Earlier quoted context omitted.
The practical difference is that with on-device scanning, the system is just a few bit flips away from scanning every photo on your device, instead of just the ones that are about to be uploaded. With server-side scanning, the separation is clear—what's on Apple's server can be scanned, and what's only on your phone cannot. This all plays so perfectly into my long-time fears about the locked down nature of the iPhone…
With server-side scanning, the separation is clear In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms: There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blow…
This is a self-delusion, I am afraid. The line has been crossed more than once, and it will be crossed again. UK and Australian governments are just two prime examples of waving terrorism and pedobear banners as a pretext to get invasive with each new legislation, and the Oz government already has a new legislation draft to make it a crime to refuse cooperation with law enforcing services when they request access to the encrypted content (think Signal messages). Also, refer to the Witness K case to see how cases that are unfavourable to the standing government completely bypass a «trustworthy» Western judicial system, including the Minister of Justice.
CSAM is guaranteed to be abused under whatever new pretext politicians can come up with, and we won't even know that Apple has been quietly subjugated to comply with it in those jurisdictions. There will be even less transparency and even more abuse of CSAM in «non-Western» countries. That is the actual worry.