Apple already scans iCloud Mail for CSAM, but not iCloud Photos
9to5mac.com
9to5mac.com
For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material.
My problem is the use of my own device to run the scan. It's a waste of system resources. Presumably, a trivial software update down the line could expand its ambit to locally stored files. And we have the issue of Apple being compelled to run searches for non-CSAM hashes.
I'll restate what I posted on another thread about this [0]. There should be a clear, bright line here.
----
In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms:
There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blows right past that line.
Our tools before the computing revolution, and our devices after, become a part of us. Our proprioception extends to include them as part of "self." A personal device -- a tool that should be wholly owned and wholly dependable, like pen and paper -- that betrays its user, is a self that betrays itself.
We have a word for what Apple is installing on your device: spyware. And it's worse than typical spyware in that it's using your device to spy on you and report its findings back to law enforcement.
But to your theme — there’s no clear bright line in client SDKs.
Devs do not think of these or handle these as if they belong to the user.
If you study the cesspool of user tracking and other privacy violations on iOS devices, it’s mostly developers using the same client-side SDKs across their apps, and users none the wiser.
Sometimes devs also have no idea. At least, they profess surprise and drop these SDKs when the user behavior harvesting is pointed out to them.
For whatever reason, everyone’s OK with this.
Perhaps the line is too blurred between client and server, thanks to emergence of concepts like node.js (“run same code on client or server”) that make this sound like a feature.
Or maybe it really shouldn’t matter where the code runs provided it respects boundaries, or better, those boundaries of intentionality and access are technically guaranteed inviolate.
The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos.
You are told about the system and you are free to turn the service off. That doesn't sound like a massive privacy invasion to me.
…and now we have a case in point of them doing shady things on our phones. This breaks the trust.
Sure, they could do something else in the future but that’s alway the risk with every update.
But now they /have/, that is the change.
Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady.
Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Apple NDA), is mega shady.
Secretly reporting people to authorities based on unverifiable novel image hashing algorithms and only image "derivatives", whatever that means, that's ultra shady.
Pretending that people are somehow "misunderstanding" if they are alarmed by this unprecedented, unverifiable scanning and secret snitching mechanism being run over their private photos, that's extra ultra mega shady, but typical of Apple.
Look at this shitshow explanation. When have you ever seen Apple being so terrible at explaining a feature? None of this smells right: https://www.youtube.com/watch?v=OQUO1DSwYN0
> Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady.
Would you rather Apple actually directly look at your images? If not then it is a privacy improvement. Because they are legally required to search their servers for this stuff when directed to by the FBI.
> Using that novel on-device scanning capability to secretly report people to authorities, that’s beyond shady.
Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.
> suing any companies that try to analyze the code running, is mega shady.
And not something their actually doing.
> Based on unverifiable
Again false people have been looking at the algorithm used.
No. Why would that be necessary?
I would expect to be reported if I willingly uploaded images matching exact hashes of CSAM to Apple servers. I don't understand why Apple employees would ever be able to, or need to, view my images, and I would expect Apple if it were really a privacy-focused company to never let that happen.
>Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.
It's client side, that's why we're having this discussion.
This is all a secret process. As I said, Apple employees look at an unspecified number of "derivatives" of people's images in a secret process, and if they tick a box, the authorities get all your data. There's nothing saying how close a "derivative" needs to be to actual CSAM to trigger this process, just "trust us, because children".
No audits, no due process, no mandatory notifying customers that are affected, no notifying of how many total customers were reported every month, just a secret illegal search and snitching mechanism with some crypto mumbo jumbo and "trust us, because children" sprinkled on top.
>And not something their actually doing.
*they're. Yes they are: https://news.ycombinator.com/item?id=28219278
From a comment: > ... “With their left hand, they make jail-breaking difficult and sue companies like Corellium to prevent them from existing. Now with their right hand, they say, ‘Oh, we built this really complicated system and it turns out that some people don’t trust that Apple has done it honestly—but it’s okay because any security researcher can go ahead and prove it to themselves.’”
>people have been looking at the algorithm used.
Who? How? Are you talking about the ones that are gagged by Apple NDA? Link to papers?
