frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: Codex Micro on Your Phone

https://github.com/maxxspotter/codex-micro-app
1•cvaman•1m ago•0 comments

Uhubctl – control USB power per-port on smart USB hubs

https://github.com/mvp/uhubctl
1•gregsadetsky•1m ago•0 comments

Don't Put an LLM Behind an MCP Server

https://www.spletzer.com/2026/07/dont-put-an-llm-behind-an-mcp-server/
1•opwizardx•2m ago•0 comments

I built a page that tells you what AI model your laptop can run

https://localsotabenchmark.engineersf.dev/
1•kumarski•2m ago•1 comments

Show HN: Exceltool.io – 120 free Excel tools, 100% private in the browser

https://www.exceltool.io
1•jamesweb•4m ago•0 comments

Debating the role of large language models in the kernel community

https://lwn.net/SubscriberLink/1083275/59c6c17c34db11d4/
2•jwilk•4m ago•0 comments

Sports solved a problem that nearly killed television

https://worksinprogress.co/issue/how-tv-learned-to-sell-itself/
1•n1b0m•4m ago•0 comments

Show HN: Turning a Dumb AC Unit Smart (Without Losing My Security Deposit)

https://prilik.com/blog/post/automating-ac-nyc/
1•daniel5151•5m ago•0 comments

Show HN: Hexagonal Game of Life Explorer

https://sidem.github.io/HexLife/
1•SciStone•7m ago•0 comments

Meta's AI Models Are Powering the First Wave of Genesis Mission Projects

https://ai.meta.com/blog/genesis-mission-lawrence-berkeley-national-laboratory-segment-anything-d...
3•surprisetalk•8m ago•0 comments

A private enterprise AI gateway

https://github.com/astaxie/TokenHub
1•astaxie•8m ago•0 comments

Cloudflare R2 is now Generally Available (2022)

https://blog.cloudflare.com/r2-ga/
1•tatersolid•8m ago•1 comments

The Download: Chinese AI divides the White House, and a record copyright payout

https://www.technologyreview.com/2026/07/21/1140685/the-download-chinese-ai-divides-white-house-a...
1•joozio•9m ago•0 comments

Show HN: QuantmLayer – kernel-enforced containment for AI coding agents

https://github.com/quantmlayer/quantmlayer
1•mquant•9m ago•0 comments

Devin Outposts: Run Devin sessions on your own infra

https://docs.devin.ai/cloud/outposts/overview
1•shenli3514•10m ago•0 comments

Canada's promises to capture carbon span almost 20 years, with little gains

https://thenarwhal.ca/canada-carbon-capture-history/
1•hn_acker•11m ago•0 comments

Iran's IRGC claims attack on Amazon's main data hub in Bahrain

https://www.euronews.com/2026/07/21/irans-irgc-claims-attack-on-amazons-main-data-hub-in-bahrain
1•r721•11m ago•0 comments

Yubikey 5.8: Verified Authorization for the New Era of Identity and AI

https://www.yubico.com/resource/whats-new-yubikey-5-8/
1•dblitt•11m ago•0 comments

Text as Music

https://www.jeravalue.com/en/text-music
1•speckx•12m ago•0 comments

Show HN: PMG, open source package firewall

https://github.com/safedep/pmg
1•abhisek•13m ago•0 comments

Show HN: OSS Cross-Harness self hosted registry and analytics for AI Agents

https://github.com/Observal/Observal
6•haz3-jolt•14m ago•0 comments

Show HN: Polymm – the Polymarket market-making bot behind my $5k wallet

https://github.com/kachence/polymm
2•kachoio•14m ago•1 comments

Stop funding data governance, run it with agents instead

https://futuregrade.substack.com/p/stop-funding-data-governance-start
2•mario_mh•15m ago•0 comments

Regular Expressions for Hcpcs Codes

https://www.johndcook.com/blog/2026/07/17/regular-expressions-for-hcpcs-codes/
2•ibobev•15m ago•0 comments

Locally everywhere does not imply everywhere

https://www.johndcook.com/blog/2026/07/21/jacobian-conjecture/
1•ibobev•15m ago•0 comments

Martin Picard's Mitochondrial Theory of Mind

https://www.quantamagazine.org/martin-picards-mitochondrial-theory-of-mind-20260717/
1•ibobev•15m ago•0 comments

