Earlier quoted context omitted.
While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…
> The Javascript that checks validity of forms before you submit them is a form of client-side scanning It is hardly difficult to draw a distinction between ensuring a field looks like an expected datatype and ML analysis guessing at photo content. In fact, trying to construct an argument conflating the two pretty much immediately runs in to the fact that one is adversarial, so it only works if you studiously ignore…
The other distinction is, if a client-side form validator detects a problem with the input, it tells the user so they can fix it, whereas if Apple's system detects a problem with your input, it potentially tells the police without giving you a chance to delete the maliciously-generated false positive files you've unwittingly received.