As another commenter posted, no amount of spin will make on-device scanning a good idea.
> This is all a secret process.
Those are in contradiction a client side process is inspectable.
As you know, there is a server-side element, the crypto mumbo jumbo makes it impossible to audit which images will trigger the automated snitching mechanism from the secret list of hashes. So it is both a secret process and doing scanning client-side.
Also Apple is busily suing companies who dare to make client-side inspection feasible, as I noted.
"We will not make software that scans files on the device"
and
"We will not allow the software we made to scan for anything other than CSAM"
Under US law it would be very hard to force apple to do the first, but no where near as hard to compel them to change the database they of files they are scanning for...
The U.S. government compelling Apple to make some small process change to this new system wouldn't be a big story by comparison.
Example: A year from now the U.S. government tells Apple they are no longer allowed to review the flagged CSAM imagery themselves but must rather report it directly to law enforcement.
A change most people wouldn't think twice about ("why does Apple need to be the ones reviewing this obscene illegal material anyway") yet would introduce a massive vulnerability into the surveillance process.
You, as a user, can turn off iCloud Photos. But your device functionality will be limited. And you cannot replace that functionality with any third-party alternative that will have the same feature-set and access to the low-level device features: Apple ensures this through the design of their OS and its extensive security features.
There is a version of "you don't have to use iCloud Photos" in which Apple opens their OS to competing cloud services. But you can't say this is an option while also locking the device down to use one cloud provider.
I use Nextcloud and it is a more or less ok user experience; the major inconvenience is that your photo library isn’t available in UIImagePickerControllers. The image preview mechanics you describe can already be simulated with file provider APIs.
Edit. I think my point more simply stated is that if you think turning off iCloud Photos or switching photo sync with another cloud provider “solved” the privacy problem, then you are in the same group of people who are annoyed that they can’t use Spotify with Siri or AirPlay 2. Welcome to the large number of 2nd class citizens on iOS. It’s not great out here, but it certainly doesn’t make the toggle a false choice.
There are several separate questions. 1) Should users have the right to opt out of scanning. Apple have answered (1) in the affirmative: yes, they understand that some users want this option and have designed their system with explicit guarantees that users can do this. This is not an accident or a miscalculation on Apple’s part. They clearly understand that forcing this scanning on non-consenting users is unacceptable and their marketing copy makes this clear.
The second question (2) is whether Apple’s compromise to preserve user privacy (allowing users to disable photo sync while providing no third-party alternatives with equivalent feature sets) is acceptable. Apple presumably thinks it is. I think that disabling Apple’s photo sync features will not be acceptable — and indeed will be actively harmful to some users. We can disagree about whether this matters but this is the heart of the disagreement. Having strong opinions doesn’t settle the question, it just demonstrates that the issue is contentious. Settling the issue requires user surveys and an economic analysis at minimum, not opinions on HN.
Then there is a third point (3): does Apple have any obligation to provide opt-out users with alternative services that bring their devices back to the full functionality that they possessed when the devices were purchased. Your view is that “this is not worth it to Apple.” We do not disagree. My claim is that Apple’s view on the issue is not necessarily the final world on the issue. Apple also believes that they should have a monopoly on app distribution and many other aspects that define the iOS experience. These views are disputed and there is no “correct” answer. My claim is that the operation of cloud infrastructure should be a part of this dispute, and Apple’s decision to make their system “opt in” should be viewed as such in light of the fact that Apple controls essential features in such a way that Apple can effectively hobble the device of any user who declines to consent, with no recourse or alternative available to the user.
I think your response to this has to grapple with Apple’s very clear argument on (1). Which means that “Apple can do whatever it wants because they’re powerful” isn’t a sufficient response. And if the rest of your answer revolves around unsupported hypotheses about what Apple users expected, then you should probably come back with some strong evidence like user surveys to support those claims.
I’m not sure why the burden to do user surveys is on me. Presumably the first order user survey is, “Will our customers abandon us?” which Apple must have done and everything past that is on you to conduct to justify your ask of them.
