Earlier quoted context omitted.
If this technology is that easily circumvented then why is there an expectation that it will be effective at all?
The CASM scanning happens on device, right? At least so we’ve heard. My sense is Apple is trying to keep CASM off their servers. Scanning phones before it gets there was their solution to what I assume is a government demand/ultimatum. “Do this or we repatriate your foreign entity taxes” or some other shit. I too feel that Apple just caved and eroded trust that took decades to build up. The only way this gets sorted…
Firstly - CASM scanning is done via fingerprinting - the image is fingerprinted on device and when uploaded to iCloud that fingerprint is compared with the "dodgy images" fingerprints and an alert raised if a threshold of matches is reached (what's the threshold and with whom?)
Secondly - there is on-device AI image recognition - when you send an image to someone else (via iMessage or the share sheet) it is checked for nudity and if the iCloud account in question is registered to a 13-year old or younger, their parents are alerted.
In both cases the fingerprinting/scanning is on-device and is triggered by the images leaving the device.