Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

61–70 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#61
post #43

Earlier quoted context omitted.

While I’m decidedly pro-encryption, I don’t like this argument. If something is the right thing, it would still be the right thing when promoted for the wrong reasons, and if it’s the wrong thing, it’s still the wrong thing even when at present nobody has ulterior motives. When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.

So invading the privacy of millions of people, even if it's just automatic scans for some specific thing is a right thing? Does this apply to mandatory drug tests for everyone everywhere? How about drug and weapon seeking drones, doing daily checks in every apartment everywhere? How about mandatory AI powered microphones everywhere that would detect threats, blackmail, any talk about anything illegal, etc.? If you ta…

You misread what I wrote. My comment is against the argument used, not against what is being argued for. Using the wrong argument diminishes one’s position. I’d prefer the stance against surveillance to not be diminished by such arguments.

Re: Apple defeats liability for not scanning iCloud for CSAM

#62

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

I don't think these are the same. Outlawing CSAM gives law enforcement the ability to shutdown markets and prevent commercial distribution of CSAM. Sexually abusing children is heinous, but sexually abusing children for financial gain is even worse.

Re: Apple defeats liability for not scanning iCloud for CSAM

#63
post #26
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever. It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing. They could do it when people are not at home. There'd no problem, nobody would even notice.

Kind of a bad analogy (not service related, no associated liability).

A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?

Re: Apple defeats liability for not scanning iCloud for CSAM

#64
post #31

I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are create…

> most people don't need cloud backups What world do you live in?

The world where the operating system on my phone (GrapheneOS) isn't conspiring against me or uploading my files to someone else's computer.

Re: Apple defeats liability for not scanning iCloud for CSAM

#66

Earlier quoted context omitted.

Apple is on the side of privacy, except when you want privacy from Apple: Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com) 161 points by Logans_Run on Feb 14, 2025 | 69 comments https://news.ycombinator.com/item?id=43047952 Apple silently uploads your passwords and keeps them (lapcatsoftware.com) 170 points by ingve on Nov 1, 2024 | 127 comments And whenever your priv…

It's telling that these come from people trying to implement tracking and high visibility into user behavior, and complaining that Apple won't let them even though Apple conceptually could. Except ublock, which can't do what it does the way it normally does, for the same reason you can't have any plugin inspecting realtime activity and doing scriptlet injection. You can have ad blocking. You can't have plugins with t…

Yep, and if you want good Adblock on iPhone use Wipr.

Re: Apple defeats liability for not scanning iCloud for CSAM

#67

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere.

Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOSSAD’ED UPON"[0]. This is specially good for me because I know the equivalent to the FBI where is live is too cheap to buy a Cellebrite [1] license.

[0] https://www.usenix.org/system/files/1401_08-12_mickens.pdf [1] https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...

EDIT: I suppose someone could ask about Meta. The reason behind their support for scanning (and removing e2e in facebook msg) is simply regulatory capture. The zucc wishes to have a letter of marque to "protect" your children and remove the "unsafe" competitors.

EDIT2: Used the wrong term, I mixed up exfiltration channel with sidechannel attack.

Re: Apple defeats liability for not scanning iCloud for CSAM

#68
post #26

Earlier quoted context omitted.

I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever. It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing. They could do it when people are not at home. There'd no problem, nobody would even notice.

[flagged]

The comment above is illustrating why the judge’s decision would be silly in another circumstance. And if it’s silly in that circumstance, it’s silly in the judge’s circumstance as well.

Re: Apple defeats liability for not scanning iCloud for CSAM

#69
Seems like the kids miss their chance at justice because of section 230 allowing platforms the freedom to remove whatever they want but not be responsible for what they keep or amplify. That is the problem with 230. Censorship is permitted and punishing the censor isn't. Twitter and Tiktok are literally microblog platforms that get away with removing good stuff and leaving evil because they "are not a publisher" while the algorithm literally publishes a chosen set of articles to people. Facebook can remove religious freedom material and leave human trafficking groups. Section 230 gives the publishers the cake and the edict too.

Re: Apple defeats liability for not scanning iCloud for CSAM

#70
post #64

Earlier quoted context omitted.

> most people don't need cloud backups What world do you live in?

The world where the operating system on my phone (GrapheneOS) isn't conspiring against me or uploading my files to someone else's computer.

That must also be the world where more than a tiny number of people are using GrapheneOS
Post reply on HN