There are many reasonable criteria under which the proposed model is superior for privacy. Perhaps the only reasonable criteria under which it is not is some kind of scope creep in what files are scanned. (Scope creep in what content is scanned for is a risk - an even greater one as there is no transparency over the hash list - of incumbent solutions as well.)
Now, what seems more likely to you? They suddenly decided to go towards scanning all offline files for no business nor legal benefit, or they tried to respect their own marketing of how their ecosystem should work?
The fundamental issue is that Apple is crossing an important privacy line: my property (my phone) vs their property (their external servers).
It's identical to saying that because USPS (or any mail carrier) is allowed to scan mail that moves through their system, across their property, they should also be allowed to come into my home and scan mail there. Hey, they promise to only look at mail while inside the home, what's the big deal. It represents the same shift: my home vs their shipping infrastructure.
People would universally go ballistic if USPS/UPS/Fedex declared they were going to begin routinely entering homes to examine mail packages before they were sent out. No matter how you dressed that up (they only do it if you print a shipping label first, indicating preparation to send a package through their system), it wouldn't assuage anyone.
You can come up with third party solutions that accomplish some portion of this use case (photo backup) but you'll never be able to accomplish what Apple does with iCloud Photos unless Apple opens its APIs.
It is not possible to write an app on iOS that has permanent, transparent background network and runtime access, and it’s also not clear allowing such apps would be a privacy benefit for users at large. Apple already makes exceptions to this for certain apps (e.g. it seems like my Verizon Wireless app has background runtime). Are you suggesting that Apple should nominate a few photo services receive the same exception?
Not sure what nation state adversaries have to do with a simple question about photo library access.
My argument is that nothing stops a photo sync solution from building much of the relevant stack themselves: you can build MGAssets and get apps to adopt your photo library view controller as an action sheet or use File Provider abstractions to build the same in file pickers. 1Password, eg, offers a direct to 1P button as an SDK for 3rd parties to use. Once you separate out what you can’t do easily because it would take a lot of investment to build yourself versus what actual platform features you’d like to force Apple to build, I think your argument that the latter should be done is even less compelling.
To the extent this is about privacy, the argument is that Apple has created an opinionated regime for scanning user photos using untested technology -- and has (quite correctly, I think) determined that privacy-conscious users should have the right to opt out. The issue here is that Apple's version of "opt out" does not allow users access to the same functionality through third-party cloud providers. Users who opt out for privacy and security reasons will be substantially worse off than users who opt in. This isn't the only reason that regulators should consider revisiting Apple's cloud integration, but it's a new and important one that did not exist before Apple announced this service.
Android has demonstrated that there is no need to whitelist this. This is purely a lock-in play for Apple.
On iOS devices, it randomly stops synchronizing, and it is necessary to manually resume sync. Very annonying; most normal (not-enthusiast) users would be bitten, that they assume their photos are synced, when they are not.
Interestingly, Android devices do not have such issue.
So the chance for a single photo to be incorrectly matched is much higher. But by setting a threshold at ~30 images before triggering a manual review, they get the odds extremely low.
My bet is that error threshold will remain a constant for them. As tech gets better, they will reduce the threshold accordingly to maintain that error rate. In five years, I’m guessing they will only need three images to trigger a review.
Turns out Android can be pleasant when you don't have to deal with oem ui changes and non-optional bloatware.
You cannot photocopy a dollar bill. Kinda makes sense.
https://en.wikipedia.org/wiki/EURion_constellation
Now imagine a "live" neural network running on your phone or camera that prevents you from taking pictures of the Eiffel Tower at night due to "Suspected Copyright Abuse".
https://www.snopes.com/fact-check/photographs-of-eiffel-towe...
Next imagine that a local government issues a digital "All Points Bulletin" which scans all pictures on all phones for a "person of interest in a crime (against the state)", conveniently associated with the emergency alert broadcast network.
First they came: https://en.wikipedia.org/wiki/First_they_came_...
Maybe I can make it clearer.
It is like you are asked or demanded to install some antivirus on your computer, but this is not a typical antivirus , it is not scanning to protect you but to find evidence against you and destroy your life.
