Expanded Protections for Children – FAQ [pdf]
apple.com
apple.com
Our process is designed to prevent that from happening. The set of image hashes used for matching are from known, existing images of CSAM that have been acquired and validated by child safety organizations. Apple does not add to the set of known CSAM image hashes.
The problem is not that Apple can't add images to the database but that organizations from the outside can inject any hashes to the new, constantly sniffing system at the heart of iOS, padOS and macOS. Apple has no way to verify those or any hashes before they get injected into the database.
If the system detects any matches only some overworked and underpaid content checker from Bangladesh is there to stop your life from being destroyed by some SWAT team crashing through your front door at 3am, killing your barking dog. And who knows if those foreign sweatshops are even trustable.
What is the feedback when such system is abused
> Existing images of CSAM that have been acquired and validated by X organizations
Will Apple be considered as responsible? punished? Will Apple or the X publish the list of images and allow regular 3rd party validation? (I see security related product companies do that)
In this era it's hard, VERY hard to entrust our private properties to these giant tech companies. There is so little to NO negative feedback to their mis-behaviours. These companies need more regulations than individual citizens.
Child protection is an exception to all standards of due process in the US and Europe. There is NO organization that can interfere when people get mistreated based on these laws (the vast majority that fall victim to "side effects" are children, of course). Only generic "quality assurance" is done. There is no protection at all for individuals, whether children, parents, or third parties.
> Will Apple be considered as responsible? punished?
The EU court has judged just a few months ago that child protection authorities cannot be held responsible for the damage they cause, EVEN if it is shown that their actions were based on incomplete or wrong data.
> In this era it's hard, VERY hard to entrust our private properties to these giant tech companies.
Okay, well if you think this is a serious problem, then let me tell you what else social services data is being used for. In Belgium, social services, including homeless shelters, enter data into your medical records which you can't see, erase, or ... emergency departments will read this data, and use it to avoid the situation that they have to use the state insurance for non-insured persons, which is a polite wording for "refusing care to homeless persons".
My point remains the same: Need more feedback on "governors/power wielding side"
This part isn’t true. Unless a threshold of multiple matches is reached, Apple won’t have a complete key to decrypt anything.
To make it perfectly clear: I am absolutely agains this scanning system, but I think that we need to keep to high-quality arguments to successfully argue agains it.
You might not believe them but they are pretty clear on that point: “we will not accede to any government’s request”
This is the standard you have to hold Apple to. As I said, you might not believe them – but if you don’t trust their statements on some level then it’s game over anyway.
What makes this time different from the other times they acceded to government requests?
Reminds me of the old Apple ad: https://www.youtube.com/watch?v=PjmVN7mAMwc
Examples :
Apple to withhold a new privacy feature in China : https://www.aljazeera.com/economy/2021/6/8/apple-to-withhold...
iCloud Data Turned Over To Chinese Government Conflicts With Apple’s “Privacy First” Focus : https://www.cpomagazine.com/data-privacy/icloud-data-turned-...
Apple removes police-tracking app used in Hong Kong protests from its app store : https://www.cnbc.com/2019/10/10/apple-removes-police-trackin...
If somebody, or another compromised device sends a large collection of CSAM to your device, they will be uploaded to iCloud, probably before you get a chance to remove them -- the equivalent of "swatting".
Besides the apps that you give permission to store photos in your Photos app, what about malware such as Pegasus we've seen again and again?
I wonder if we'll start hearing a year from now about journalists, political dissidents, or even candidates running for office going to jail for being in possession of CSAM. It would be much easier to take out your opponents when you know Apple will report it for you.
I guess all this does is disincentivize anyone who cares about their privacy from using iCloud Photos, which is sadly ironic since privacy is what Apple was going for.
Major cloud providers already scan photos for CSAM. So this feature does not change anything in this regard. If you are using cloud photo storage, you can be targeted with this attack no matter whether you use an iPhone, some android Phone or anything else, really.
Which is why they focused their research on differential privacy.
My understanding (high level) is their system is designed to improve user privacy by meaning they don't need to be able to decrypt photos on iCloud (which is, if I understand correctly, how other cloud providers do this scanning, which they are required to do by law?), but rather do it on the device - without going in to the upsides and downsides of either approach, I'm surprised they didn't manage to communicate more clearly in the initial messaging that this is a "privacy" feature and why they are taking this approach, and instead are left dealing with some quite negative press.
What’s the upside to me, for this tech? There’s less of this content in the world? I don’t see it anyway, so for me, it doesn’t do anything except become a potential (low) risk liability.
I don’t see why I’m paying their power bill to do something they’re legally obligated to do.
I don't think that is required by law - at least not in EU or US.
There was already a lot of online outrage in July when EU passed regulation that allowed such scanning for the next 3 years - I imagine requiring it would be much worse.
I find the answer to this question unconvincing.
If we think very selfishly from the company's perspective - Apple already had one of the most secure, private and trusted platforms. And they must have anticipated the backlash against the new feature. So I still don't get why a company like Apple would consider the marginal benefit from this to be worth the cost.
Something like the PRISM program: https://www.theguardian.com/world/2013/aug/23/nsa-prism-cost...
How is Apple validating the datasets for non-US child safety organisations?
This is not about what people have on their own phones. This is about what people are uploading to iCloud, because Apple does not want CSAM on their servers!
As the document states, they do not want to scan all images server-side for privacy reasons. They just want to flag the positives while keeping privacy standards as high as posible for everyone else.
If you go back and read the earlier mega-threads, there were many people pointing this out and downvoted to oblivion. Hysteria is a helluva drug.
For anyone concerned about the hypothetical framing attack via WhatsApp auto-saving, you can selectively control which apps have access to your photo library (and thus iCloud) in settings.
Corporations have a terrible record about breaking non-revenue-impacting pinkie swears. Breaking this one - especially when “what about the children” is involved - would have no meaningful impact on their revenue or share price, it could even go up.
This is not the case - we do understand how it works, and we think it's a bad idea.
Will Apple notify a user once an image has been (/erroneously) flagged and will be inspected by Apple employees?
And even then, the voucher doesn’t include the key to decrypt the photo itself.
Apple has documentation that explains all of this.
So my question remains the same. Do users get a notification once they are (/erroneously) flagged.