Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

111–120 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#111
post #72

Earlier quoted context omitted.

> We've always put our trust on Apple to not do any shady things on our phone …and now we have a case in point of them doing shady things on our phones. This breaks the trust.

I don’t see what’s shady about this because it’s so public. They could do everything that’s happening on phone on the iCloud servers without telling you. So at worst it uses extra bandwidth per upload and some processing power and thus battery life from your phone. The minor advantage is you can actually inspect their procedural hashing algorithm, though not how they compare images server side. Sure, they could do so…

It's the same point as above. They could do shady things with your data on their server. They could do shady things with the data on your phone. They always /could/, and up till now I trusted them not to.

But now they /have/, that is the change.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#112
post #69

Earlier quoted context omitted.

Per the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.

The threat model people are buying into here is that Apple can’t do what they want today , but if they deploy this CSAM detector, only then will they be able to do whatever they want.

The threat model is that Apple has been capable of doing whatever they want, and this CSAM detector has demonstrated that Apple will do whatever they want.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#113
post #69

Earlier quoted context omitted.

Per the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.

The threat model people are buying into here is that Apple can’t do what they want today , but if they deploy this CSAM detector, only then will they be able to do whatever they want.

Wow from your description people here sound like idiots. Sounds like you're pretty frustrated, what's up?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#114
post #69

Earlier quoted context omitted.

The threat model people are buying into here is that Apple can’t do what they want today , but if they deploy this CSAM detector, only then will they be able to do whatever they want.

The threat model is that Apple has been capable of doing whatever they want, and this CSAM detector has demonstrated that Apple will do whatever they want.

Then by that logic, what they want is build a complex and highly narrow mechanism for checking only the photos that are uploaded to iCloud Photo Library for CSAM, and absolutely nothing more.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#115
post #69

Earlier quoted context omitted.

The threat model people are buying into here is that Apple can’t do what they want today , but if they deploy this CSAM detector, only then will they be able to do whatever they want.

Wow from your description people here sound like idiots. Sounds like you're pretty frustrated, what's up?

What part makes people sound like idiots?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#116

Earlier quoted context omitted.

Can you elaborate on why you think this gives us way more privacy than we had before? I don't see how adding on-device scanning does that. I think that people generally understand what's going on and where this might lead us in the future.

It's less about scanning (they were already doing that on their side) and more about keys. Before, there were two keys. The one on your device, and one for accessing the data on their servers. Apple could be compelled to decrypt that data and hand it over to the government, and the government could ask for literally anything. So all the fear about "what if they decide to scan for images of XYZ" is a fear that already…

Thanks. I can agree that the process sounds very secure, but I still can't agree that it's more private. Apple had and will have the capability to decrypt iCloud data, so why add the additional scanning on the phone, of all places?

> Unless/until I see technical documents showing why there is a privacy issue for people who don't have CSAM

For me, it's about trust. Why not just do the scanning on their servers? With moving the scanning to the client, they've crossed the Rubicon. Apple has built a generic, automatic reporting tool for content on phones, which to my knowledge hasn't existed to date. On top of that, they've set the example that it's acceptable to perform client-side scanning.

Today it's against CSAM, but what about tomorrow? What will happen in authoritarian countries? Prior to this, I believe Apple had the high ground and could say, "we don't have the capability to scan devices and exfiltrate data". But now, it's there.

Perhaps you may say that this is the "slippery slope" argument, and maybe it is. I hope it never expands to include other things. Though I have a hard time imagining that this doesn't get expanded in the future.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#117
post #114

Earlier quoted context omitted.

The threat model is that Apple has been capable of doing whatever they want, and this CSAM detector has demonstrated that Apple will do whatever they want.

Then by that logic, what they want is build a complex and highly narrow mechanism for checking only the photos that are uploaded to iCloud Photo Library for CSAM, and absolutely nothing more.

Today. They didn't want to do that yesterday. They will certainly want to do something else tomorrow.

Apple has a history of modifying devices that people bought in ways they didn't want and could not change (like putting a non-removable News app on their computers), but the CSAM episode shows Apple is willing to do a lot more, and more importantly, explained this to users who didn't care about the past abuses.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#118
post #72

Earlier quoted context omitted.