A list of facts, let me know if you disagree with the reality or my conclussion
Apple could have scanned iCloud already, why did they not do it so far? Either there is a super low number of CP on iCloud which implies this feature is not needed OR Apple was lazy, incompetent or had some other reason and let a lot of bad guys escape . I would conclude from this that Apple , if they really care of children, should freaking start scanning the existing iCloud images now.
From the above I am inclined to believe that this is not an action to protect the children, the reality does not fit, if there is so much CP on iCloud but Apple just woke up then WTF is that all PR about protecting children.
And for all we know it may have already happened and someone is currently rotting in jail who shouldn't be there.
Middle aged dude raided by cops who find CSAM on their cloud accounts, claims that his phone got hacked. Lying sack of shit pedo, of course he'd say that, right?
And backing up one level, this is why I’m finally working hard to take control of my devices and data from companies like Apple. This most recent episode shows that “a trivial software update” such as the one in iOS 14.3 can introduce this on-device scanning where non existed before. We knew it was possible of course, but now we have a clear cut example of it. They’ve lost my trust and that’s that.
Exactly how I feel. I used to cautiously kinda trust Apple's so-called "commitment" to privacy, but this change just shows us that any such promises are purely theater.
Now that the damage is done, I doubt it can be undone, especially in my case. My opinion on Apple's credibility has crashed through the floor. In my opinion, they're now as untrustworthy as Google or Facebook.
I'm starting to look at companies to see if they meet these must-haves:
1. E2E encryption
2. Open source hardware and software
Everything else is "nice to have". The current options out there are missing a lot of "nice to haves", but they will get better. I'll be a vocal customer telling them what I want.
Same here. There's a finality to this, closure.
I'm done reading about it, nothing more I need to say about Apple. I just purchased a System76 laptop and am ditching my MBP. I've been a Mac Addict for 20 years and now I've outgrown Apple. Privacy is a human right.
What I'm wondering now is "how do I replace my iPhone, AirPods, and iPad?"
Ask HN: Do you use Purism, PinePhone, or Fairphone? https://news.ycombinator.com/item?id=28216287
Ask HN: Do you use a Linux-first laptop? (System76, Librem, Dell XPS Dev Ed) https://news.ycombinator.com/item?id=28216287
I haven't tried them, though the Sony ear buds look like a great option to AirPods: https://www.sony.com/lr/electronics/truly-wireless/wf-1000xm...
As far as the tablet goes... I dunno. I haven't tried an android tablet and I'm not too keen on it. Maybe a Surface? The iPad is damn good at what it does...
And yeah, iPad...
Pinephone has options: https://pine64.com/product-category/tablets/
As for 'alternatives' like you listed towards the bottom, I fully recommend setting up your own Nextcloud instance. It's a really versatile little thing, capable of hosting your photos/documents/music/whatever from a decent online interface (or WebDav, if you're a nerd.)
https://madebyjamie.design/articles/2021-08-20-advocating-fo...
Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.
If you take as an axiom that mainstream businesses will be forced to protect themselves against contributing to CSAM distribution, then the choice to offer encrypted cloud storage to non-technical end users REQUIRES doing the scan on a trusted computer (Apple has chosen the phone itself).
I think the arguments that this can be abused are very real, but it's worth talking about how to fix that, because I think the alternative might be sacrificing E2EE cloud storage in the mainstream (as has happened with every other mainstream company). Perhaps more thought should be put into making this process auditable by the device owner (or by a trusted 3rd party -- say the EFF).
Or perhaps the scanning could be federated -- say I don't want Apple doing that, but I might trust a privacy oriented non-profit to "certify" to Apple that my personal photo album is CSAM-free. Can that 3rd party scan be blinded, such that I send data that is representative of my images, but I've already anonymized my photos using a transformation?
Could we audit (similar to certificate transparency):
1) What data from the device is being scanned? What data is being uploaded?
2) What "hashes" are being matched against, and how are those changing over time? Can the data lineage of the NCMEC database be audited? Would that pick up malicious hashes injected into the database?
Generally, I think our privacy paradigm needs to be built in such a way that it can actually be deployed in our policy environment. More realpolitik, less ethical grandstanding.
