You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.
You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.
iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E.
But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning.
As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.
I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy, not capability, and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".
I could maybe understand the new implementation if Apple had announced they'd also be enabling E2E encryption of everything in iCloud, and explained it as "this is the only way we can prevent CSAM from being stored on our servers."
Why is that supposed to be their responsibility?
Given the scale of their business, there is effectively a certainty that people are transmitting CSAM via Comcast's network. That's no excuse for them to ban end to end encryption or start pushing out code to scan client devices.
When you hail a taxi, they don't search you for drugs before letting you inside.
Because they're not the police. It isn't their role to enforce the law.
They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it.
It's like how a doctor is a mandated reporter regarding physical abuse and other issues.
Because they're not the police. It isn't their role to enforce the law.
They're not enforcing the law; if the CSAM reaches a certain threshold, they check it out and if it's the real deal, they report to National Center for Missing and Exploited Children (NCMEC); they get law enforcement involved if necessary.
I don't think that's correct. My understanding is that if they find CSAM, they're obligated to report it (just like anyone is). I don't believe they are legally obligated to proactively look for it. (It would be a PR nightmare for them to have an unchecked CSAM problem on their services, so they do look for it and report it.)
Consider that Apple likely does have CSAM on their servers, because they apparently don't scan iCloud backups right now. I don't believe they're breaking any laws, at least until and unless they find any of it and (hypothetically) don't report it
Quite honestly, my opinion is that any service not scanning for CSAM is living on borrowed time.
Scanning on their servers is much less privacy preserving for users but don't fret, Dropbox, Facebook, Microsoft, etc. already scan stored photos.
Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan your phone." It's now quite trivial for a government to say "We don't have a special database of just CSAM, and a different database of just Winnie the Pooh memes. We just have one big DB of 'illegal images', and that's what we want you to use to scan the phones."
Have been whining about big data for and ML recognition systems for years.
At last in Apple's case, ML is used only if a minor child (less than 13 years old) who is on a Family account where the parent/guardian has opted-in to the ability to be alerted if potentially bad content is either sent or received using the Messages app.
Because it’s something to push back against governments by saying « I can’t ». But it’s a societal issue if a corporation can say « I don’t want » to a government.
It’s really not the same thing and Apple just burned their « I can’t » card and are implying they can just say « no » to governments. Which is quite an even more dystopian thing.
The statement from Apple is that they will say no. Whether that actually ever happens is something we will see, one way or another.
Do you really think they would care in the slightest about banning iPhone?
Or that Putin cares more about people not being able to buy what amounts to a luxury item, than being able to hunt down opposition supporters?
Ohh... oops.
Any chance this is already operational there?
And, in all honesty, there's a lot of those.
Sounds like political suicide on either side: government interference with the country's largest company, an iconic brand, for no reason other than to hopefully spy more on your citizens.
I can guarantee that some industry bigwigs are salivating at the prospect of this tech. Imagine youtube copyright strikes but local to your device.
That really depends. And is quite a strange, perhaps worrying, take.
Because, for many people, copyright strikes are the least of their problems.
Not that I disagree on it being an issue.
Democratic countries are much more of a danger because Apple has offices in them and cannot easily pull out of the market if they feel the laws are unconscionable.
(Yes, I know, it sounds like I'm splitting hairs distinguishing between copyright maximalism and copyright trolling. Please, humor me.)
What copyright maximalists really want is an end to the legal protections for online platforms (DMCA 512 safe-harbor) so they can go after notorious markets directly. They already partially accomplished this in the EU. It's way more efficient from their end to have one throat to choke. Once the maximalists get what they want, platforms that want to be legitimate would be legally compelled to implement filters, ala YouTube Content ID. But those filters would apply to content that's published on the platform, not just things on your device. Remember: they're not interested in your local storage. They want to keep their movies and music off of YouTube, Vimeo, Twitter, and Facebook.
Furthermore, they largely already have the scanning regime they want. Public video sites make absolutely no sense to E2E encrypt; and most sites that deal in video already have a content fingerprinting solution. It turns out it was already easy enough to withhold content licenses to platforms that accept user uploads, unless they agreed to also start scanning those uploads.