FBI Forced to Reveal New Details on How It Redacted Epstein Files

https://newrepublic.com/post/212994/fbi-reveal-redacted-epstein-files-foia
5•hn_acker•17m ago•0 comments

What Modern NVMe Storage Can Do, and How to Exploit It [pdf]

https://www.vldb.org/pvldb/vol16/p2090-haas.pdf
1•rbanffy•18m ago•0 comments

Android 17 desktop also runs the Linux desktop

https://www.youtube.com/watch?v=LD9A024yAgc
2•Vasant1234•18m ago•1 comments

On Building Daily Puzzles, On Ending Them, and Other Thoughts

https://dailybaffle.com/on-ending-morphology
2•windowshopping•19m ago•0 comments
Open in hackernews

Apple Defeats Liability for Not Scanning iCloud for CSAM

https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm
162•speckx•2h ago

Comments

jobs_throwaway•2h ago
A win for privacy and freedom
hosteur•2h ago
Indeed. And a rare one at that.
amazingamazing•2h ago
It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level.

Apple could easily not do this stuff and it may even be easier to not.

cryo32•1h ago
Indeed.

But they are until they are actually defeated. I would rather plan for failure. We are in a global climate where court rulings can be ignored.

avidiax•1h ago
> It is crazy people think apple isnt on the side of privacy.

> It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.

I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare quotes there because I don't think that political or religious dissidents would find that the same or similar technology used to discover and persecute them is "privacy preserving". And that's really the problem with Apple here. They provided a model for scanning for any kind of message or material while purportedly maintaining privacy.

mmmlinux•1h ago
Is it different than telling your therapist something in confidence and then finding police waiting for you in the lobby.
arcticbull•1h ago
Yes, in the sense that you have a legal doctor-patient privilege that binds what they can share with whom. There's not really an Apple cloud user privilege.

No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

busterarm•47m ago
> No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

And therapists are legally mandated to report you if you told them you viewed or possessed CSAM.

Dylan16807
LatencyKills•1h ago
I was an engineer at both MS and Apple. At Apple, privacy was baked into every new feature from the start. At MS, the privacy component was glued on at the very end, if ever.

Like OP said, Apple isn't perfect nor will they ever be, but they do prioritize privacy better than most.

an0malous•1h ago
I said this in another thread a while ago, and one of these people who thinks Apple isn’t on the side of privacy cited a lawsuit they settled around Siri listened to conversations: https://www.scientificamerican.com/article/apple-settles-cla...

People understood this settlement to mean Apple was spying on their conversations and selling them to advertisers, when it seems to have more to do with people accidentally triggering Siri. But people don’t care about this kind of nuance or actually tallying up all the ways Apple is pro privacy against rare issues like this one. It’s all just tribalism at the end of the day.

fsflover•1h ago
Apple is on the side of privacy, except when you want privacy from Apple:

Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)

161 points by Logans_Run on Feb 14, 2025 | 69 comments

https://news.ycombinator.com/item?id=43047952

Apple silently uploads your passwords and keeps them (lapcatsoftware.com)

170 points by ingve on Nov 1, 2024 | 127 comments

And whenever your privacy contradicts their control over "your" device, you are also out of luck, e.g., you can't have Ublock Origin on an iPhone. Relevant discussion: https://news.ycombinator.com/item?id=44804921

dd8601fn•1h ago
It's telling that these come from people trying to implement tracking and high visibility into user behavior, and complaining that Apple won't let them even though Apple conceptually could.

Except ublock, which can't do what it does the way it normally does, for the same reason you can't have any plugin inspecting realtime activity and doing scriptlet injection.

You can have ad blocking. You can't have plugins with that kind of low level access to your browser activity.

You can prefer something that allows dangerous behavior as a trade-off for greater capabilities, but you can't deny it's a safety trade-off where Apple picked what's safer.

anon7000•1h ago
Yep, and if you want good Adblock on iPhone use Wipr.
SXX•1h ago
Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

At least on Desktop we have usable Linux, but on the phones there is literally nothing usable because thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

Yes its possible to make Andoid spy on you a little less, but even for tech savvy person its damn inconvinient and Google making platform worse with every single release.

