Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

311–320 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#311
post #244
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

This is truly mind-boggling because it’s Apple and such an important topic. We are right to expect better from these bright people. It worries me that Sarah Gardner seems to be truthful when she hints at that no one at Apple reached out to her after Apple killed the plan in December 2022. She must have also missed articles like the one at The Verge [1]. Gardner’s message to Tim is dated 2023-08-30 03:24:37 (CEST). Er…

>It would be helpful to know the time when Apple’s reply was sent to deduce whether Apple had time for additional deliberations before writing the email to Gardner.

In the old days, and I assume it is still the case, judging from observing Apple for the past 20+ years, every single public response has to go through Apple PR. Even public interview before hand they were given lots of preparation.

It is likely Apple has this prepped for a long time. Or even it was another PR case scenario [1] where the CEO was baited to send this email before a response was given and somehow "leaks" to the press.

[1] Read Submarine PR by Paul Graham.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#312

Earlier quoted context omitted.

In my opinion their goal was to get stuff to a state where they could encrypt everything on iCloud so that even they can't access it. To counter the "think of the children" -argument governments use to justify surveillance, Apple tried scanning stuff on-device but the internet got a collective hissy-fit of intentionally misunderstanding the feature and it was quickly scrapped.

> but the internet got a collective hissy-fit of intentionally misunderstanding the feature how was it misunderstood? your device would scan your photos and notify apple or whoever if something evil was found. wasn't that what they were trying to do?

Your device would've scanned your photos ONLY if you would've uploaded them to Apple's cloud service anyway.

And it wouldn't have notified Apple of "something evil", just specifically known and human-verified actual real child abuse photos. And not even that, it would have needed multiple matches of those very real and verified abuse photos before it flagged them so that a real human could see a "visual derivative" of the photos.

Only if those multiple matches of derivatives were deemed as actual, very real, child pornography the authorities would've been called.

But nope. Now they just scan ALL your data in the cloud when the authorities demand it. And that's somehow better according to the internet in a way I still can't understand.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#313

Earlier quoted context omitted.

Let's take a step back here and bring in some facts. "Apple" wasn't scanning your phone, neither was there a "backdoor". If you would've had iCloud upload enabled (you'd be uploading all your photos to Apple's server, a place where they could scan ALL of your media anyway), the phone would've downloaded a set of hashes of KNOWN and HUMAN VERIFIED photos and videos of sexual abuse material. [1] After THREE matches of…

You might've read the spec but you're missing the point and your approach is naive. For me it's about crossing the line. If you want to be snooping around my phone or my house, you need a warrant and go to official channels provides by my gov officials. And you really think it's as simple as picking apples from oranges? I mean come on. Yes, it's easy to implement hash check to see if u have some known child porn in y…

First of all, your analogy of "sending officials to your home without a warrant" is again you completely misunderstanding the feature.

The local scanning would've been enabled only if you would've uploaded the photos to iCloud anyway.

To complete your crappy analogy: You had already agreed to send the information of everything contained in your apartment to a company, and now you're getting into a hissy-fit when they are sending a robot visit your house with a list of known child pornography photos and checking if you have any?

There weren't any "hard decisions" it wasn't a "this has a naked person in it" -scanner. It wasn't an "abuse checked" it was specifically created to find known CP.

It checked your photos against a NeuralHash of KNOWN child pornography. So the only chance your sauna photos would've been flagged if they were included in a set of CP photos distributed widely enough so that they're added to the CSAM database.

And nobody claimed the system would magically cure the world of grooming, where did you get that idea from? Although the current filters in iMessage might help if the abuser is stupid enough to use that for grooming.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#314

Earlier quoted context omitted.

Let's take a step back here and bring in some facts. "Apple" wasn't scanning your phone, neither was there a "backdoor". If you would've had iCloud upload enabled (you'd be uploading all your photos to Apple's server, a place where they could scan ALL of your media anyway), the phone would've downloaded a set of hashes of KNOWN and HUMAN VERIFIED photos and videos of sexual abuse material. [1] After THREE matches of…

> "Apple" wasn't scanning your phone, neither was there a "backdoor". Yes, you're right. But I've seen calls for phones to scan all content before being uploaded or encrypted, and it often feels, at least in some countries, that could still plausible happen. I suppose that's what I had in mind when I wrote my comment. > But the exact same risk exists when you upload stuff to the cloud anyway and on an even bigger sca…

ALL cloud providers are actively scanning all of your content right now, unless you specifically encrypt it yourself.

It's a cost of doing business pretty much, you need to give the authorites access to customers data or they can go "but think of the children, there might be child abuse material in there!" and that's really damn hard to argue against.

Thus: checking stuff on-device and keeping the cloud locked so that not even the hoster can access it nor can they create a backdoor.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#315

Earlier quoted context omitted.

