[1] https://appleprivacyletter.com/
[2] https://act.eff.org/action/tell-apple-don-t-scan-our-phones
[3] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
As of right now, is there even a database other than the one NCMEC has? I suspect they are waiting for the NCMEC to spin up its European branch.
A decade ago, all those things were on the Internet worldwide.
https://www.bbc.com/news/world-asia-china-57759480
Many of the closed WeChat accounts display messages saying that they had "violated" Internet regulations, without giving further details.
The account names have also been deleted and just read "unnamed".
"After receiving relevant complaints, all content has been blocked and the account has been suspended," the notice said.
The crackdown is the latest example of what some call growing intolerance toward the LGBT community. Last year, Shanghai Pride week, modelled on Pride events in the West, was cancelled without explanation after 11 years of it going ahead.
In 2019, the Oscar-winning Freddie Mercury biopic Bohemian Rhapsody was released in Chinese cinemas, but references to the Queen singer's sexuality and AIDS diagnosis were censored.
In 2018, Weibo said all posts related to homosexuality would be taken down, although it backtracked after massive outrage.
I have a theory about this that isn't politically correct, but here goes. This has nothing to "conservative values" or homophobia or whatever you call sexual repression in places like Arkansas and Afghanistan. It's not based on religion or culture. It's just the CCP running an actuarial table.
The CCP is a blunt force instrument. It realized some time ago that the one-child policy had left it holding the bag on taking care of a rapidly aging population without enough young people to power the economy in 10-20 years. Not only that, you couldn't easily just repeal the policy and expect a baby boom. They took a look at Japan and realized they were about to hit a demographically driven, deflationary wall. So the party planners moved from repealing the 1CPolicy to actually offering cash bonuses for second children. This volte-face happened within a few short years. But it didn't work as well as expected. Their sudden magnanimous gesture didn't bump their 5-year plan's crop of new Han for a few reasons: A shortage of women (unexpected consequence of the 1CP), more women in the workforce who don't want to have children, video game culture which makes young men stay home instead of going out and impregnating girls -- which is why they're now limiting screen time, gender fluidity / queerness which suppresses baby-generation, and of course western individualism, the great bugbear of "harmony," which encourages people to wait for love and financial stability before having children. At the end of 5 years of encouraging people to have babies, they don't have enough babies. So now they have to get harder on the edge cases.
It's probably safe to assume that gays and lesbians represent at least 10% of the Chinese population as they do in most countries. So that's what, 120 million people? Let's say half of whom are young enough to have at least one child? So we're talking about an extra 30-60 million children if you can somehow get a replacement rate.
That's what I believe all these recent moves by the CCP have been about. And banning test study programs? Same thing. No point having more babies if you're also getting overproduction of elites. They need construction workers and factory workers. And someone was told, we ain't gonna become Germany by bringing them in from Tajikistan, so take this data and figure out how to squeeze as much Han production as possible out of it in the next 5 years.
In the West we have already tried to force LGBTQ people to accept the behavior of their assigned sex. Result? Increased suicides, depression and drug use.
Obviously, after decades/centuries of failure we finally decided to recognize the reality of the facts: you cannot force people into a heteronormative life, nor to make children.
They are in for a hard failure.
This is not even remotely the same as the Taliban banning music or China cracking down on LGBTQ stuff.
> Christopher Rufo reported[2] that 30 public school districts in 15 states are teaching a book, Not My Idea, that tells readers that “whiteness” leads white people to make deals with the devil for “stolen land, stolen riches, and special favors.” White people get to “mess endlessly with the lives of your friends, neighbors, loved ones, and all fellow humans of color for the purpose of profit,” the book adds.
> There are plenty of other examples that prove racial essentialism and collective guilt are being taught to young students. In Cupertino, California, an elementary school required[3] third graders to rank themselves according to the “power and privilege” associated with their ethnicities. Schools in Buffalo, New York, taught students[4] that “all white people” perpetuate “systemic racism” and had kindergarteners watch a video of dead black children, warning them about “racist police and state-sanctioned violence.” And in Arizona, the state’s education department sent out[5] an “equity toolkit” to schools that claimed infants as young as 3 months old can start to show signs of racism and “remain strongly biased in favor of whiteness” by age 5.
[1] https://www.washingtonexaminer.com/opinion/yes-critical-race...
[2] https://twitter.com/realchrisrufo/status/1413292881264005126
[3] https://www.city-journal.org/identity-politics-in-cupertino-...
[4] https://www.city-journal.org/buffalo-public-schools-critical...
[5] https://www.washingtonexaminer.com/news/arizona-education-ba...
From here[1]:
> Christopher Rufo, a prominent opponent of critical race theory, in March acknowledged intentionally using the term to describe a range of race-related topics and conjure a negative association.
> “We have successfully frozen their brand — ‘critical race theory’ — into the public conversation and are steadily driving up negative perceptions,” wrote Rufo, a senior fellow at the Manhattan Institute, a conservative think tank. “We will eventually turn it toxic, as we put all of the various cultural insanities under that brand category. The goal is to have the public read something crazy in the newspaper and immediately think ‘critical race theory.’”
[1] https://www.washingtonpost.com/education/2021/05/29/critical...
When it comes to teaching children Not My Idea, definitely seems to be more to the concern than just shadows:
The fallacy of ‘whiteness’ https://www.bostonglobe.com/2021/08/08/opinion/fallacy-white...
> According to recent reports, public and private elementary schools across the United States have used, as part of racial equity education, an illustrated children’s book called “Not My Idea,” in which a devil with a pointy tail offers the young reader a “contract binding you to whiteness.” The contract promises “stolen land,” “stolen riches,” and “special favors”; in exchange, whiteness gets “your soul” and power over “the lives of your friends, neighbors, loved ones, and all fellow humans of COLOR.”
I looked at some of the illustrations of "Not My Idea"... it's a bit wired and cringe worthy sometimes. Still compare that to the indoctrination that is in some of the schoolbooks:
Slavery was just "black immigration" https://www.theguardian.com/education/2021/aug/12/right-wing...
The kkk was not morally wrong ... ?? https://www.nbcnews.com/politics/politics-news/texas-senate-...
Banning of Black and Latino Authors https://www.mcall.com/news/pennsylvania/mc-nws-pa-banned-boo...
Teaching creationism: https://www.arkansasonline.com/news/2021/apr/08/house-advanc...