(Side note: I genuinely think that the entire concept of safe harbors for online platforms is going to go away, just as soon as the proposals to do so stop being transparently partisan end-runs around the 1st Amendment. Pre-Internet, the idea that an entity could broadcast speech without having been considered to be the publisher of it didn't really exist. Publishers were publishers and that was that.)
But bad people will always have power.
Prior to motorised vehicles and the telegraph for example, borders were almost impossible to enforce on the general population without significant leakage.
Ironically in spite of powered flight, freedom of movement is in a sense significantly less than even 200 years ago when it comes to movement between countries that do not already have diplomatic ties to one another allowing for state authorized travel.
Incidentally, this is part of why many punishments in the medieval age were so extreme - the actual ability of the state to enforce the law was so pathetically limited by today's standards that they needed a strong element of fear to attempt to control the population.
Borders in medieval Europe weren't nearly as necessary because the physical ability to travel was limited. Forget traveling from Germany to France - just going to the next town over was a life-threatening affair without assistance and wealth. Legally speaking, most peasant farmers were property of their lord's manor. But practically speaking, leaving the manor would be quite difficult on your own.
Many churches railed against motor vehicles because the extra freedom of movement they made possible also broke sexual mores - someone might use that car to engage in prostitution! You see similar arguments made today about birth control or abortion.
Prior to the Internet, American mass communication was effectively censored by the government under a series of legally odd excuses about public interest in efficiently-allocated spectrum. In other words, this was a technical limitation of radio, weaponized to make an end-run around the 1st Amendment. Getting rid of that technical limitation increased freedom. Even today, getting banned from Facebook for spouting too much right-wing nonsense isn't as censorious as, say, the FCC fining you millions of dollars for an accidental swear word.
Whether or not a technology actually winds up increasing or reducing freedom depends more on how it's distributed than on just how much of it there is. Technology doesn't care one way or the other about your freedom. However, freedom is intimately tied to another thing: equity. Systems that economically franchise their subjects, have low inequality, and keep their hierarchies in check, will see the "technology dividend" of increased freedom go to their subjects. Systems that impoverish people, have high inequality, and let their hierarchies grow without bound, will instead squander that dividend for themselves.
This is a feedback effect, too. Most technology is invented in systems with freedom and equality, and then that technology goes on to reinforce those freedoms. Unequal systems squander their subjects' ability to invent new technologies. We didn't see this with Nazi Germany, because the Allies wiped them off the map too quickly; but the Soviet Union lost their technological edge over time. The political hierarchy they had established to replace the prior capitalist one made technological innovation impractical. So, the more you use technology to restrict, censor, or oppress people, the more likely that your country falls behind economically and stagnates. The elites at the top of any hierarchical system - aside from the harshest dictatorships - absolutely do not want that happening.
Capitalism is completely compatible with hierarchies and censorship - indeed one could argue that capitalism is completely incompatible with a true flattening of hierarchies since it rests on the ability of an owner class holding a monopoly over the means of production. The majority of dictatorships around the world use capitalism as the basis of it's economy. Following the dissolving of the USSR, Russia continues to be authoritarian and arguably more so than the USSR was past the Stalin era.
Aside from that, I think it's a little premature to frame the internet's ultimate effect on the world as reducing the ability of the government to censor the population when it's only been around for less than 30 years and we are already seeing mass adoption and development of both censorship and surveillance tech that goes beyond even the wildest dreams of 20th century era dictators.
I don't really buy the argument that most technology is invented in systems with freedom and equality either. It just sounds more like something we want to believe than something borne out by data. The internet and rocket ships were the product of the military - an institution that has more to do with using force to enact the will of it's host nation on others and limiting their freedoms than preserving the freedoms of their own, especially for superpowers like the USA and the CCP, which are effectively immune to conquest by military force.
This is in fact the same for the Silicon Valley and most private industry, you only think all this tech is the product of your freedom and equality because all of the actual extreme inequality and lack of freedom is kept compartmentalised to the global south through long and convoluted supply chains. It's not really freedom if only 10% of the actual people involved in the sustaining of an economy have any semblance of it -leaving aside the observation that for even this 10% that represents the average US citizen, their actual democratic agency in the state or in their job is vanishingly low.
First, the Soviet Union didn't have a prior capitalist hierarchy; the whole reason for Leninism as such was that Russia was a feudal, agrarian society, which in Marx's theory had not progressed to the stage of capitalism and therefore could not progress to communism.
