Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

21–30 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#21

Earlier quoted context omitted.

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Not Cool, now we can enforce all kinds of arbitrary censorship on encrypted data. Be careful what you wish for.

Also, the Apple system allows for a way of verifying matches to screen for false positives which the encrypted approach would not.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#22
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning?

Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your thoughts/reasoning. I really did what to know what people thought about this in the context of an E2E iCloud-* and it's been hard to pick that out of all the other discussions.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#23
post #14

Earlier quoted context omitted.

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Are photos uploaded to iCloud encrypted client-side? I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA. These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.

> Are photos uploaded to iCloud encrypted client-side?

Well, I can share a link to them and others can see them, including anonymous users. Just leads me to believe that either they aren’t or if they are, they have the key.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#24
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

[deleted]

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#25
post #12
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#26
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Alternatively, someone could realize that existing CSAM that's so widespread it's in the database basically equals water under the bridge, whereas creating CSAM that isn't in the DB requires to harm more children.

Poverty and power imbalance is what harms children the most, by far. But we can't tackle that without stepping on the toes of greed, so we do circus instead.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#27
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…

I'd pick the latter. I doubt iCloud will ever be a zero-knowledge service.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#28
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…

Probably the latter, because frankly E2E encryption means very little to me when one end is the world's most powerful company.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#30
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?

Nobody does, but that's the current status-quo anyways. Almost every cloud-based service provider will do this anyways, Apple's only change is that they've moved their surveillance from their computers to mine. If I can't know how secure my phone is at all times, then I frankly can't feel comfortable using it.
Post reply on HN