Are you as outraged about that as you are about a fringe law theory?
Can you name numbers comparing how many books with problematic woke content are used versus the books mentioned from the guardian?
These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong. Each of these stories (dubiously) explain and obsesses over some aspects of the world, and ignores other aspects completely.
No, its not.
Though there is a mythic anti-”Critical Race Theory” story created by the American Right, and the thing within it called “Critical Race Theory” is a (particularly incoherent, because a number of unrelated and opposing things from the real world that share only that they concern race, and they are disliked by the American Right, and they are not actually Critical Race Theory, are jammed into it) mythic story.
> These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong.
Actual critical race theory (like critical legal studies, from which it stems) holds the existence of objective features of social structures, with tangible, material, effects.
Like many hypothesized social phenomenon, the complexity of the systems involved may make falsification difficult on a practical level, but the claims it makes are fact claims which are objectively true or false.
I'm also always surprised how little US citizens know about their own history. Ask somebody about "Birth of a Nation" and see what they can tell you about it.
Ask them if they know about the "Pro American Rally" in 1939 and see what they say.
These things are not taught in school and it's a shame. I know what I'm talking about I'm German and I hated our history education in school as we were discussing the 3rd Reich nearly every year. Yet, reflecting on it and seeing that the same stupid ideas get a hold today again, it was not nearly enough. We should have taught more. The same holds for the German colonial history (that was not covered and is changing slowly).
If you don't know your past, you are condemned to repeat it.
https://www.washingtonpost.com/local/education/150-years-lat...
https://www.theguardian.com/education/2021/aug/12/right-wing...
Not quite. Rufo knows what CRT is, and importantly, what shares the same problems CRT does. That is to say, different branches of the same general ideology that operate on different topics. The CRT model is kinda like ideological lego, you can just plug in a topic). The demon is legion and has many names. Rufo's stuff is mostly about calling woke thought in general CRT, since the name stuck. I haven't yet seen Rufo label things that aren't wokeness or influenced by wokeness CRT.
It's the same kind of thing as when we call Catholicism, Eastern Orthodoxy and all the Protestant sects "Christianity" even though they are not the same, or how we still call Zen "Buddhism" even though it lacks the supernatural component of its older cousins. None of those things is the same, but they share a family resemblance, they have a character to them that makes them unique among the sea of ideologies, religions and philosophies. Rufo's nailing "CRT" to that family resemblance, because the family is there, the demon is real, and it needs a name to be talked about usefully, not a legion of them.
30 school districts (out of how many?) use a book Rufo doesn't like.
Any reason why anyone, aside from Rufo, should care?
Half of the nation doesn't teach sex ed because skyperson doesn't like when people bang without signing an exclusive banging agreement in public first. Half the nation teaches kids that the Confederacy was formed to protect "states' rights", carefully omitting that the right in question was to own black people as livestock[1]. But hey, 30 districts use a white-people-bad, and that's the real problem.
And what does the last part of your comment (about AZ) have to do with anything? Telling educators that 5-year-olds can absorb shitty beliefs is now a cOnTrOvErSiAl tHeOrY?
I don't even know where to start here, let's set this one aside.
So, let's focus on this question first: assuming the book you mentioned is bad, which percentage of pubic schools use it, and in which way?
[1] TX is my go-to example. They were teaching that slavery was a "side issue" in the Civil War when I was living there in 2010-2017.
I'm not even going to bother dissecting the bullshit they peddle these days. Feel free to dig in.
Texas oversees 1,247 school districts. Tell me more about the problem of CRT in schools though.
https://www.smithsonianmag.com/smart-news/texas-will-finally...
> this is happening and it's good
Rufo is trying to create the world's biggest molehill.
[1] https://ballotpedia.org/Public_school_district_(United_State...
Indeed, the NCMEC database does not have an especially good reputation, much like MCMEC themselves.
ICMEC is a fork of NCMEC.
So...
a) a bad actor is going to target someone, and have the resources to generate enough collisions that(b) look like CP, but aren't CP? but are close enough (c) to pass human review and cause an investigation so (d) they need the hash collisions to look like CP, but not be real CP? or ????
If a bad actor wants to frame someone, it's easy to do this today - hack their system or home network, open it to the internet, place the photos, call the FBI and report an anonymous tip, with the URL where it is hosted and open to the internet. Don't need hash collisions.
Hacking someone's iPhone (How do you get the photos on there without forensic logs that they were added?) or iCloud so that you can place hash collisions that look like crap and fail to pass the review doesn't make sense and leaves too much of a trail. Oh? And someone won't notice thousands of photos just added to their phone?
A bigger threat would be deepfake CP. When that becomes a reality, it will be a mess, because an attacker could theoretically generate an unlimited amount of it, and it will be extremely difficult to tell if it is authentic. Those hashes wouldn't be in the CSAM database, but if the attacker put them out on a server to be taken down, they would get added eventually and then show up in a scan elsewhere.
But I'd be pretty horrified (and definitely call my attorney, Apple, and local FBI field office) if thousands of CSAM images just showed up in my iPhone photo stream.
Edit: Downvotes are fine, and I completely understand other arguments against this, but this one has just not made sense to me...
Edit: Downvotes because?...
For example when CIA/NSA tools leaked, one of them had precisely this purpose.
Conversely, the governments of the world get to keep trying, over and over.
It's significantly harder to develop collisions for an algorithm you cannot inspect or obtain the output of.
(well also, emailing actual CSAM is way easier and mostly just gets the sender reported)
You're exposing the hashes to the world, you're not able to E2E encrypt anything if you need to server side scan, which you probably do since trusting the client no matter what is generally bad in potentially adverserial situations, and you get all this negative press and loss of reputation and potentially pressure from governments around the world to use this for other ends. Cui Bono?
The second scan applies only for those images which are flagged as positive, which are then accessible by Apple. This is applied to detect adversarial hashes. The rest of the images stays encrypted. So, indeed on-device scanning is the only way to enable at least partial E2EE with CSAM detection.
Yes, this was PR failure Apple. They rushed the announcement because of the leaks, and secondly they thought that people will understant the system when they did not. There is too much misundersting. That scanning for example is built-in so deep into the iCloud pipeline, that one does not simply change the policy for scanning the whole phone.
On a technical level I think you're correct. As a holistic approach to the problem, I still disagree. This is too cute for its own good. The PR misunderstanding is a symptom of that.
