Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

101–110 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#101
post #76

Earlier quoted context omitted.

What people make this aurguement fail to understand is that legally there is a HUGE difference between "We will not make software that scans files on the device" and "We will not allow the software we made to scan for anything other than CSAM" Under US law it would be very hard to force apple to do the first, but no where near as hard to compel them to change the database they of files they are scanning for...

This is a dubious legal theory. The compelled action the government asked Apple to take in the case of Apple vs. FBI was a very minor technical change.

It's not about the technical complexity of the change. It's about the public blowback from such a change. The U.S. government compelling Apple to install some all-access backdoor would be a big story.

The U.S. government compelling Apple to make some small process change to this new system wouldn't be a big story by comparison.

Example: A year from now the U.S. government tells Apple they are no longer allowed to review the flagged CSAM imagery themselves but must rather report it directly to law enforcement.

A change most people wouldn't think twice about ("why does Apple need to be the ones reviewing this obscene illegal material anyway") yet would introduce a massive vulnerability into the surveillance process.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#102

Earlier quoted context omitted.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

Pretty obviously the only reason to scan on-device is that you intend to expand on-device scanning to all files on the device, regardless of whether they are uploaded or not. ("We don't want child molesters to get away by turning off uploads," said Apple spokesperson.) Literally no reason to develop this otherwise. Scanning cloud images would be 100x easier.

Either that, or Apple really doesn’t want their server to access (ie. decrypt) all photos by default. Maybe they actually weren’t lying when they defended being more private by having all computing happen on-device, and the server not accessing your data.

Now, what seems more likely to you? They suddenly decided to go towards scanning all offline files for no business nor legal benefit, or they tried to respect their own marketing of how their ecosystem should work?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#103

Earlier quoted context omitted.

This is a dubious legal theory. The compelled action the government asked Apple to take in the case of Apple vs. FBI was a very minor technical change.

It's not about the technical complexity of the change. It's about the public blowback from such a change. The U.S. government compelling Apple to install some all-access backdoor would be a big story. The U.S. government compelling Apple to make some small process change to this new system wouldn't be a big story by comparison. Example: A year from now the U.S. government tells Apple they are no longer allowed to rev…

I don’t see what public blowback has to do with legal arguments, at least without also assuming some kind of legal realism.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#104
post #74
post #68

Earlier quoted context omitted.

> Or images of tank man in mainland China. The Chinese government forcibly installs spyware on people’s phones today . What Apple does or doesn’t do is of no consequence to them.

> The Chinese government forcibly installs spyware on people’s phones today. What Apple does or doesn’t do is of no consequence to them. And that makes this okay? You're defending this use against us too.

Did someone say it was ok? The point is that it’s silly to say this CSAM mechanism makes a difference in China.

Does the US government have the power to order Apple to scan everyone’s phones for politically undesirable images?

I don’t think so.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#105
post #88

Earlier quoted context omitted.

Regarding Apple scanning images, you actually gain more privacy than you have now. Way more. But the near-universal dislike of this initiative leads me to believe people do not understand either a) the current way in which Apple handles images and subpoena requests; or b) some aspect of the (admittedly complex) scanning implementation. But I don't know the precise area that people are getting hung up, so it's tough t…

Can you elaborate on why you think this gives us way more privacy than we had before? I don't see how adding on-device scanning does that. I think that people generally understand what's going on and where this might lead us in the future.

It's less about scanning (they were already doing that on their side) and more about keys. Before, there were two keys. The one on your device, and one for accessing the data on their servers. Apple could be compelled to decrypt that data and hand it over to the government, and the government could ask for literally anything. So all the fear about "what if they decide to scan for images of XYZ" is a fear that already exists. Apple has made it clear that they do not want to aid the government in any way, and stated so directly to congress in 2019. Congress, in turn, made it clear that if they (big tech) didn't come up with a solution, they would legislate some kind of "backdoor" requirement, which would be terrible for everyone.

So they had to come up with some kind of solution that:

1. Keeps the government happy enough that they don't pass terrible legislation.

2. Keeps Apple's servers from storing illegal content.

3. Keeps Apple from being involved in the subpoena process.

4. Maintains user privacy – because that's the whole point of this exercise.

I genuinely think if people understood how they accomplished this they would see that Apple accomplished two of the objectives (1, 4) and will eventually accomplish #3 as well.

