There is no way Apple released their initial PR piece without thinking it through and deliberately fusing all those new features together as one big unassailable initiative. It was typical my way or the highway.
Which also make it funny now that they attempt to distinguish between them and run into same hole that they dug for other people.
But in this case, of course, if you're an adult, the Messages part of this doesn't apply to you at all, and the photos part can be completely avoided by not using iCloud Photos.
Apple:
- Isn't going to be remote work friendly.
- Shut down internal polls on compensation.
- Bows to the FBI, CIA, FSB, CCP.
- Treats its customers as criminals.
- Treats its employees as criminals.
- (Spies on both!)
- Doesn't let customers repair their devices or use them as they'd like.
- Closes up (not opens up) the world of computing. Great synergy with the spy dragnet.
Take your time and talent elsewhere. This bloated whale is bad for the world. There are a lot of good jobs out there that pay well and help society.
There's a facade that we really work for other reasons, and money is just an inconvenient byproduct. During a job interview, you may be asked "Why do you want to work for us?". And for some reason "So I can afford to buy food" is not a good answer.
But usually not solely for the money. And usually there are lines people aren't willing to cross just for the paycheck.
As opposed to what??? Free apple stickers??
Of course we might not know of cases that got resolved by internal pressure, because they got resolved, however we do know this was not one of them.
I don't know what you and tharne are talking about here. There was definitely confusion. HN is a tech forum and I still saw plenty of people here worried about how they would get in trouble for having innocent photos of their own children on their phone. You are allowed to be against Apple's plan while still recognizing that many people didn't understand what exactly was part of that plan.
It was not universally understood that this would only apply to photos sent to iCloud.
It was not universally understood that this was only looking for previously known CSAM.
It was not universally understood that they were using some sort of hash matching so photos you took yourself would not trigger the system.
I understand if you consider the where more important than the others, but it is simply a fact that there was confusion on what exactly was happening here.
This is ignorance in extreme.
To the extent that other parts of this story was explained to us by Apple, I did try to clarify some exaggeration in other thread.
A lot of the contention wasn't about the specifics of their plan, but rather how subtle changes could vastly expand the scope of their plan.
"this would only apply to photos sent to iCloud." for now, until scope creeps.
"this was only looking for previously known CSAM." for now, until scope creeps.
"using some sort of hash matching so photos you took yourself would not trigger the system." well this one is immediately concerning even within claimed scope because there ARE going to be false positives that apple records some database. Millions of iphone users are going to have a non-zero "possible childporn" score.
They are building an engine for iphone users to self-incriminate. If they rigidly hold the scope to only what they announced and never expand, it could be argued that this is a reasonable concession to fight CSAM. However, in making the announcement, they boldly stepped past their existing hard line in privacy (local device content is private and not surveilled by apple), so it seems naive to expect that this announcement reflects the eventual scope of this self-incrimination engine for the next decade of apple updates.
The how helps show us how changing this system is not a subtle change. It isn't like they can flip a switch and suddenly they are identifying new suspected CSAM on people's phones. That would require a new system since the current one is only hash matching.
>However, in making the announcement, they boldly stepped past their existing hard line in privacy (local device content is private and not surveilled by apple), so it seems naive to expect that this announcement reflects the eventual scope of this self-incrimination engine for the next decade of apple updates.
This is an arbitrary line that is being drawn. These are photos that are marked for sending to iCloud. Whether the scanning happens on the phone before they are sent or in the cloud after they sent is largely immaterial when it comes to the impact of the code. People are acting as if the line Apple drew was motivated by technology. That was never the deciding factor. Technology is the easy part here. That line was only a policy line and that policy has not changed. Only photos that are sent to iCloud are scanned. If you fear Apple changing that policy going forward, you should have always feared Apple changing that policy.
This is a strawman. Identifying *novel* CSAM is a very hard problem to do accurately - the reason they can't flip the switch is because they don't have the technical capability. All of the other things people are concerned about are things that apple does have the capability to do.
EDIT to reply since at max thread depth: *novel* image detection was never on the table, I think you missed that word
> This is an arbitrary line that is being drawn.
It seems the vast majority of people in this thread disagree that this line is arbitrary.
EDIT: whether the threshold is "verging on impossible." depends entirely on the effective false positive rate. If apple's claimed 1 in 1 trillion rate is true, it's probably not a concern. However, I find it unlikely that perceptual hashes on portions of images won't have higher false positive rates when subject matter is similar (non-CSAM legal adult porn, or images of children in swimsuits, etc). If that rises to 1 in 1 million for these types of images, that's hundreds of thousands of people being falsely accused.
You just used this as an argument against this system. Why do you fear this if you don't think Apple can even accomplish this technologically?
>It seems the vast majority of people in this thread disagree that this line is arbitrary.
I would argue that people who believe that this decision crossed that line were being naïve to not have always known this was a possibility. I don't think this move brings us any closer to Apple scanning our devices for anti-government memes or whatever the fear is because what was stopping that was always more policy than technology.
Also to go back to your earlier comment, in the time since you posted it has now been revealed that this system needs to trigger 30 times before any action is taken. The odds of 30+ false positives is likely verging on impossible.
Maybe. I wonder how many people are choosing not to respond because they’ll only be voted down by the people who feel very strongly about this. I’ve curtailed and hedged many my contributions to this topic on HN because of this.
This is a common issue when social media is used to debate matters which are highly emotionally asymmetric.
I'm a huge Apple fan and a Mac devotee of 30+ years. I love my iPhone. If this thing becomes real, I will go shopping for another phone.
This is absolute insanity. I can't believe they even thought about launching this.
I'm completely disgusted.
I don't think this is right. The apple pdf on the features says
> With the initial match threshold chosen as described above, iCloud Photos servers learn nothing about any of the user's photos unless that user's iCloud Photos account exceeded the match threshold.
This implies to me that they are using some sort of encryption to prevent iCloud from learning even how many matches there are until the threshold is met.
- Whose fault is it that those points were not clearly communicated?
- Who wrote the perceptual hash matching code?
- Who is allowed to audit the code, the review system, and the hash database?
- Who updates this code?
- Who decides if your phone OS is updated?
- Who decides the iCloud upload defaults?
- Who decides if you are reported?
- Who asked for this feature?
* It was not universally understood that this would only apply to photos sent to iCloud.
Since the scanning doesn't happen on iCloud, this distinction is irrelevant.
"We are going to intrusively scan the subset of your photos that you care enough to back up to the cloud that we've been pushing to you for years" is pretty clear.
* It was not universally understood that this was only looking for previously known CSAM.
It was only looking for whatever is in an opaque database which, according to a third party we don't have any contract with, contains CSAM.
* It was not universally understood that they were using some sort of hash matching so photos you took yourself would not trigger the system.
Yeah right, I feel totally safe knowing that I won't be falsely reported to FBI by a "some sort of" hash matching.