>The second scan applies only for those images which are flagged as positive, which are then accessible by Apple.
In the end, Apples software is scanning all of the images, why is it any more privacy respecting to do it this way? I guess reasonable people can disagree on that, personally I wasn't fully aware of the cloud side scanning either, and I don't think the public was either. This is similar to Snowden's revelations, if you were paying attention you probably already knew a lot of that, but the incident made everyone aware of it in a very blunt way.
>The rest of the images stays encrypted
I think this is unclear, Apple can still decrypt those other images, how else could you view them in a browser?
This goes back to what Stratechery said about capability vs policy.
Obviously there is change coming to iCloud. Otherwise whole PSI protocol is pointless.
Tangentially, I think keeping their servers clear of illegal material is actually Apple's main motivation. This, in turn, supports claims made by nay-sayers that Apple could scan for other types of images/content in more repressive countries (but not necessarily report the people who did it). However, this assumption also contradicts arguments that Apple will start scanning for pictures of (e.g.) drugs, or weapons. Such images are not inherently illegal and therefore of no interest to Apple.
My guess about this whole debacle is that - with pressure from the government to scan their cloud storage - that this is the alternate scenario to avoid giving up (or being forced to) the "encryption" guarantees of their cloud. I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
Saying that I can maybe see a way the pressures are on this doesn't mean that I'm saying this is a good solution though. Clearly technically implementing this is opening a can of worms that can't really be closed again and makes a lot of other scenarios "closer".
Also, evidently, people are a lot more comfortable with the idea of them actively scanning stuff people store in the cloud than transmitting the information in a side channel so they don't even need to handle decrypted data without a hit.
This is exactly the case. https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
> I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
They have master keys that can be used to decrypt almost everything you upload. They can be compelled to decrypt and turn over information on anyone. Another (unsourced) comment in this thread indicated they do so 30,000 times per year. The new encryption scheme will effectively stop this for photos, and no doubt other files in the future.
Apple's side will begin using shared key encryption, which will require ALL ~31 keys to decrypt the offending images.
The decryption keys are only generated on-device, and only from a hash that results from a CSAM match. The other photos, simply won't have the decryption keys generated, so they don't even exist.
As an interesting side note, this means that a person who surpasses the CSAM threshold will still only reveal the images that actually match the CSAM database. Every other image, including those that have CSAM unknown to authorities remain encrypted. This is hardly a big win for the big scary government. They now have far less ability to search for evidence of any other crimes. You could upload video of your bank robbery to iCloud, and as long as your personal device remains secure, nobody will know.
Even if that was a goal (and I would argue they have a hard stance against it), this system as built is not usable for that.
While they can scan locally, every step of recording, thresholds, and subsequent automated/manual auditing is built to require content to be uploaded to iCloud Photos.
Even assuming that is true that iCloud is trivially “hackable” - and as I understand it, that was never clear how those leaks happened - how does uploading to iCloud help when it specifically needs to be uploaded from the users phone along with the scanning metadata.
In fact, isn’t apples proposed implementation here the _only_ cloud service that protects against your proposed attack - while other clouds scan stored data and can be triggered by your attack, Apple’s requires you to upload specifically from a registered phone on their account; data stored on-cloud is never scanned.
The response to this is “yeah but then a human will review it and nothing will happen to the victim of the attack, because it’s just some slightly blurry ordinary images”. But it ignores to entirely likely harms that could result from that.
1) Law enforcement use it as the basis of getting a search warrant, but conveniently leave the bit about the alerts being false alarms off the warrant application.
2) The list of people who have had CSAM alerts is inevitably leaked to the public, and the victim has to spend the rest of their lives explaining to people like employers why Apple flagged them as possessing child sexual abuse material.
At the end of the day, all the gaslighting about “no potential for inadvertent harm” is bs, because it’s my device, so get lost. Go run your anti-privacy software somewhere else, imo.
- Law enforcement doesn't get _anything_ unless it triggers a large number of images that match the perceptual hash
- It also needs to match a -private- perceptual hash, that isn't distributed to devices, and so we don't have a reliable way of generating collisions for or even knowing that collisions are generated
I mean this whole thing is bad enough on its own without having to artificially manufacture extremely specific scenarios and extrapolating from there to invent hysteric conclusions.
But you’re right though, the possibility of the list being leaked and ruining countless innocent lives is the much more likely of the two scenarios I described.
In that case, nothing is stopping them from scanning everything already uploaded anyway, and nothing is stopping them pushing code to your device to scan it without telling you about it. Nothing is stopping them or the government from making these "lists" anyway.
I'm not saying you (or anyone) should trust Apple, but if you already don't - then this changes literally nothing.
Feel free to respond to my point about the alert catalog inevitably being leaked and ruining lives. Or you could just have a go at gaslighting me a little more if you prefer.
- Send colliding images
- image gets uploaded to icloud automatically
- image _also_ collides with private hash <- completely unclear how this happens
- Only the colliding images are looked at by apple and are determined to be innocent
- user goes on a list (This is an imagined scenario)
- User is reported to law enforcement even though the images are innocent (This is an imagined scenario)
- Law enforcement uses this hypothetical report to file a warrant (This is an imagined scenario)
- Law enforcement uses the hypothetical warrant to extract images that are completely innocent, and somehow build a case around this
- The "List", which is entirely a hypothetical of yours, "leaks" (This is an imagined scenario)
Which also requires:
- Apple does not counter the meaning of "the list"
- Apple is not sued for vast quantities of money
I expect the first argument is that none of this matters as long as "the idea" is out there, the reputational damage is already done. Except if that's true, then none of this is necessary at all, just make the accusation.
So, sure, continue to thread the needle between "They are automatically sending all information to the government, so promises are meaningless" and "This new process, on top of them potentially sending all information to the government, somehow makes it worse".
I mean, this is all a million times more difficult and less likely than just, like, sending them CP in the first place. Or uploading it to their Gmail or any other cloud they use. Or just send a report that they have it to the police without actually doing anything.
All it requires is somebody to send somebody else a colliding image.
This will send an event to Apple. There is nothing imaginary about that, it is exactly how the system works.
Now that Apple has this information, the only thing left is for it to be leaked or compromised in some way.
This is much simpler than the scenario you’ve described, because they require the attacker to first commit the crime of possessing CP. Its also possible to do without tipping off the victim in any way.
