Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

121–130 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#121

Earlier quoted context omitted.

With all the attention it has been getting I think its only a matter of time before CSAM-SWATing starts to happen on those cloud services. The amount of people who know that scanning is happening just dramatically increased in the past month. And for all we know it may have already happened and someone is currently rotting in jail who shouldn't be there. Middle aged dude raided by cops who find CSAM on their cloud ac…

We've had plenty of time for it to have already happened since various services have been scanning for CSAM for some time.

> The amount of people who know that scanning is happening just dramatically increased in the past month.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#122

Earlier quoted context omitted.

iCloud does more than just uploading. It enables transparent sync and offloading of photos. This means if your device has limited storage, iCloud Photos can shunt photo data out to the cloud while maintaining a local representation of the photo's existence. These iCloud features are "baked into" the APIs that apps use to integrate with the system photo library, e.g.: https://developer.apple.com/documentation/photokit…

A third party could implement the PHAsset abstraction over their own implementation of a photo library action sheet and the file provider APIs. It wouldn’t get you to feature parity, but the major differences are but minor frictions if your privacy threat model involves nation state adversaries. It is not possible to write an app on iOS that has permanent, transparent background network and runtime access, and it’s a…

I’m unclear if you’re saying that one can implement a new access mechanism to Apple’s default photo library (the one managed by the Photos app and that the camera saves to by default) or if you’re suggesting that I need to design my own alternative photo album. If the latter, then “but minor frictions” seems… unreasonable.

Not sure what nation state adversaries have to do with a simple question about photo library access.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#124

Earlier quoted context omitted.

Alternatively, someone could realize that existing CSAM that's so widespread it's in the database basically equals water under the bridge, whereas creating CSAM that isn't in the DB requires to harm more children. Poverty and power imbalance is what harms children the most, by far. But we can't tackle that without stepping on the toes of greed, so we do circus instead.

You say water under the bridge, others will say where there's smoke there's fire.

But this isn't smoke, this is a photo of smoke. And as I said, the raging fires all of us can see in plain view go mostly unchecked. Where there is a photo of smoke, there may be fire, but where there is obviously a huge blazing fire, there surely is fire.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#125
post #118

Earlier quoted context omitted.

It's the same point as above. They could do shady things with your data on their server. They could do shady things with the data on your phone. They always /could/, and up till now I trusted them not to. But now they /have/, that is the change.

Ok they lost your trust and it’s completely your choice to make that decision however you want, but how was this shady?

Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady.

Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady.

Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Apple NDA), is mega shady.

Secretly reporting people to authorities based on unverifiable novel image hashing algorithms and only image "derivatives", whatever that means, that's ultra shady.

Pretending that people are somehow "misunderstanding" if they are alarmed by this unprecedented, unverifiable scanning and secret snitching mechanism being run over their private photos, that's extra ultra mega shady, but typical of Apple.

Look at this shitshow explanation. When have you ever seen Apple being so terrible at explaining a feature? None of this smells right: https://www.youtube.com/watch?v=OQUO1DSwYN0

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#126
post #118

Earlier quoted context omitted.

Ok they lost your trust and it’s completely your choice to make that decision however you want, but how was this shady?

Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady. Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady. Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Appl…

Ok, so you are largely misunderstanding the details.

> Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady.

Would you rather Apple actually directly look at your images? If not then it is a privacy improvement. Because they are legally required to search their servers for this stuff when directed to by the FBI.

> Using that novel on-device scanning capability to secretly report people to authorities, that’s beyond shady.

Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.

> suing any companies that try to analyze the code running, is mega shady.

And not something their actually doing.

> Based on unverifiable

Again false people have been looking at the algorithm used.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#127

Earlier quoted context omitted.

