> As described here, the scanning only applies to images also uploaded to iCloud ("[the] algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system"). While we don't know whether this description is accurate, it suggests that if you don't back up images to iCloud your device won't do any scanning locally. Apple already has the keys to your iCloud backups, so if you value privacy you're probably not backing up to iCloud anyhow.
If we had a way to guarantee that it would stay that way, it'd be less concerning. As it stands, clearly there are plans to scan on the device itself, otherwise there would be no need to roll out software on iPhones at all.
> Hash collisions aside, this should only produce matches against images that are already in a government database. It will match manipulated images (e.g., rotated or cropped), but it won't match new images.
Agreed, but the issue is the government can stick whatever photos in the DB they want. And we have no way to verify what's in there, since they're not gonna release thousands of CP images for us to audit them.
> Apple has the control to do all sorts of invasive things to our privacy. They could be scanning and reporting all kinds of things already, and we might not even know. Or they could start doing so tomorrow. From this point of view we're already trusting them to do right by us as their customers, and this feature doesn't change that.
It changes plenty. Currently Apple more or less promises not to spy on you, and so they have to actually be lying to do so. Is lying an option for them? Sure, but that's different than them just announcing in advance "hey we're gonna start scanning every photo you have and crossreferencing against a somewhat-transformation-invariant secret government database". I'd prefer that they have to lie to me to spy on me, since that at least has the potential for backlash if discovered. If they get this feature rolled out we're all fucked.