Thanks to Google "security" I can use my banking apps on 9 years old device with 6 years outdated firmware, but not on GrapheneOS.

Cider9986•50m ago
> Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

They probably use E2EE just so they don't have to respond to court orders and such.

Pfhortune•25m ago
> hanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

I've been using GrapheneOS for years and that hasn't been my experience. There are two financial apps that don't work for me, and that's it. Pretty much everything else I use is fine. But, to be fair, I'm very scrupulous about my apps and tend to avoid installing an app for every little thing that wants me to.

amelius•59m ago
Apple may be on the side of privacy, but since they are competing everybody out of the market with their slick consumer products they actually form a threat to privacy since now the government has to only implement a backdoor at one vendor.
macintux•47m ago
I have a suspicion that Google and Android aren't going to just vanish.
goolz•47m ago
It is crazy that I do not trust a multi-trillion dollar company who has forced labor in their supply chain to have my best interests in mind? It is crazy to me you would think they do not understand the concept of lip service.

These companies are liars. I do not trust liars. It has served me well.

mikenew•45m ago
Apple is on the side of privacy if it serves their marketing. Which is why they would rather build and normalize CLIENT SIDE CONTENT SCANNING so they can continue to market iCloud as "secure and private".

If Apple's interests sometimes align with ours then great. I'll take it. But don't attribute to this ~5 trillion dollar company some kind of altruism.

Isamu•24m ago
Privacy is a natural fit for Apple in that they make money on discrete devices, but services have grown tremendously. That’s where the erosion of privacy happens.

So once there’s a profit motive for violating your privacy, the justification for eroding your privacy will proceed. It’s really the inertia of Apple starting out as privacy-compatible that makes them hesitant to throw that away.

i3ima•2h ago
the judge is indeed wise
JSR_FDED•1h ago
The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections.

As sad as this is, end to end encryption means no CSAM scanning.

As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too.

This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

al_borland•1h ago
Children are often used as a weapon to erode freedoms, like privacy and speech. Those pushing it rarely actually care about the children.
layer8•1h ago
While I’m decidedly pro-encryption, I don’t like this argument. If something is the right thing, it would still be the right thing when promoted for the wrong reasons, and if it’s the wrong thing, it’s still the wrong thing even when at present nobody has ulterior motives.

When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.

ajsnigrutin•1h ago
So invading the privacy of millions of people, even if it's just automatic scans for some specific thing is a right thing? Does this apply to mandatory drug tests for everyone everywhere? How about drug and weapon seeking drones, doing daily checks in every apartment everywhere? How about mandatory AI powered microphones everywhere that would detect threats, blackmail, any talk about anything illegal, etc.?

If you take a 1000 random people of the street now,how many of them are sharing CSAM via icloud?

If you take a 1000 random politicians, how many of them have corruption scandals? Why not start with them instead, a bodycam and an AI powered microphone that would detect corruption automatically... let them lead as an example, before they apply the laws onto "the rest of us".

twuopf•1h ago
I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me

The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen.

The criminal and disgusting tail end of this type of material deserves the worst of consequences for the perpetrators and all the support in the world for the victims, but these are mostly - you guessed it - poor and unprivileged children from far away places and they certainly can’t put this much pressure on apple

alistairSH•1h ago
Do you have a citation for that? Sounds plausible, but I'm not sure I've ever seen it stated that way in any of the related media reports on CSAM efforts.
mschuster91•1h ago
In Germany, the rise in "youth porn" material has been attributed to such kinds of cases where youth send intimate pictures to each other [1].

Our legal systems are not built to deal with that mess, and it may hang around your neck for the rest of your life. Unfortunately, the law is very explicit, leaving barely any avenue for the courts to drag us out of the mess, and politicians - even if they are actually interested in the topic in the first place - won't touch that area with a ten foot pole for fear of getting blamed a pedophile themselves.

[1] https://www.n-tv.de/panorama/KI-treibt-Jugendporno-Fallzahle...

aljgz•1h ago
Are there statistics backing up the "VAST" majority claim?

While on statistics, I wonder, are there reliable statistics about child abuse of different types? Studying correlations with other social metrics, like sex education, liberal/conservative, policies regarding prostitution, and others can provide support for/against decisions.

