And then they notify law enforcement if they get a hit. Which means even if you're innocent - all your devices get confiscated for months, you probably rack up tens of thousands of dollars in legal fees, maybe lose your job, probably lose your friends and get the boot from any social organizations or groups.
They're waiting for two things.
One, CSAM to get out of the news cycle and the furor among users about CSAM to die down. This is standard corporate PR "emergency" management practice.
Two, to slide it into a point release after some minor, inconsequential change to say they "listened to users." iPhones with auto-updates enabled won't automatically upgrade to a new major release, but they will happily automatically upgrade to a point release.
You can of course upgrade to iOS 15 and turn off auto-updates, but then you won't get security updates, like the people staying on iOS 14.
Stay on iOS 14 until Apple surrenders completely on this.
That's why from some perspectives it is a net privacy win versus Google/Microsoft's similar tools that require them to have decryption backdoor keys on their clouds to process these CSAM requests and other FBI/TLA/et al warrants. Apple is saying they don't have backdoor keys at all on iCloud and if they are forced to do CSAM scanning it has to be on device, without leaving the device to have access to the unencrypted images. Only if you hit the reporting threshold (supposedly 30+ hash violations) would it also encrypt copies to a reporting database on iCloud (and again only if you were uploading those photos to iCloud in the first place).
More details in [1], but briefly:
They hash the images that you're uploading to iCloud. If it matches one of the hashes in the database, then it gets encrypted and transmitted to them. No single data packet can be decrypted, they need 30 (?) matches with that database in order to get a decryption key that then allows them to review the uploaded images. They don't send the actual images to the reviewers, it's altered in some way. At that point the reviewer will have 30 (?) thumbnails (?) to review. If the images look like CSAM, then they'll report it to NCMEC who then report it to law enforcement (NCMEC is not, itself, a law enforcement agency).
The ? are because I don't think they've publicly stated (or I've not read) what the threshold for decryption is or how they modify the images that get sent to the reviewers.
[0] https://www.apple.com/child-safety/
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Not as closely as some people. That's why I asked the question in the first place. But thanks for answering.
(i.e. They're encrypted in transfer and while stored, but Apple holds the keys: https://qr.ae/pGSHY8, https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app... [search for 'iCloud'])
> Each file is broken into chunks and encrypted by iCloud using AES128 and a key derived from each chunk’s contents, with the keys using SHA256. The keys and the file’s metadata are stored by Apple in the user’s iCloud account. The encrypted chunks of the file are stored, without any user-identifying information or the keys, using both Apple and third party storage services—such as Amazon Web Services or Google Cloud Platform—but these partners don’t have the keys to decrypt the user’s data stored on their servers.
As far as I can tell, they don't say anything specific about where or how Apple stores the keys and metadata, so it should be assumed that Apple could decrypt your photos if they wanted to.
Which is fine, because I use iCloud and many other cloud services, but you have to acknowledge the fact.
Apple had plans (and, an inside source tells me, an implementation) to do E2E for iCloud Backup, but the FBI asked them not to, so they scrapped it:
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
This undermines the credibility of those who are claiming, without evidence, that this clientside CSAM scanning is a prelude to launching E2E for iCloud data.
This raises the followup question of "why bother scanning the images on-device?", but I can infer two fairly obvious answers. First, the encryption still keeps AWS/Azure/GCP from seeing my photos. Second, and more cynically, they'd have to pay to do computation in the cloud; on-device computation is free to them.
> This undermines the credibility of those who are claiming, without evidence, that this clientside CSAM scanning is a prelude to launching E2E for iCloud data.
I agree; this is consistent with my initial point of confusion. Thanks!
How do you imagine that Google and Microsoft are able to scan the entire contents of your account? They can all read the data on their servers
>This raises the followup question of "why bother scanning the images on-device?
Because running the scan on device and encrypting the results protects users from having their account associated with the inevitable false positives that are going to crop up.
Apple can't decrypt the scan results your device produces until the threshold of 30 matching images is reached.
If someone issues a warrant to Apple for every account that has a single match, they can honestly report that they don't have that information.
Google and Microsoft give you no such protection. Any data held on their server is wide open for misuse by anyone who can issue a warrant.
The fact that the FBI stopped them once before and they've been working to build active solutions to what the FBI tells them their needs are should be evidence alone that E2E is their goal. It seems pretty credible to me.
And exactly how are they obligated to keep those policies? Answer: they aren't. There isn't some law saying '30 hits before we report you', and Apple is certainly going to drop the number as the public gets more used to the idea of CSAM. They'll keep dropping it until the news articles start coming out about how it's destroying lives.
