Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

31–40 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#31
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?

Yeah, I don't get the cloud/device distinction people are making. Increasingly they are one and the same (if you know what I mean).

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#32

Earlier quoted context omitted.

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Alternatively, someone could realize that existing CSAM that's so widespread it's in the database basically equals water under the bridge, whereas creating CSAM that isn't in the DB requires to harm more children. Poverty and power imbalance is what harms children the most, by far. But we can't tackle that without stepping on the toes of greed, so we do circus instead.

You say water under the bridge, others will say where there's smoke there's fire.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#33
post #12
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

My pre-owned Pixel arrives tomorrow and I'm looking forward to playing around with open-source alternatives. I think I'm going to start with this: https://lineage.microg.org/

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#34
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…

I'd happily pick cloud based scanning. At least that way I can opt out by not using their cloud. I have serious doubts that choosing not to use iCloud will actually stop Apple from running scanning code on my device. Having a capability pretty much ensures that it will be used, and likely misused.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#35

"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.

I've honestly always interpreted their privacy activism that way. Apple acts as the warden of your data. Backups are encrypted for your privacy, but they hold a copy of the key. Traffic is obfuscated through fake Tor, but they manage the network. iMessage seems safe enough, but the source code is tightly sealed away, only accessible to Apple's eyes. It's still a valid way to advertise the company because I trust Appl…

More than "the customer", Apple is, in the end, beholden to government and its laws, whims, etc.

Until a company is more powerful than the government I'm not sure how anyone can have an absolute assurance of privacy from a corporation.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#36

Earlier quoted context omitted.

No. https://apnews.com/article/fact-checking-369404345862

[flagged]

Not sure why you're being downvoted when this is a proven privacy issue. It's not about democrats v. republicans or iPhone vs Android, it's about our leadership as a whole, and what kinds of powers they have. The fact that our government even has access to our private communications should feel like a conflict of interests, especially in a nation that prides itself on freedom.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#37
post #8

Earlier quoted context omitted.

Open source hardware and software is the only sustainable path forward. Perhaps that DIY processor fab discussion is worth a re-read. Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208 HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315

I mean what if apples search decides that I am suspicious? Will they unlock my keychain and give all my logins to some police or worse random people somewhere to check my stuff? Very disappointing indeed

I don't believe Apple can unlock your Keychain. It requires your biometric (touch/face) to unlock from the Secure Enclave.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#38
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…

My house shouldn't be full of eyes and ears.

CSAM today, political materials another. This could also be used to identify whistle blowers, reporters' sources, and more.

I'd hate to have gay porn on my iPhone in a Sharia law state.

Or images of tank man in mainland China.

Imagine when the detector extends to not just files. Things typed or said.

This is a steep cliff, and we're drawing closer to the edge.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#39
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

In some ways, I think privacy advocates could be shooting themselves in the foot here. I think that mainstream storage encryption (mainstream as in WhatsApp and Signal, as opposed to encrypting your NAS using linux commands) is very important for privacy, and that deploying it without running into CSAM objections and legislation is a Sisyphean task for for-profit businesses. Messaging seems to be more legally defensible than storage from a business perspective.

If you take as an axiom that mainstream businesses will be forced to protect themselves against contributing to CSAM distribution, then the choice to offer encrypted cloud storage to non-technical end users REQUIRES doing the scan on a trusted computer (Apple has chosen the phone itself).

I think the arguments that this can be abused are very real, but it's worth talking about how to fix that, because I think the alternative might be sacrificing E2EE cloud storage in the mainstream (as has happened with every other mainstream company). Perhaps more thought should be put into making this process auditable by the device owner (or by a trusted 3rd party -- say the EFF).

Or perhaps the scanning could be federated -- say I don't want Apple doing that, but I might trust a privacy oriented non-profit to "certify" to Apple that my personal photo album is CSAM-free. Can that 3rd party scan be blinded, such that I send data that is representative of my images, but I've already anonymized my photos using a transformation?

Could we audit (similar to certificate transparency):

1) What data from the device is being scanned? What data is being uploaded?

2) What "hashes" are being matched against, and how are those changing over time? Can the data lineage of the NCMEC database be audited? Would that pick up malicious hashes injected into the database?

Generally, I think our privacy paradigm needs to be built in such a way that it can actually be deployed in our policy environment. More realpolitik, less ethical grandstanding.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#40
post #16

Correct me if I'm wrong, but I find the idea of people sending this kind of materials via email to be asking for trouble, to put it mildly.

While I agree, law enforcement in the U.S. is supposedly bound by the "expectation of privacy" where, I think we can all agree, we ought to have an expectation of privacy when we send an email directly to one of our contacts.

Of course Google and Gmail (as an obvious example) are not law enforcement so they can specify the terms of privacy when you sign up, scan your email if they wish, etc.

Post reply on HN