The Times Australia
The Times World News

.
The Times Real Estate

.

Apple can scan your photos for child abuse and still protect your privacy – if the company keeps its promises

  • Written by Mayank Varia, Research Associate Professor of Computer Science, Boston University

The proliferation of child sexual abuse material[1] on the internet is harrowing and sobering. Technology companies send tens of millions of reports per year[2] of these images to the nonprofit National Center for Missing and Exploited Children[3].

The way companies that provide cloud storage for your images usually detect child abuse material leaves you vulnerable to privacy violations by the companies – and hackers who break into their computers. On Aug. 5, 2021, Apple announced a new way to detect this material[4] that promises to better protect your privacy.

As a computer scientist[5] who studies cryptography, I can explain how Apple’s system works, why it’s an improvement, and why Apple needs to do more.

Who holds the key?

Digital files can be protected in a sort of virtual lockbox via encryption, which garbles a file so that it can be revealed, or decrypted, only by someone holding a secret key. Encryption is one of the best tools for protecting personal information as it traverses the internet.

Can a cloud service provider detect child abuse material if the photos are garbled using encryption? It depends on who holds the secret key.

Many cloud providers, including Apple, keep a copy of the secret key so they can assist you in data recovery[6] if you forget your password. With the key, the provider can also match[7] photos stored on the cloud against known child abuse images held by the National Center for Missing and Exploited Children.

But this convenience comes at a big cost. A cloud provider that stores secret keys might abuse its access[8] to your data[9] or fall prey to a data breach[10].

A better approach to online safety is end-to-end encryption[11], in which the secret key is stored only on your own computer, phone or tablet. In this case, the provider cannot decrypt your photos. Apple’s answer to checking for child abuse material that’s protected by end-to-end encryption is a new procedure in which the cloud service provider, meaning Apple, and your device perform the image matching together.

Spotting evidence without looking at it

Though that might sound like magic, with modern cryptography it’s actually possible to work with data that you cannot see. I have contributed to projects that use cryptography to measure the gender wage gap[12] without learning anyone’s salary[13], and to detect repeat offenders of sexual assault[14] without reading any victim’s report[15]. And there are many more examples[16] of companies and governments using cryptographically protected computing to provide services while safeguarding the underlying data.

Apple’s proposed image matching[17] on iCloud Photos uses cryptographically protected computing to scan photos without seeing them. It’s based on a tool called private set intersection[18] that has been studied by cryptographers since the 1980s. This tool allows two people to discover files that they have in common while hiding the rest.

Here’s how the image matching works. Apple distributes to everyone’s iPhone, iPad and Mac a database containing indecipherable encodings of known child abuse images. For each photo that you upload to iCloud, your device applies a digital fingerprint[19], called NeuralHash. The fingerprinting works even if someone makes small changes in a photo. Your device then creates a voucher for your photo that your device can’t understand, but that tells the server whether the uploaded photo matches child abuse material in the database.

a diagram with a representation of a smartphone and icons representing a photo and digital fingerprints Apple’s new system for comparing your photos with a database of known images of child abuse works on your device rather than on a server. courtesy Apple[20]

If enough vouchers from a device indicate matches to known child abuse images, the server learns the secret keys to decrypt all of the matching photos – but not the keys for other photos. Otherwise, the server cannot view any of your photos.

Having this matching procedure take place on your device can be better for your privacy than the previous methods, in which the matching takes place on a server – if it’s deployed properly. But that’s a big caveat.

Figuring out what could go wrong

There’s a line in the movie “Apollo 13”[21] in which Gene Kranz, played by Ed Harris, proclaims, “I don’t care what anything was designed to do. I care about what it can do!” Apple’s phone scanning technology is designed to protect privacy. Computer security and tech policy experts are trained to discover ways that a technology can be used, misused and abused, regardless of its creator’s intent. However, Apple’s announcement lacks information to analyze essential components[22], so it is not possible to evaluate the safety of its new system.

Security researchers need to see Apple’s code to validate that the device-assisted matching software is faithful to the design and doesn’t introduce errors. Researchers also must test whether it’s possible to fool Apple’s NeuralHash algorithm into changing fingerprints by making imperceptible changes to a photo[23].

It’s also important for Apple to develop an auditing policy to hold the company accountable for matching only child abuse images. The threat of mission creep was a risk even with server-based matching. The good news is that matching devices offers new opportunities to audit Apple’s actions because the encoded database binds Apple to a specific image set. Apple should allow everyone to check that they’ve received the same encoded database and third-party auditors to validate the images contained in this set. These public accountability goals can be achieved using cryptography[24].

Apple’s proposed image-matching technology has the potential to improve digital privacy and child safety, especially if Apple follows this move by giving iCloud end-to-end encryption[25]. But no technology on its own can fully answer complex social problems. All options for how to use encryption and image scanning have delicate, nuanced effects[26] on society.

These delicate questions require time and space to reason through potential consequences of even well-intentioned actions before deploying them, through dialogue[27] with affected groups and researchers with a wide variety of backgrounds. I urge Apple to join this dialogue so that the research community can collectively improve the safety and accountability of this new technology.

