff and subsequently leaked, telling the iGiant's engineers not to worry about the scanning technology's critics, described them as "the screeching voices of the minority."
Now infosec bods are [14]reverse-engineering the technology to see how it really ticks. If it can be shown that the image-matching algorithm can be fooled into flagging up an entirely innocent picture, such as via a hash collision, it will render the content-scanning tech of limited use for its stated purpose. ®
Get our [15]Tech Resources
[1] https://cdt.org/wp-content/uploads/2021/08/CDT-Coalition-ltr-to-Apple-19-August-2021.pdf
[2] https://www.theregister.com/2021/08/09/apple_csam_faq/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YR7UnZCeJW0mXzoPBVFf@gAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR7UnZCeJW0mXzoPBVFf@gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YR7UnZCeJW0mXzoPBVFf@gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/18/apples_csam_hashing/
[7] https://www.theregister.com/2021/08/17/corellium_apple_bounty/
[8] https://www.theregister.com/2021/08/09/apple_csam_faq/
[9] https://www.theregister.com/2021/08/16/ai_vision_apple/
[10] https://www.theregister.com/2021/08/09/apple_csam_faq/
[11] https://cdt.org/insights/international-coalition-calls-on-apple-to-abandon-plan-to-build-surveillance-capabilities-into-iphones-ipads-and-other-products/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR7UnZCeJW0mXzoPBVFf@gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2021/08/09/apple_csam_faq/
[14] https://www.theregister.com/2021/08/18/apples_csam_hashing/
[15] https://whitepapers.theregister.com/
Re: Apple has learned a lot from China
> I can't wait for the federal lawsuits that will be triggered by this moronic idea if Apple doesn't backtrack and forgets about it.
Hopefully before innocent lives are ruined
Re: Apple has learned a lot from China
Someone needs to tell the US that the US is not China.
"The idea of a private, constant, secret and for-profit US Department Of Suspicion"
How about a [1]not-for-profit group?
[1] https://seditionhunters.org/
"Now infosec bods are reverse-engineering the technology to see how it really ticks. If it can be shown that the image-matching algorithm can be fooled into flagging up an entirely innocent picture, such as via a hash collision, it will render the content-scanning tech of limited use for its stated purpose."
This article is slightly behind the Register article earlier today about someone already did that. It took less than a day after the public part of the algorithm was released.
Apple isn't this dumb. This is a 'think of the children' smokescreen to get us on the slippery slope that countries like the PRC are strong-arming them into, but trying to save face with this farce/smokescreen of a feature.
Finally
Seems like the crickets have finally been silenced.
It's good to hear that there are official entities raising shields against this egregious invasion of privacy.
Think of the children is a nice excuse - let's not push it too far.
Coming at this from the angle that Apple is pushing, I think everyone with a functioning, modern moral compass can agree that harming innocents—children or otherwise—is a Bad Thing. But I personally do not think it is or should be Apple's responsibility to become the Arbiter of All that is Good. Companies and governments should stay well away from private citizens, even if it means that Bad Things can potentially occur. In addition, I believe the protection of our youth should be the responsibility of the parent(s) and the community around them, not a faceless international megacorp using proven less-than-reliable automated detection methods.
I also have reservations with the idea that someone dumb enough to store such unmentionable, illegal files on their iCloud would also be the type to actually produce such content. How will it help law enforcement find and capture active producers? Will their technology even help stop the harm of children? Given the sensitive nature of the matter, I doubt we would ever know should the technology be utilized for real. And that makes it even less trustworthy.
Apple has learned a lot from China
Someone needs to tell Apple that the US is not China.
And no, I am not in the screeching minority - whatever that is. I do, however, have a brain. And so do many others.
The idea of a private, constant, secret and for-profit US Department Of Suspicion - which, in my view, is exactly what Apple is trying to become - just does not sit well with a lot of folks, myself included.
I can't wait for the federal lawsuits that will be triggered by this moronic idea if Apple doesn't backtrack and forgets about it.