Here's a hash function: f(x) = 0 for all x
It's "some sort of" hash, too.
It’s really not irrelevant. A third party photo library that avoids using the PhotoKit library would not be touched by the CSAM detector. There are many of these on the App Store.
One step further and store the photos encrypted, with a custom renderer that decrypts the content on the heap, and that would take some tremendous performance-hitting detection abilities it’s extremely unlikely to ever happen.
OK.
Misrepresenting each other’s arguments is not how you have a discussion.
I hope that's precise enough, and sure, everyone is welcome to make their own decisions regarding this.
> HN is a tech forum and I still saw plenty of people here worried about how they would get in trouble for having innocent photos of their own children on their phone.
They're confused about this. NeuralHash doesn't look for pictures of naked kids. It looks for pictures that are identical to the ones they've put in their signatures list.
The problem is that Apple claims that the signatures in their list are all pictures of sexually-abused kids, but we have no way of verifying that. Heck, they don't even have any way of verifying that. Everyone just has to take NCMEC's word for it.
The public does not know what the false positive rate is for 'average iphone user pictures'. As engineers we can be certain the false positive rate is not zero. This means that some number of iphone users are going to have non zero "possible child pornographer" scores in the apple database.
The false positive rate is crucial to understanding how concerning this should be. If the average iphone user has 1000 photos, and the false positive rate is the claimed 1 in 1 trillion, there is a 1 in a billion chance that you'll be flagged as a potential child pornographer. (~1 in the world will be falsely accused). This seems reasonable enough with the apple-internal screening step.
If the chunking and perceptual hashing functionally ends up having a much higher false positive rate for images which have similarities to the dataset (parents' pictures of kids playing shirtless, legal adult porn, etc), the false positive rate could actually be more like 1 in 1 million or worse. In which case there are potentially hundreds of thousands of people who will be falsely accused by this system.
How many matches will US judges require before they sign warrants for arrests, search and seizure of digital devices? If they are technically competent it shouldn't only be 1, but I don't trust all judges to understand probability well enough to require multiple matches.
I yet to understand what happens to people who only have those synthetic positives? Regardless of what counter threshold is, can’t those people be hoovered up by a subpoena of counter >0 ?
That's really really really user-hostile design.
Even that doesn't come without issue. How long before '1' becomes the value, because, say for example the number is ten, there's also a horrendous PR spin of "Apple has a high degree of suspicion that you have CSAM on your device, but since there's only 8 images, they won't do anything about it" - "Apple allows up to X non-reported CSAM images on Apple devices" is hard to represent in any positive fashion.
If allowed to go forward, it is only a matter of time before the capability is expanded.
So it's a big no to the scanning capability, you would think that Apple had gotten the message by now.
And the other initiative is also open for abuse, by allowing the device administrator to spy on the user. Admittedly not as bad as the on-device scanning.
EDIT: It has now come out that you need to trigger the system 30 times before Apple acts on it. I can't imagine the odds for someone to have 30 hash collisions.
But I haven't seen any positive discussions about it, which is odd.
I don't like the feature. Putting this on the client device is dubious and should never have made it past the brainstorming stage.
Having said that, technology companies, big and small, are bound in the US to do this. By law. If anything Apple was by far the laggard of the bunch (with reporting counts magnitudes lower than peers, despite a larger customer base). As I said in another comment, no company can protect you from your government.
Much has been made about it being on device, which while a serious optics issue...the hot takes being given on here are manifestly absurd. Like, literally the company that holds all of your data, all of your passwords, all of your info and you need to invent slippery slopes to imagine up what they "might" do?
If they want to have their way with your data, they could have been doing it for decades.
They should never have announced two very different systems at the same time. Contrary to some of the insincere claims given in this very thread, there is massive disinformation and confusion about them. In the end I feel like 98% of the "the end is nigh!" comments are by long time Apple detractors who just see this glorious opening.
And while I still hope that Apple says "Mea culpa, we're just going to scan on the ingress to iCloud Photos", whatever they do in a month this is going to be completely forgotten.
Other companies scan their servers instead. And what law banned E2E encryption?
This potentially means all of iCloud, not just photos, could start to use E2E encryption as well - which is fantastic.
What law do you think banned real E2E encryption?
And I said information. The hash matching is information.
[1] https://www.apple.com/child-safety/pdf/Security_Threat_Model...
They have to scan things that are not photos. What if the bad guys just zip their photos and upload that?
There also needs to be a solution to CSAM uploaded before NCMEC had a chance to tag it, especially to cases where the bad guys uploaded their CSAM and deleted it from their iPhone. What happens then, the bad guys get E2E and nobody can find them? There has to be a technical solution in mind for this, and everything I can think of has implications (Let the iPhone store hashes of deleted images? Would it be enough to scan also during download?)
IMHO, any serious attempt to find CSAM using Apple's client-side approach requires more scanning, and Apple not being forward on that makes me trust them less. Also, the moment they expand the scanning, we should think carefully if there actually are any privacy benefits.
Putting it server side is categorically worse. Putting it in the client SDK for iCloud (architecturally speaking) rather than on cloud storage or in the OS is clearly the better correct technical choice, tying surveillance’s hands in a way server side or OS would not.
Most every client SDK routinely checks content before upload, it’s a best practice. Careful examination suggests this was engineered better than that practice.
(Note: even tech trade posts such as LWN, Stratechery, or Daring Fireball trying to write well about this need to sit down a minute and have how it actually works walked through for them, as do many in this community.)
FWIW, I agree with much of the rest of your post except the rationale for low reporting counts.
It's basically engineering with the goal of creating a perception of privacy rather than actual privacy. I don't really care that much about Apple policing what you upload to iCloud, but this disingenuous architecture does annoy me a bit, and there's also the added insult of having a device in your pocket that by design works against its owner (reminiscent of "treacherous computing"). These problems would go away if they just did the check on the server side.
The architectural reason is to do things the server couldn’t.
> You're uploading a photo to iCloud, encrypted with a key that Apple controls.
The architectural reason is so the server doesn’t have to be able to read the photo, and it need not be a key Apple controls.
Your first two sentences are the exact reason to do it on the client instead of on the server, such that it’s possible to have e2e encryption opaque to the server.
Why? Putting it server-side means that it's only possible to examine the images that they claim they are targeting -- those going to the cloud. That seems like a much better and more private way to do it, because it's putting the surveillance "in their house", so to speak, instead of mine.
The list of apps is such a treasure trove. Signal? Clubhouse? Telegram?
https://developer.apple.com/documentation/security/complying...
I need to research what Signal does on iOS. My next canary is encryption of messaging apps other than iMessage.
Plenty of people believe that the Facebook and Instagram apps are recording audio 24/7 and target you ads based on the speech the apps hear. That doesn't stop people from using the apps.