Not that I hope these will impact people's and governments' choices, but I want to challenge my intuitions.

m3kw9•1h ago
If these judges are so righteous, they should go further and mandate the OS to do mandatory scanning of personal hd.
dilap•1h ago
Don't worry, we'll get there soon enough.
stronglikedan•1h ago
It's still a shade of gray to me. If I offered some homegrown cloud storage to my friends, and one of them uploaded CSAM to it, you can bet your ass that I would be arrested for it.
polski-g•1h ago
Does Sundar get arrested if someone uploaded CSAM to GDrive?
izacus•39m ago
No, because Google will report it to the law enforcement.
majorchord•1h ago
IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.

Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.

megous•1h ago
There's no issue with mega. There are third party apps and as long as you don't login to mega.nz with their website you're fine. And they also have SDK you can use that they'll not be able to control/manipulate without your knowledge.
kyralis•1h ago
This is based on a faulty understanding of the underlying systems. The risk with this sort of E2E encryption is not that the service provider pinky promises not to decrypt what they have, it's that they promise they will not insert a new key into your circle of trust to subsequently start decrypting things.
IshKebab•32m ago
I think you've imagined this faulty understanding. There are many mechanisms by which Apple could actually decrypt the data despite pinky promises not to. You listed one. There are others.
slashdave•1h ago
Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion).

If the company is misleading, any encryption technology is irrelevant anyway.

St0n3d•1h ago
“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)

kyralis•1h ago
Also, Apple's E2E iCloud encryption vastly predated the NeuralHash efforts.
drnick1•1h ago
I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are created, for their own good, of course.
slashdave•1h ago
> most people don't need cloud backups

What world do you live in?

drnick1•1h ago
The world where the operating system on my phone (GrapheneOS) isn't conspiring against me or uploading my files to someone else's computer.
slashdave•1h ago
That must also be the world where more than a tiny number of people are using GrapheneOS
yoz-y•48m ago
Everybody needs cloud backups for their photos at least.

Most people don’t have computers, those who do, do not regularly backup their photos on them.

In both family and extended family many a cry would be avoided if people paid the 5 bucks it costs to backup their photos before your phone gets stolen or lost.

poolnoodle•
djoldman•1h ago
I am not a lawyer.

There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example:

  * A: physical sexual abuse of children. B: possession or distribution of CSAM
  * A: drug trafficking or tax evasion. B: structured cash withdrawals
The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A.

It's my understanding that conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person: one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

It's my understanding that one can be convicted of structured withdrawals that are not driven by, linked to, or in any way related to anything nefarious.

joshred•1h ago
I don't think these are the same. Outlawing CSAM gives law enforcement the ability to shutdown markets and prevent commercial distribution of CSAM. Sexually abusing children is heinous, but sexually abusing children for financial gain is even worse.
carljungslabtek•52m ago
There are even people involved in commercial distribution of it that claim to not even be interested in children, just in profit or even allegedly “for a sense of community” (someone actually said this after getting caught, he was in his 20s but I can’t remember his name — he might have been one of the red room guys).

On top of that, while there are different types of child abusers, the worst ones almost invariantly collect CSAM to the point of hoarding. So it really isn’t that bad of a proxy.

The root comment is implying that legalizing or decriminalizing csam would somehow help with prosecution of child abuse? I’m kind of speechless. Csam IS child abuse. The fact that there are consumers encourages producers to, well, produce!

IncreasePosts•
wbl•1h ago
IANAL but I thought the whole reason scanning worked was it wasn't required so there weren't fourth amendment issues.
quaddoggy•1h ago
Ah, the CSAM saga. Very poorly handled by Apple. Suspect it may have taken Hair Force One off the shortlist of CEO succession.
economistbob•1h ago
Seems like the kids miss their chance at justice because of section 230 allowing platforms the freedom to remove whatever they want but not be responsible for what they keep or amplify. That is the problem with 230. Censorship is permitted and punishing the censor isn't. Twitter and Tiktok are literally microblog platforms that get away with removing good stuff and leaving evil because they "are not a publisher" while the algorithm literally publishes a chosen set of articles to people. Facebook can remove religious freedom material and leave human trafficking groups. Section 230 gives the publishers the cake and the edict too.
junon•40m ago
You're conflating "what's illegal" with "what a private entity doesn't want". I don't like it any more than you do, but the first is very clear, the second is a bit harder to "solve".
•
42m ago
No matter how or why? That seems like a terrible mandate.
busterarm•35m ago
> No matter how or why? That seems like a terrible mandate.