This is corporate law enforcement. You don't have a right to due process, any say in their policies, or protection via any sort of oversight.
So, yes. It's the same.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Apple disagrees with you.
Which part of "what I store on my device is not even remotely the business of the manufacturer of the device" do you not understand?
idk, Hash collisions?
Google and Microsoft have been scanning everything in your account against a hash database for the past decade.
Also, unlike Apple's system which doesn't even notify Apple of the first 30 positive results (to protect you from the inevitable false positives) Google and Microsoft offer users no such protection.
>then they notify law enforcement if they get a hit. Which means even if you're innocent - all your devices get confiscated for months, you probably rack up tens of thousands of dollars in legal fees, maybe lose your job, probably lose your friends and get the boot from any social organizations or groups.
Again, Google and Microsoft have already been doing this for the past decade.
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account
https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
Also, if you have anything that may be matched by unknowable and unverifiable matching hashes and algorithms provided by multiple nation states now or ever in the future, including but not limited to political activists, protests, anti-animal-abuse activists, climate activists, and select ethnicities, or copyright violations of any kind… switch off iCloud sync.
Until that switch gets ignored.
This cannot and will not be limited to CSAM. The matching is much more complicated than “hashes of existing images.”
Here’s a good in-depth interview on the tech and the issues.
I read it more as "if you don't like it, use another cloud storage solution"
if you don't trust the switch, then why trust any switch on iOS. Why do you trust that they're not already doing it?
why are you using an iPhone?
As there is no clear legislation, every company is implementing what they feel comfortable with.
These sorts of dragnet warrants have become increasingly common.
>Google says geofence warrants make up one-quarter of all US demands
https://techcrunch.com/2021/08/19/google-geofence-warrants/
It's not like we haven't seen Google's on-server data hordes misused to falsely accuse users before.
>Innocent man, 23, sues Arizona police for $1.5million after being arrested for MURDER and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime
https://www.dailymail.co.uk/news/article-7897319/Police-arre...
Apple's system is designed to protect you from being associated with false positives, until that threshold of 30 matches is reached. Even then, the next step is to have a human review the data.
Google has never been willing to hire human beings to supervise the decisions an algorithm makes.
Our police and prosecution ought to be enough review on its own. If our own elected government fails to do something so simple, I say fix the government. I don’t want to be forced to rely on the goodwill of a for-profit company.
They are not.
>Innocent man, 23, sues Arizona police for $1.5million after being arrested for MURDER and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime
https://www.dailymail.co.uk/news/article-7897319/Police-arre...
The government should be held to a high standard, and when it fails we, the people, should fix it and not turn to private companies and ask why they didn’t step up to the plate.
Nope. Google and Microsoft have been scanning your entire account for the past decade. Apple has not.
>TechCrunch: Most other cloud providers have been scanning for CSAM for some time now. Apple has not. Obviously there are no current regulations that say that you must seek it out on your servers, but there is some roiling regulation in the EU and other countries. Is that the impetus for this? Basically, why now?
Erik Neuenschwander: Why now comes down to the fact that we’ve now got the technology that can balance strong child safety and user privacy. This is an area we’ve been looking at for some time, including current state of the art techniques which mostly involves scanning through entire contents of users’ libraries on cloud services that — as you point out — isn’t something that we’ve ever done
https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
I doubt it will happen. Apple is not known for that sort of interaction. Whatever will happen it will happen silently without Apple admitting to bend down to any backlash.
Also, the pressure to implement device scanning is coming from governments. So it is naive to think Apple will ever surrender. Most probably in the near future every single electronic device will try to leak your data as much as it physically can do.
Apple was not known to err on the side of "think of the children" or "let's help catch criminals" instead of personal privacy. But now they're known for new things.
Or vote with your wallet and abandon the Apple ecosystem. But nobody will because they don't have the bollocks.
Install Google Play Services and Google gets whatever info they want from your phone.
I mean 15.X - 15.Y will likely occur automatically while the phone is connected to WiFi and charging.. but 14 to 15 should require user approval, meaning we should be safe as long as we never upgrade >14..?
https://arstechnica.com/gadgets/2021/09/psa-you-dont-have-to...
I’m hoping they’ll realise that they confused privacy and trust and get back on track soon enough.
It's also not too difficult to have your unencrypted photos synced to Google Photos, Dropbox, One Drive or another provider as an alternative. They will scan your photos in the cloud which people on this site seem to have a vastly strong preference for. If you don't trust any of those then you're probably already using NextCloud or something like it.
For now. It will spread.
edit: more info in sibling comment https://news.ycombinator.com/item?id=28596442