A few years ago some of the most famous people in their world had their iClouds accounts hacked and had their naked photos leaked. That is a lot of people's worst fear. People literally commit suicide over this sort of thing. It didn't hurt the iPhone's market share.
People largely don't care.
1. The penalty of social ostracism due to the network effect. This is a severe punishment to most humans - particularly in today's socially disconnected world. Without these apps, a large # of people would not have any contact with much of their social circle - including family.
2. Learned helplessness. I think that many people have just given up. Even if they knew how to fight for their privacy, they see time and time again that money always wins.
Who knows how much it will matter in the end? But it is hard to argue it doesn't matter.
Take all the paranoia and “muh privacy” around contact tracing or the European Green Pass: It’s as anonymous as it can be, yet millions of people argue against them across the political chasms that separate them. So yes: unless it becomes a divisive topic (which would be undesirable), this CSAM scanning will go away with the news cycle.
About your comment on celebrities’ “sex-tapes”. I guess it takes a certain kind of extroversion and (positive) narcissism to be one, and they’re expected to be gossiped about or to show their bodies in movies or photos so I don’t think those victims blinked that much - some like P. Hilton probably manufactured some porn to ride the wave. On the other hand, revenge porn did drive ordinary people to suicide because in this case the victims weren’t prepared or expected to let the public to see that.
This is old thinking. In the 90s and 00s it was miraculous to trade in a little privacy for some awesome free service on the internet. Google, Facebook and others became huge, and everyone has been influenced / manipulated by them and people are getting tired of having a family dinner conversation next to their smart speaker and seeing ads for six weeks for Depends diapers because someone told a bad joke at the dinner table.
Disagree.
Something this ludicrously intrusive, over-reaching, reckless and trust-destroying is a dealbreaker for exactly the demographic of technology enthusiasts who influence others purchasing. It may not be instantaneous, but it would certainly propagate.
It's anecdotal, but I know zero people who are NOT reconsidering even lifelong loyalty to Apple over this.
It's just too crazy big a wrong, it's like the company just had a nuke go off inside it and is trying to pretend nothing happened.
They may as well have announced a partnership with Trump to put MAGA engravings on all future products, and then in the ensuing furore say they "regret the confusion", whilst carrying on with it regardless.
Though I suppose in that scenario they'd at least be targeting a significant market.
The same can't be said for the size of "sign me up for software-automated police raids" market. A market whose naiveity-induced initial "size" would rapidly shrink after the first few innocents went down, as they absolutely would.
I mean depending on the targets chat software preferences, could a malicious actor potentially ruin an Apple iOS users life just by sending them an image?
There are many troubling scenarios one could imagine. In fact, there is nothing but troubling scenarios.
It's not a can of worms so much as a wormhole, blasting an endless stream of worms at the speed of light.
I'm left not just questioning Apple's leadership, but - honestly - their mental faculties. Really.
No innocent person wants to walk around with an automated snitch in their pocket - I mean, hacking? Bugs? Oversights? Just the overall preponderance of fear that every millisecond you walk around with this thing, it - and its parent corporation and all the depersonalised machinations that go along with it - could be busy organising a blithely mistaken police raid on your family?
Say, because someone you've never met, sent you a message on that new chat app you forgot you installed, that autosaves all media to your iCloud? Or because someone stole the spare phone you keep in a drawer at work, used it for God-knows what and you didn't even notice it was gone? Or, maybe your teenage son got sent something from his teenage girlfriend who unbeknownst to any of them had her phones images uploaded and subsequently catalogued and flagged? Or any number of other entirely plausible scenarios that provide the very reason we have law enforcement protocols and procedures for reporting crimes and that are complex, nuanced and have evolved over hundreds of years and mountains of cases into a massive structure that exists primarily to protect the innocent from exactly this kind of freaking crazy shit?
And Apple expects people to pay them to carry the weight of all that around with them?
I keep seeing this asserted, but there is never any legal citation. What exactly compels a software company to make their software product scan for CSAM?
I get that a service provider like cloud storage may need to scan what they themselves are storing to avoid possessing such material themselves. And iCloud could scan uploaded blobs all day to fulfill their legal department's recommendation.
But what exactly compels a software developer to include a content scanning function in code they distribute? And does this requirement also apply to the authors of rclone?
Apple only scans photos being uploaded to iCloud photos. Google scans. Facebook scans. Microsoft scans. Even tiny image hosting sites scan.
Apple decided to implement this functionality on device, but they could as easily (with much less fanfare and dissent) have placed it on the ingress to iCloud.
When iCloud scans stored files like Google Drive, nobody complains. It's understandable that risk adverse legal departments have come to the conclusion that doing such things is necessary, to avoid a company being in possession of trivially-discoverable CSAM. And from an individual security perspective, you should consider everything you upload unencrypted to be the subject of similar analysis.
If iOS were to encrypt all files before uploading, making any iCloud scanning mostly pointless, Apple would still not be running afoul of any law. Apple is making general software for end users, and encrypting files to upload would be doing the basic user diligence I alluded to. If users end up using the software to do bad things, those specific users are liable and not Apple.
As far as I am aware, there is no legal requirement for a software developer to modify their software to perform scanning of content it will process while being run by other people. But this is what is implied when you say that Apple is forced to do this by law.
Furthermore if this development was driven by iCloud worrying about legal liability from the combined system, then iCloud should be spun out into a separate company that cannot affect the development of the iOS software.
Law requires reporting CSAM. They are not required to scan for it.
They are surely not required to scan client devices, and that was a foolishly, ill-considered plan (that I still would wager they will abandon), however they absolutely must scan iCloud Photos unless they were technically incapable of doing this. US law doesn't say "you go to jail if you don't", it says "you face enormous liability if you don't".
Those are not US companies but I've never heard of AWS, DO, etc. scanning people's storage either.
Pre-Snowden, that was insourced by the NSA.
Except with an iPhone, you don't have a choice.
I'm tossing the mac and iphone because my phone is mine.
Yep. They just altered that deal. (Darth Vader quote deleted)
Upcoming contenders like Purism [1] and the Pine Phone [2] will start gaining a great deal more traction from this. Other SV firms will sense business opportunity..... If merely 5% of the TAM around mobile is willing to prioritize non-spying features that would be enough to stand up very healthy businesses.
It isn't like an iPhone is very customizable, repairable, or that usable with all the App restrictions Walled-Garden stuff.
I’ll bet you $500 to the charity of your choice that this won’t come to be. Set the terms on how you want to measure the outcome.
Since you want to have a friendly competition around "put your money where your mouth is" will look into whether or not Purism is accepting investments and what the terms are. AAPL valuations are pretty lofty right now at ~$149 a share if you'd be interested in the reverse :)
AAPL closed 90 cents short of an all time high share price today. Why isn’t the market pricing in the loss of market share?
It's a hit to their brand from technically knowledgable people for sure though. When someone asks their tech friend if they should buy Apple, more people will likely say, "yabut," or "nah." We'll see if that makes a difference in a year or three.
