Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

61–70 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#61
post #8

Earlier quoted context omitted.

I mean what if apples search decides that I am suspicious? Will they unlock my keychain and give all my logins to some police or worse random people somewhere to check my stuff? Very disappointing indeed

I don't believe Apple can unlock your Keychain. It requires your biometric (touch/face) to unlock from the Secure Enclave.

Per the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#62
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

Pretty obviously the only reason to scan on-device is that you intend to expand on-device scanning to all files on the device, regardless of whether they are uploaded or not. ("We don't want child molesters to get away by turning off uploads," said Apple spokesperson.) Literally no reason to develop this otherwise. Scanning cloud images would be 100x easier.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#63
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

> [...] They’ve lost my trust [...]

Exactly how I feel. I used to cautiously kinda trust Apple's so-called "commitment" to privacy, but this change just shows us that any such promises are purely theater.

Now that the damage is done, I doubt it can be undone, especially in my case. My opinion on Apple's credibility has crashed through the floor. In my opinion, they're now as untrustworthy as Google or Facebook.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#64

Earlier quoted context omitted.

But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?

Yeah, I don't get the cloud/device distinction people are making. Increasingly they are one and the same (if you know what I mean).

>Yeah, I don't get the cloud/device distinction

Maybe I can make it clearer.

It is like you are asked or demanded to install some antivirus on your computer, but this is not a typical antivirus , it is not scanning to protect you but to find evidence against you and destroy your life.

A list of facts, let me know if you disagree with the reality or my conclussion

Apple could have scanned iCloud already, why did they not do it so far? Either there is a super low number of CP on iCloud which implies this feature is not needed OR Apple was lazy, incompetent or had some other reason and let a lot of bad guys escape . I would conclude from this that Apple , if they really care of children, should freaking start scanning the existing iCloud images now.

From the above I am inclined to believe that this is not an action to protect the children, the reality does not fit, if there is so much CP on iCloud but Apple just woke up then WTF is that all PR about protecting children.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#65
post #12

Earlier quoted context omitted.

This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

What you said changes nothing about the concerns the parent comment/s raised: which is, having the scanning on the device in any manner what-so-ever. That is the objection.

The fundamental issue is that Apple is crossing an important privacy line: my property (my phone) vs their property (their external servers).

It's identical to saying that because USPS (or any mail carrier) is allowed to scan mail that moves through their system, across their property, they should also be allowed to come into my home and scan mail there. Hey, they promise to only look at mail while inside the home, what's the big deal. It represents the same shift: my home vs their shipping infrastructure.

People would universally go ballistic if USPS/UPS/Fedex declared they were going to begin routinely entering homes to examine mail packages before they were sent out. No matter how you dressed that up (they only do it if you print a shipping label first, indicating preparation to send a package through their system), it wouldn't assuage anyone.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#66
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

> Presumably, a trivial software update down the line could expand its ambit to locally stored files.

Sure but this is equally true now as it will be after they deploy the CSAM detector.

It’s not a real argument against the detector.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#67
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

You've hit the nail on the head for me. The part that offends me is that the scanning is happening on my device that I paid for, and had no knowledge of the eventual introduction of when I bought the phone. If they want to scan cloud storage, by all means. But I shouldn't have to have my device bogged down with this extra pointless computation.

The idea that it’s going to slow your device down is an odd one.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#68
post #38

Earlier quoted context omitted.

Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…

My house shouldn't be full of eyes and ears. CSAM today, political materials another. This could also be used to identify whistle blowers, reporters' sources, and more. I'd hate to have gay porn on my iPhone in a Sharia law state. Or images of tank man in mainland China. Imagine when the detector extends to not just files. Things typed or said. This is a steep cliff, and we're drawing closer to the edge.

> Or images of tank man in mainland China.

The Chinese government forcibly installs spyware on people’s phones today. What Apple does or doesn’t do is of no consequence to them.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#69

Earlier quoted context omitted.

I don't believe Apple can unlock your Keychain. It requires your biometric (touch/face) to unlock from the Secure Enclave.

Per the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.

The threat model people are buying into here is that Apple can’t do what they want today, but if they deploy this CSAM detector, only then will they be able to do whatever they want.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#70
It definitely makes sense to scan things that are passed around - mail is an example of that, and Gmail [and also Facebook, Twitter] scan for this, along with scanning for computer viruses, and in some cases (public posts) copyrighted content.

It makes absolutely no sense to scan people's photos that they aren't sharing with anyone else. Why are they bothering with scanning people's photo backups at all?

With the exception of "shared photo albums", I don't see why they're doing this.

Post reply on HN