Live data from Hacker News

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

9to5mac.com

71–80 of 142 posts

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#71

Earlier quoted context omitted.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

Pretty obviously the only reason to scan on-device is that you intend to expand on-device scanning to all files on the device, regardless of whether they are uploaded or not. ("We don't want child molesters to get away by turning off uploads," said Apple spokesperson.) Literally no reason to develop this otherwise. Scanning cloud images would be 100x easier.

Apple has declared their criteria for evaluating the privacy of their CSAM scanning approach in their USENIX talk, and none of it relies on scanning all files. If you want to accuse them of lying, you will need to bring a lot more evidence since (i) presumably you believe they weren’t lying in the past and (ii) it would be an enormous liability if they were now.

There are many reasonable criteria under which the proposed model is superior for privacy. Perhaps the only reasonable criteria under which it is not is some kind of scope creep in what files are scanned. (Scope creep in what content is scanned for is a risk - an even greater one as there is no transparency over the hash list - of incumbent solutions as well.)

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#72

Earlier quoted context omitted.

This comment should be way up. People afraid of "what else" Apple can start scanning on our devices has always been a reality, way before CSAM. If they ever decided to remove the feature, it's not like it will magically make it impossible for Apple to ever scan our devices again in the future. They can run whatever code they want on their device. We've always put our trust on Apple to not do any shady things on our p…

> We've always put our trust on Apple to not do any shady things on our phone …and now we have a case in point of them doing shady things on our phones. This breaks the trust.

I don’t see what’s shady about this because it’s so public. They could do everything that’s happening on phone on the iCloud servers without telling you. So at worst it uses extra bandwidth per upload and some processing power and thus battery life from your phone. The minor advantage is you can actually inspect their procedural hashing algorithm, though not how they compare images server side.

Sure, they could do something else in the future but that’s alway the risk with every update.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#73

It definitely makes sense to scan things that are passed around - mail is an example of that, and Gmail [and also Facebook, Twitter] scan for this, along with scanning for computer viruses, and in some cases (public posts) copyrighted content. It makes absolutely no sense to scan people's photos that they aren't sharing with anyone else. Why are they bothering with scanning people's photo backups at all? With the exc…

You can view other peoples iCloud photos. https://macpaw.com/how-to/icloud-photo-sharing

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#74
post #68
post #38

Earlier quoted context omitted.

My house shouldn't be full of eyes and ears. CSAM today, political materials another. This could also be used to identify whistle blowers, reporters' sources, and more. I'd hate to have gay porn on my iPhone in a Sharia law state. Or images of tank man in mainland China. Imagine when the detector extends to not just files. Things typed or said. This is a steep cliff, and we're drawing closer to the edge.

> Or images of tank man in mainland China. The Chinese government forcibly installs spyware on people’s phones today . What Apple does or doesn’t do is of no consequence to them.

> The Chinese government forcibly installs spyware on people’s phones today. What Apple does or doesn’t do is of no consequence to them.

And that makes this okay? You're defending this use against us too.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#75
post #59

Earlier quoted context omitted.

iOS doesn't allow other cloud photo services to upload in the background except via flaky hacks, so the choice for iPhone users is really between iCloud Photos and crippled alternatives.

I use NextCloud which syncs my photos from my iPhone to my in-home server. Then I use borgbackup to encrypt my photos/videos and send them to a cloud provider. All of it is automated and wasn't too much of a hassle to setup.

iCloud does more than just uploading. It enables transparent sync and offloading of photos. This means if your device has limited storage, iCloud Photos can shunt photo data out to the cloud while maintaining a local representation of the photo's existence. These iCloud features are "baked into" the APIs that apps use to integrate with the system photo library, e.g.: https://developer.apple.com/documentation/photokit/phasset#1...

You can come up with third party solutions that accomplish some portion of this use case (photo backup) but you'll never be able to accomplish what Apple does with iCloud Photos unless Apple opens its APIs.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#76

Earlier quoted context omitted.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

This comment should be way up. People afraid of "what else" Apple can start scanning on our devices has always been a reality, way before CSAM. If they ever decided to remove the feature, it's not like it will magically make it impossible for Apple to ever scan our devices again in the future. They can run whatever code they want on their device. We've always put our trust on Apple to not do any shady things on our p…

What people make this aurguement fail to understand is that legally there is a HUGE difference between

"We will not make software that scans files on the device"

and

"We will not allow the software we made to scan for anything other than CSAM"

Under US law it would be very hard to force apple to do the first, but no where near as hard to compel them to change the database they of files they are scanning for...