Apple, in case you didn’t know, is a company that had already been the source of a couple of the most notorious data breaches ever (and has somehow managed to so far avoid getting “sued for vast quantities of money” for them).
What you’re trying to do here is quintessential gaslighting.
And again, there is the whole fact that you received the email and there is a log that you received it.
Additionally, the images sent to review are significantly downscaled versions of the original & could easily be made to be ambiguous.
The most difficult challenge in this SWAT story is that Apple has a secret secondary hash that's checked on a collision. That's the part of the SWATting story that feels difficult on a technical level. However, there are also really smart people out there so it wouldn't surprise me if a successful attack strategy is developed at some point given time.
No one is going to be prosecuted on "significantly downscaled ... ambiguous" versions of original fake images with a hash collision that flagged a review and was handed to the FBI accidentally because a "minimum wage" fatigued person passed it on.
I get the counter-arguments, but the hash collision thing is just, sort of... weird? I even get the argument that an innocent hash collision may have your personal and private images reviewed by some other human - and that's weird. But I can't really see it going further (you'll be arrested and sentenced to life in prison from the HASH COLLISIONS!).
It's just using technical terms to scare people who don't understand hashes and collisions and probability, and not really founded on reason.
Which typically will be a court case, or at least questioning by police. This can be quite a destructive event on someone's life. Also, there's no mechanism for whitelisting outlined in the paper, nor can I imagine a mechanism that would work (i.e. now you've got a way to distribute CP by abusing the whitelisting fingerprint mechanism or you only match exact cryptographic hashes which is an expensive CPU operation & doesn't scale as every whitelisted image would have to be in there).
Also, your entire premise is predicated on careful and fair review by authorities. At scale, I've not seen this actually play out. Instead either the police will be underworked & not investigate legitimate cases (too many false positives) or they'll aggressively police all cases to avoid missing any.
Even if uploaded to iCloud (such as pictures sent via WhatsApp by default), and above the threshold, they would still be scanned by a second algorithm and subject to human review. So, your "very simple" attack fails on at least three counts.
(I think) the complaint is: how is that different from just using CSAM images, no collision required?
And, to at least respond to two obvious counter-arguments I've looked into:
"But it's just one line of code to change it to scan images (that aren't uploaded to iCloud) (that are anywhere on the device)!" No, it isn't; if you read the technical documentation and the more technically-oriented interviews Apple's given on this, there isn't just one hash that needs to be matches, there are two hashes, one on the device and one on the server. (I think Apple did a very poor job of communicating this to a general audience; it certainly wouldn't have alleviated all the concerns, but if it was understand as "client-server scanning" rather than "client-only scanning" it might have at least changed the tenor of the conversation.) That doesn't mean they can't do a combination client-server scan on every single image or even file on the device, but it makes it both more difficult to do and more difficult to hide.
"But what if the system doesn't work as Apple's described it?" Well, if you don't trust Apple to some degree, all bets are off. They already do ML-based image analysis of all photos in your photo library regardless of iCloud status and they've literally demoed this on stage during iPhone keynotes, so if Apple was going to secretly give government access to on-device scanning, a different technology -- one that works (questionably well) on all images, not just already-learned ones -- is literally already there. The only way you "know" what Apple is doing with your data on or off device comes from a combination of what they tell you and what third-party security researchers discover.
If they get caught doing secretly this in China that would be a big blow. But if they are doing openly and it is known that the government provides the hash, they can wash their hands.
I think there _is_ an argument to be made about a system like this being used to track the spread of political material, and it's easy to see how such a system would be terrible for anyone trying to hide from an authoritarian power of some type, but that'd already require Apple is absolutely and completely compromised by an authoritarian regime, which isn't high on my list of concerns.
As recently posted on HN [1] one should be very wary of backdoors, no matter how much one believes only the right guys could ever use them. Once they're there, they're there: it's arrogant beyond believe to think that opponents of yours won't exploit them.
I won't use an apple product with this feature. I've been using apple's ecosystem since about 1994.
[1] https://twitter.com/matthew_d_green/status/14334701097425182... and https://news.ycombinator.com/item?id=28404219
I don't understand this, they can just be legally compelled.
But a motivated bad actor has a lot easier time just putting an image of the Taiwanese flag or propaganda on someone's phone than trying to make it a hash collision that triggers... If an attacker is really after someone, I would expect them to put the actual material on that person's phone...
... It's like trying to frame someone for drugs in their car and going through the hassle of synthesizing a chemical that triggers drug dogs to react, but it isn't actually the drug. Wouldn't they just... buy drugs and stick them in the car?
Maybe they want to create too many false positives deliberately, or maybe they do it just because they want to see if and how synthesizing such a chemical can be done.
When putting pictures on someone's phone or computer, there are ways to add false positives as well as maybe doing false negatives sometimes (e.g. by encrypting the picture or using an uncommon file format so that it must be converted, or using complicated HTML/JS/CSS to render it instead of just a picture file).
Also, if someone has the picture or drug or whatever to find if it is what they are, can you accuse them (maybe they are the police) of liking pictures and drugs, too?
But, to be clear, you make a legitimate point.
How so? Unlike other cloud providers, which do scan all uploaded images server side, this system is specifically designed to prevent this.
(As you say, if Apple is entirely compromised, then all bets are off anyway.)
So Apple called them out on it by letting the market decide. They now have that evidence.
It'll go live around December when the Christmas sales push for iPhones is winding down and people are distracted with everything else going on.
When the tech news cycle is dominated by bad press about a move like this, and every tech nerd community is discussing this topic almost daily, it would be insane for Apple not to take some notice.
I know many are pessimistic about this, but Apple has learned from bad mistakes before. They rarely directly admit they're wrong, but conceding to pressure from the community is not unprecedented: see the return to the "Magic Keyboard" in their laptops.
Edit: removed the word “never” and replaced it with “rarely directly”.
It might not happen every day, but it happens frequently enough that it's easy to find a lot of examples.
Apple admits mistake, says it’s back in EPEAT https://channeldailynews.com/news/apple-admits-mistake-says-...
Apple Admits the Mac Pro was a mess https://www.theverge.com/2017/4/4/15175994/apple-mac-pro-fai...
Apple Admits iPhone 7 Manufacturing Fault https://www.theguardian.com/money/2019/feb/11/apple-iphone7-...