But back to keys. Your device has a master key for decrypting the photos, and that's always been the case. What I'm about to talk about Apple's servers only, and not your device:

Imagine the two-key system required to launch a nuke, or the big Hollywood bank vault that requires two people to simultaneously get retina scans. "Shared Key Encryption" is the same idea – no one person with a key can decrypt the target. What's cool about this is you can have as many keys as you want, and all of them must be present in order to decrypt the contents. How many keys is Apple using? Well in this particular encryption layer, they are using ~31 keys, and Apple only has ONE.

If we stop right there, you can already see how this is way more secure. A government cannot compel Apple to hand over your unencrypted data. Apple has been able to do this in a much simpler way for a long time, but not without causing the government to pass counter-legislation in response. They haven't implemented better security before this for that very reason.

So where do the other keys come from? They are generated anytime a match is found in the CSAM database on your phone. Even that database is hashed, so your CSAM database and its hashes are unique from every other iPhone user. If there is no match with the CSAM database for a particular image, the keys for its decryption are never generated. Meanwhile each time CSAM match is made, another of the 31 keys gets generated. So in a (super over-simplified) way, the "bad" images are keys for each other. This is why Apple has set a "threshold" for how many CSAM images must be detected before Apple is notified. They have to meet that threshold in order to have all the keys to be able to decrypt all the offending images. Even then, all other images in your account still remain encrypted and inaccessible.

All of this keeps the government happy enough to keep the bad legislation at bay. It's not a perfect solution, but it's better than the alternative, and it results in greater privacy than we have today.

Unless/until I see technical documents showing why there is a privacy issue for people who don't have CSAM, I am 100% in favor of this solution.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#106

Earlier quoted context omitted.

It's not about the technical complexity of the change. It's about the public blowback from such a change. The U.S. government compelling Apple to install some all-access backdoor would be a big story. The U.S. government compelling Apple to make some small process change to this new system wouldn't be a big story by comparison. Example: A year from now the U.S. government tells Apple they are no longer allowed to rev…

I don’t see what public blowback has to do with legal arguments, at least without also assuming some kind of legal realism.

I wasn't commenting on the law, rather the claim about the technical complexity of the change.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#107

Earlier quoted context omitted.

“Trust” is entirely my issue with Apple too. I spent some time - and even wrote a post on my site - trying to clarify my thoughts and the steady erosion of trust seemed to be what I most object to. I too am trying to take control and responsibility for the computers I use now. Proving tricky, but baby steps…

Care to share the link to the post on your site?

Not that person but is this it?

https://madebyjamie.design/articles/2021-08-20-advocating-fo...

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#108
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

My problem is the use of my own device to run the scan. It's a waste of system resources. I'll restate what I posted on another thread about this [0]. There should be a clear, bright line here. ---- In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms: There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed…

You're exactly right.

We have a word for what Apple is installing on your device: spyware. And it's worse than typical spyware in that it's using your device to spy on you and report its findings back to law enforcement.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#109

Earlier quoted context omitted.

iCloud does more than just uploading. It enables transparent sync and offloading of photos. This means if your device has limited storage, iCloud Photos can shunt photo data out to the cloud while maintaining a local representation of the photo's existence. These iCloud features are "baked into" the APIs that apps use to integrate with the system photo library, e.g.: https://developer.apple.com/documentation/photokit…

A third party could implement the PHAsset abstraction over their own implementation of a photo library action sheet and the file provider APIs. It wouldn’t get you to feature parity, but the major differences are but minor frictions if your privacy threat model involves nation state adversaries. It is not possible to write an app on iOS that has permanent, transparent background network and runtime access, and it’s a…

It's a benefit for users at large because they get to use services that provide more benefits (like Google Photos search and automatic video creation), services with more privacy (like self-hosted photo services), or services that are cheaper (like Amazon Photos).

Android has demonstrated that there is no need to whitelist this. This is purely a lock-in play for Apple.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#110

Earlier quoted context omitted.

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

“Trust” is entirely my issue with Apple too. I spent some time - and even wrote a post on my site - trying to clarify my thoughts and the steady erosion of trust seemed to be what I most object to. I too am trying to take control and responsibility for the computers I use now. Proving tricky, but baby steps…

Just read through your blog post, there's plenty of great insights on there and I appreciated someone being so thoughtful and tactful with their response. As a Rust developer, I fully encourage you to push through and learn the language: I've walked a few tenured web devs through the language, and they're always surprised by how strongly typed and simple everything is once you understand the syntax. Truly one of my favorite languages to work with!

As for 'alternatives' like you listed towards the bottom, I fully recommend setting up your own Nextcloud instance. It's a really versatile little thing, capable of hosting your photos/documents/music/whatever from a decent online interface (or WebDav, if you're a nerd.)

Post reply on HN