[The Conversation’s science, health and technology editors pick their favorite stories. Weekly on Wednesdays[28].]

References

  1. ^ child sexual abuse material (www.nytimes.com)
  2. ^ tens of millions of reports per year (www.missingkids.org)
  3. ^ National Center for Missing and Exploited Children (www.missingkids.org)
  4. ^ announced a new way to detect this material (www.apple.com)
  5. ^ computer scientist (scholar.google.com)
  6. ^ data recovery (support.apple.com)
  7. ^ the provider can also match (www.macobserver.com)
  8. ^ abuse its access (www.vice.com)
  9. ^ to your data (www.telegraph.co.uk)
  10. ^ data breach (epic.org)
  11. ^ end-to-end encryption (ssd.eff.org)
  12. ^ measure the gender wage gap (thebwwc.org)
  13. ^ without learning anyone’s salary (www.usenix.org)
  14. ^ detect repeat offenders of sexual assault (www.mycallisto.org)
  15. ^ without reading any victim’s report (static1.squarespace.com)
  16. ^ many more examples (drive.google.com)
  17. ^ Apple’s proposed image matching (www.apple.com)
  18. ^ private set intersection (blog.openmined.org)
  19. ^ applies a digital fingerprint (www.apple.com)
  20. ^ courtesy Apple (www.apple.com)
  21. ^ line in the movie “Apollo 13” (www.youtube.com)
  22. ^ lacks information to analyze essential components (twitter.com)
  23. ^ making imperceptible changes to a photo (twitter.com)
  24. ^ can be achieved using cryptography (www.bu.edu)
  25. ^ giving iCloud end-to-end encryption (www.reuters.com)
  26. ^ delicate, nuanced effects (mobile.twitter.com)
  27. ^ dialogue (cyber.fsi.stanford.edu)
  28. ^ Weekly on Wednesdays (theconversation.com)

Read more https://theconversation.com/apple-can-scan-your-photos-for-child-abuse-and-still-protect-your-privacy-if-the-company-keeps-its-promises-165785

The Times Features

Why Staying Safe at Home Is Easier Than You Think

Staying safe at home doesn’t have to be a daunting task. Many people think creating a secure living space is expensive or time-consuming, but that’s far from the truth. By focu...

Lauren’s Journey to a Healthier Life: How Being a Busy Mum and Supportive Wife Helped Her To Lose 51kg with The Lady Shake

For Lauren, the road to better health began with a small and simple but significant decision. As a busy wife and mother, she noticed her husband skipping breakfast and decided ...

How to Manage Debt During Retirement in Australia: Best Practices for Minimising Interest Payments

Managing debt during retirement is a critical step towards ensuring financial stability and peace of mind. Retirees in Australia face unique challenges, such as fixed income st...

hMPV may be spreading in China. Here’s what to know about this virus – and why it’s not cause for alarm

Five years on from the first news of COVID, recent reports[1] of an obscure respiratory virus in China may understandably raise concerns. Chinese authorities first issued warn...

Black Rock is a popular beachside suburb

Black Rock is indeed a popular beachside suburb, located in the southeastern suburbs of Melbourne, Victoria, Australia. It’s known for its stunning beaches, particularly Half M...

What factors affect whether or not a person is approved for a property loan

Several factors determine whether a person is approved for a real estate loan. These factors help lenders assess the borrower’s ability to repay the loan and the risk involved...

Times Magazine

What workers really think about workplace AI assistants

Imagine starting your workday with an AI assistant that not only helps you write emails[1] but also tracks your productivity[2], suggests breathing exercises[3], monitors your mood and stress levels[4] and summarises meetings[5]. This is not a f...

Aussies, Clear Out Old Phones –Turn Them into Cash Now!

Still, holding onto that old phone in your drawer? You’re not alone. Upgrading to the latest iPhone is exciting, but figuring out what to do with the old one can be a hassle. The good news? Your old iPhone isn’t just sitting there it’s potential ca...

Rain or Shine: Why Promotional Umbrellas Are a Must-Have for Aussie Brands

In Australia, where the weather can swing from scorching sun to sudden downpours, promotional umbrellas are more than just handy—they’re marketing gold. We specialise in providing wholesale custom umbrellas that combine function with branding power. ...

Why Should WACE Students Get a Tutor?

The Western Australian Certificate of Education (WACE) is completed by thousands of students in West Australia every year. Each year, the pressure increases for students to perform. Student anxiety is at an all time high so students are seeking suppo...

What Are the Risks of Hiring a Private Investigator

I’m a private investigator based in Melbourne, Australia. Being a Melbourne Pi always brings interesting clients throughout Melbourne. Many of these clients always ask me what the risks are of hiring a private investigator.  Legal Risks One of the ...

7 Reasons Why You Need to Hire an SEO Expert for Your Business

Ranking on Google isn’t just an option—it's essential for business success. Many businesses striving for online visibility often struggle to keep up with the complex and ever-changing world of search engine optimisation (SEO). Partnering with an SE...

LayBy Shopping