Honestly shocked that anyone would even say this, but even giving you the benefit of the doubt here -- the one case where I could imagine this might not happen would be if you're a police officer investigating such cases. But they also have their own therapists dedicated/trained in police-specific issues.

Dylan16807•20m ago
Even if someone went browsing for it, yes that's illegal but there's no benefit in their therapist reporting them for just visiting terrible websites.

But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.

AlexandrB•11m ago
A better analogy is a storage locker. AFAIK police need a warrant to search "your" storage locker even though it's on someone else's property. I don't see why data in the cloud should be any different. Pre-emptively scanning everyone's data is equivalent to officers rummaging through all the storage lockers in a facility "just in case" they find something illegal.
bayindirh•1h ago
> It proved that it was technically feasible, and was "privacy preserving".

Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?

If not, I'll happily stand corrected, but please share sources.

Addenda:

- Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...

- Paper breaking the hash: https://arxiv.org/abs/2111.06628

yogorenapan•26m ago
> to reveal blurred version of the images being hashed

Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.

So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.

I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have

comex•23m ago
The paper you linked doesn’t reveal blurred versions of the images being hashed. It does train a classifier to determine which of 1,000 ImageNet classes an image belongs to, which “achieved a top-1 test accuracy of 4.34%”.
trollbridge•1h ago
I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help.

Very different than trying to narc out users to the authorities.

pavon•1h ago
That is what they actually deployed. They were planning on performing client-side scanning of all images uploaded to iCloud for CSAM and reporting it to the authorities, but backpedaled after public push-back.
FireBeyond•24m ago
I still also totally don't get their policy.

Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines:

"Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

xphos•6m ago
Imagine you have pictures of someones baptism and the kid was nude. Is it CSAM? I think the program would have to say use but morally I'd say no. The issue with client scanning is it has to assume the worst, or they are than liable. If its the person has 20+ different baptism of nude babys well huh that actually might be CSAM because the context of how that concentrated photos implies but even than its hard what if that person actually has 20 God Children its less crazy than one thinks... Especially if they have multiply phones from a single baptism.

You might not like pictures that way but honestly I think more important in procescuting CSAM is to go after the large sources of CSAM generation. Its trafficing in East Asia, and in Europe. I think weirdly America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures. Abuse definitely happens in the US but making policy decisions like this produces bad policy.

Does iCloud rehost the photos to other people I don't really know because I use andriod tbh. If they are being rehosted (I assume to members of your contacts) that can be problematic but I think honestly the issue a lot more complex than just protect the children which the source of critic is a lot attacks against apples are coming from

layer8•1h ago
You misread what I wrote. My comment is against the argument used, not against what is being argued for. Using the wrong argument diminishes one’s position. I’d prefer the stance against surveillance to not be diminished by such arguments.
al_borland•46m ago
Calling out the ulterior motives can help clear the deck to focus on what is right or wrong, without as much emotional manipulation in the picture.
layer8•39m ago
One problem with that is that it’s difficult to prove motives. So you’re on shaky and disputable ground. It’s much better to point out how the proposed mechanisms are prone to be misused, which is independent of current motives. Get rid of the shaky ground. Saying “these are disingenuous people proposing this” is exactly an attempt at emotional manipulation, in the sense of an ad hominem fallacy.
majorchord•1h ago
> As sad as this is, end to end encryption means no CSAM scanning.

I think it depends on your definition of e2ee and where the "end"s are.

If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?

cortesoft•1h ago
The locally running application is one of the 'ends' of the end to end encryption.
majorchord•1h ago
Then in that case I think the previous statement of "end to end encryption means no CSAM scanning" would be false.
megous•1h ago
I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever.

It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing.