"They’ve lost my trust and that’s that." Same here. There's a finality to this, closure. I'm done reading about it, nothing more I need to say about Apple. I just purchased a System76 laptop and am ditching my MBP. I've been a Mac Addict for 20 years and now I've outgrown Apple. Privacy is a human right. What I'm wondering now is "how do I replace my iPhone, AirPods, and iPad?" Ask HN: Do you use Purism, PinePhone, o…

Me too. Not a huge Mac user, but I use my iPad and AirPods a lot. I haven't tried them, though the Sony ear buds look like a great option to AirPods: https://www.sony.com/lr/electronics/truly-wireless/wf-1000xm... As far as the tablet goes... I dunno. I haven't tried an android tablet and I'm not too keen on it. Maybe a Surface? The iPad is damn good at what it does...

The biggest convenient of AirPods for me is how damn easy they connect and disconnect. Wonder if there's a way to support that on other devices and platforms. It's a dream.

And yeah, iPad...

Pinephone has options: https://pine64.com/product-category/tablets/

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#128

Earlier quoted context omitted.

Can you elaborate on why you think this gives us way more privacy than we had before? I don't see how adding on-device scanning does that. I think that people generally understand what's going on and where this might lead us in the future.

It's less about scanning (they were already doing that on their side) and more about keys. Before, there were two keys. The one on your device, and one for accessing the data on their servers. Apple could be compelled to decrypt that data and hand it over to the government, and the government could ask for literally anything. So all the fear about "what if they decide to scan for images of XYZ" is a fear that already…

I like your point about ~31 keys. Hadn't realized it worked like that with all images now being encrypted.

One caveat is that according to this article out today, Apple was not scanning iCloud Photo Libraries for CSAM previously: https://9to5mac.com/2021/08/23/apple-scans-icloud-mail-for-c...

"Apple has confirmed to me that it already scans iCloud Mail for CSAM, and has been doing so since 2019. It has not, however, been scanning iCloud Photos or iCloud backups."

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#129
post #126

Earlier quoted context omitted.

Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady. Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady. Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Appl…

Ok, so you are largely misunderstanding the details. > Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady. Would you rather Apple actually directly look at your images? If not then it is a privacy improvement. Because they are legally required to search their servers for this stuff when directed to by the FBI. > Using that novel on-device scanning cap…

>Would you rather Apple actually directly look at your images?

No. Why would that be necessary?

I would expect to be reported if I willingly uploaded images matching exact hashes of CSAM to Apple servers. I don't understand why Apple employees would ever be able to, or need to, view my images, and I would expect Apple if it were really a privacy-focused company to never let that happen.

>Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.

It's client side, that's why we're having this discussion.

This is all a secret process. As I said, Apple employees look at an unspecified number of "derivatives" of people's images in a secret process, and if they tick a box, the authorities get all your data. There's nothing saying how close a "derivative" needs to be to actual CSAM to trigger this process, just "trust us, because children".

No audits, no due process, no mandatory notifying customers that are affected, no notifying of how many total customers were reported every month, just a secret illegal search and snitching mechanism with some crypto mumbo jumbo and "trust us, because children" sprinkled on top.

>And not something their actually doing.

*they're. Yes they are: https://news.ycombinator.com/item?id=28219278

From a comment: > ... “With their left hand, they make jail-breaking difficult and sue companies like Corellium to prevent them from existing. Now with their right hand, they say, ‘Oh, we built this really complicated system and it turns out that some people don’t trust that Apple has done it honestly—but it’s okay because any security researcher can go ahead and prove it to themselves.’”

>people have been looking at the algorithm used.

Who? How? Are you talking about the ones that are gagged by Apple NDA? Link to papers?

As another commenter posted, no amount of spin will make on-device scanning a good idea.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#130
post #114

Earlier quoted context omitted.

Then by that logic, what they want is build a complex and highly narrow mechanism for checking only the photos that are uploaded to iCloud Photo Library for CSAM, and absolutely nothing more.

Today. They didn't want to do that yesterday. They will certainly want to do something else tomorrow. Apple has a history of modifying devices that people bought in ways they didn't want and could not change (like putting a non-removable News app on their computers), but the CSAM episode shows Apple is willing to do a lot more, and more importantly, explained this to users who didn't care about the past abuses.

>… explained this to users who didn't care about the past abuses.

There is no abuse here.

Post reply on HN