Earlier quoted context omitted.
There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…
Pretty obviously the only reason to scan on-device is that you intend to expand on-device scanning to all files on the device, regardless of whether they are uploaded or not. ("We don't want child molesters to get away by turning off uploads," said Apple spokesperson.) Literally no reason to develop this otherwise. Scanning cloud images would be 100x easier.
There are many reasonable criteria under which the proposed model is superior for privacy. Perhaps the only reasonable criteria under which it is not is some kind of scope creep in what files are scanned. (Scope creep in what content is scanned for is a risk - an even greater one as there is no transparency over the hash list - of incumbent solutions as well.)