The scanning occurs in order to upload files to iCloud photos. Your device is attesting that data you upload to iCloud photos is not pre-established CSAM. If you do not like the privacy implications of having your content inspected locally, on your device, simply choose another cloud photo provider and turn off iCloud photos.
You are told about the system and you are free to turn the service off. That doesn't sound like a massive privacy invasion to me.
So the chance for a single photo to be incorrectly matched is much higher. But by setting a threshold at ~30 images before triggering a manual review, they get the odds extremely low.
My bet is that error threshold will remain a constant for them. As tech gets better, they will reduce the threshold accordingly to maintain that error rate. In five years, I’m guessing they will only need three images to trigger a review.
You can come up with third party solutions that accomplish some portion of this use case (photo backup) but you'll never be able to accomplish what Apple does with iCloud Photos unless Apple opens its APIs.
It is not possible to write an app on iOS that has permanent, transparent background network and runtime access, and it’s also not clear allowing such apps would be a privacy benefit for users at large. Apple already makes exceptions to this for certain apps (e.g. it seems like my Verizon Wireless app has background runtime). Are you suggesting that Apple should nominate a few photo services receive the same exception?
Android has demonstrated that there is no need to whitelist this. This is purely a lock-in play for Apple.
Not sure what nation state adversaries have to do with a simple question about photo library access.
My argument is that nothing stops a photo sync solution from building much of the relevant stack themselves: you can build MGAssets and get apps to adopt your photo library view controller as an action sheet or use File Provider abstractions to build the same in file pickers. 1Password, eg, offers a direct to 1P button as an SDK for 3rd parties to use. Once you separate out what you can’t do easily because it would take a lot of investment to build yourself versus what actual platform features you’d like to force Apple to build, I think your argument that the latter should be done is even less compelling.
To the extent this is about privacy, the argument is that Apple has created an opinionated regime for scanning user photos using untested technology -- and has (quite correctly, I think) determined that privacy-conscious users should have the right to opt out. The issue here is that Apple's version of "opt out" does not allow users access to the same functionality through third-party cloud providers. Users who opt out for privacy and security reasons will be substantially worse off than users who opt in. This isn't the only reason that regulators should consider revisiting Apple's cloud integration, but it's a new and important one that did not exist before Apple announced this service.
On iOS devices, it randomly stops synchronizing, and it is necessary to manually resume sync. Very annonying; most normal (not-enthusiast) users would be bitten, that they assume their photos are synced, when they are not.
Interestingly, Android devices do not have such issue.
…and now we have a case in point of them doing shady things on our phones. This breaks the trust.
Sure, they could do something else in the future but that’s alway the risk with every update.
But now they /have/, that is the change.
Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady.
Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Apple NDA), is mega shady.
Secretly reporting people to authorities based on unverifiable novel image hashing algorithms and only image "derivatives", whatever that means, that's ultra shady.
Pretending that people are somehow "misunderstanding" if they are alarmed by this unprecedented, unverifiable scanning and secret snitching mechanism being run over their private photos, that's extra ultra mega shady, but typical of Apple.
Look at this shitshow explanation. When have you ever seen Apple being so terrible at explaining a feature? None of this smells right: https://www.youtube.com/watch?v=OQUO1DSwYN0
> Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady.
Would you rather Apple actually directly look at your images? If not then it is a privacy improvement. Because they are legally required to search their servers for this stuff when directed to by the FBI.
> Using that novel on-device scanning capability to secretly report people to authorities, that’s beyond shady.
Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.
> suing any companies that try to analyze the code running, is mega shady.
And not something their actually doing.
> Based on unverifiable
Again false people have been looking at the algorithm used.
No. Why would that be necessary?
I would expect to be reported if I willingly uploaded images matching exact hashes of CSAM to Apple servers. I don't understand why Apple employees would ever be able to, or need to, view my images, and I would expect Apple if it were really a privacy-focused company to never let that happen.
>Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you.
It's client side, that's why we're having this discussion.
This is all a secret process. As I said, Apple employees look at an unspecified number of "derivatives" of people's images in a secret process, and if they tick a box, the authorities get all your data. There's nothing saying how close a "derivative" needs to be to actual CSAM to trigger this process, just "trust us, because children".
No audits, no due process, no mandatory notifying customers that are affected, no notifying of how many total customers were reported every month, just a secret illegal search and snitching mechanism with some crypto mumbo jumbo and "trust us, because children" sprinkled on top.
>And not something their actually doing.
*they're. Yes they are: https://news.ycombinator.com/item?id=28219278
From a comment: > ... “With their left hand, they make jail-breaking difficult and sue companies like Corellium to prevent them from existing. Now with their right hand, they say, ‘Oh, we built this really complicated system and it turns out that some people don’t trust that Apple has done it honestly—but it’s okay because any security researcher can go ahead and prove it to themselves.’”
>people have been looking at the algorithm used.
Who? How? Are you talking about the ones that are gagged by Apple NDA? Link to papers?
As another commenter posted, no amount of spin will make on-device scanning a good idea.
> This is all a secret process.
Those are in contradiction a client side process is inspectable.
As you know, there is a server-side element, the crypto mumbo jumbo makes it impossible to audit which images will trigger the automated snitching mechanism from the secret list of hashes. So it is both a secret process and doing scanning client-side.
Also Apple is busily suing companies who dare to make client-side inspection feasible, as I noted.
"We will not make software that scans files on the device"
and
"We will not allow the software we made to scan for anything other than CSAM"
Under US law it would be very hard to force apple to do the first, but no where near as hard to compel them to change the database they of files they are scanning for...
The U.S. government compelling Apple to make some small process change to this new system wouldn't be a big story by comparison.
Example: A year from now the U.S. government tells Apple they are no longer allowed to review the flagged CSAM imagery themselves but must rather report it directly to law enforcement.
A change most people wouldn't think twice about ("why does Apple need to be the ones reviewing this obscene illegal material anyway") yet would introduce a massive vulnerability into the surveillance process.
You, as a user, can turn off iCloud Photos. But your device functionality will be limited. And you cannot replace that functionality with any third-party alternative that will have the same feature-set and access to the low-level device features: Apple ensures this through the design of their OS and its extensive security features.
There is a version of "you don't have to use iCloud Photos" in which Apple opens their OS to competing cloud services. But you can't say this is an option while also locking the device down to use one cloud provider.
I use Nextcloud and it is a more or less ok user experience; the major inconvenience is that your photo library isn’t available in UIImagePickerControllers. The image preview mechanics you describe can already be simulated with file provider APIs.
Edit. I think my point more simply stated is that if you think turning off iCloud Photos or switching photo sync with another cloud provider “solved” the privacy problem, then you are in the same group of people who are annoyed that they can’t use Spotify with Siri or AirPlay 2. Welcome to the large number of 2nd class citizens on iOS. It’s not great out here, but it certainly doesn’t make the toggle a false choice.
There are several separate questions. 1) Should users have the right to opt out of scanning. Apple have answered (1) in the affirmative: yes, they understand that some users want this option and have designed their system with explicit guarantees that users can do this. This is not an accident or a miscalculation on Apple’s part. They clearly understand that forcing this scanning on non-consenting users is unacceptable and their marketing copy makes this clear.
The second question (2) is whether Apple’s compromise to preserve user privacy (allowing users to disable photo sync while providing no third-party alternatives with equivalent feature sets) is acceptable. Apple presumably thinks it is. I think that disabling Apple’s photo sync features will not be acceptable — and indeed will be actively harmful to some users. We can disagree about whether this matters but this is the heart of the disagreement. Having strong opinions doesn’t settle the question, it just demonstrates that the issue is contentious. Settling the issue requires user surveys and an economic analysis at minimum, not opinions on HN.