They could do it when people are not at home. There'd no problem, nobody would even notice.

kthinckley•1h ago
have you lost your mind?! I really hope you are joking, if not, you are a truly a sick individual
Terr_•1h ago
They are being sarcastic.
eagle2com•1h ago
It is drowning in sarcasm, so I would say yes, it is a joke.
theoreticalmal•1h ago
The comment above is illustrating why the judge’s decision would be silly in another circumstance. And if it’s silly in that circumstance, it’s silly in the judge’s circumstance as well.
slashdave•1h ago
Kind of a bad analogy (not service related, no associated liability).

A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?

pantalaimon•5m ago
> Can the landlord randomly check for criminal behavior?

Absolutely not.

an0malous•1h ago
-
semiquaver•1h ago
The judge’s dicta about protecting children in her pro-privacy ruling upholding existing law “tips their hand” that they are somehow part of a global conspiracy to eliminate privacy?

I think your conspiracy theory needs work, to be perfectly honest with you.

0cf8612b2e1e•1h ago
People can also distribute heinous things through snail mail, but we are not yet at the point where the government reads all letters looking for wrongthink.

Just because we technically can make a privacy destroying drag net does not mean we should. Had phones existed 250 years ago, I have no doubt the founders would have thought it obvious that a cellphone’s contents were your personal papers which could not be freely searched.

ajsnigrutin•1h ago
More effort should be done to find real-world equivalents of such actions and "think of the children".

An icloud is like a storage locker or a safety deposit box... the owner should go through all your stuff there, just in case you have some CSAM!

Metadata is just tracking info about who, where and with whom... every bartender should take your IDs and log when you came to the bar, who you sat with and how long you talked there.

EU Chat control is like general eavesdropping... every time you sit down and talk with someone, an EU bureaucrat should sit next to you and listen and write down your conversations, just in case.

etc.

Somehow people think that "it's ok if it's on the internet", even when it's stuff they'd never accept in real life.

timcambrant•54m ago
But that's mostly because it's impractical. They do use dogs to sniff for drugs and explosives, so if CSAM smelled or was visible through X-ray then it would probably be a different story. And let's not forget snail mail is by far a more uncommon way to spread that material than the Internet is. The Internet came into broad use just ~15 years after commercial CSAM was openly being sold by mail order in Europe.

Personally, I am on the side of privacy, just to be clear.

projektfu•36m ago
If East Germany can, why can't we? /s
slashdave•1h ago
> end to end encryption means no CSAM scanning

Not true. There is the option of scanning on the device.

yason•42m ago
Owning your device (instead of the manufacturer, a set of unlisted governments, big software corporations, etc.) means no scanning.
pantalaimon•6m ago
It also means no banking app will work
SepiaSapient•14m ago
Truly being honest, I think CSAM scanning of private comms is ineffective in the long term anyways. Pedophiles aren't stupid, you'll drag a bunch at first but the networks will be reestablished and sharing will be done via sneakernet.

The primary focus should always in preventing the creation of CSAM.

- Comprehensive Sex Ed starting young so kids can identify grooming and seek help from a trusted adult, even if abuse comes from a family member.

- Fixing schools in general so homeschooling isn't as attractive for parents. Keep a tab on home schooled children and identify social isolation.

- Bigger resources for actual honest to god on the ground investigations.

To be clear I'm not saying that homeschooling = child abuse, simply there's a lack of the mechanisms to detect it in homeschooling settings.

mrkeen•1h ago
That's the fun of it. Try to find out? Straight to prison.
aljgz•11m ago
Really sad. I read a lot of psychology. But I've never encountered psychology of child sexual abuse (I know there is if I look it up, but that's my point, it should be shared around, discussed, challenged).

Why would some adults find kids sexually attractive? Is it abusive/aggressive behavior manifesting itself in sexuality? Or is it sexuality channeled in the wrong direction? If it's the second, is it out of desperation, and would happen less if the culture makes it easier for them to satisfy their needs with adults, or would it happen regardless? On the victim's side, are the shy and less social ones more in danger, or the socially active ones? From my social scientist friends I hear a lot that most child sexual abuse is domestic. What are measures that a society can take to prevent these, without turning the society into a surveillance state, which will ultimately harm everyone more, including the children? What can be done to make sure children speak up, so that such behavior is dealt with at the beginning (and maybe while the more terrible things have not happened yet), and not turn into a multi-year childhood trauma?

What are signs (and early signs) on the abuser's side and the child's side? How to deal with these signs?

