Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

91–100 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#91
post #14

Earlier quoted context omitted.

The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.

Are photos uploaded to iCloud encrypted client-side? I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA. These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.

This boils down to “I have nothing to hide.” I encourage you to review https://www.schneier.com/essays/archives/2006/05/the_eternal... and consider if you really feel this way.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#92

Earlier quoted context omitted.

It is hard to square the idea that Apple’s proposed CSAM detection pipeline is a fundamental affront to privacy, a human right, with the argument that turning off iCloud Photos is a false choice because alternatives don’t or can’t have feature parity. Even more so because every cloud photo service with the scale and quality of iCloud Photos is doing the same (and arguably worse!). I use Nextcloud and it is a more or…

I don’t think you need to square those options. I think that scanning people’s photos is very much an affront to privacy. Apple clearly agrees with me at some level because they are advertising that their system is “opt in”: you only get scanned if you turn on iCloud Photos. But this argument assumes that for most users this is a choice. For many users who have purchased iPhones with lower storage levels this is not…

The user to whom Apple’s offer is a false choice is one that assumed they would always be able to update to the latest iOS while uploading whatever photos they wanted into iCloud Photo Library without any kind of content scanning. Turning private API into public API is a huge investment, and I’ll be honest: this hypothetical user seems quite far-fetched, and I don’t see how this investment is worthwhile for Apple to make. Especially so because most of the criticism is about a slippery slope where all rules don’t apply: Apple could just as easily scan the photos the 3rd party processes as well. So what incremental privacy do they even gain?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#93
post #69

Earlier quoted context omitted.

Per the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.

The threat model people are buying into here is that Apple can’t do what they want today , but if they deploy this CSAM detector, only then will they be able to do whatever they want.

Fair point. You are right.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#94

Earlier quoted context omitted.

Yeah, I don't get the cloud/device distinction people are making. Increasingly they are one and the same (if you know what I mean).

With all the attention it has been getting I think its only a matter of time before CSAM-SWATing starts to happen on those cloud services. The amount of people who know that scanning is happening just dramatically increased in the past month. And for all we know it may have already happened and someone is currently rotting in jail who shouldn't be there. Middle aged dude raided by cops who find CSAM on their cloud ac…

We've had plenty of time for it to have already happened since various services have been scanning for CSAM for some time.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#95
post #88

"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.

Regarding Apple scanning images, you actually gain more privacy than you have now. Way more. But the near-universal dislike of this initiative leads me to believe people do not understand either a) the current way in which Apple handles images and subpoena requests; or b) some aspect of the (admittedly complex) scanning implementation. But I don't know the precise area that people are getting hung up, so it's tough t…

Can you elaborate on why you think this gives us way more privacy than we had before? I don't see how adding on-device scanning does that.

I think that people generally understand what's going on and where this might lead us in the future.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#96
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

"They’ve lost my trust and that’s that."

Same here. There's a finality to this, closure.

I'm done reading about it, nothing more I need to say about Apple. I just purchased a System76 laptop and am ditching my MBP. I've been a Mac Addict for 20 years and now I've outgrown Apple. Privacy is a human right.

What I'm wondering now is "how do I replace my iPhone, AirPods, and iPad?"

Ask HN: Do you use Purism, PinePhone, or Fairphone? https://news.ycombinator.com/item?id=28216287

Ask HN: Do you use a Linux-first laptop? (System76, Librem, Dell XPS Dev Ed) https://news.ycombinator.com/item?id=28216287

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#97
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

My problem is the use of my own device to run the scan. It's a waste of system resources.

I'll restate what I posted on another thread about this [0]. There should be a clear, bright line here.

----

In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms:

There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blows right past that line.

Our tools before the computing revolution, and our devices after, become a part of us. Our proprioception extends to include them as part of "self." A personal device -- a tool that should be wholly owned and wholly dependable, like pen and paper -- that betrays its user, is a self that betrays itself.

[0]: https://news.ycombinator.com/item?id=28162412

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#98

Earlier quoted context omitted.

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

> [...] They’ve lost my trust [...] Exactly how I feel. I used to cautiously kinda trust Apple's so-called "commitment" to privacy, but this change just shows us that any such promises are purely theater. Now that the damage is done, I doubt it can be undone, especially in my case. My opinion on Apple's credibility has crashed through the floor. In my opinion, they're now as untrustworthy as Google or Facebook.

For me it's a step further. I cannot trust any company for more than privacy theater. Apple was simply the last to fall.

I'm starting to look at companies to see if they meet these must-haves:

1. E2E encryption

2. Open source hardware and software

Everything else is "nice to have". The current options out there are missing a lot of "nice to haves", but they will get better. I'll be a vocal customer telling them what I want.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#99

Earlier quoted context omitted.

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

“Trust” is entirely my issue with Apple too. I spent some time - and even wrote a post on my site - trying to clarify my thoughts and the steady erosion of trust seemed to be what I most object to. I too am trying to take control and responsibility for the computers I use now. Proving tricky, but baby steps…

Care to share the link to the post on your site?
Post reply on HN