Earlier quoted context omitted.
This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.
But you do like the idea of a server-level scanner for a hash database assuming that you're guilty until proven innocent?
Apple already scans iCloud Mail for CSAM, but not iCloud Photos
31–40 of 142 posts
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#32Earlier quoted context omitted.
The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.
Alternatively, someone could realize that existing CSAM that's so widespread it's in the database basically equals water under the bridge, whereas creating CSAM that isn't in the DB requires to harm more children. Poverty and power imbalance is what harms children the most, by far. But we can't tackle that without stepping on the toes of greed, so we do circus instead.
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#33The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…
This is correct. I have no problems of them scanning my icloud mail or photos. I just don't like the idea of there being a system level scanner for a hash database on my device assuming that I'm guilty until proven innocent. I was going to upgrade my iPhone this fall to latest model, now I'm very hesitant to do so and looking at alternatives.
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#34The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…
Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#35"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.
I've honestly always interpreted their privacy activism that way. Apple acts as the warden of your data. Backups are encrypted for your privacy, but they hold a copy of the key. Traffic is obfuscated through fake Tor, but they manage the network. iMessage seems safe enough, but the source code is tightly sealed away, only accessible to Apple's eyes. It's still a valid way to advertise the company because I trust Appl…
Until a company is more powerful than the government I'm not sure how anyone can have an absolute assurance of privacy from a corporation.
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#36Earlier quoted context omitted.
No. https://apnews.com/article/fact-checking-369404345862
[flagged]
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#37Earlier quoted context omitted.
Open source hardware and software is the only sustainable path forward. Perhaps that DIY processor fab discussion is worth a re-read. Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208 HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315
I mean what if apples search decides that I am suspicious? Will they unlock my keychain and give all my logins to some police or worse random people somewhere to check my stuff? Very disappointing indeed
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#38The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…
Genuine question. I know this is not the situation we find ourselves in but, if your options were on-device scanning for CSAM+encrypted iCloud Photos (that Apple could not decode) OR cloud-based scanning of iCloud Photos which would you pick? Are you still opposed to all on-device scanning? Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your tho…
CSAM today, political materials another. This could also be used to identify whistle blowers, reporters' sources, and more.
I'd hate to have gay porn on my iPhone in a Sharia law state.
Or images of tank man in mainland China.
Imagine when the detector extends to not just files. Things typed or said.
This is a steep cliff, and we're drawing closer to the edge.
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#39The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…
The point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.
If you take as an axiom that mainstream businesses will be forced to protect themselves against contributing to CSAM distribution, then the choice to offer encrypted cloud storage to non-technical end users REQUIRES doing the scan on a trusted computer (Apple has chosen the phone itself).
I think the arguments that this can be abused are very real, but it's worth talking about how to fix that, because I think the alternative might be sacrificing E2EE cloud storage in the mainstream (as has happened with every other mainstream company). Perhaps more thought should be put into making this process auditable by the device owner (or by a trusted 3rd party -- say the EFF).
Or perhaps the scanning could be federated -- say I don't want Apple doing that, but I might trust a privacy oriented non-profit to "certify" to Apple that my personal photo album is CSAM-free. Can that 3rd party scan be blinded, such that I send data that is representative of my images, but I've already anonymized my photos using a transformation?
Could we audit (similar to certificate transparency):
1) What data from the device is being scanned? What data is being uploaded?
2) What "hashes" are being matched against, and how are those changing over time? Can the data lineage of the NCMEC database be audited? Would that pick up malicious hashes injected into the database?
Generally, I think our privacy paradigm needs to be built in such a way that it can actually be deployed in our policy environment. More realpolitik, less ethical grandstanding.
Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos
#40Correct me if I'm wrong, but I find the idea of people sending this kind of materials via email to be asking for trouble, to put it mildly.
Of course Google and Gmail (as an obvious example) are not law enforcement so they can specify the terms of privacy when you sign up, scan your email if they wish, etc.