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#77
post #9

The clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Pr…

> Presumably, a trivial software update down the line could expand its ambit to locally stored files. And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course…

“Trust” is entirely my issue with Apple too. I spent some time - and even wrote a post on my site - trying to clarify my thoughts and the steady erosion of trust seemed to be what I most object to. I too am trying to take control and responsibility for the computers I use now. Proving tricky, but baby steps…

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#78

Earlier quoted context omitted.

There is an alternative, more reasonable way to look at the Apple proposal. The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos. You are told abo…

iCloud Photos is a synchronization service that is integrated very tightly into the core iOS system. Even the basic APIs that allow apps to integrate with the system photo library are "iCloud aware" in the sense that the photo might not be on your device. iCloud Photos makes it possible to page photos on and off your device, which is a critical feature for people who can't afford to pay for the high-end iOS devices w…

It is hard to square the idea that Apple’s proposed CSAM detection pipeline is a fundamental affront to privacy, a human right, with the argument that turning off iCloud Photos is a false choice because alternatives don’t or can’t have feature parity. Even more so because every cloud photo service with the scale and quality of iCloud Photos is doing the same (and arguably worse!).

I use Nextcloud and it is a more or less ok user experience; the major inconvenience is that your photo library isn’t available in UIImagePickerControllers. The image preview mechanics you describe can already be simulated with file provider APIs.

Edit. I think my point more simply stated is that if you think turning off iCloud Photos or switching photo sync with another cloud provider “solved” the privacy problem, then you are in the same group of people who are annoyed that they can’t use Spotify with Siri or AirPlay 2. Welcome to the large number of 2nd class citizens on iOS. It’s not great out here, but it certainly doesn’t make the toggle a false choice.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#79

Earlier quoted context omitted.

iOS doesn't allow other cloud photo services to upload in the background except via flaky hacks, so the choice for iPhone users is really between iCloud Photos and crippled alternatives.

This is the tradeoff of the Apple ecosystem. For most users the trade off is a no-brainer because they don't care about the theoretical concerns that, in expectation, do not apply to them. I mean, what is the probability of this technology causing an innocent user harm? 1/1,000,000 ? 1/10,000,000? 1/100,000,000?

According to Apple, 1/1 Trillion chance of a false report per year.

So the chance for a single photo to be incorrectly matched is much higher. But by setting a threshold at ~30 images before triggering a manual review, they get the odds extremely low.

My bet is that error threshold will remain a constant for them. As tech gets better, they will reduce the threshold accordingly to maintain that error rate. In five years, I’m guessing they will only need three images to trigger a review.

Re: Apple already scans iCloud Mail for CSAM, but not iCloud Photos

#80
post #59

Earlier quoted context omitted.

I use NextCloud which syncs my photos from my iPhone to my in-home server. Then I use borgbackup to encrypt my photos/videos and send them to a cloud provider. All of it is automated and wasn't too much of a hassle to setup.

iCloud does more than just uploading. It enables transparent sync and offloading of photos. This means if your device has limited storage, iCloud Photos can shunt photo data out to the cloud while maintaining a local representation of the photo's existence. These iCloud features are "baked into" the APIs that apps use to integrate with the system photo library, e.g.: https://developer.apple.com/documentation/photokit…

A third party could implement the PHAsset abstraction over their own implementation of a photo library action sheet and the file provider APIs. It wouldn’t get you to feature parity, but the major differences are but minor frictions if your privacy threat model involves nation state adversaries.

It is not possible to write an app on iOS that has permanent, transparent background network and runtime access, and it’s also not clear allowing such apps would be a privacy benefit for users at large. Apple already makes exceptions to this for certain apps (e.g. it seems like my Verizon Wireless app has background runtime). Are you suggesting that Apple should nominate a few photo services receive the same exception?

Post reply on HN