I could go on for pages, but I trust the point is made.
Mac Pro was a mess when one of their largest customer told them they will switch their whole studio away from Apple right in front of Eddy's Cue face before some thing was being done.
It's like the three seashells. They don't know how to use them.
These days it's hard to find an app that can get by without Cmd+click which is harder than click on the right button, which would be even easier if the right button was physically distinguishable. Long-press is super annoying as well as force click--I never want the action that comes up when I accidentally force-click. With the prevalence of touch phones, the two-finger-tap might be the easiest of them to remember (if not as precise).
People just dont realise how normal people have problem with mouse. Of course as we progress I think Two Button mouse could make sense as default. The role of PC also changed. The PC for everyone is now an Smartphone.
No, no, GP clearly has direct insight into the values, ulterior motives, and decision process of Tim Cook and other top brass at Apple.
Ten bucks says they take a page out of our politicians' handbooks and sneak it in as a small, vague footnote in a much larger, unrelated announcement once the initial bad press blows over.
Apple learned a valuable lesson here. Roll the panopticon out in secret, and don't announce it. They've done a very good job locking down their modern devices, enough that security researchers would have an exceptionally difficult time proving that they're doing it anyway.
GrapheneOS is still a viable option until Google ends upstream security updates in 2023. That's a solid two years for Purism, PinePhone, and anyone else working on linux phones to bring their performance and feature set up to modern standards.
The correct course of action is to buy a Pixel 5, run GrapheneOS for the next couple years, while donating to the main privacy-focused linux phone projects, and make the switch again in 2023.
That's a terrible idea. Apple knows that researchers are going through every bit of assembly code on the phone.
If all of a sudden they say "Hey we found some code that scans all your photos and sends information up to the cloud" how bad would that look? It's better to explain upfront rather than get found, because they will get found.
Not a jailbreaker at all, so happy to be completely wrong on this.
Alternatively, get a Linux phone right now and donate time by contributing bugfixes.
Are you asking Apple to come out and say that they are supporting privacy against state-level actors? After snowyD, why would anyone believe that anyway?
I'm not advocating against or for - I'm only wanting to add more clarity to the discussion because I think it is an important distinction that is often left out.
The cat is out of the bag. You and I have realized Apple can make these type of changes whenever they want.
I'm disappointed to report that Linux needs a lot of improvement to be viable for most people. I'm forging ahead, donating to open source software and hardware projects, filing bug reports, and generally bringing the Mac spirit to Linux. "It just works."
What phone did you switch to?
But network location provider doesn't work, that's an issue.
Though proprietary hardware plus mostly open OS is better than proprietary everything.
I'm continually surprised that people are continually surprised by this. I'm sure this post will get a lot of anecdotal replies; of course it can work fine for many people, but that's not the point. I used it exclusively on the desktop from 1995 to 2002. I could make it work for me, today, if I wanted to.
> You and I have realized Apple can make these type of changes whenever they want.
Was this not obvious? I'm pretty shocked that, for example, Docker can decide to change their license, and now in a few months a bunch of companies owe them money for every single user they have, even if the users don't do anything different. If they opened the license agreement and chose NOT to upgrade. If they never use the software again. But bam, terms changed, now you owe us money.
I tried Ubuntu last year, briefly. Almost everything worked fine, except ... OK, I'm a trackpad user. I have a couple Apple Magic Trackpads and I prefer to use those over a traditional mouse.
It worked fine for, like, a day? And then out of nowhere it just stopped responding. Reset or reinstalled everything I could think of and it still failed to work. OK, whatever, I bought a traditional bluetooth mouse. Which went to sleep every time it remained still for more than a split second, rendering it basically unusable (not a problem on Windows on the same machine).
Maybe a whiz could have fixed one or both issues, but googling completely failed me. This was pretty basic stuff, surely? And yet I couldn't even get bluetooth mice to work on the most mainstream distro.
(Now, admittedly, the trackpad doesn't work properly out of the box in Windows either, since Apple doesn't provide drivers that work outside of Boot Camp. But at least there are paid drivers that work really well.)
Anyway, I don't know. People have all sorts of annoying issues with Linux that end up being things that I have never encountered before. I usually use wireless mice with USB transceivers, which have never had problems and I feel like not everyone has such a bad experience (although I know many people who do). Perhaps it's because it's Apple hardware or something, but, admittedly, I have had MacBooks work perfectly on Linux before.
I think that, however, you use Linux on a desktop rather than a laptop, you will find that the hardware experience is quite pleasurable and does not have nearly the same number of issues. Between the two, Linux does manage to shine decently on desktops.
Not really. I just had them ["non-bluetooth wireless devices"] laying around and I think the non-Bluetooth ones are cheaper.
> I'm wondering if the future of Linux might be abandoning bluetooth entirely.
Abandoning Bluetooth just because your experience was unsatisfactory is not something I agree with at all, sorry. IME, Bluetooth support is completely fine for all the Bluetooth devices I have (like speakers or my cell phone)—and I know others who haven't had any issues either.
Besides, Android uses the Linux kernel. While I don't know if Android uses Bluetooth drivers from the mainline kernel, if it does, that would just make Android's life harder while pointless removing something that usually works fine.
Get that Pangolin before they sell out! Is there a Labor Day sale or something?
My main disappointment is that it doesn't "just work" with the kernels shipped by Ubuntu. System76 provides their own kernel packages, but they sometimes cause weird conflicts with other low level packages, and it can't hold its charge when suspended. I haven't attempted to debug the issue because I usually stay plugged in when I'm working, but I suppose I ought to engage tech support. They have been helpful in the past.
At the end of the day, I'll probably still give them my first look if I'm shopping for another laptop.
Compare this to my migration to a M1 MacBook Pro: I love it, but it is rough doing deep learning on it.
My first was a Galago Pro, and my only complaint was that I went HiDPI. That was just a bad choice on my part. The software supports it fine, I just don't prefer it in a laptop unless it's literally a Mac-level Retina-quality panel. It wasn't, but it's half the price point.
My other is a Gazelle 15", which dual-boots Arch and Windows. I use it primarily as a gaming box when I travel (remember those days?). I spent a lot of raid nights on various MMOs from hotel rooms. It works great.
Really looking forward to the Pangolin. Mine is still in "building" status.