> "Apple" wasn't scanning your phone, neither was there a "backdoor". Yes, you're right. But I've seen calls for phones to scan all content before being uploaded or encrypted, and it often feels, at least in some countries, that could still plausible happen. I suppose that's what I had in mind when I wrote my comment. > But the exact same risk exists when you upload stuff to the cloud anyway and on an even bigger sca…

ALL cloud providers are actively scanning all of your content right now, unless you specifically encrypt it yourself. It's a cost of doing business pretty much, you need to give the authorites access to customers data or they can go "but think of the children, there might be child abuse material in there!" and that's really damn hard to argue against. Thus: checking stuff on-device and keeping the cloud locked so tha…

> you need to give the authorites access to customers data

At least some cloud providers require a warrant before doing so.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#316

Earlier quoted context omitted.

What else is obscene? And why would I have to accept an US jury's opinion? Also you didn't define 'otherwise objectionable'. For example what I think is excessive violence may be considered normal by a jury in the US...

> What else is obscene? Quite a lot of things may or may not fall under that definition. Thats how the law works. > And why would I have to accept an US jury's opinion? Well, because they and judges are the ones empowered by the government monopoly on violence to judge the law and then have it be enforced, thats why. Ignore the law at your own peril. But anyway, even if you did ignore the law, this doesn't have anyth…

> Well, because they and judges are the ones empowered by the government monopoly on violence to judge the law and then have it be enforced, thats why.

... by the US government on US territory, i think. They have no business defining "otherwise objectionable" elsewhere.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#317

Earlier quoted context omitted.

> What else is obscene? Quite a lot of things may or may not fall under that definition. Thats how the law works. > And why would I have to accept an US jury's opinion? Well, because they and judges are the ones empowered by the government monopoly on violence to judge the law and then have it be enforced, thats why. Ignore the law at your own peril. But anyway, even if you did ignore the law, this doesn't have anyth…

> Well, because they and judges are the ones empowered by the government monopoly on violence to judge the law and then have it be enforced, thats why. ... by the US government on US territory, i think. They have no business defining "otherwise objectionable" elsewhere.

> They have no business defining "otherwise objectionable" elsewhere.

The principles that I have describe also apply to other countries as well.

So yes it is absolutely the case that in other countries there are judges and juries that apply the law via the process of judges and juries.

But once again, no matter what some other country thinks, on this specific topic, it is about a company getting immunity from USA enforcement. So all other countries do not matter on this topic, because this is about US law.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#318
post #269

Earlier quoted context omitted.

Pointing out a few app vendors simply isn't impressive. Of course some app vendors can take a stand against mid-tier governments. It's great marketing for them, and the corporate risk isn't so high. It's the platform vendors which have much at stake. And of the three big platform vendors, two of them already scan private photos for CSAM right now — Google and Microsoft. Yet nobody is outraged because nobody actually…

Neither Google nor Microsoft operate a secure messaging platform that matters (email, yes, but email security is a lost cause), unlike WhatsApp (and Facebook Messenger), iMessage, Telegram or Signal. I'm not giving Google & Microsoft a pass, they're just irrelevant for the discussion at hand.

Why are Google and Microsoft irrelevant to this discussion? Please, be specific.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#319
post #249

Earlier quoted context omitted.

To be clear, they positively stated that they do not perform any server side scanning when this feature was first announced.

Then how would they respond to warrants asking for all user identities that upload image x? "Sorry, no"? I don't think so. If they are served a valid warrant that isn't overbroad and they have the data, they are legally compelled to provide it. Whatever they said, it was probably worded to give you this impression, without actually saying that. Apple is extremely careful and goes to great pains to actively mislead an…

They confirmed here: https://9to5mac.com/2021/08/23/apple-scans-icloud-mail-for-c...

Apple clearly has very limited ongoing scanning because they report on the order of hundreds of instances of CSAM to NCMEC every year whereas other services with pervasive scanning report on the order of tens of millions of instances.

It’s ok, you are one of the vast majority of people commenting on this topic while reasoning from false premises.

> Then how would they respond to warrants asking for all user identities that upload image x?

Dragnet warrants like this aren’t even legally permissible in the United States, and if they were Apple would obviously reject them. They state that they only provide specific named user account information in response to warrants.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#320
post #262

Earlier quoted context omitted.

Signal and Meta (WhatsApp) don’t scan your messages. Apple’s actions have shown they are untrustworthy, and even if they’ve reversed this particular decision, compromising on principle has put authoritarians on notice they are open to compromise in the future, like the UK’s horrific Online Safety Bill.

Pointing out a few app vendors simply isn't impressive. Of course some app vendors can take a stand against mid-tier governments. It's great marketing for them, and the corporate risk isn't so high. It's the platform vendors which have much at stake. And of the three big platform vendors, two of them already scan private photos for CSAM right now — Google and Microsoft. Yet nobody is outraged because nobody actually…

Wholesale scanning of private data is unaaceptable, and the fact you engage in such mental gymnastics to justify it is a sign that everyone should be distrusting any platform by default. Simple as.

Enjoy the exodus.

Post reply on HN