IshKebab•26m ago
It's probably impossible to get reliable statistics about that given how both groups are trying to keep everything secret. But you can consider how many paedophiles there are vs how many horny teenagers there are. Based on that it would be extremely surprising if he was wrong.

The real question is what happens when a horny teenager sends another a nude. There definitely have been insane cases where they get stitched up for creating child porn. I don't know if that's the normal outcome today though.

majorchord•1h ago
Children cannot legally consent to most things in most places, especially until near the end of their teen years.
pixel_popping•1h ago
They can't consent but it does make sense that it's true, I would genuinely bet that more nudes are being shared between 17-year olds than some freak, as this is common to the point where I feel a very large portion of all existing teens have done it.
intrasight•1h ago
In the near future, when a 17 year old asks her phone to take a nude selfie, the phone will say "no".
pixel_popping•16m ago
It wouldn't be so bad tbh, would avoid all the leaks and regrets that comes with it. In term of awareness, I would say that a late teen is fully aware of his/her actions but might not calculate consequences properly.
kstrauser•1h ago
I think you’re right, but from another angle. In the state where I lived way back when, a state representative put forth a bill to explicitly make e-CSAM illegal. I guess it was already illegal for print media and this covered a gap in the law about cell phone pics, etc. Thing is, it had no allowance for the age of the picture taker, or even whether the picture taker was the photo subject. If a 16 year old girl took a nude selfie and sent it to her boyfriend, she was a felon.

I wrote to the rep and explained my concerns. I wholeheartedly agreed with the intent of the law, but the code was buggy. To my surprise, he wrote back in horror to say he hadn’t considered that and pulled the bill immediately. I’m proud of having done that.

I’m 100% pro yeeting child pornographers into the sun. I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.

Aurornis•1h ago
The proposed CSAM scanning used perceptual hashing to try to identify CSAM material known to law enforcement.

It was not a tool to identify private images as being underage. That’s an impossible task.

trollbridge•1h ago
I'd say modern AI tools could probably do this pretty effectively. They're very effective at describing anything else about an image. I have a workflow that churns through large amounts of images, describes them, and then looks for things I specifically want (in my case, auction listings that are not described accurately on the auction website).
philipkglass•38m ago
I need to process a modest amount of imagery (about 25 million images, and growing) for NSFW content and general captioning/description. About 5% of it contains nudity or partial nudity, and about 20% of that 5% contains sexual activity.

In theory, modern vision language models could classify human nudity and sexual activity very thoroughly. But every model I have tried is reluctant to clearly describe what is notable about sexualized/nude images. The models are deliberately under-exposed to nude and sexualized content during training and further RLHF'd away from generating straightforward descriptions of such images.

Models also occasionally hallucinate WTF captions for ordinary adult sexual activity. I recently ran a baseline test with frames extracted from adult videos and about 1/3000 of them was mis-captioned as involving a child according to Gemma 4 12b.

cortesoft•58m ago
It's impossible to do with perfect accuracy, but that doesn't mean it isn't done.

Just ask the dad who was investigated for taking pictures of his toddler for the doctor: https://www.koffellaw.com/blog/google-ai-technology-flags-da...

dfxm12•1h ago
I won't pretend to be so knowledgeable about how so much CSAM is being created, but keep in mind, there are laws against distribution & mere possession, too. Revenge porn is an obvious thing to be mindful of in this context in addition to other types of distribution. Consent to create doesn't imply consent to distribute (probably even to cloud storage) & is completely immaterial to issues of possession if it ends up in some 3rd party's hands. So the scope goes way wider than you're letting on. If you're saying all of these these laws are being abused, like they exist primarily to punish a state senator's daughter's ex-boyfriend, I would ask for something to back that up.

Yes, poor and unprivileged children can't really defend themselves here, but this is the system working to find some legal mechanism to do what it can, as a more powerful force. Protecting people from exploitation is a good use of government. If this was shot down for legal reasons, OK, the system is working and I hope there is a way to expand protections that fits into our system.

IshKebab•30m ago
Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you.

That's obviously only the case if they aren't also the sole providers of the "ends".

SepiaSapient•1h ago
Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere.