I see a lot of sh*t written about System76 because they are just rebranded Clevos. Well...yeah? They are, and they are fine. I would rather give money to a company like System76 a thousand times over than someone dripping with anti-consumer behavior like Dell.
Re: Clevo - obligatory copy pasta from System76 Chief Engineer right here on HN [1]
"System76 UX architect here! This vastly trivializes the work System76 does for months and sometimes years leading up to a product release. We don't simply take an off-the-shelf product that already exists, throw an OS on it, and sell it.
System76 works with upstream manufacturers (like, yes, Clevo for laptops) to determine what types of products to develop, including their specifications, design, etc. for months up to a release. These products do not exist before we enter into these conversations.
Once that has been determined, designed, and goes into production, we start on firmware. We ensure all components are working together and with the Linux kernel (often requiring changes to the components' low level interactions with the OS, since the upstream components themselves are often manufactured with the assumption they will be used by Windows).
Once that is complete, we test with Ubuntu and Pop!_OS specifically, ensuring the OS is working perfectly with the hardware. If there are any OS-specific changes to be done, we write that behavior into Pop!_OS and/or our "driver" which is preloaded on all machines (and available in any Ubuntu-based distro, Arch, Fedora, etc.), with the intent to upstream that into Ubuntu, GNOME, and/or Linux itself as quickly as possible. When this is more generic like ensuring HiDPI works great out of the box, this actually ends up benefiting competitors like Dell's XPS 13 probably as much as it benefits us, but we put in the effort to file the bugs, track them, write the code, and get it upstreamed.
Once all of that is complete, we finally offer it for purchase and market it with all of our pretty photographs, sales pages, etc.
What ends up happening, then, is Clevo offers a machine with a similar-looking chassis for sale as a barebones laptop. This is the result partially of the decision making System76 has made for what to produce in the first place. These products, however, do not contain any of the firmware or driver work that System76 has invested in. They do benefit from the nice photography and advertising System76 has done, and since they look similar, people assume they're going to get the same machine for cheaper "directly from the manufacturer."
Edit: regardless, this is a bit beside the point of the linked blog post, and is also becoming less and less true as we work on designing and manufacturing our products completely in-house."
Their work on both the firmware front and with Pop!_OS should not be overlooked. And, it should be mentioned, if one is familiar with their whole product line - they now go far beyond just laptops for the open source community. And their powerhouses are absolutely not from some other OEM.
If I could just get a decent higher-than-1080 panel from System76, I might consider it for my next laptop. I've been spoiled by Macs. As it is I might go with a Framework laptop instead.
IMO it would go a long way if we taught computer literacy and specifically Linux literacy to everyone in school. Microsoft and Google have all the school contracts and they bring people up on systems that "just work" (actually they have paid system administrators). If we taught people from a young age to use Linux and handle problems, then the small problems that often come up with open source need not be barriers to adoption. Even if every regular person can't always solve every linux problem, if they were familiar enough to use it and had at least one expert friend, they'd be fine.
That's not to say we shouldn't strive to make Linux "just work" for most people, but we can attack the problem from other angles as well.
But Linux is just far more than I can handle, even just to install apps and configure settings. For example just trying to get my mouse not to stutter, I dig and find a solution. I copy and paste it into the terminal. It doesn't work and I try 3 different solutions. I'm curious about solutions but it wears my curiosity out pretty fast. I need to get work done.
In the sense that computers are like cars, I'm okay not knowing how exactly it works under the hood.
Also FWIW I have learned, even though I run debian, to check the Arch Wiki for tips on problems like that. One more place to check in addition to stack overflow.
Evergreen.
With broad addaption use cases like this will be solved.
You can install and configure Linux Desktop nowadays without touching the terminal.
I think they cannot really sneak it in. Some people do read updated TOS. And I think a "featurechange" like this, requires one.
And yes, the question will be, if the broad attention to the topic can be brought back on to it, if that happens. And they clearly say it will come, only with some "improvements" (but I cannot think of any improvements, that can be made, without abondoning the basic concept):
"we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features"
The concept of scanning for CSAM during the upload process, or the concept of making the user's device do it? Apple could do the former on their own servers and essentially nobody would be upset.
The algorithms never work 100% right. That means there will be always humans in the loop, sorting through false positives etc. which means probably very private pictures here in this context.
And to the end user it does not matter, whether this happens on the server or on their device. The message is: your pictures are not private with apple.
If that's too abstract, it matters in that it's a foothold for further scanning of data on your device. Without this system, if a state wanted to pressure Apple to create spyware and add it to their operating system to look for something else, that would have been easy to refuse. With this system, the spyware is already there, and despite Apple's protests to the contrary, it's just a matter of a few tweaks to repurpose it.
I doubt it , they will bring this up again very soon , if they cancel it, they’ll get very bad press too.
And second, a company that once shows its intention to breach your personal privacy while disregarding its user’s best interests altogether. Wont hesitate to do it again.
https://www.statista.com/statistics/276306/global-apple-ipho...
Apple is delaying this, I suspect, because it confuses the privacy message: If every time they talk about privacy someone can make them look like hypocrites by pointing out the on-device scanning, well that's just ugly for Apple. I suspect the on-device scanning element is going to be removed and it'll be on ingress to iCloud, which is what I said on my very first post to this. It was ill-considered to do it on device given Apple's privacy push.
More importantly, there is an oligopoly in tech and up until now, only one of the manufacturers of tech devices cared about privacy. And to that extent, I wouldn't be surprised if vast majority of developers who care about privacy have biased themselves towards apple. And now they have a reason to treat apple like every other privacy invading company.
That’s right. I like the idea that on android, I can use stock tools like rsync to manage the photos/music on my phone. With Apple it’s been a constant battle against iTunes to do those basic things. The only reason I chose Apple last time I bought a phone is because I’m willing to sacrifice a bit of convenience for the perception of better security/privacy. If they lose on that front, then I’ll hop to whichever phone is easiest for me to use the way I want to.
I remember, when that recalcitrant dentist was dragged of a United plane, endless predictions of United's imminent demise, people would never fly United again, yada yada yada. Needless to say, nothing much happened.
> I suspect the on-device scanning element is going to be removed and it'll be on ingress to iCloud, which is what I said on my very first post to this. It was ill-considered to do it on device given Apple's privacy push.
Not sure about that. Apple's approach (private set intersection run on half client, half server) preserves more privacy than scanning it in the cloud, and leaves the door open for E2EE.