Second, food shortages and mass poverty did not end with the establishment of the Soviet Union; in fact, they became enormously worse. Even before being invaded by Germany in WWII, the Soviet system caused the Holodomor, a famine unprecedented in the history of the Ukraine.
Third, the internet has been around for 52 years, not less than 30. I've personally been using it for 29 years, and I can tell you that it already had a long history when I started using it. One of the founders of Y Combinator first became well-known as a result of breaking significant parts of the internet 33 years ago, an event which resulted in a criminal trial.
Fourth, the internet was the product of universities, although the universities were funded by ARPA. Rocket ships have a long evolution including not only militaries but also recreational fireworks, Tipu Sultan of Mysore, Tsiolkovsky, Goddard, the peaceful space agencies, H. G. Wells, and possibly Lagâri Hasan Çelebi.
Fifth, I don't think the argument is that the technology is necessarily produced by systems with freedom and equality, but that it is invented by them. This is somewhat dubious, but not as open-and-shut wrong as your misunderstanding of it. Goddard's rockets were put into mass production as the V2 in Nazi Germany using slave labor, but he invented them at WPI and Princeton. Tsiolkovsky lived in the Czar's Russia and then the USSR, and his daughter was arrested by the Czar's secret police, but he himself seems to have had considerable freedom to experiment with dirigibles and publish his research (but no slaves to build rockets for him), and indeed he was elected to the Socialist Academy.
I think we can make an excellent case that certain kinds of intellectual repression, whether grassroots or hierarchical, fall very heavily on the kinds of people who tend to invent things. William Kamkwamba's family thought he was insane, Galileo spent the last years of his life under house arrest, Newton was doing alchemical research that could have gotten him burned at the stake in Spain, Qin Shi Huang buried the Mohists alive, Giordano Bruno was in fact burned at the stake, and the repression of Lysenko's intellectual opposition was a major reason for the USSR's and PRC's economic troubles in the 01950s and 01960s.
Living in the so-called "global south" (a term which I have come to regard as useless for understanding the world system, if not actively counterproductive) I have to tell you that there's very little production of advanced technology going on here. But I live in Argentina, and the situation is different in different countries; Indonesia, Thailand, Vietnam, etc., have all done significant technical production for the world economy while in the grip of dictatorships, even though Argentina never has. But most countries don't. If tantalum cost ten times as much, we'd still have cellphones, and you probably wouldn't even be able to detect the price difference.
Something strikes me as odd; Why do you say “Russia” but not “Germany”? Why not say “Soviets” or something similar?
Is it because Russia is still portrayed as the bogeyman in the Anglosphere whereas the Germans are cool now?
But what people are afraid of is how little it takes when the technology is there. And how Western governments seem to morph towards that. And how some bastions of freedom are falling
Even a Jew stuck in a ghetto in Nazi Germany enjoyed significantly better privacy at home from both the state and capital than a wealthy citizen in a typical western liberal nation today.
Soviet Russia and Nazi Germany in fact prove the exact opposite of what point you think you're making. They were foremost in using the "magic tech" of their day - telecommunications and motorised vehicles.
Even then, they had several rebellions and uprisings that were able to develop thanks to lacking the degree of surveillance tech found today.
This is incorrect.
Apple has been saying—since 2019![0]—that they can scan for any potentially illegal content, not just images, not just CSAM, and not even strictly illegal.
That's what should be opposed. CSAM is a red herring.
[0] https://www.macobserver.com/analysis/apple-scans-uploaded-co...
1) The list of CSAM hashes is that provided by the relevant US government agency, that is it.
2) The project is not targeted to roll out anywhere other than the USA.
3) The hashes are baked into the OS, there is no capability to update them other than on signed and delivered Apple OS updates.
4) Apple has exactly the same leverage with EvilGov as at any other time. They can refuse to do as asked, and risk being ejected from the country. Their stated claim is that this is what will happen. We will see.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
For example here is a broken PSI protocol in terms of point 3. I don’t think normally in PSI this is considered broken because the server knows the value so it is part of its private set.
Server computes M_s = g . H(m) . S_s
where g is a generator of an elliptic curve, H(m) is the neural hash of the image and S_s is the server blinding secret.