To me, it just feels icky. I'm sick of all the spying. I've been in computers since the Commodore. The current computer world is shit because of spying. It killed any passion I had left. It seems like no last vestige of privacy remains.
As for market share, this might barely register on people's radar outside the tech community beyond "Apple is trying to prevent child porn."
There are legitimate privacy concerns, and Hacker News users are right to be upset. But that's not an excuse to pretend like this issue is broadly understood.
1. I don't want to financially support anyone going through my private things in conjunction with what is basically the police, looking for reasons to imprison me. Reasonable suspicion first, thankyou very much.
2. I don't trust them to use this in a politically neutral way. This is too much power.
3. I don't trust them to manage the false positive rate. Everyone knows how reliable software engineers are when they claim a system does something. At heart they aren't 1 in a trillion people.
This is a great time to be outraged. I can't really do much about what they do on their servers, but I can certainly get antsy about what happens on my phone.
They just gave a talk at the USENIX Security Symposium on how this works and the safeguards put in place. The scanning functionality is part of the icloud photo upload module. Security researchers can determine if they change the scanning algorithm in future updates. I don't know what else you can hope for.
Going back to the slipper slope argument, you could say nothing stops them (or Google on Android) from uploading your passcode and share it with X. It's all just software in the end that they write that powers the lock screen and security checks.
If they start claiming they do that then I'll get angry about that too. You'll notice that only the fringe is accusing Apple of being liars or acting in bad faith here. Apple are pretty up front about what they do.
The problem with this plan is they're claiming they are only going to do selective law enforcement (only 1 US law, only things that are strongly supported by consensus and even then only sometimes). That isn't a position with a reasonable foundation, they are going to change their mind. I want them to change it in the "we don't snoop on people's phones" direction rather than open season.
Again, I don't expect them to do this. But they could add a useful level of trust if they were really motivated to do so.
As for no company giving up rights, I did say I didn't expect Apple to actually do this, only that they could. Though, companies do actually make binding contractual promises all the time. It's just that they don't tend to do it with consumers or small businesses who have no negotiating leverage and/or no desire to insist on those promises.
Regarding your hypothetical, anything that's actually legally mandated by the government generally overrides contract law since the courts won't enforce illegal contracts and illegality is a defense to breach of contract. They can always do what the law actually requires.
But we're not talking about the government mandating things, since both the iOS 14 behavior and the iOS 15 behavior comply with the law.
Which means this action is just a charade, as I pointed out. Because fundamentally it doesn't really matter. The gov is going to do what they do, and Apple is not going to create a situation in which an external group can determine how or if they can be sued in court based on how overreaching they feel that day.
Also go check how many arbitration clauses exist in your ToS, just as an exercise. I'm all for banning arbitration clauses and allowing consumers recourse in actual courts. I don't believe we should have companies sign their death sentence prior to doing business, this raises the barrier to entry and results in even less competitors who have to do the same.
I could hope for being able to trust that an intensely personal device such as a smartphone isn't something that I have to be constantly suspicious of.
Admittedly, that ship sailed a long time ago, but I could still hope.
You being able to trust them is a personal choice. It seems people are happy to trust companies that don’t talk about what they do with their data rather than the ones that do. Which, while understandable seems counter intuitive.
You cannot be serious.
Could they write and deploy something overnight that hoovered up everyone's data? Maybe on iOS, less so on OS X, but now they're going to ship with that capability. I don't understand how some people can't see the difference between "they could always push some nasty update," versus literally shipping hardware and software with a backdoor.
Do you know this for certain about any vendor? If a company the size of Apple were pushing the same update to everybody, then it would likely be known about by the world pretty quickly. But... if a targeted signed update is sent to a handful of selected devices, that's harder for the world to find out about. It's risky, but it's definitely technically possible.
But it would be very hard to spot new weights of the neural network and a new list of target hashes. These are pretty much guaranteed to change regularly as they retrain the embedding network and/or change the list of known target images. So it will be very hard if not impossible to see what they're searching for. That latest update could just add the ability to recognize CSAM pictures that had meme texts added to them. Or it could change the embeddings and target list to spot unlicensed posting of copyrighted still frames from movies. Or it could now retrieve any picture of people in police uniform. No way to know if you don't have a hunch and a targeted picture you want to test with.
It's Sir <firstname> or Sir <firstname> <lastname>.
https://www.geni.com/projects/Naming-Conventions-for-Knights...
Let’s compare:
— Apple’s market cap is more than twice of Facebook’s.
— Apple’s user base is less than half of Facebook’s. Even fewer use iCloud Photos (and much fewer upload more than the free 5 GB, shared across photos and other content).
— Facebook is entirely made of UGC with no storage limit for a given user, and their moderators have to review every bit of content to ensure the gore is away from advertising targets’ eyeballs (and, indeed, report CSAM). Apple only needs to review images that trigger multiple hash matches occurring within the same account.
Considering the above, my intuition is that Apple’s NeuralHash would have to be completely broken for a company this size to not be able to afford enough moderators to manage the false positive rate. I sincerely doubt they are so inept, and I’d be willing to live with the potentiality of an Apple employee peeking at a photo of mine once a year (me using Apple tech already implies I trust them enough, as I’d never be able to personally verify every privacy claim they make).
What is worth screaming about, and what is eroding my trust, is the fact that since 2019 Apple’s ToS (quietly changed, presumably, to accommodate this feature currently in the news) give them carte blanche for pre-screening any content that they deem potentially illegal. Unless they tighten up that phrasing to limit it to CSAM only, they’re allowing it to be used as a political prosecution tool.
Edit: Factual error, iCloud Photos does have a free tier.
Anyone trusting Facebook with a level of access to their life comparable to a mobile phone is foolish. There is no way I would pay money for Facebook to control my phone.
If it costs them too much money to have too many people personally looking over every single positive hit to make sure it’s not false, then they’re not going to do it even if they technically could.
I live in a place where the government arrests you for having a VPN installed on the phone and labels you a terrorist outright. My phone is checking with physical frisking on the roadside and content critical of state gets automatic manhandling and trip to the police station where I am treated as a criminal.
How I see this as a problem not because I am not going to buy an iPhone in future, but because such ideology would be made normal. That is what is scaring me
The technical implementation is trying to hide the fact that the design mojo of this system is an actual Backdoor for governments of the world to oppress, censure and do whatever they like.
The technical implementation is optimized towards minimizing the cost for Apple. That's why they scan on the device. And this decision is made with knowledge that in the near future "scanning" will be not limited only to hashes. Scanning and processing will be required for $Some_Cool_Functionality to work.
The same slippery slope applies there.
Something I bet wouldn't have happened when Katie Cotton was in charge. But yeah. Tim Cook thought he need new PR direction. And that is what we got. The new Apple PR machine since 2014.