I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA.
These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.
Well, I can share a link to them and others can see them, including anonymous users. Just leads me to believe that either they aren’t or if they are, they have the key.
Poverty and power imbalance is what harms children the most, by far. But we can't tackle that without stepping on the toes of greed, so we do circus instead.
If they want to scan cloud storage, by all means. But I shouldn't have to have my device bogged down with this extra pointless computation.
Edit: Thank you all for your replies. I don't share the exact same concerns as some of you but I appreciate you sharing your thoughts/reasoning. I really did what to know what people thought about this in the context of an E2E iCloud-* and it's been hard to pick that out of all the other discussions.
(My take is that if I can't trust Apple when they say this is the case, I also can't trust that they're not already being made to scan all my photos locally, so...)
CSAM today, political materials another. This could also be used to identify whistle blowers, reporters' sources, and more.
I'd hate to have gay porn on my iPhone in a Sharia law state.
Or images of tank man in mainland China.
Imagine when the detector extends to not just files. Things typed or said.
This is a steep cliff, and we're drawing closer to the edge.
The Chinese government forcibly installs spyware on people’s phones today. What Apple does or doesn’t do is of no consequence to them.
And that makes this okay? You're defending this use against us too.
Does the US government have the power to order Apple to scan everyone’s phones for politically undesirable images?
I don’t think so.
The generous interpretation is that Apple moved this on-device to preserve user privacy. They just miscalculated the response to an admitted backdoor.
Sure but this is equally true now as it will be after they deploy the CSAM detector.
It’s not a real argument against the detector.
This is my only complaint. I don't care what you do on your own cloud, don't try and force my device to do the heavy lifting especially when the activity is not in my own interest.
When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.
It's still a valid way to advertise the company because I trust Apple more than I trust Google or Microsoft, who are Apple's biggest competitors. I'd much rather use Apple's cloud integration than Google's or Microsoft's within their operating systems as well.
But don't think they don't have any data on you. Apple knows about as much about you as Google, but Apple keeps the data to themselves instead of selling access to advertisers. Always consider the possibility that the Apple four years down the line might not have the same ideals as the Apple of today or yesterday. We've seen Microsoft slide from a "you pay money, we give you software" to a "free software if you hand us your data" model and there's no reason why Apple couldn't choose to do the same.
Good point about changing of Apple leadership. Tim Cook has said that 10 years from now he won't be the Apple CEO. That means someone new is coming in.
I purchased a Linux-first System76 laptop and will switch out my other iDevices. It's not just about Apple - any sort of closed source software/hardware just seems unsustainable long term. Having "trust" in organizations seems misplaced.
Until a company is more powerful than the government I'm not sure how anyone can have an absolute assurance of privacy from a corporation.
I think that people generally understand what's going on and where this might lead us in the future.
So they had to come up with some kind of solution that:
1. Keeps the government happy enough that they don't pass terrible legislation.
2. Keeps Apple's servers from storing illegal content.
3. Keeps Apple from being involved in the subpoena process.
4. Maintains user privacy – because that's the whole point of this exercise.
I genuinely think if people understood how they accomplished this they would see that Apple accomplished two of the objectives (1, 4) and will eventually accomplish #3 as well.
But back to keys. Your device has a master key for decrypting the photos, and that's always been the case. What I'm about to talk about Apple's servers only, and not your device:
Imagine the two-key system required to launch a nuke, or the big Hollywood bank vault that requires two people to simultaneously get retina scans. "Shared Key Encryption" is the same idea – no one person with a key can decrypt the target. What's cool about this is you can have as many keys as you want, and all of them must be present in order to decrypt the contents. How many keys is Apple using? Well in this particular encryption layer, they are using ~31 keys, and Apple only has ONE.
If we stop right there, you can already see how this is way more secure. A government cannot compel Apple to hand over your unencrypted data. Apple has been able to do this in a much simpler way for a long time, but not without causing the government to pass counter-legislation in response. They haven't implemented better security before this for that very reason.