The client computes M_sc = M_s . S_c where S_c is the client ephemeral secret. This M_sc value is the shared key.
The client also computes M_c = g . H(m) . S_c
and sends the M_c value to the server.
The server can now compute M_cs = M_c . S_s = M_sc since they both used the same H(m) values. This allows the server and client to share a key based on the shared image.
However, what happens if the client does it’s step using the ‘wrong’ image. If 3) is to hold it should not be possible for the server to compute the key.
Client computes:
M_sc = M_s . S_c
M_c = g. H(m’) . S_c
The clients final key share is: M_sc = g . H(m) . S_c . S_sNow server computes: M_cs = M_c . S_s = g . H(m’) . S_c . S_s
The secret shares don’t match. But if the server knows H(m’) it can compute:
M_cs’ = M_cs . inv(H(m’)) . H(m)
and this secret share will match
Normally this client side list in PSI is just used to speed up the protocol so the server does not have to do a crypto operation for every element in its set. It is not a pre-commitment from the server.
Also, maybe the way I’m doing it here is just normally broken because it is not robust against low entropy inputs to the hash function.
I've also reversed some of apple's non-public crypto that is used in some of it's services and they have made dubious design decisions in the past they have created weird weaknesses. Without knowing exactly what they are doing I would not try and infer properties that might not exist or trust their implementation.
I think it's hilarious that one of the world' great nations would scan for exactly this.
However, the difference between having a feature enabled based on the value of a seemingly-unrelated user-controlled setting, versus having that feature enabled all the time... is basically zero. Additionally, extending this feature to encompass other kinds of content is a matter of data entry, not engineering. That's the policy angle.
When you don't yet have a capability, it might take a lot of work and commitment to develop it. But on the contrary, policy can be changed with the flip of a switch.
Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.
1. About 3 years ago, there were empty files taking up storage on my iCloud account, and they weren't visible on the website so I couldn't delete them. All it showed was that an excessive amount of storage was taken up. Apple advisors had no idea what was going on and my entire account had to be sent to iCloud engineers to resolve the issue. They never followed up, but it took months for these random ghost files to stop taking up my iCloud storage.
2. Sometimes flipping them on and off a lot causes delays in the OS and then you have to kill the Settings app and re open it to see if they're actually enabled. Back when ATT was just being implemented, I noticed it was grayed out on my phone every time I was signed in to iCloud, but was completely operational when I was signed out. Many others had this issue and there was literally no setting to change within iCloud; it was a bug that engineering literally acknowledged to me in an email (they acknowledged that it happened for some users and fixed it in a software update).
Screwups happen in an increasingly complex OS and I just feel that there will be a day when this type of bug surfaces in addition to everything that already happens to us end users.
OK, but what if Apple silently pushes out an update (or has existing code that gets activated) that "accidentally" sets that number to zero? Or otherwise targets a cryptographic weakness that they know about because they engineered it? That wouldn't require "significant modification".
Funamentally, it's closed software and hardware. You can't and shouldn't trust it. Even if they did do some "significant modification" how are you going to notice/prove it?
I see this number very quickly getting set to '1', because the spin in the opposite direction is "What, so you're saying, people get X freebies of CSAM that they can store in iCloud that Apple will never tell anybody about?"
_That_ is a whole other PR disaster.
After they introduced AirTags I went and disabled item detection on all my devices. Yesterday I went into settings and guess what, that feature is enabled again. On all my devices! I’m not sure when that happened, but my guess would be that latest iOS update caused that…
My point is, you will only have things working to the extent you have testing for, and test coverage is likely less robust for less popular features or where perception tells developers that “no one is going turn that mega-feature off”.
Only images that match the hashes of the database of CSAM held by the National Center for Missing and Exploited Children (NCMEC) that are uploaded to iCloud Photos are checked.
Based on their technical documents, it's not even possible for anything else to be checked; even if they could, they learn nothing from documents that aren't CSAM.
Incorrect. All files on the phone will be checked against a hash database before being uploaded to iCloud. Any time before, which means all the time, if you have iCloud enabled.
A cryptographic safety voucher is created for each photo as they're uploaded. The iPhone doesn't know wether or not anything matched. Nothing happens unless the user reaches a threshold of 30 CSAM images that have been uploaded to iCloud Photos.
