Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

11–20 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#11
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers.

Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#12
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#13
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Not Cool, now we can enforce all kinds of arbitrary censorship on encrypted data. Be careful what you wish for.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#14
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Are photos uploaded to iCloud encrypted client-side?

I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA.

These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#15
post #5

Good to get these reminders that our data is in fact not private and that our computers have other owners than us..

Open source hardware and software is the only sustainable path forward. Perhaps that DIY processor fab discussion is worth a re-read. Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208 HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315

https://www.crowdsupply.com/sutajio-kosagi/precursor

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#17

"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.

I've honestly always interpreted their privacy activism that way. Apple acts as the warden of your data. Backups are encrypted for your privacy, but they hold a copy of the key. Traffic is obfuscated through fake Tor, but they manage the network. iMessage seems safe enough, but the source code is tightly sealed away, only accessible to Apple's eyes. It's still a valid way to advertise the company because I trust Appl…

Well said, appreciate the long term perspective and summary of what you see across backups, fake Tor, and closed source iMessage.

Good point about changing of Apple leadership. Tim Cook has said that 10 years from now he won't be the Apple CEO. That means someone new is coming in.

I purchased a Linux-first System76 laptop and will switch out my other iDevices. It's not just about Apple - any sort of closed source software/hardware just seems unsustainable long term. Having "trust" in organizations seems misplaced.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#18

Earlier quoted context omitted.

Open source hardware and software is the only sustainable path forward. Perhaps that DIY processor fab discussion is worth a re-read. Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208 HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315

https://www.crowdsupply.com/sutajio-kosagi/precursor

Everything Sutajio Kosagi puts out is high quality and a futuristic.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#19
post #12
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

You might find this helpful in your search -- HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#20
post #14

Earlier quoted context omitted.

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Are photos uploaded to iCloud encrypted client-side? I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA. These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.

Yes, they’re encrypted client-side, then unencrypted in browser. This is relatively easy to verify if you do not trust an anonymous comment, and I suggest you do so.
Post reply on HN