So where do the other keys come from? They are generated anytime a match is found in the CSAM database on your phone. Even that database is hashed, so your CSAM database and its hashes are unique from every other iPhone user. If there is no match with the CSAM database for a particular image, the keys for its decryption are never generated. Meanwhile each time CSAM match is made, another of the 31 keys gets generated. So in a (super over-simplified) way, the "bad" images are keys for each other. This is why Apple has set a "threshold" for how many CSAM images must be detected before Apple is notified. They have to meet that threshold in order to have all the keys to be able to decrypt all the offending images. Even then, all other images in your account still remain encrypted and inaccessible.
All of this keeps the government happy enough to keep the bad legislation at bay. It's not a perfect solution, but it's better than the alternative, and it results in greater privacy than we have today.
Unless/until I see technical documents showing why there is a privacy issue for people who don't have CSAM, I am 100% in favor of this solution.
> Unless/until I see technical documents showing why there is a privacy issue for people who don't have CSAM
For me, it's about trust. Why not just do the scanning on their servers? With moving the scanning to the client, they've crossed the Rubicon. Apple has built a generic, automatic reporting tool for content on phones, which to my knowledge hasn't existed to date. On top of that, they've set the example that it's acceptable to perform client-side scanning.
Today it's against CSAM, but what about tomorrow? What will happen in authoritarian countries? Prior to this, I believe Apple had the high ground and could say, "we don't have the capability to scan devices and exfiltrate data". But now, it's there.
Perhaps you may say that this is the "slippery slope" argument, and maybe it is. I hope it never expands to include other things. Though I have a hard time imagining that this doesn't get expanded in the future.
One caveat is that according to this article out today, Apple was not scanning iCloud Photo Libraries for CSAM previously: https://9to5mac.com/2021/08/23/apple-scans-icloud-mail-for-c...
"Apple has confirmed to me that it already scans iCloud Mail for CSAM, and has been doing so since 2019. It has not, however, been scanning iCloud Photos or iCloud backups."
Perhaps that DIY processor fab discussion is worth a re-read.
Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208
HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315
Apple has a history of modifying devices that people bought in ways they didn't want and could not change (like putting a non-removable News app on their computers), but the CSAM episode shows Apple is willing to do a lot more, and more importantly, explained this to users who didn't care about the past abuses.
There is no abuse here.
I wonder if the “you know they already do this server-side, right?” people feel the slightest bit chastened.
Of course Google and Gmail (as an obvious example) are not law enforcement so they can specify the terms of privacy when you sign up, scan your email if they wish, etc.
The expectation that personal correspondence should remain private is centuries old. In the 1750s, for example, Postmaster Benjamin Franklin instituted a policy forbidding postmasters from reading individuals’ letters.
So it is dismaying that the Postal Service, the Inspection Service and the DOJ are not upfront with the public as to when they feel fit to open private mail.
https://www.rstreet.org/2014/11/19/yes-the-government-can-op...
Electronic mail does not enjoy enhanced protections over regular mail. Arguably, as electronic mail is sent through a chain of third parties without an envelope, the expectation of privacy is less.
Email is like postcards: “privacy” depends on being one in a sea of items, and a postal worker averting their eyes.
We ought.
But in my country I once received a piece of physical mail from a more important institution in a more special (but not shady) country and the mail literally arrived open. I realised this is how people under communist regimes must have felt.
It makes absolutely no sense to scan people's photos that they aren't sharing with anyone else. Why are they bothering with scanning people's photo backups at all?
With the exception of "shared photo albums", I don't see why they're doing this.
See [1] 18 USC 2258A, relevant part below.
(f) Protection of Privacy. Nothing in this section shall be construed to require a provider to— (1) monitor any user, subscriber, or customer of that provider; (2) monitor the content of any communication of any person described in paragraph (1); or (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b).
Or here's another cite in plain English-
... for CSAM, to hold platforms liable, the government would have to prove that they did not take action when they knew federally illegal content was on their sites. The law doesn’t create an obligation for platforms to go out and proactively monitor... [2]
[1] https://www.law.cornell.edu/uscode/text/18/2258A [2] https://freedomhouse.org/article/qa-social-media-regulation-...