Communication safety in Messages is only available for accounts set up as families in iCloud. Parent/guardian accounts must opt in to turn on the feature for their family group. Parental notifications can only be enabled by parents/guardians for child accounts age 12 or younger.
https://www.apple.com/child-safety/pdf/Expanded_Protections_...
If they suddenly start to break you trust - who knows what they will push to that black box next time ? You have no way to tell or prevent that, other than leaving the whole platform altogether.
We don't actually know what is implemented. We only know what Apple's PR machine is saying about it, or do we have the source code somewhere?
There's a very good reason Signal (and previously Whatsapp) were recommended over iMessage.
Not to mention the inability to swap iMessage off for SMS which has made it a favourite exploit target for hacking firms like NSO.
They don't have the keys, so how exactly would they decrypt these messages?
I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data.
And two, opt-out is a dark pattern. Particularly if you surround it with other hurdles, like long click-wrap and confusing UI, it's no longer a fair choice, but psychological manipulation to have users concede and accept.
Third, as it's hinted, smarter criminals, the ones the FBI should actually worry about, will know to opt-out. So instead the vast majority of innocent users have their privacy violated in order to help authorities catch "dumb" criminals who could have very well been caught through countless other avenues.
disclaimer: I just read Bruce Schneier's "Click Here To Kill Everybody" after the pipeline ransomware attack, and these points come straight from it.
I guess some people just see dark patterns where I don’t.
Making things "opt-out", without even making it hard, dramatically increases the number of people who opt-in. It can be used for many reasons.
For example, the UK switched it’s organ donation laws from opt-in to opt-out.
Another example, my government has decided that them selling their citizen's personal information to garages, insurance companies, etc, when we buy cars, should also be opt-out.
So they freely sell the car make, acquisition date, buyer's name,… [1][2]
Unless it has changed with GDPR. I’ve never bought a car.
While we're on the topic of GDPR, that is exactly why it insists on making cookies, tracking, and the "sharing of information with partners" opt-in.
And that is without hiding what you’re doing, making it unclear or confusing, or requiring multiple actions to change it.
(Links in French, sorry)
[1]: https://mobile.interieur.gouv.fr/Repertoire-des-informations...
[2]: https://www.carte-grise.org/actus/2014/05-12-L-Etat-vends-le...
We have, yet oddly, it's still called "organ donation".
Because most often, when there’s even the sliver of a doubt on the deceased one's wishes, the corpse will keep all it’s organs to the grave / incinerator.
How is my will involved here?
Which is the bare minimum if you want others to be able to even consider respecting it.
The default choice being, in the absence of any information, the one that increases chances of survival of actually living humans doesn’t seem misguided to me.
——
If you want compulsory and overreaching (although not necessarily bad. Got no opinion on that aspect) rules, over here we:
- can’t disinherit a descendant. The state decides the minimum each one of your genetic or legal relatives can get from your assets
- have to financially support our adult children until an arbitrary time decided by the law
- have to support and assist our parents and grand-parents if they can’t provide for themselves
- basically can be legally compelled to financially assist any ascendant or descendant
- may end up having to pay up after a divorce, even if you had an iron-clad contract, to compensate for the loss of QoL of the spouse with a lesser income
... and if you do not know that an opt-out is required to not have your organs removed, then how can it be said that you have willingly contributed them. And if your organs are removed by default, without you actually willing that this be the case, then how can this practice be called "donation"?
So instead, shall we call it "organ retrieval", "organ harvesting" and so on? All rather ugly words. But when the words that accurately describe what you are doing appear ugly, instead of looking for words which inaccurately describe what you are doing, perhaps you should ask yourself if you should be doing what you are doing.
And I'd be interested to know of the percentage of UK adults who are aware of the opt-out. I had a search around but couldn't find any surveys, are you aware of any?
"Do you want to enable iCloud photos? Your private photos will be uploaded encrypted to Apple's servers, so that only you can access them. Before uploading, your photos will be locally scanned on your device for any illegal content. Apple will only be notified once a sufficient volume of illegal content is detected."
An option like this, after the lawyers get at it, will be 14 pages long.
"We can change this at any time", "except by court order", "no guarantee", "not liable", and on and on and on...
This would be a large change from the way it works today, where Apple can view your iCloud photos. They’ve not made any statements indicating that is going to change.