The developers are going nowhere so long as the money is there to be made from iOS.
Did they all quit when it was revealed that Apple was part of PRISM? Of course not. They barely blinked.
It doesn't matter if a billion developers sign a petition. It's empty. The vast majority of them will promptly capitulate if Apple goes forward. By vast majority I mean 99%.
Did you see all the people desperately fleeing from Australia due to the rise of the extremist police state there? Nope. Did you see the tens of millions of people flee from the US when the Patriot Act was passed or PRISM was revealed? Nope. Did you see everyone rapidly flood over to mainland Europe as Britain became a police state? Nope. How about the hundreds of millions of people fleeing out of China over the past decade with the rise of Xi and the entire demolition of all human rights in China? Nope. Perhaps you're spotting a predictable human nature trend in all of this.
All the tech employees of Google, Facebook, Amazon, Microsoft, Apple, etc. They've all quit in droves over the past decade over human rights abuses - including vast privacy abuses - and concerns for what these companies are doing? Whoops, no, the exact opposite. There was a price for their integrity as it turns out, and they grabbed the money, which is what most people do.
The iOS developers are going nowhere, either. Besides the fact that their livelihoods depend on it, there's no vast green field to run to from what's happening. Sure, some might change jobs, or switch industry segments, it will be a small group though. It's going on in just about every liberal democracy simultaneously. What huge platform are developers going to flee to that's better and is never going to feature forced on-device scanning spyware? It's coming for Android too, bet on it.
iOS is where all the profitable users are. While that holds true, developers will be there to sell things to the profitable users.
The principled indie developers might leave in protest, and that would be a terrible loss for the platform's soul, but realistically the vast bulk of money flowing through the App Store is not going to the indie developers.
I won't be purchasing any more iPhones, and I've had every one.
They were just out by 37 years.
The battle is not over though, as you say Apple might include the feature unchanged in a later release.
If they do, should come as no surprise that they will lose a lot of business.
The correct business decision will be to cancel the feature and double down on the privacy angle.
Yeah, very few have the financial independence to be able to do something like that. However, over the next few years when everyone gets their free upgrades, I imagine we'll see some slower, yet more robust, switching.
But to me, it did at least look like this scared the shit out of Apple PR.
It would be nice if the general public and the news therefore now picked up on the issue of opaque "automatic updates". To date, they have been trained to always every update without question.
Conventional wisdom: Never, ever question any particular automatic update. Don't think, just enable. All updates are created equal.
Assumptions: Every update is for users benefit. Software companies never operate out of self-interest. There are no trade-offs. Whats good for them is good for users and vice versa. Theres no reason for end users to trial updated versions of software ("A/B test") before deciding to use them "in production".
Thought experiment: User installs Software from Company to perform "Function #1". Company makes changes to Software, described as "Fixes and other changes." Software now performs Function #1 plus Function #2. User allows new software to be installed automatically. (Automatic updates enabled per "expert" advice.") When user downloaded and installed Software she based her desicion to use Software on its ability to perform Function #1; however, did she have any interest in Function #2. Did she agree to Function #2. Company says yes. Developers say yes. What does User say. The license agreeement places no limits on what might comprise Function #2. It could be anything. It could have no benefit whatsoever for User. Moreover, Company is under no oblgation to disclose Function #2 to User. With automatic updates, Company is free to keep changing Software. User originally chose Software for Function #1 but Software may look very different after many "automatic updates". Would she choose it again in its current state. Segue to discussion of "lock-in".
Push to the level of their target's discomfort, then back off – without respecting the "no!", pretending to hear only "not now".
Come back later from a superficially-different angle, when the victim's defenses are down.
Couch the next attempt, or the next, or the next, in some combination of feigned sweetness ("but I waited & changed things for you"), or esteem-attacks ("you're so nasty you deserve this"), or inevitability ("this is going to happen whether you like it or not, so stop fighting").
• Unmasked proximity with non-household member
• Unlicensed gathering of more than 6 people
• Association with unidentifiable individuals (no faceprints on record)
These are your 2nd, 3rd, and 4th strikes so your phone has been disabled and you are now under arrest. Do not leave your immediate vicinity. As always, keep your phone on, charged, and in your personal possession at all times.
Due to large violation volumes, we are currently experiencing long physical arrest team hold times. Your arresting agents should arrive at your location in approximately... 5... hours.
Thank you for using Apple products, the leaders in Social Safety. 'Better Safe – Or You'll Be Sorry!'™"
It's a way to inch toward the unthinkable by obtaining concessions. You propose the unthinkable and after extreme push-back, the concession seems completely reasonable. However, if the concession would have been proposed alone instead of the unthinkable, it would have been rejected. It's an absolute deceptive manipulation technique.
Another example of manipulative Overton window shift at play: You may also recall deep state puppet Kathy Griffin showing Trump's severed head as the deep state testing the waters of a possible coup or assassination. The more you expose the public to the unthinkable, the more it becomes acceptable.
https://en.wikipedia.org/wiki/Overton_window
See also the Door-in-the-face technique and Foot-in-the-door technique
https://en.wikipedia.org/wiki/Door-in-the-face_technique https://en.wikipedia.org/wiki/Foot-in-the-door_technique
The door-in-the-face (DITF) technique is a compliance method commonly studied in social psychology.[1][2] The persuader attempts to convince the respondent to comply by making a large request that the respondent will most likely turn down, much like a metaphorical slamming of a door in the persuader's face. The respondent is then more likely to agree to a second, more reasonable request, than if that same request is made in isolation.[1][2] The DITF technique can be contrasted with the foot-in-the-door (FITD) technique, in which a persuader begins with a small request and gradually increases the demands of each request.[2][3] Both the FITD and DITF techniques increase the likelihood a respondent will agree to the second request.[2][3]
Foot-in-the-door (FITD) technique is a compliance tactic that aims at getting a person to agree to a large request by having them agree to a modest request first.[1][2][3]
This technique works by creating a connection between the person asking for a request and the person that is being asked. If a smaller request is granted, then the person who is agreeing feels like they are obligated to keep agreeing to larger requests to stay consistent with the original decision of agreeing. This technique is used in many ways and is a well-researched tactic for getting people to comply with requests. The saying is a reference to a door to door salesman who keeps the door from shutting with his foot, giving the customer no choice but to listen to the sales pitch.
