Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

41–50 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#41

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion).

If the company is misleading, any encryption technology is irrelevant anyway.

Re: Apple defeats liability for not scanning iCloud for CSAM

#42
post #21

“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.” Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with…

Also, Apple's E2E iCloud encryption vastly predated the NeuralHash efforts.

Re: Apple defeats liability for not scanning iCloud for CSAM

#43
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

Children are often used as a weapon to erode freedoms, like privacy and speech. Those pushing it rarely actually care about the children.

While I’m decidedly pro-encryption, I don’t like this argument. If something is the right thing, it would still be the right thing when promoted for the wrong reasons, and if it’s the wrong thing, it’s still the wrong thing even when at present nobody has ulterior motives.

When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.

Re: Apple defeats liability for not scanning iCloud for CSAM

#44

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

Apple is on the side of privacy, except when you want privacy from Apple:

Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)

161 points by Logans_Run on Feb 14, 2025 | 69 comments

https://news.ycombinator.com/item?id=43047952

Apple silently uploads your passwords and keeps them (lapcatsoftware.com)

170 points by ingve on Nov 1, 2024 | 127 comments

And whenever your privacy contradicts their control over "your" device, you are also out of luck, e.g., you can't have Ublock Origin on an iPhone. Relevant discussion: https://news.ycombinator.com/item?id=44804921

Re: Apple defeats liability for not scanning iCloud for CSAM

#45
post #31

I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are create…

> most people don't need cloud backups

What world do you live in?

Re: Apple defeats liability for not scanning iCloud for CSAM

#46
post #26

Earlier quoted context omitted.

I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever. It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing. They could do it when people are not at home. There'd no problem, nobody would even notice.

[flagged]

They are being sarcastic.

Re: Apple defeats liability for not scanning iCloud for CSAM

#47
post #21

“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.” Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with…

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#48
post #14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help.

Very different than trying to narc out users to the authorities.

Re: Apple defeats liability for not scanning iCloud for CSAM

#49
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

Is it different than telling your therapist something in confidence and then finding police waiting for you in the lobby.

Yes, in the sense that you have a legal doctor-patient privilege that binds what they can share with whom. There's not really an Apple cloud user privilege.

No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

Re: Apple defeats liability for not scanning iCloud for CSAM

#50
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

I won't pretend to be so knowledgeable about how so much CSAM is being created, but keep in mind, there are laws against distribution & mere possession, too. Revenge porn is an obvious thing to be mindful of in this context in addition to other types of distribution. Consent to create doesn't imply consent to distribute (probably even to cloud storage) & is completely immaterial to issues of possession if it ends up in some 3rd party's hands. So the scope goes way wider than you're letting on. If you're saying all of these these laws are being abused, like they exist primarily to punish a state senator's daughter's ex-boyfriend, I would ask for something to back that up.

Yes, poor and unprivileged children can't really defend themselves here, but this is the system working to find some legal mechanism to do what it can, as a more powerful force. Protecting people from exploitation is a good use of government. If this was shot down for legal reasons, OK, the system is working and I hope there is a way to expand protections that fits into our system.

Post reply on HN