If a Chinese company came to the US or EU and ignored US or EU rules and lawful directives from government, we would quite rightly be up in arms about that.
With regards to CSAM, I think the same applies. After all the CSAM issue only exists because the US government has decided that invasive monitoring is the only way to counter CSAM.
I note that no other western country takes such an authoritarian approach to CSAM, an approach that seems to be primarily driving by evangelist Christian keen on outlawing sex in general. As oppose to actually helping victims of CSAM.
I understand your trepidation in saying it. That is simply a fact of reality as it stands and how businesses operate under the current incentives, not a value judgement.
However, it makes me think that liberal democracies should play hardball. The USA already has the Foreign Corrupt Practices Act [0] and the UK the Bribery Act 2010 [1], which hold their own businesses and citizens criminally liable for business-related corruption in a foreign country. Also, many countries apply universal jurisdiction for crimes such as child abuse [2].
Maybe liberal democracies should start applying a similar set of rules to businesses who are licenced to operate within their country, forbidding them from performing certain types of tasks (e.g. ideological censorship) for any government.
I am well aware of how incredibly complex a law of this kind would need to be, but let businesses choose – if they want to operate in the EU, USA, UK, etc. then they need to play by the no political repression rules worldwide. Would losing the markets of repressive regimes not be worth it? Well, they're free to move their headquarters to those countries and lose the liberal democratic market.
[0] https://en.wikipedia.org/wiki/Foreign_Corrupt_Practices_Act
(Plus also IMO being banned from FB and Twitter are materially much more harmful to a political movement than being banned from an app store. EDIT: Maybe not, since per other comment it was being used to organize election results.)
But then, why do they have laws punishing corruption in a foreign country? And why do they care if one of their citizens travels to a foreign country and performs a sexual act which, while not technically a crime at the current location, would be a crime back home?
Whether the motivation of these rules is purely utilitarian ("We don't want our businesses to get good at corruption, in case they start bringing it back" or "It's easier to catch active paedophiles having this option"), honestly moral ("Corruption/sex tourism is a scourge for developing countries, we must do anything to stop it") or even cynically electoral ("Let's look tough on crime to win votes"), any of these three options could be applied to a law against collaboration with repressive regimes.
In particular, given the dependence of our economies on the likes of Alphabet, Apple, Facebook, etc. and the increased power of China, I think that the utilitarian motivation should be enough. We don't want businesses that are so entrenched in our day-to-day to be so cozy with repressive authoritarian regimes which may sooner than later start to apply their own requirements on how businesses should operate in other countries if they want to have access to their own lucrative market.
If I were to hazard cynical guesses, I'd say anti-corruption drives are genuine, in that corruption hurts American business interests, and anti-sex-crimes stuff is convenient to intelligence services who use sexual transgressions as black mail (e.g. Alexander Acosta explaining why he cut a sweet-heart deal for Epstein: "I was told Epstein 'belonged to intelligence' and to leave it alone").
But I agree that the government's themselves don't give a rats arse about this stuff, as long as they can keep winning elections.
However, following laws that contradict one’s marketing materials will lead to some understandable questions about those “values”.
† Really "CSAM", since there's no way to verify nor ensure it's only scanning for CSAM. What they are building is a prohibited content scanner, and what it will scan for is whatever governments would like it to scan for.
It not reasonable to hold Apple to pledges they've made to western customers, when talking about a service provided to non-western customers.
As much as we wish it wasn't true, the scope for providing privacy is substantially greater in the west than it is elsewhere.
Создавая продукты Apple, мы прежде всего заботимся о том, чтобы защитить вашу личную информацию и предоставить вам контроль над ней. [0]
Which translates to:
When we create Apple products, our primary concern is to protect your data and give you control over it.
I think it's reasonable: We hold people account across borders for serious violations (extraditions), so it's completely reasonable to hold a company accountable for its serious violations outside of the country that you're buying from.
No-one is forcing Apple to support those countries with oppressing citizens either.
No it hasn't. There is no legislation that the government passed or enforces that says Apple must scan people's private data on their devices for CSAM. Apple decided to do that all on their own.
On this specific point I think reasonable to believe that Apple want to E2E iCloud photos, and their stated approach to CSAM is how they'll achieve E2E iCloud photos, while remaining compliant with the requirement to scan for CSAM they might be hosting.
Now there's a very strong argument to be made that Apple have made an appalling trade-off here, prioritising E2E over not doing on device scanning. But it's a trade-off that's only happened due to the requirement for CSAM scanning.
An interesting approach Apple could take, is apply E2E iCloud photos in Europe, and continue with on server scanning (and no E2E) for the US.
This is categorically false. The law is very clear. Known CSAM must be reported. There is no obligation to search for it. The law explicitly exempts service providers from having to search for anything in a paragraph aptly named “protection of privacy”.
The text of the law: https://www.law.cornell.edu/uscode/text/18/2258A
Here's the thing: if they wanted this they should have said so, because until then I'm not going to make this assumption. I can only make decisions on information I have, not on wishful thinking.
That's possibly the most inefficient way anyone can imagine. If they can control Apple, they can just tell them to search Mail.app and Photos.app. What you are proposing is a Rube Goldberg machine.
And I'm 99% certain various agencies are already reading all your emails, with or without Apple's help. They are not hiding that they are spying on Swedish citizens, with the help of our intelligence services. Pretty sure they spy on you as well.
This is exactly what's going to happen, especially in countries like Russia and China. Children are just the perfect political weapon to make people accept the system.