I googled that name and gawker article from 2014 showed up… and I’m speechless…
Industry is learning from omnibus bills
Five years from now it'll be: "you're wrong"
HN will as usual agree and take pride in being wrong.
I suppose it's great if you're looking for entertainment value. For rational, informed discussion of the technology and its political and social ramifications, not so much. It's just the same refrain of "we never bother to actually RTFA but we imagine a boot stomping on a human face forever."
Most of the commentary on this more recent issue is similarly misrepresented and inaccurate.
I think Apple's mistake here was a PR one, they shouldn't have announced this until they had e2ee ready. Then they could have announced that which would have gotten most of the (positive) press attention. Then they could have gone into details about how they were able to do it while still fighting CSAM.
It wasn’t “one of the most widely accepted and ergonomic grips people use”.
The entire thing was a non-scandal, it wasn’t a real issue. In a lot of ways this is similar.
Compared to their Keyboard which took nearly 3 years before they have a programme for free repair.
We drank the Apple Privacy Kool-aid, and now we are holding them to it.
This is totally a battle worth fighting!
Are you sure? My local Apple store is just as crowded as it was two weeks ago.
I think the pros list stays longer than the cons list.
I needn't be holding child pornography to be concerned about a third party viewing my photos, writing, or other media on a device that is just mine and not published, public content.
The weirdly less discussed aspect of this is that anyone who is storing their images of any kind on someone else’s computer and network thinks that nothing could have been viewed before. If Apple or Google or Amazon want to scan the data you store with them they could be doing it, so if that was a concern for a person from the get go then they wouldn’t have been storing their data with third parties to begin with.
I honestly don't understand why this is a relevant point. It's still surveillance.
> that anyone who is storing their images of any kind on someone else’s computer and network thinks that nothing could have been viewed before
I don't think that's the confusion. I think a huge part of the issue is that the surveillance is not taking place on someone else's computer, it's taking place on your smartphone. Yes, Apple says it only happens if you're uploading to the cloud -- but that's just Apple saying "trust us". If they did the scanning on their computers instead of yours, it wouldn't be necessary to trust them on this point.
My point is we've already been taking the same risks and the only reason it’s something now is because it’s a transparent process. It’s always a “trust us” scenario unless a person routinely scans all software they is and all updates for malicious server calls or some other kind of recording of data and maybe opening of a back door.
Where you put these will depend on your view on a lot of the issues, certainly.
But, in the past decade:
- Every interaction with your primary device is now, by default, an opportunity for aggressive data collection, often in ways even the people who write the software don't know (because they rely on tons of other libraries and toolkits that are doing this quietly under the hood).
- The default is now that you use a smartphone for everything, with the desktop experience limited or turned into a crappy version of the smartphone version (Image! Video! Scroll, scroll, scroll, never stopping, always seeing more ads! Text, who cares about that ancient stuff?)
- The default has gone from "If you're alone in a social space, you talk to other people" to "You stare at your phone." Certainly was a trend before, with the Walkman/iPod/etc, but it accelerated dramatically.
- Everything has been turned into either a subscription service, or a "Free-to-play" world in which the goal is addiction and microtransactions.
There are plenty of benefits of smartphones, but culturally we're exceedingly bad at looking at the opportunity costs of new technology, and they're increasingly becoming harder to ignore.
If you can honestly evaluate the device and decide it's a net positive, great. But I know an increasing number of people, myself included, who are evaluating them and saying, "You know, never mind. They're not worth the downsides."
I’m starting graduate school in the fall. A few weeks ago, I went in to pick up my new college ID card. The security guard would not let me into the building until I downloaded an app called “Everbridge” on my phone and used it to answer a series of health screening questions (ie, have you tested positive for COVID in the past 14 days).
The app was for iOS and Android. There was no web version. There was no option to fill out a paper form. I was not warned in advanced. But I guess it wasn’t a problem for anyone (including me), because who the heck doesn’t have a smartphone? It’s like having a wallet now—an expected requirement for modern life, even in situations when an analog solution could have worked just as well.
Again, I'm at a point where I can be a thorny pain in the ass about stuff like this, but you carrying a smartphone, even though you (presumably?) know it's evil means that people can do things like this - expect you to download some large blob of unknown code that you're going to run.
As long as they don't encounter people who literally can't comply, it's fine. It works for them.
I mean, I would have refused to download an unknown app I'd never heard of, but... if I pull out a clearly-not-a-smartphone, what are they going to make me do? Go down the street to Best Buy, buy a phone, and come back?
What if your phone was too old to run the app (which looks like a steaming pile, based on reviews)?
Unless there was something in the application documentation about "owning a modern smartphone and being willing to install random applications as required by the university," I would have plopped right down, pulled out a laptop, and started making phone calls to figure it out.
But, again, I'm at a point in my life where I can be a thorny pain in the ass about stuff like this without any real consequences.
For the past week (entirely related to this being a kicker of a motivation on top of a bunch of other simmering long term concerns over Apple and the tech industry in general), I've been carrying around a Nokia 8110 4G - also known, for very understandable and valid reasons, as "The Bananaphone." It's quite literally curved and bright yellow.
The world hasn't ended yet...
It's a bit less of a step for me than other people because I'm already pretty cell-phone hostile. My iPhone (I regret buying a 2020 SE to replace my 6S under the assumption that the 6S wouldn't get iOS 15, which it's getting... maybe...) was pretty well nerfed to start with - very few apps, literally the only apps on my homescreen were person to person or group chat apps (Signal, iMessage, Google Chat, and the Element Matrix client, plus phone, browser, and camera in the bottom). Everything else had to live in the app library thing, which increased friction to use it, and I really didn't have much on there.
But that has been shut down except for a few 10-15 minute windows the past week, and I've been trying, very hard, to work out the transition back to a "dumbphone" (or, as we used to call them, a cellphone).
The main pain point so far is that all my messaging apps used to come to a central point on my phone - so if someone wanted to contact me, it didn't matter what they used, it would ping me if I had my phone on me. Now, that's split (my wife is the main party impacted, I'm pretty high lag on other platforms anyway). If I'm out and about, I can get SMS, but not Matrix/Signal/Chat. If I'm in my office, I can get all of them, but would rather not have a long conversation over T9 - except some of them don't do a great job of notifying me, depending on what machines are running and muted at any given time. Etc. I'm still working this out, and some of it is simple enough - add audio notifications to my "Chat Pi" by wiring in a speaker instead of relying on my phone to chirp if I get a message in Chat or element. That my M1 Mac Mini is going out the door at some point gives me added motivation to solve this.
When out and about, I do at least have the option of tethering to the banana - so I could carry some other device that handles more than the phone does (which seriously isn't much). I'm debating between going back to a small tablet (2nd gen Nexus 7 would be a perfect form factor), or something like a YARH (http://yarh.io) of some variety - a little Pi based mobile computer thing that is exceedingly "We didn't invent smartphones"punk.
I'm at a point in my life (professionally, socially, culturally, etc) where I can happily do "You're weird... whatever..." sort of things with regards to technology, and I'm going to pull the thread until I either figure out alternatives, or determine that they simply don't exist and I can't live without them.
I thought you were going to say it's cellular, modular, interactivodular.
And we're on Hacker News. People know about ROMs and how to use them. Get a Pixel and throw Lineage onto it. It'll be at minimum $100 cheaper and the specs are pretty damn close (minor trades in either direction).
Yes, and I've used it. I'll admit, it is nice. Apple is great about things "just working," but there are also costs to that feature. I'm not sure why people think this is the only way to have said convenience. The major difference is just that Apple this convenience is by default. Honestly Google provides most of this by default too.
> I haven't used others and I am telling you how it looks from my point of view.
And I've used both, and telling you how it is from my point of view. Stop having strong opinions about things that you admittedly don't have experience with. It isn't a good look.
> I will have to invest resources to discover the things you talk about.
You had to invest resources to adapt Apple's ecosystem.
> And there are lots of assumptions in the things you suggested, like that I am fine with using Google or Linux,
Well Google, Linux, Windows, and third party ROMs like Lineage are essentially the only other options out there, so I'm not sure I made many assumptions. And of the most popular, for phones your options are most likely to be Google (i.e. Android) or iOS. The only other option is... third party ROMs. I guess for desktop you could in fact develop your own (besides Linux or Windows), but I think this would fall under a third party custom ROM (if phone) or Linux (if computer). Then again, you could be a BSD person or someone that insists it is GNU/Linux. Let's be real, that's just pedantic, you know what I mean. I'm not going to name every alternative (that's impossible), especially since I covered by far the most popular ones, which share >90% of user share. Why do we have to be so pedantic?
I don't know man, the more you're fighting against this the more it seems like you're just saying "I don't want to try something new." That's fine, but just be open about it. I get it, new things are scary, different, and require you to relearn some things. But that's a different argument. Just state that argument if that's what you're trying to say. Don't make me work for it. Just be honest.
I already own a Pinephone but it's not at a point where I'd want to use it as a daily driver. But they're only $150-$200, so worth taking a chance if you don't want an Android alternative. You may end up liking it. I do know people who are using it daily. It's just not for me. Not yet.
If you want to look into the Android alternatives further, this HN discussion about CalyxOS went into some great detail about that OS, and about other alternatives too.
On a side note: I went to Apple site trying to find that page for all those new features and I could not find one (at least by going to obvious places). The way I was able to get it to link in my posts is by googling it… this whole thing is not yet obvious to laypeople.
I guess what I'm saying is, at least for me, this backlash is blurring their entire privacy and security pitch. Apple built a walled garden, told me it was for my own protection, then come to find out the cameras are all pointing to the inside.
Still, I think Apple misjudged the whole cloud vs. device thing in this case. They’ve historically preached a lot about how everything should happen on the users device, not the cloud. I think that got myopic for them, and led them to this decision.
But in this case I think users would be much happier if Apple had just said “under pressure from law enforcement we are now scanning photos when they arrive at the iCloud data centers. If you don’t want scanning don’t use iCloud.” Because it’s not so much the scanning of uploaded photos that has people upset, it’s the fact that the scanning and phoning home is baked into the device itself.
Many people (like myself) are worried about the slippery slope where this is turned on for all photos, since why not? Not all abusers will upload their CSAM content to the cloud, why wouldn't Apple flip a flag in the future to scan everything, including photos and downloaded content? If they are serious about fighting CSAM and have this great privacy preserving platform, I don't see why they wouldn't do this?
The point of the feature is to prevent people from using iCloud to distribute CSAM. If you’re recording it with your phone, it’s no different than using an slr camera. The cloud part is what they’re worried about.
edit: like many comments here already say, reporting doesn’t sound terrible for CSAM, but nothing about the feature guarantees it wont be extended to other kind of content.
Right, which is why it's so utterly baffling that they don't do this scanning server-side instead of client-side.
Also, the matches are supposedly only to actual babyporn pictures. We have 0% way to verify that, as even employees of NEMSEC are not all allowed to view them. Such DBs are often full of unreviewed fluff, and why not unrelated photos entirely, cookware, computer cases, who knows, as long as “some degree of matching” with your photos allows Apple to send a .zip to the police.
In terms of the privacy intrusion, what difference does it make whether the images are scanned on your device or on their servers? They're getting scanned just the same either way.
But if they did it on their servers, it would provide a technical impediment to expanding beyond the use of iCloud, and remove the need to trust Apple as much. That seems like it would be much better for users while still allowing the functionality they claim to be seeking.
That's for now. The first update can change that and you will have no recourse.
What makes you say this? They announced this change after all. Why wouldn’t they announce future changes?
And I don't think that would include photos saved in other apps.
Apple promising not to use the scanner is a weak promise they know they can’t keep (NSLs)
People assumed this opens the door for Apple to alerted of any known file uploaded to its iCloud storage.
IOW, they assumed Apple can check what someone is uploading,1 despite alleged "end-to-end encryption" and a gazilion promises of "privacy".
No one except the people managing the "detection software" know what files the hashes represent.
Theres no way for the owner of an Apple computer to verify what files Apple is actually checking for.
Is this confusion. It sounds more like lack of trust.
1 Mind you, for a majority of computer owners the uploading is likely occuring by default, automatically, outside of the owner's awareness. As opposed to the owner consciously deciding to upload a particular file to a computer in an Apple datacenter. Tech cmpanies know that users rarely change defaults.
Remember how Apple had zero accountability:
https://www.newscientist.com/article/dn26133-jennifer-lawren...
https://arstechnica.com/information-technology/2014/09/what-...
Ricky Gervais' advice made sense. Wonder why he deleted it.
I can't imagine how they thought this would go well.
It's another example of Apple being stuck in an echo chamber and not being able to objectively assess how their actions will be perceived.
How many times have they made product and PR blunders like this?
Apple has spent billions in engineering and marketing to establish themselves as the privacy leader, all wiped away by this idiotic system so full of holes you could serve it on crackers.
Me (Last month): "Apple is taking privacy very seriously. I'm going to vote with my dollars and switch from Android."
Me (This month): "..."
I sold every share the day they announced this.
And that's the crux of the problem.
Limiting the scanner to iCloud is a policy decision one NSL away from changing.
(There are many ways this can be a slippery slope, but we don't have to pretend they could just so what ever body else is doing just as easily and they just want to do it on your phone because they are lazy or whatever. This is a solution to a legitimate problem and also it turns out that people are rightfully worried about what's next; those two facts can coexist)
The second issue is that it will alert authorities.
In regards to CSAM content those issues may not sound terrible. But the second it is expanded to texts, things you say, websites you visit or apps you use it's a lot scarier. And what if instead of CSAM content it is extended to alert authorities for _any_ activity deemed undesirable by your government
Just to be clear, "false positive" in this case means an innocent person is accused of trafficking in child sexual abuse material. It's likely they will be raided.
Sure, that's bad if you're Apple, but it's a lot worse if you're the alleged predator.
Which could also be spun as "Apple allows X freebies of known/highly suspected CSAM on your device before they'll tell anybody".
The amount of PR failure that has gone into all this is huge and multi-level.
From now on, when asked to check whether a user's encrypted phone contains arbitrary content the FBI wants to know about, Apple can no longer say "we don't have a way to do that." Sooner or later, you can bet they will start doing it, whether they want to or not.
If this feature leads to anyone losing their job due to incorrect criminal accusations it will not even make the papers because we expect the accused are guilty anyway. Apple won't shed a tear until there is a class action.
This seems worded to get a Yes answer. So, yes.
It's a big deal because it's unprecedented (to my knowledge) outside of the domain of malware*. Other cloud providers run checks of their own property, on their own property. This runs a check of your property, on your property. That's why people care now. The fact that this occurs because of an intention to upload to their server doesn't really change the problem, not unless you're only looking at this like an architectural diagram. Which I fear many people are.
A techie might look at this and see a simple architectural choice. Client-side code instead of server-side. Ok, neat. A more sophisticated techie might see a master plan to pave the way for E2EE. A net-win for privacy. Cool. But the problem doesn't go away. My phone, in my pocket, is now checking itself for evidence of a heinous crime.
*I hope the comparison isn't too extra. I was thinking, the idea of code running on my device, that I don't want to run, that can gather criminal evidence against me, and report it over the internet... yeah I can't get around it, that really reminds me of malware. Not from society's perspective. From society's perspective maybe it's verygoodware. But from the traditional user's perspective, code that runs on your device, that hurts you, is at least vigilante malware, even if you are terrible.
I see your point here - this is a slippery slope for Apple. However I don’t see how anyone could achieve both purposes - no fingerprint reporting and prevention of CSAM storage on Apple servers.
Also, a practical thing to do is to just not store your photos on iCloud but use something else for sync and backup - there might be a startup opportunity here if enough people care.
iTunes Match is an iCloud service which (if you buy it and opt-in) scans your local on-device music library for copyrighted songs, tells Apple you have them, and then they let you listen to high quality versions of those songs on all your devices. And it's not filename or id3 tag matching, it's doing a fuzzy match that can identify the same song in low quality rips and in different file formats. It would be concievable for them to scan for banned audio lectures, or scan your whole device outside the iTunes library, or change it to check for other copyrighted files e.g. movies. It could concievably be reporting you to the MPAA/RIAA if it finds certain songs along with your public IP address so they can check if that IP address has ever been logged as torrenting those songs. It could "in future" be changed to look for and report evidence of torrenting or movie copying. There's nothing technical or regulatory(?) stopping Apple from saying "people with CSAM on their computers can't use iTunes Match" and making it scan the computer as a condition of use, is there? There's nothing technical stopping a government from asking "can your iTunes Match scan engine report video files in the iTunes library which match popular Tiannamen Square video MD5 hashes?", is there?
I do get that these are not the same seriousness, iTunes Match isn't (so far as we know) scanning to report crime but in so far as "Unprecedented on-device scanning for known content using an opaque database and a closed-source fuzzy-matching engine, it would only take a small change to make it look for other things, governments will definitely pressure them to do that and since they willingly built this system they will definitely agree, and all you can do is trust them", are they not samey enough to be relevant?
At least in the US, the historical distinction between verygood searches and mal searches is given in the 4th amendment: "no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
Of course that has been twisted and stretched before, and this is more of the same. But if literally everything is being scanned, "probable cause" is completely absent from the process. It is a fishing expedition of the exact type that the 4A was designed to prevent.
Also, no one(well, most people) has any issue with photos being scanned in the iCloud. Photos in Google Photos have been scanned for years and no one cares. The problem is that apple said that photos are encrypted on your device and in the cloud, but now your phone will scan the pictures and if they fail some magical test that you can't inspect, your pictures will be sent unencrypted for verification without telling you. So you think you're sending pictures to secure storage, but nope, actually their algorithm decided that the picture is dodgy in some way so in fact it's sent for viewing by some unknown person. But hey don't worry, you can trust apple, they will definitely only verify it and do nothing else. Because a big American corporation is totally trustworthy.
Because that doesn’t sound correct to me…
Ignoring the nasty aspects of doing that kind of work, I don't see any way to buttress the fact that Apple has taken another step on the universally one way street of ever increasing surveillance. And whataboutism in the form of "oh but other cloud providers are already doing this" is an extremely weak argument because I don't want to use other cloud providers. I liked Apple, because irrespective of their real motives (ie money), they seemed to be privacy focused. The backhanded way they tried to sell this "feature" shows that they are just as bad as the others.
Apple's solution to this problem is that their employee will actually verify the picture before sending it to authorities. Which again, is one of the problems people have with this system.
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
I think what people are getting riled up about is not the technical ability, it’s the lack of restraint, the willingness to search through everyone’s personal stuff on their phones. This is like the cops sending a drug-sniffing dog into everyone’s home once a day, with the excuse that it is privacy-preserving because no human enters the premises, and that only truly bad people will get caught. There is a difference between scanning in the cloud and scanning on device. One is looking through your stuff after you’ve stored it in a storage unit, and the other is looking through your stuff while it is still in your home. Apple’s excuse is that you were going to move it anyway, but somehow that doesn’t actually excuse things.
If I own my data, someone processing this data on my behalf has no right or obligation to scan it for illegal content. The fact that this data sometimes sits on hard drives owned by another party just isn't a relevant factor. Presumably I still own my car when it sits in the garage at the shop. They have no right or obligation to rummage around looking for evidence of a crime. I don't see abstract data as any different.
> (f)Protection of Privacy.—Nothing in this section shall be construed to require a provider to—
(1) monitor any user, subscriber, or customer of that provider; (2) monitor the content of any communication of any person described in paragraph (1); or (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b).
Which is exactly why these policies are so dim witted.
Dragnet violation of everyone’s privacy while anyone even remotely sophisticated can easily evade it by just encrypting the data upfront.
This has been mentioned on here before, but it's known CSAM possession that's illegal. Apple keeps your files encrypted until its algorithm thinks your encrypted file is too similar to CSAM, and then it decrypts it and sends it to Apple for review. There's a few things here.
- The algorithm is a black box, so nobody knows how many false positives it hits.
- Apple's willingness to decrypt files without the consent of the owner makes the encryption seem like a bit of a sham.
- I imagine many are skeptical of Apple's ability to judge CSAM accurately. If I take a photo of my kids in a bathtub, is that CSAM? What about teenagers in a relationship sharing nudes. The law is a blunt and cruel instrument, and we've gotten away without hurting too many innocent people so far because the process is run by humans, but computers are not known for being gracious.
