Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

11–20 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#11
post #9

If these judges are so righteous, they should go further and mandate the OS to do mandatory scanning of personal hd.

It's still a shade of gray to me. If I offered some homegrown cloud storage to my friends, and one of them uploaded CSAM to it, you can bet your ass that I would be arrested for it.

Re: Apple defeats liability for not scanning iCloud for CSAM

#12
IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.

Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.

Re: Apple defeats liability for not scanning iCloud for CSAM

#13
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

Children are often used as a weapon to erode freedoms, like privacy and speech. Those pushing it rarely actually care about the children.

Re: Apple defeats liability for not scanning iCloud for CSAM

#14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy.

> It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.

I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare quotes there because I don't think that political or religious dissidents would find that the same or similar technology used to discover and persecute them is "privacy preserving". And that's really the problem with Apple here. They provided a model for scanning for any kind of message or material while purportedly maintaining privacy.

Re: Apple defeats liability for not scanning iCloud for CSAM

#15

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

I was an engineer at both MS and Apple. At Apple, privacy was baked into every new feature from the start. At MS, the privacy component was glued on at the very end, if ever.

Like OP said, Apple isn't perfect nor will they ever be, but they do prioritize privacy better than most.

Re: Apple defeats liability for not scanning iCloud for CSAM

#16
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

Do you have a citation for that? Sounds plausible, but I'm not sure I've ever seen it stated that way in any of the related media reports on CSAM efforts.

Re: Apple defeats liability for not scanning iCloud for CSAM

#17
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

> As sad as this is, end to end encryption means no CSAM scanning.

I think it depends on your definition of e2ee and where the "end"s are.

If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?

Re: Apple defeats liability for not scanning iCloud for CSAM

#18
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

Are there statistics backing up the "VAST" majority claim?

While on statistics, I wonder, are there reliable statistics about child abuse of different types? Studying correlations with other social metrics, like sex education, liberal/conservative, policies regarding prostitution, and others can provide support for/against decisions.

Not that I hope these will impact people's and governments' choices, but I want to challenge my intuitions.

Re: Apple defeats liability for not scanning iCloud for CSAM

#19

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

There's no issue with mega. There are third party apps and as long as you don't login to mega.nz with their website you're fine. And they also have SDK you can use that they'll not be able to control/manipulate without your knowledge.

Re: Apple defeats liability for not scanning iCloud for CSAM

#20

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

I said this in another thread a while ago, and one of these people who thinks Apple isn’t on the side of privacy cited a lawsuit they settled around Siri listened to conversations: https://www.scientificamerican.com/article/apple-settles-cla...

People understood this settlement to mean Apple was spying on their conversations and selling them to advertisers, when it seems to have more to do with people accidentally triggering Siri. But people don’t care about this kind of nuance or actually tallying up all the ways Apple is pro privacy against rare issues like this one. It’s all just tribalism at the end of the day.

Post reply on HN