Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

41–50 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#41

Earlier quoted context omitted.

[flagged]

Not sure why you're being downvoted when this is a proven privacy issue. It's not about democrats v. republicans or iPhone vs Android, it's about our leadership as a whole, and what kinds of powers they have. The fact that our government even has access to our private communications should feel like a conflict of interests, especially in a nation that prides itself on freedom.

because people are so polarized the idea of engaging corporations to intrude on your private messages is ok if its your 'team'.

People never seem to realize what they're setting up are mechanisms and agreements that will facilitate further interventions. The mechanisms will be used against everyone, forever. This is just further increasing the centralization of power behind politicians who never deserve it and who use it on people with no power to resist, no matter whose team they're on.

or they realize and are so pre-occupied with their team they don't care, which is sad and short sighted.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#42
post #12
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

There is an alternative, more reasonable way to look at the Apple proposal.

The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos.

You are told about the system and you are free to turn the service off. That doesn't sound like a massive privacy invasion to me.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#43
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

FHE doesn't let the other party access the results of algorithms run on your data. Other parties can run an algorithm on your encrypted data, but only you can interpret the results.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#44
Something wasn’t squaring between the claims that Apple has already been scanning iCloud Photos for years, that Apple reports hundreds of instances of CSAM while Facebook reports millions, and that Apple knows they have a major CSAM problem. Good to find out the problem was with the first one.

I wonder if the “you know they already do this server-side, right?” people feel the slightest bit chastened.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#45
post #16

Correct me if I'm wrong, but I find the idea of people sending this kind of materials via email to be asking for trouble, to put it mildly.

While I agree, law enforcement in the U.S. is supposedly bound by the "expectation of privacy" where, I think we can all agree, we ought to have an expectation of privacy when we send an email directly to one of our contacts. Of course Google and Gmail (as an obvious example) are not law enforcement so they can specify the terms of privacy when you sign up, scan your email if they wish, etc.

Interesting, I don’t have an expectation of privacy when it comes to unencrypted emails. Likely due to them being regularly scanned and archived at work etc.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#46
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

The surveillance infrastructure IS the point. NO point just doing it in the cloud. It HAS to be on device.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#47

Earlier quoted context omitted.

But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?

Yeah, I don't get the cloud/device distinction people are making. Increasingly they are one and the same (if you know what I mean).

ODINN => On Device, Intrusive, Neural Network.

You cannot photocopy a dollar bill. Kinda makes sense.

https://en.wikipedia.org/wiki/EURion_constellation

Now imagine a "live" neural network running on your phone or camera that prevents you from taking pictures of the Eiffel Tower at night due to "Suspected Copyright Abuse".

https://www.snopes.com/fact-check/photographs-of-eiffel-towe...

Next imagine that a local government issues a digital "All Points Bulletin" which scans all pictures on all phones for a "person of interest in a crime (against the state)", conveniently associated with the emergency alert broadcast network.

First they came: https://en.wikipedia.org/wiki/First_they_came_...

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#48
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

You've hit the nail on the head for me. The part that offends me is that the scanning is happening on my device that I paid for, and had no knowledge of the eventual introduction of when I bought the phone.

If they want to scan cloud storage, by all means. But I shouldn't have to have my device bogged down with this extra pointless computation.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#49
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

iOS doesn't allow other cloud photo services to upload in the background except via flaky hacks, so the choice for iPhone users is really between iCloud Photos and crippled alternatives.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#50
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

This comment should be way up. People afraid of "what else" Apple can start scanning on our devices has always been a reality, way before CSAM. If they ever decided to remove the feature, it's not like it will magically make it impossible for Apple to ever scan our devices again in the future. They can run whatever code they want on their device. We've always put our trust on Apple to not do any shady things on our phone. This new outrage makes no sense at all. As you said, people can turn iCloud Photos off to disable the scan. Therefore people need to STFU.
Post reply on HN