Earlier quoted context omitted.
> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.
This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…
Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
241–250 of 336 posts
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#242Earlier quoted context omitted.
> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.
This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#243I haven't forgot about the guy that sent photos of his child to his doctor and was investigated for child pornography. With these systems, in my humble opinion, you are just one innocent photo at the beach away from your life turned upside down.
That scenario would've been impossible with Apple's system.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#244> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…
It worries me that Sarah Gardner seems to be truthful when she hints at that no one at Apple reached out to her after Apple killed the plan in December 2022. She must have also missed articles like the one at The Verge [1].
Gardner’s message to Tim is dated 2023-08-30 03:24:37 (CEST).
Erik Neuenschwander's reply was printed out 2023-08-31 14:41:00 (probably PDT).
So that’s a period of about 44 hours that the print out [0] represents.
It would be helpful to know the time when Apple’s reply was sent to deduce whether Apple had time for additional deliberations before writing the email to Gardner.
Regardless, as reported by The Verge they obviously had deliberations shortly after the public outcry, killed the plan in December 2022, and then presumably failed to inform Gardner about the reasons.
If that’s the case, far smaller companies have checks and balances in place to keep that from happening.
[0]: https://s3.documentcloud.org/documents/23933180/apple-letter...
[1]: https://www.theverge.com/2022/12/9/23500838/apple-csam-plans...
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#245Earlier quoted context omitted.
No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…
> Should we also outlaw high performance cars Yes. If consumer cars’ speed was capped to 100 mph it would affect a very small percentage of people and zero legitimate use. The difference with encryption is that while it protects criminals from the police, it also protects legitimate users from criminals.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#246Earlier quoted context omitted.
Because the idea is that the iCloud data would be encrypted so their servers couldn’t scan it. With the plan being they would do on device scanning of photos that were marked as being stored on iCloud. It’s objectively better than what google does but I’m glad we somehow ended up with no scanning at all.
that sounds strange, I mean i'm not sure what's the big difference. If data is scanned on icloud, this means it's not encrypted, got it, if scanned on devices, data is fully encrypted on icloud, but apple has access by scanning it on devices and can send unencrypted matches, so it behaves as an unencrypted system, that can be altered at apple's will, just like icloud... but still, why scanning locally only if icloud…
The policy is meant to ensure Apple's servers are not storing and distributing CSAM, not that Apple wants to become a police investigative force.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#247Earlier quoted context omitted.
That scenario would've been impossible with Apple's system.
It would’ve been less likely, not impossible. Perceptive hashing absolutely has issues with false positives.
And that's ignoring the fact that his photo wouldn't have matched anyway because it isn't in any CSAM database.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#248Earlier quoted context omitted.
> Should we also outlaw high performance cars Yes. If consumer cars’ speed was capped to 100 mph it would affect a very small percentage of people and zero legitimate use. The difference with encryption is that while it protects criminals from the police, it also protects legitimate users from criminals.
Plenty of people who own performance cars take them to racetracks where driving above 100mph is entirely legitimate. So doing this wouldn't affect zero legitimate use.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#249The vast majority (99%+) of iCloud Photos are not e2ee and are readable to Apple. You can rest assured that they are scanning all of it serverside for illegal images presently. The kerfuffle was around clientside scanning, something that it has been reported that they dropped. I have thus far seen no statements from Apple that they actually intended to stop the deployment of clientside scanning. Serverside scanning h…
To be clear, they positively stated that they do not perform any server side scanning when this feature was first announced.
Whatever they said, it was probably worded to give you this impression, without actually saying that. Apple is extremely careful and goes to great pains to actively mislead and deceive whilst avoiding actual lies.
Could you please link to or quote these statements from Apple? I would bet any money they say something different than what you claim, a "not wittingly"-style hedge.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#250Earlier quoted context omitted.
> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.
This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…
The file encryption part was based on using a hash of the file as the key.
It's always nice to later find out that one's quick amateur idea turns out to be an independent rediscovery of something legit. Now that I've learned it is called "convergent encryption" Googling tells me it it goes back to 1995 and a Stac patent.