Russia is a sovereign nation, with the right to rule as they wish. If you're not happy with there way of life, then I would encourage you to contact your democratic representatives and tell them to either apply greater pressure to the Russian government to live up to our ideals, and follow our laws; and if that fails, declare war.
The cynic in me believes this was either or both of these:
---
- Marketing ploy. The new iMessages app allows for scanning of the sent and received pictures for nudity and notifies parents if parental controls are enabled.
This is supported by the very large order of iPhones apple made for this year, roughly 90 million iirc.
- Bending the definition of E2EE, that is, enabling them to bend to governments "without breaking" their privacy "stance". Meaning that it is entirely possible to scan for content provided the government targets without losing E2EE. Effectively creating a special class of back window, where one can take a peek without the ability to execute arbitrary code.
It should be noted that given that the model is fast and can run with minimal impact (thank god for accelerators on SOCs /s), it could in theory run in realtime as part of the display pipeline, further removing restrictions like requiring that the content is downloaded with the images and iCloud sync is enabled.
---
But all of that is pure speculation from a random netizen.
The story that keeps getting mentioned is that Facebook reports about 55k images a day, Google reports about 1500/day, whereas Apple was reporting 250 a year.
I will state though that Google Photos has in-servers CSAM detection, and Dropbox. You can have your own opinion about all of that.
The stated reason they do it this way is to protect privacy. Presumably a lot more people would complain if they scanned the camera feed.
The police in America have proven repeatedly that they will ignore individual freedoms to look indiscriminately for people doing bad things.
Apple creates a tool that enables pattern matching without consent. But they promise they won’t use it for more than CSAM, and that only they will hold the keys.
Okay so imagine that your HOA enacts a rule they’re now allowed to review all of your purchases by comparing known hashes used by drug lords to determine if you are cooking meth in your basement. And if they find a match, without your knowledge, they will report you to the police who will have a defensible justification for a warrant to come enter your house and look for meth lab stuff. Sounds fine as long as you have nothing worth hiding right? Might as well let them just go through everyone’s house preemptively looking for meth labs and skip the hash checking right? Oh you don’t support that leap? Don’t worry, others do.
If HOA means home owners association, I don’t see the connection. They can’t influence Apple either.
There is no manual review of the image by Apple employees. What is viewed is a derivative image, which is scaled down and blurred. It would be trivial for someone to use legal pornographic images and put it through a NeuralHash collision generator, which upon viewing the scaled down derivative image, would look like CSAM.
There's also the fact that iOS exploits are so plentiful that they're cheaper than Android exploits.
Because that requires possessing illegal images, while legal pornography that also happens to cause a hash collision with NeuralHash doesn't.
Again, no one at Apple is reviewing the source image. They're reviewing obfuscated derivative images, and then informing law enforcement if they suspect they're illegal images.
What law enforcement then does is get warrants for all of the accused's electronic devices and raids their home and workplace in order to collect evidence.
It's another version of SWATing. Sure, eventually the authorities might find out that the accused isn't actually a mass shooter or holding hostages, but by then the damage is already done.
And are you really saying that the images Apple reviews are so blurry that they can’t review them? That seems like a very stupid system.
In any case, your scenario sounds pretty far fetched. Even if it actually works, I wouldn’t say it’s a major blocker.
Because they have a reasonable suspicion that they're illegal images, and it's quite literally job of the police to collect evidence to determine whether or not a suspect can be charged with a crime or not.
> And are you really saying that the images Apple reviews are so blurry that they can’t review them? That seems like a very stupid system.
Are you saying that Apple built a system that can detect CSAM, and then chose to build a system for distributing and viewing said illegal material, considering that the acts of distributing and viewing CSAM are both very, very illegal?
Again, it isn't Apple's job to determine what's CSAM or not, that's the job of the police and courts. Apple's obligation is to report what they believe could be CSAM to authorities, who will take the investigation from there.
I'm saying that I'm pretty sure they will not turn you in to the police for possession of child porn without being damn sure that's what it is. How do you think the other FAANGs do it? I have never heard of anyone falsely reported for CSAM by Facebook for example, have you? Why would it be different for Apple?
I really don't think you are being honest about this.
Of course they don't care about CASM to switch their business model to do this legally... And their valuation will crash if their balance sheet expands so much and management would be fired.
In this case it IS linked to iCloud though, as you probably know. Images are only scanned on their way to iCloud, and they won't be scanned if you don't use iCloud.
They think this is some kind of new system that gives Apple new access to things. It's not. They access they have here is nothing compared to what they have always had.
They can and do scan all your messages and photos already, locally, for features such as photo classification and making reminders from emails.
Apple could spy on anything they want, without this system. And this system is an incredibly impractical way to spy on people.
It's also pretty obvious that they wouldn't tell us if they were planning to spy on us, they would just do it.
In short: I have no idea if Apple spies on us, but I can say for certain that they will not use this system for it.
In this case the company retains direct control over your property, and changed what it does after you bought it and paid for it.
I think having these for-profit busybodies butting in how you can live your life is a great threat to invidividual liberty.
The same will happen with physical devices that you bought - a car, an electric bike, a smart coffee machine. Imagine a car detecting you are smoking dope, or taking an issue with your trip to the abortion clinic.
You think it's not gonna happen, its too absurd? I just had to sign a 42 page lisence agreement to ride a bike.
You can even store copyrighted porn, they won’t try and stop you.
If a car could detect if the driver was smoking dope that would be excellent. I don’t think you have the right to drive around blunted.