Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At least part of the concern is that a hash collision is basically "cause" for Apple to then dump and begin manually (like, with humans) reviewing the contents of your device, all of which will be happening behind the closed doors of a private corporation, outside of any of the usual oversight or innocent-presumption mechanisms that come from it happening through the courts.

That, combined with a (pretty reasonable) expectation that the pool of sus hashes will greatly expand as law enforcement and others begin to understand what a convenient side-step this is for due process.



That is literally the status quo with every cloud service. Apple, unlike the others, has said that they will evaluate you on the basis of what’s included in the associated data of your safety voucher, and you can inspect those contents because they’re shipped in the client. Facebook, for all I know, might be calculating a child predator likelihood score on my account based on how often I look up my middle school ex-girlfriend on Instagram.

In addition, “pretty reasonable” is an opinion not fact. Where is the evidence that PhotoDNA hashes have been compromised in this way in the fifteen years they’ve been used?


I don't think we can just appeal to the status quo here and assume it's acceptable. There's a couple reasons.

First, how many people really understood this previously? Did society at large actually knowingly accept the current state of things, or did it just happen without most people realizing it? Even here on HN where we'd expect to find people way more knowledgeable about it than in general I'm not sure how well known it was about what was actually happening, though I'd assume most would be aware it was possible.

Secondly, there's a significant difference between your own device or Apple's server doing this. On the technical side of things, right now, it might not matter that much since it currently is limited to things you upload to iCloud. But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them.


If the problem is a lack of understanding of the status quo, then it isn't fair to criticize Apple alone. People ought to demand answers about the state of server-side scanning from Facebook and Microsoft and everyone else that employs PhotoDNA as well. The most popular article submitted to HN with "PhotoDNA" in the title garnered hardly any interest at all, even though someone there implied that a hash collision might be possible five years in advance.

https://news.ycombinator.com/item?id=11636502


> But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them.

This literally only works once you willing send photos to iCloud.


You can't buy a car in EU that doesn't have a sim card. All Tractors have a computer that locks out the machine if it doesn't like something and phones home. Almost every TV on sale is 'smart' and spies on what you are saying. Coffee machines, lights and toasters are now internet connected, and all of them send data to a server that will be scanning for the 'wrong' material. in 10 years there will be nowhere to hide.


> You can't buy a car in EU that doesn't have a sim card.

Wait, what?


Its used for an emergency rescue system, and i believe it's mandatory in all new cars

https://ec.europa.eu/transport/themes/its/road/action_plan/e...


Right. I mentioned that. It's still your own device doing it.

It's like announcing to your family member you're going to tell your neighbor you committed a crime and your family member turns you in first. Yeah, you could expect your neighbor to do the same, but are you really not going to feel any differently about the fact it was your family that turned you in?


For now. There is no technical hurdle preventing them from scanning everything locally and reporting back.


There wasn’t such a hurdle before or in the counterfactual where they built infrastructure to scan iCloud while also keeping iCloud Backups for every device.


I mean, that has always been the case. I'm not sure why there is so much paranoia over this hypothetical situation when this hypothetical has actually existed since the first iPhone shipped in 2007.


I don't understand technie people on HN being okay with apple breaching the spirit of the 4th amendment and becoming the FBI agent in your phone. Scanning the stuff in the cloud is one thing but this is crossing a line. I am shedding all my apple hardware over it. If you want to trust them fine but one day it will bite you on the ass.


For ideological consistency, are you dumping every service provider that scans the contents of your account and reports offending data to law enforcement?


What they would be reviewing would be scaled version of the specific photos that triggered the hash alert. It’s not a broad fishing expedition. There is no mechanism to start browsing the photos on your phone.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: