> The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, except in this specific case, secured and controlled by your device.
If the CSAM detection were released with encrypted iCloud backups (or generally E2EE iCloud), then I think I'd probably be entirely less outraged. This narrative would make sense then.
Apple claims the on-device CSAM scanning only occurs on device if the photo in question is uploaded to iCloud. Apple is surely already scanning iCloud photos on their cloud, so without E2EE to iCloud, what's the point?
My ability to control a device I own, with Apple, was already suspect. Apple's use of on-device scanning is a slippery slope: it's not a question of if it will be used for nefarious means, but when. The claim that the scanning is only done for cloud-destination images is suspect and could be changed by gagged government coercion and a minor update.
The feature itself has little going for it in efficacy too: like most of the US's punishment bureaucracy / legal system / policing. Real child predators likely already avoid the cloud. These kind of slippery slope arguments against crime are often used by law enforcement to erode privacy rights: they don't actually catch more bad guys, but they do spy on more law abiding citizens.
Who's to say that in the future, law enforcement won't use this kind of technology for the war on drugs or other failed law enforcement initiatives? Law enforcement often uses violence or terrorism, for example, as justification for its own expansion and more privacy-invading initiatives, but terrorism is a very low threat, and only 4% of crimes in the US are violent (as defined by the FBI). CSAM has been used for decades as justification for the state to nose more in private citizens' business too. It's certainly an issue, but there have to be better ways to reduce child harm.