Then there is a third point (3): does Apple have any obligation to provide opt-out users with alternative services that bring their devices back to the full functionality that they possessed when the devices were purchased. Your view is that “this is not worth it to Apple.” We do not disagree. My claim is that Apple’s view on the issue is not necessarily the final world on the issue. Apple also believes that they should have a monopoly on app distribution and many other aspects that define the iOS experience. These views are disputed and there is no “correct” answer. My claim is that the operation of cloud infrastructure should be a part of this dispute, and Apple’s decision to make their system “opt in” should be viewed as such in light of the fact that Apple controls essential features in such a way that Apple can effectively hobble the device of any user who declines to consent, with no recourse or alternative available to the user.
I think your response to this has to grapple with Apple’s very clear argument on (1). Which means that “Apple can do whatever it wants because they’re powerful” isn’t a sufficient response. And if the rest of your answer revolves around unsupported hypotheses about what Apple users expected, then you should probably come back with some strong evidence like user surveys to support those claims.
I’m not sure why the burden to do user surveys is on me. Presumably the first order user survey is, “Will our customers abandon us?” which Apple must have done and everything past that is on you to conduct to justify your ask of them.
There are many reasonable criteria under which the proposed model is superior for privacy. Perhaps the only reasonable criteria under which it is not is some kind of scope creep in what files are scanned. (Scope creep in what content is scanned for is a risk - an even greater one as there is no transparency over the hash list - of incumbent solutions as well.)
Now, what seems more likely to you? They suddenly decided to go towards scanning all offline files for no business nor legal benefit, or they tried to respect their own marketing of how their ecosystem should work?
The fundamental issue is that Apple is crossing an important privacy line: my property (my phone) vs their property (their external servers).
It's identical to saying that because USPS (or any mail carrier) is allowed to scan mail that moves through their system, across their property, they should also be allowed to come into my home and scan mail there. Hey, they promise to only look at mail while inside the home, what's the big deal. It represents the same shift: my home vs their shipping infrastructure.
People would universally go ballistic if USPS/UPS/Fedex declared they were going to begin routinely entering homes to examine mail packages before they were sent out. No matter how you dressed that up (they only do it if you print a shipping label first, indicating preparation to send a package through their system), it wouldn't assuage anyone.
Turns out Android can be pleasant when you don't have to deal with oem ui changes and non-optional bloatware.
You cannot photocopy a dollar bill. Kinda makes sense.
https://en.wikipedia.org/wiki/EURion_constellation
Now imagine a "live" neural network running on your phone or camera that prevents you from taking pictures of the Eiffel Tower at night due to "Suspected Copyright Abuse".
https://www.snopes.com/fact-check/photographs-of-eiffel-towe...
Next imagine that a local government issues a digital "All Points Bulletin" which scans all pictures on all phones for a "person of interest in a crime (against the state)", conveniently associated with the emergency alert broadcast network.
First they came: https://en.wikipedia.org/wiki/First_they_came_...
Maybe I can make it clearer.
It is like you are asked or demanded to install some antivirus on your computer, but this is not a typical antivirus , it is not scanning to protect you but to find evidence against you and destroy your life.
A list of facts, let me know if you disagree with the reality or my conclussion
Apple could have scanned iCloud already, why did they not do it so far? Either there is a super low number of CP on iCloud which implies this feature is not needed OR Apple was lazy, incompetent or had some other reason and let a lot of bad guys escape . I would conclude from this that Apple , if they really care of children, should freaking start scanning the existing iCloud images now.
From the above I am inclined to believe that this is not an action to protect the children, the reality does not fit, if there is so much CP on iCloud but Apple just woke up then WTF is that all PR about protecting children.
And for all we know it may have already happened and someone is currently rotting in jail who shouldn't be there.
Middle aged dude raided by cops who find CSAM on their cloud accounts, claims that his phone got hacked. Lying sack of shit pedo, of course he'd say that, right?