Sure, the NSA, GCHQ and Mossad have a way to get the encrypted data by a sidechannel but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOSSAD’ED UPON"[0]. This is specially good for me because I know the equivalent to the FBI where is live is too cheap to buy a Cellebrite [1] license.

[0] https://www.usenix.org/system/files/1401_08-12_mickens.pdf [1] https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...

EDIT: I suppose someone could ask about Meta. The reason behind their support for scanning (and removing e2e in facebook msg) is simply regulatory capture. The zucc wishes to have a letter of marque to "protect" your children and remove the "unsafe" competitors.

21m ago
I gotta say handling my ever growing photo collection is a pain in the ass but I'm just not okay with uploading it to some server I don't control.
51m ago
There's also the argument that CSAM can act as a gateway leading people from just being a pedophile in their head, to going out and doing something to some child.
MichaelDickens•13m ago
Yes, this is an argument that exists. But it's not supported by evidence. It's the same as the old "video game violence should be outlawed because it might cause real violence", which is just as unsubstantiated.
pembrook•13m ago
Yes, it’s an argument but there’s zero data to support it, in fact the opposite.

If this were true then widespread availability of pornography on the internet would have resulted in a massive increase in rape of adult females. When in fact, assault numbers have been on a steady decline for decades.

goalieca•1h ago
Our society is pretty aligned that distribution is another kind of harm. Non-consented distribution of sexual images (eg: revenge porn) is also a crime. Children don’t need to be the ones to press charges in child porn unlike with adults. That’s a good thing.
ux266478•58m ago
> Our society is pretty aligned that distribution is another kind of harm.

As well as possession. I don't actually know if those are different for CSAM, but I would assume so because they are for drugs.

ux266478•1h ago
> one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

This isn't necessarily the case in the US, though I believe only for drawings. AI-generated CSAM probably wouldn't fly in a court of law.

Regardless, it's a naive conception of a system of law to think of it as a utilitarian system of restitution in contexts of "this individual harmed this individual". In fact, that would fall under the category of a "tort" rather than a "crime". The law is just as much about enforcing social mores and norms as it is about dealing with individuals harming each other. Hence why locales like Canada outlaw all forms CSAM, even fictional ones. The victim taken is to be society itself. The possession of this material, implicitly entailing enjoyment of it, is so gross a violation of society's norms and mores that it becomes elevated to a legal matter.

voxic11•52m ago
For drawings it has to additionally be "obscene" (since obscenity isn't protected by the first amendment). And there is also a specific law that criminalizes even non-obscene realistic computer generated imagery.
Manuel_D•38m ago
Not quite. There can be more restrictions on the distribution or promotion of obscene material, but mere possession of obscene material is protected by the first Amendment: https://en.wikipedia.org/wiki/Stanley_v._Georgia

The reason why the Supreme Court upheld bans on possessing CSAM is not because it's obscene, but because it incentivizes abuse of children to produce it.

voxic11•12m ago
Stanley v. Georgia considered the question from the right to privacy side, not the first amendment. The relevant cases are https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit... and United States v. Williams https://en.wikipedia.org/wiki/PROTECT_Act_of_2003#Supreme_Co...
afarah1•10m ago
>The victim taken is to be society itself. [...] a violation of society's norms and mores that it becomes elevated to a legal matter

Sounds a lot like what an authoritarian society, driven e.g. by a conservative religion would look like. Something closer to the alternative you dismiss as naive sounds a lot more just to me.

engeljohnb•6m ago
> The law is just as much about enforcing social mores and norms

This shouldn't be the case in a society that supposedly values liberty.

pushcx•52m ago
No. In short, in US law, CSAM is a visual depiction of a real-world act of child sexual abuse. Visual depictions like you're describing are covered under a different law, and I'm not aware of it having a short name. There's a good expert thread on this with links to the relevant federal laws here: https://bsky.app/profile/rahaeli.bsky.social/post/3lbt7zkvlq...
Manuel_D•51m ago
At least in the US, fictional content is legal even if it depicts minors sexually: https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit...

There have been a handful of convictions based on fictional content, but usually the defendants also possessed real CSAM so there wasn't much point in contesting the charges over fictional images.

kimjune01•16m ago
a 17 year old can take a nude selfie and be charged as an adult in possession of CSAM