So we know for sure they're not just using PhotoDNA?
> If I take a photo of my kids in a bathtub, .....
Kinda the same question. If they're using PhotoDNA, then that's not really a risk, right? Isn't this technology well understood at this point?
- There's a system to catch CSAM that is either PhotoDNA or something that works similarly.
- There's a system to detect novel nudes, and notify parents if their children view them.
I think I got these two mixed together.
That's fair. Apple did a shit job of explaining themselves, and it has been compounded by a lot of misinformation (deliberate or not) in response. I'm trying really, really hard to moderate my reaction to this whole mess until I feel like I actually understand what Apple intends to do. I don't make platform jumps lightly.
You could argue that a minecraft server is technically in possession of CSAM if that's the case, but you could spend an infinite amount of money looking at various possible sequences and are bound to find many more false positives than true positives.
Services should have a duty to report CSAM when they notice it, but the lengths they should go to search for CSAM should be limited by cost/benefit and privacy concerns.
This type of scenario is what happened with the messaging service Kik, which was reportedly used to distribute CSAM in private chats. Law enforcement agencies said the company wasn't providing timely responses and that children were being actively abused as a result. This is about as damaging of an accusation you can leverage against a company.
Laws against CSAM worldwide are not going away for good reasons, so there is always going to be a justifiable argument that storing certain classes of data is illegal. Hence, anyone wanting to run a cloud service that stores user data will have to obey by those laws, regardless of how proactive they are in scanning for the material. Absolute privacy in the cloud is impossible to achieve with those rules in place.
Let’s not beat about the bush, if someone wants to store information in a form that can’t be decrypted by Apple, they can. This is a stupid dragnet policy that won’t catch anyone sophisticated.
Apple focused the last years pitching themselves as the tech giant who actually cares about privacy. They seemed to be consciously building this image.
To now implement scanning of private information and then try and sell this obvious 180degree slippery slope turnaround in the most weasel worded “but think of the children” trope is an insult to the customers’ intelligence.
I was a keen Apple consumer because I felt that even if their motivation was profit, this was a company who focused on privacy. It was a distinct selling point.
I certainly won’t be buying more Apple products.
For me, Apple lost the main reason to buy their stuff. If they are going to do the same thing everyone else is doing, I refuse to pay the premium they charge.
They are scanning images on iPhones and iPads prior to uploading those images to iCloud. If you're not uploading images to iCloud, your photos won't be scanned -- but if you are using iCloud, Apple will absolutely check images on your device.
From Apple's Child Safety page:
> Apple’s method of detecting known CSAM is designed with user privacy in mind. Instead of scanning images in the cloud, the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations. Apple further transforms this database into an unreadable set of hashes that is securely stored on users’ devices.
> Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the known CSAM hashes. This matching process is powered by a cryptographic technology called private set intersection, which determines if there is a match without revealing the result. The device creates a cryptographic safety voucher that encodes the match result along with additional encrypted data about the image. This voucher is uploaded to iCloud Photos along with the image.
Yes, they will check the images you have chosen to upload. No ‘scanning is involved’.
Claiming this is ‘scanning users devices’ is just dishonest - it’s obvious that it creates a false dichotomy impression of what they are actually doing.
Don’t do that.
Frame it the way you want. It is the device.
If you say Apple is scanning the device, you are lying. They are not scanning the device. They are scanning photos chosen for upload.
Suppose we know there are people who smuggle drugs on airplanes on their person for the purpose of something terrible, like addicting children or poisoning people. If I run an airport I could say: to stop this, I'm going to subject everyone who flies out of my airport to a body-cavity search. Tim, and Craig, are you OK with this? If I can say, "Don't worry! We have created this great robots that ensure the body cavity searches are gentle and the minimum needed to check for illegal drugs," does it really change anything to make it more acceptable to you?
I was just pointing out a falsehood you wrote about what is actually being done.
Anyway, someone in here can accept what the other can't, so let's leave at that and let history tells.
If Chrome scanned downloaded files for viruses and you described that to someone as "scans your computer for viruses" do you think the listener would come away with an accurate understanding of what was happening and accurate understanding of what they were and were not being protected from?
If BestBuy GeekSquad offered a service to "check your device for problems" and all they did was open your photo collection, would you walk away arguing that it proves the screen and mouse and CPU and disk must function and nobody could expect them to do any more than that, service provided, full marks, that's "the device" checked? Or would you hope that "checking the device for problems" might involve at least exercising all the major features like speakers, wifi, bluetooth, at least once, and preferably with stress and thermal tests?
When the TSA ask you to switch your device on to demonstrate that it's not a bomb, are you on the side of "if the screen lights up, the device is thoroughly and effectively tested and cannot contain anything else" or on the side of "an attacker could make up many ways to make the screen glow while hollowing out the insides, this does not really demonstrate that 'the device' is safe"?
"Device scans photos" and "Apple scans device" imply two very different things about how much is scanned, and you're using the latter because you know that if you describe it accurately readers won't be as panicked as you want them to be.
>They are scanning photos chosen for upload
That's pretty much scanning on the device.
That is different from scanning the device. Saying they are ‘scanning the device’ is a lie.
Yes, Apple could scan the device in future. It’s still a lie to say they are doing it now.
>Yes, Apple could scan the device in future. It’s still a lie to say they are doing it now.
Puh..i am relieved now...wait i don't even have a apple product.
EDIT: For Question below
https://technokilo.com/apple-child-safety-feature-third-part...
>Apple didn’t announce any timeframe about when will they implement child safety features in third-party apps. Apple said that they still have to complete testing of child features and ensure that the use of this feature in third-party apps will not bring any privacy harm
Do they? Where have they said that?
Were you aware of that when you posted it?
The Q&A mentioned has no date or time. No Apple Spokespeople are named. There are no actual quotes. No well known news outlets have mentioned this very consequential detail.
This has all the indicators of a fake.
I'd call that photo scanning... and they are scanning the photos on the device.
This isn’t some ambiguous case that needs to be addressed philosophically. They aren’t scanning anything other than the photos being uploaded.
When people say that the device is being scanned for pictures, they know what that means. So it is fine for them to say that the device is being scanned for pictures.
This is about the 16th time I have seen language just like this used to explain away this concern. I don't know if you realize, but this wording makes it sound like you can select some photos and leave others local. I can find no indication anywhere, including on my phone, that iCloud Photos is anything other than an All Or Nothing singular toggle in iCloud settings. If you have instructions to the contrary, I will be happy to stand corrected.
Seriously, everybody is wording it like this. "Photos you choose..." and similar.
If you intentionally make someone think that anything other than the photos they are uploading are being scanned, then you are deceiving them.
Deceiving people to make your point doesn’t help anything. It just makes you a liar and the other person misinformed.
If this is a massive privacy violation in itself, then you shouldn’t need to exaggerate it.