If this was a problem, would we not be seeing a slew of complaints about innocents being dragged through the mud with OneDrive and PhotoDNA? The only thing unique about Apples implemention is that it's client-side.
If this was a problem, would we not be seeing a slew of complaints about innocents being dragged through the mud with OneDrive and PhotoDNA? The only thing unique about Apples implemention is that it's client-side.
If Google decides to implement this, which doesn't seem very unlikely because of the optics of NOT implementing this, people who aren't tech savvy won't really have a realistic way to opt out.
I just don't think there is very much evidence that in practice false positives are a big issue and the article is very much pushing that argument.
I would agree on a purely technical level your phone is already pwned by Apple so worrying about this on a technical level is closing the barn door after the horse got out. However from a social perspective one of the holdouts against photo scanning has stopped being a holdout, and doing things from client-side makes it seem less wrong to do other things client-side.
Besides the privacy stuff, this also is a bit more of a slide towards software that you purchase being ultimately controlled by and for the benefit of parties other than yourself.
That said, many hosted providers/social networks have similar features - they just have server-side implementations and might not have felt the need for disclosure.
In practice any major cloud provider is going to or is already doing this. We need a better regulatory approach, it isn’t practical to put the responsibility on providers.
That has to be done on the phone because Messages is end-to-end encrypted. If they are going to have to have hash matching on the phone anyway for that, it makes sense to also use that for checking images that are to be sent to the cloud.
https://www.macrumors.com/2021/08/05/apple-csam-detection-di...
"CSAM image scanning is not an optional feature and it happens automatically, but Apple has confirmed to MacRumors that it cannot detect known CSAM images if the iCloud Photos feature is turned off."
We won't get one though, because the "think of the children!!!" crap is extremely pervasive and anyone going against it will be smeared as a pedo defender.
In that mindset, the answer is absolutely to combat and to attempt to change broken laws first.
Also, it isn't just "think of the children". For instance, there have been some _terrible_ proposals under the banner of Right to Repair. People tend to not want to invest the time in understanding the ramifications of the actual proposals, and instead vote for or against the concept. One of the reasons ballot measures are both empowering and terrifying.
Good regulations take time and care - and generally, less is more.
You are consenting to the upload and are aware that it can be searched so not a legal problem.
Law enforcement will also review the picture in the cloud instead of busting your door to search your phone and the whole scenario from article.
When they do it client side they can't just upload your content on hash collision. (or maybe they do which is also a problem in itself)
- The scanning will be performed only if photos are to be uploaded to iCloud.
- The database will be encrypted multiple times in a way that it can't be clearly read.
- There's not notification to Apple in any way in case of matches.
- Instead, each match result is again encrypted in a way that is inaccessible to Apple and uploaded together with photo
- If there a lot of positive matches, they eventually will become able to decrypt it. That's when they will do manual check, lock the account if it is correct and notify authorities.
Presumably it is client side so that they can do anonymization/encryption of photos on the server, and treat any data access outside the account and account they have shared the photo with as an audited and cross-organizational event.
But if you want to use another hosted service, you can... and likely get their implementation of a similar system. Presumably this is US regulatory compliance.
This is going to bite more innocent people through false positives than criminals who already know how to get away with these things.
It is not a ML model but a list of known image hashes, and is only enabled for US-based accounts, furthering my suspicions this was minimum-effort for regulatory compliance.
Note they _do_ have a feature (also announced today) that uses ML models, but it is meant for local filtering and parental controls/notifications. This feature is also US-only and the parental notifications policy is fixed and age-based. I believe this is both to fit into regulations (e.g. US recognition of rights based on age) and into cultural norms.
I suspect they will have different rules in different jurisdictions when this rolls out further in the future.
[1]: With separate key escrow HSMs for account recovery and legal compliance with e.g. court-ordered access.
the tech runs locally, but only on those photos.
Even if the hashing and matching happen on the local device, a match can only be revealed server-side. The hash database distributed to local devices will be blind hashed with a server-side secret key and the locally derived hash match will need to be decrypted with that key to be read by Apple. So theoretically if the local device doesn't upload content to iCloud, no content matching can be revealed, even if the hashing and matching has been done locally.
Of course, you also need to trust that Apple won't be uploading those locally derived hashes to iCloud without the user's permission if iCloud backups are disabled.
[1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
and in real life governments elected by the people have been pushing for this for years. the result has been google and all the other cloud providers already implementing this. apple was the last big one to hold out.
will they expand this in the future? sure, whatever. the system is so broken, and i’m so powerless, that at this point in time it doesn’t matter what i want.
at least it will only apply to the US. the ROW is spared. at least for now.
- You don't like storage provider - you don't use it
- You don't like ecosystem/smartphone provider - you don't use it
On top of that you can opt out even now by disabling updates it just means that you won't have access to the newest iOS and take risk that at some point software developers will stop supporting OS you decided to stick to.
This just doesn't work like this in our day and age. We are one ecosystem (android) away from complete domination of this scanning technology. You could argue that I could use a librem or something but at that point all librem users automatically become suspicious because "all major manufacturers have this, he probably has something to hide".
you could as well live in woods away from society, but that's obviously not the solution to bad laws
Yeah, the only thing unique is installation of Spyware Engine in personal device that will do 'who knows what' later. What can possibly go wrong?
Other hosting providers do similar scans, but they do not do them within the client-side component. Presumably, this is done to give the hosting environment no access to the actual data (e.g. data access such as by subpoena becomes a cross-organizational auditable event)
This is just another case of, 'your phone' is not yours. People stores their lives and thoughts in a device that they have no control of.
I am not against those use per se. I am worried about what it means legally. The minimum that we need is a more clear legal framework. This is a private company accessing personal data without consent and without any formal requirement from law enforcement.
This is specific to photo synchronization to the cloud, which is an optional service.
In that sense, it isn't really doing anything different than say a OneDrive photo sync app - except it is doing the check on the client side, rather than having the server decrypt to do the check.
It is part of the default install and setup wizard, but thats a battle we lost decades ago in the PC world. You still have to opt into iCloud synchronization for this to be enabled.
In the story it didn't became a well known issue since it would happen only to few unlucky individuals.
The same goes for the unintended asset freezing.