Exactly. Note this description of the cycle of abuse:
"[The abuse] cycle involves four stages:
1) building tension
2) an incident of abuse
3) reconciliation
4) calm
Rinse and repeat."
Source: https://www.healthline.com/health/relationships/cycle-of-abu...
Editing to add: I think this will play out more like the butterfly keyboard debacle. They won’t ever really acknowledge how bad the original thing was, but they’ll return to a solution the community finds palatable (server side scanning), and wrap it up in a bow like they did with the “magic keyboard, now on our laptops”.
My read is that Apple is trying to placate governments by throwing them a bone without totally abandoning their privacy stance, hence the drive to put the scanning on the actual device so all your photos don't have to be shared as-is with Apple. That way they can encrypt iCloud but still keep the feds from accusing them (in bad faith) of being a child porn trading platform.
The alternative is to keep iCloud unencrypted and scan in the cloud, which is what they and everyone else already does.
One of the pieces of feedback they got though is that people are more okay with that than with scanning on the device. People expect that things that go to the cloud are no longer private unless you run some kind of local encryption that you control.
The reason they don't care about photos not sent to iCloud is the trading platform angle. It's one thing to let people store shit on their own devices. It's another thing to be a large scale and easy to use secure channel that people can use to share CP. The nightmare scenario for Apple would be to become a de-facto standard in the CP underworld for sharing content.
Sure people can use Tor, private VPNs and mesh networks, PGP, or many other things, but that requires a level of technical knowledge that greatly reduces the size of the audience.
Maybe a better alternative for Apple would be to add iCloud encryption but to stipulate that any sharing of content disables encryption for the shared content. That way they could scan shared content only. For unshared content iCloud is basically just an encrypted backup.
You would believe this if you only read/watch Apple PR and ignore reality. The actual reality is that Apple always collaborates with all governments. The reality is that Apple did not announce any new end to end encryption that would use this feature and did not promise such a feature.
In China and other more authoritarian nations that means cooperating a lot. If you don't you do no business in China. In the USA they seem to be looking for a new minimum level of cooperation, or trying to enhance privacy a little without moving the needle.
In any case this particular strategy looks like a failure in the market. They might re-engineer it or backpedal or just toss the whole idea of encrypting iCloud.
Maybe if you define privacy that Google and FB do not track you and only Apple do. You open an application on your Mac and the event was sent insecure to Apple , find a definition of privacy that is not contradictory with what Apple was doing.
Morality barely matters and legality is something easily skirted around with the right legal argument. Apple, google etc with continue working with governments so long as their profit can flow from those countries.
https://www.reddit.com/r/MachineLearning/comments/p6hsoh/p_a...
It's like being asked to have an invasive, detailed scan of your body shown to TSA personnel (and recorded) when you fly. The motive is apparently to prevent violence. But there were still incidents on flights when that was being done. It wouldn't have caught the box cutters on 9/11. The stated motive ceases to be part of the equation for me.
There's also images that can be abusive if made public but non-abusive if kept private. For example what about a kid taking pictures of themselves nude (many kids don't have parental moderated accounts) and putting them on icloud (iphone does this automatically with default settings).
It's a complete nuthouse and there's no way to do it.
(Also don't get me started on drawn artwork (or 3D CG) that people can create that can show all sorts of things and is fully or partially legal in many countries.)
To add, there are natural neural hash collisions in ImageNet (a famous ML dataset). Images that look nothing alike to us humans.
The issue here is not the trustworthiness of the pinky swear...
In other words, a situation that seems to be a feature toggle away from becoming terrible is terrible in itself.
If you look at the tone of all of it, they also honestly felt this was the most privacy preserving way to do CSAM scanning - likely so they can enable E2EE on everything iCloud.
What they got very very wrong was the public reaction to it.
Refers to facts not in evidence.
Additionally, they have previously voluntarily declined to enable e2e on systems to aid government surveillance.
This is baseless speculation, and, given what we know about Apple's history with e2e, not only baseless but actually unlikely.
Apple has not announced E2EE for files stored on iCloud. If that is their intent, they likely would have had a somewhat improved public response by announcing it at the same time as the on-device spyware.
What they got very wrong is that this fundamentally changes the nature of iPhones -- they are no longer user agents; in fact, they're actively scanning user data on behalf of another party. That change doesn't just make people feel uncomfortable, it opens the door for untold myriads of abuses.
It's one thing if iCloud servers scan user data - those servers never were assumed to be user agents. It's entirely different when user-owned devices do this.
I'm afraid good faith is not gonna protect your privacy.
- The government is pressuring us to do things that don't fit with our "privacy is good" sales pitch
- Let's propose something, but in a ham-handed enough way that it gets a ton of public push back
- Now we can argue our point with the government in a way that has already has more public support and existing discourse/debate
Somewhat risky though, since it hurt their public image.
My favorite theory is this:
Apple wants to create a chilling effect on reverse engineering iOS. They're starting to catch regulatory attention and lost their recent suit against Corellium. By putting neural hashes in the encrypted OS image, they can accuse anyone who reverse engineers iOS of:
1. Being in cahoots with child abusers
2. Knowingly possessing CSAM
I would hope that most courts would see through that paper thin logic, but the idea would be simply to introduce enough doubt that most reverse engineers don't want to risk it.
What basis could there be for that? And I'd be even more skeptical if this originated from a single case of abuse.
How does Apple get leverage if Apple gets all the negative publicity, and can't even say "TLA made us do it"?
NSLs are routinely issued to silence companies.
It was that Apple somehow gets negotiating leverage with a three letter agency.
So how does Apple get negotiating leverage in a context with a TLA when they can't say "they made us do it"?
Did we? I suspect the real issue the original client-side proposal had a lot of holes. What if the bad guys upload CSAM which hasn't been tagged by NCMEC yet? What if they then delete it from the device (but keep it on iCloud)? Or what if they zip the CSAM images and backup that?
In order to be even semi-effective, the client-side scanning has to be more invasive, or they have to implement server-side scanning too. Apple may well be looking whether they can implement this scanning without even more backlash.
Sooner or later government and NCMEC will push them to complete the feature (understandably so from their POV), and when they do, Apple will have to expand scanning. Apple may have already been pressured to do so.
Sometimes choosing the middle ground is like choosing to drive on the white line in the middle of the road as a 'compromise' between the lanes.