I don’t see what’s shady about this because it’s so public. They could do everything that’s happening on phone on the iCloud servers without telling you. So at worst it uses extra bandwidth per upload and some processing power and thus battery life from your phone. The minor advantage is you can actually inspect their procedural hashing algorithm, though not how they compare images server side. Sure, they could do so…

It's the same point as above. They could do shady things with your data on their server. They could do shady things with the data on your phone. They always /could/, and up till now I trusted them not to. But now they /have/, that is the change.

Ok they lost your trust and it’s completely your choice to make that decision however you want, but how was this shady?

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#119

Earlier quoted context omitted.

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

"They’ve lost my trust and that’s that." Same here. There's a finality to this, closure. I'm done reading about it, nothing more I need to say about Apple. I just purchased a System76 laptop and am ditching my MBP. I've been a Mac Addict for 20 years and now I've outgrown Apple. Privacy is a human right. What I'm wondering now is "how do I replace my iPhone, AirPods, and iPad?" Ask HN: Do you use Purism, PinePhone, o…

Me too. Not a huge Mac user, but I use my iPad and AirPods a lot.

I haven't tried them, though the Sony ear buds look like a great option to AirPods: https://www.sony.com/lr/electronics/truly-wireless/wf-1000xm...

As far as the tablet goes... I dunno. I haven't tried an android tablet and I'm not too keen on it. Maybe a Surface? The iPad is damn good at what it does...

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#120

Earlier quoted context omitted.

I don’t think you need to square those options. I think that scanning people’s photos is very much an affront to privacy. Apple clearly agrees with me at some level because they are advertising that their system is “opt in”: you only get scanned if you turn on iCloud Photos. But this argument assumes that for most users this is a choice. For many users who have purchased iPhones with lower storage levels this is not…

The user to whom Apple’s offer is a false choice is one that assumed they would always be able to update to the latest iOS while uploading whatever photos they wanted into iCloud Photo Library without any kind of content scanning. Turning private API into public API is a huge investment, and I’ll be honest: this hypothetical user seems quite far-fetched, and I don’t see how this investment is worthwhile for Apple to…

You seem to be conflating a number of very different issues. It would be a lot simpler if you didn’t do that.

There are several separate questions. 1) Should users have the right to opt out of scanning. Apple have answered (1) in the affirmative: yes, they understand that some users want this option and have designed their system with explicit guarantees that users can do this. This is not an accident or a miscalculation on Apple’s part. They clearly understand that forcing this scanning on non-consenting users is unacceptable and their marketing copy makes this clear.

The second question (2) is whether Apple’s compromise to preserve user privacy (allowing users to disable photo sync while providing no third-party alternatives with equivalent feature sets) is acceptable. Apple presumably thinks it is. I think that disabling Apple’s photo sync features will not be acceptable — and indeed will be actively harmful to some users. We can disagree about whether this matters but this is the heart of the disagreement. Having strong opinions doesn’t settle the question, it just demonstrates that the issue is contentious. Settling the issue requires user surveys and an economic analysis at minimum, not opinions on HN.

Then there is a third point (3): does Apple have any obligation to provide opt-out users with alternative services that bring their devices back to the full functionality that they possessed when the devices were purchased. Your view is that “this is not worth it to Apple.” We do not disagree. My claim is that Apple’s view on the issue is not necessarily the final world on the issue. Apple also believes that they should have a monopoly on app distribution and many other aspects that define the iOS experience. These views are disputed and there is no “correct” answer. My claim is that the operation of cloud infrastructure should be a part of this dispute, and Apple’s decision to make their system “opt in” should be viewed as such in light of the fact that Apple controls essential features in such a way that Apple can effectively hobble the device of any user who declines to consent, with no recourse or alternative available to the user.

I think your response to this has to grapple with Apple’s very clear argument on (1). Which means that “Apple can do whatever it wants because they’re powerful” isn’t a sufficient response. And if the rest of your answer revolves around unsupported hypotheses about what Apple users expected, then you should probably come back with some strong evidence like user surveys to support those claims.

Post reply on HN