It's fine if you know you want to be the sole person in the world who can get to your data and have the discipline to store master passwords, and you accept Apple support cannot help you even if you have a purchase receipt for the device. But for the average older person that's not a good default.
Apple just needs to design good UX to help these people.
Perhaps a large cardboard 'key' comes with every phone. When first setting up the phone, you scan a QR code on it to encrypt your data with the key, and then you tell the owner that of they ever lose the key to their phone, they won't be able to get in again.
People understand that - it's like losing the only key to a safe.
From time to time you require them to rescan the key to verify they haven't lost it, and if they have, let them generate a new one.
I really like E2E encryption of messages with proper backups on my end. It's good to know the carrier of my messages can't scan them for advertising purpose. But for my phone if I know there is no way to easily get the data back if I have an issue that seems like a major hassle with very little upsides.
It's better if the key is generated when you already have the phone.
For even better security they can instead provide an NFC smartcard or hybrid NFC + USB (like a Yubikey) where the key is stored in hardware and can't be extracted.
Everything about Apples messaging makes you believe otherwise. That seems pretty disingenuous.
Then again, 99% of consumers have very little choice that doesn’t include huddles and complicated setup. We all get the same moon goo, under a differ different brands.
Good, bad, or just the fact of life?
iCloud data is encrypted at rest (edit: except for Mail apparently). The type of encryption (service or end-to-end [E2E]) is specified here: https://support.apple.com/en-us/HT202303
It can be argued that from a user's viewpoint not having E2E encryption is tantamount to not having encryption at all, but from a technical standpoint the data is encrypted.
According to the table on the second link iCloud Photos are encrypted on the server (at rest). Am I missing something?
Apple (and thus, LEO) absolutely can look at your photos on iCloud. What you are missing is that "encrypted at rest" is essentially "not encrypted in any meaningful way".
Edit: I also meant iCloud backups in my original post and how Apple can decrypt your E2E encrypted iMessages with the key the backups contain. But I posted it last night and couldn't edit it once I caught the error. It would be amazing for other iCloud services to have E2E encryption so long as the implications of iCloud backups having your encryption keys is stated front and center when choosing to opt-in.
Unsophisticated users who have lost or forgotten their passphrase can recover their data.
Sure it is—just don't use iCloud Photos. They've been quite clear about this.
Even with iCloud off, the other endpoint (the phones you're iMessaging with) will be leaking your conversations to Apple because they will still have iCloud Backup defaulted to on.
iMessage is no longer an e2e messenger, and Apple intentionally preserves this backdoor for the FBI and IC.
They access 30,000+ users' data per year without warrants.
This is mistaken. If you turn off iCloud sync, Apple isn't continuously scanning your phone.
Not to be nit-picky but IIRC, this isn't exactly how it went down. icloud backups have always been decryptable and Apple had announced they were planning on changing this and making them fully encrypted but when pressured by the FBI, they scraped those plans and left them the way they are.
Unless you use iCloud Backup for iMessage, in which case Apple holds the keys to decrypt them.
This is not accurate. Scanning doesn’t happen without iCloud photos enabled.
You can’t turn that off!!
There’s no way to tell the iPhone, “stop with the AI recognition on my photos.”
Since Apple has decided it’s going to categorize all your photos based on AI, it was just a matter of time before they started categorizing some bad stuff.
iOS 15 beta has new recovery option by secret (which is useful only on E2EE?)
And Child Safety was released most likely because the leaks. Motive of the leaks is unknown. They might be waiting for September now.
As far as encrypted backups go, it's an open question whether they want to deal with the legal and support headaches that such a change would bring. If they continued to do nothing, Congress might force their hand by legislatively outlawing stronger encryption - they had to shit or get off the pot.
For users, if you enable this feature, but then lose your password, you are entirely screwed and Apple can't help you. Encrypting "In-transit" as a middle ground is likely good enough for most people, until researchers manage to come up with a better solution.
Exactly the same with the phone if you forget your PIN/passcode. So they already do this.
The amount of money that is spend on their devices is just insane.
Second, my comment was meant in the context of iCloud - if you don't enable the feature as described, Apple may be able to decrypt and recover something, but if you do go all the way to the logical end, yes, you're out of options.