corrected: their intent is to scan all photos in your photo library, on your device, including images automatically pulled in from from various sources such as messages, if you have iCloud Photo enabled.
corrected: their intent is to scan all photos in your photo library, on your device, including images automatically pulled in from from various sources such as messages, if you have iCloud Photo enabled.
As far as I am aware, this is false and there is no mechanism on iOS by which images are "automatically pulled into" the photo library from anywhere, Messages or otherwise. Do you have a source or an example of how that could happen?
(edit: people are mentioning Whatsapp, which I guess has an option to auto-save received photos. Fair enough, but that's a third-party app and requires you to enable photos access anyway, so it's pretty clearly not what the parent meant).
> their intent is to scan all photos in your photo library, on your device ... if you have iCloud photos enabled
Yes, that's what I said. Enabling iCloud photos uploads your photo library to the cloud, so it's scanning your cloud photos.
Per Apple [0]
>Shared with You works across the system to find the (...) photos, and more that are shared in Messages conversations, and conveniently surfaces them in apps like Photos (...) making it easy to quickly access the information in context.
---
>Yes, that's what I said. Enabling iCloud photos uploads your photo library to the cloud, so it's scanning your cloud photos.
Being disingenuous about it is still a thing though. You stated
> More accurately put, their intent is to scan cloud photos (...) (like every other cloud provider, including Google)
which makes it appear that the photos are only scanned server side "like every other cloud provider". Client side scanning is something that no other provider does, in contrast to what you stated.
[0]: https://www.apple.com/newsroom/2021/06/ios-15-brings-powerfu....
I was not being disingenuous, frankly. I said that Apple is scanning your cloud photos, i.e. they are scanning photos that are uploaded to the cloud. Photos not being uploaded to the cloud are not scanned. I made no claims about where the scanning is happening, and I'm not particularly sure why it matters in any material sense.
Still: they scan photos locally - those are not cloud photos, those are local photos. And they have deployed the technical capability. You can bet that once capability exists, they will bend to government demands - there's ample precedent for that.
SO, yes, Apple, unlike all others, scans your photos locally. If they are going to be uploaded to cloud, or if they are forced to.
They are cloud photos. I say that because:
1. The photos are in the process of being uploaded to the cloud when they are scanned
2. The result of the scan is attached to the photo only when it is uploaded to the cloud. If the photo is deleted from the cloud, or the upload is canceled, the scan result is discarded
Practically, the system works precisely the same whether or not the scanning happens on device before the image reaches the cloud, or on the server after the image reaches the cloud.
The only well-intentioned argument about why on-device vs. on-server scanning matters is that "slippery slope" argument, which presupposes that:
1. Apple putting this scanning code in iOS not only somehow makes it easier/more tempting to use it for non-CSAM, but all but guarantees it will be used for non-CSAM.
2. Apple does not already have the ability to run whatever code they want, on any of your devices, without you ever knowing
3. Apple folds very easily to government demands, especially when it comes to privacy, their core differentiator
I don't think any of these are true. You might think they are, but then I'm not sure what point there is in discussing any more.
> or if they are forced to.
I'm not sure what this implies. If someone forces you to upload a photo to the cloud, surely that will get scanned regardless of whether the scanning is performed on-device or on-server?
Therefore, the scanning is local. There's really nothing more to it: The distinction is based on where the input is read from, in addition to where the input is processed. Both are happening inside the phone while you hold it in your hand.
It is scanning images locally.
This is totally unacceptable, and should never become acceptable.
This is what I don't understand about the whole argument about this CSAM debacle. I've read quite a bit of the discussion about this, as I'm someone who takes privacy fairly seriously, and it never really gets discussed. Could someone maybe point me in the direction of some literature about this? Is someone doing extensive load and packet analysis? Don't they(Apple) upload at least some E2E data?...
My iPhone already does an insane amount of "indexing", including image classification. This is all under the hood and I have no idea what else its doing, for all I know its mining Monero. Additionally all my iOS devices seem to send an inordinate amount of data to the cloud; I'm particularly sensitive to this because I don't have a strong internet connection, and frequently have to turn off WiFi on my phone or iPad when playing online games to stabilize my ping.
I'm also skeptical that you can really insure privacy from a 5 eyes country. Maybe I just read too many spy novels as a kid, but it doesn't take a lot of imagination for me to guess how any given decently large western company could be completely infiltrated by a multinational espionage coalition.
Idk, I tend to like that Apple is fighting against Ad-tech, as that power dynamic is at least believable. I do think that playing around with deGoogled Android is fun and in my experience is much more suited to dropping off the cellphone grid. I have an Android running Lineage and microG and with OSM and Kiwix(wikipedia is indispensable, IMO) as well as a handful of other apps, it serves the majority of the purposes of a cellphone without the need for data. I still daily drive my iPhone, mostly because the UX is a lot better than deGoogled Android.
Now if Apple developed a special update that they sent to only a few choice targets, that might be able to go under the radar.
You can wrap intrusions in form of 'think about the kids' (what is used here), think about security/terrorism and so on. This playbook has been used ad nausea, isn't it about time to learn?
That was my point: they get caught if/when they try.
If _Apple_ are forced to (e.g. by a judge), and they can't claim the ask is technically impossible.
But yes, I agree with the comment, there's no reason to hide between details: Apple plans to introduce the capability of scanning photos on your local device and comparing hashes against an opaque (non-reviewable) list of hashes that they (along with governments) control (details about how they plan to initially employ this capability are irrelevant).
What no one has done before and what I totally don't accept is someone scanning photos on my device, which is what Apple is doing.
The in the cloud vs. on your device aspect of this debate is the most important part and cannot be glossed over.
I really do think it's a weird aspect to fixate on, though.
So long as Apple is only scanning the photos that're being uploaded to its servers, it genuinely doesn't matter to me where that scanning happens. It's a scan that could have happened in either location, and the version where it's happening locally is arguably more private/secure-from-fishing-expeditions. If I don't like that the scanning occurs, I can disable the uploading.
The distinction would matter if the local-scan involved things that weren't being uploaded. But it doesn't, so from my perspective the only difference is an implementation detail.
You can already do that today (I do).
> But it doesn't
Maybe, maybe not. Even if I were to trust Apple 100% it's again a matter of principle (no local scanning).
Imagine the uproar if Microsoft Defender (which comes in-box enabled-by-default on all Windows 10/11 PCs) were to suddenly start scanning photos (it already scans executables and Office documents), hashing them against some opaque "database" and attaching tokens to suspicious ones that would be analyzed when uploaded to OneDrive (again, enabled by default for your Documents\Photos on Windows 10/11 if you use a MS Account).
Then on top of that, imagine Windows was a walled garden a-la iOS and you couldn't uninstall / disable / replace Defender with a different tool (which you totally can today).
I think there would be massive outrage in the press with MS being dragged through the mud for months, and droves of users switching to alternatives (like Linux) overnight. Yet (except for a few privacy / freedom organizations and a little press bleep) Apple gets to shake it off scot-free; I don't understand the dissonance.
If you want to "correct" the claim to say their intent is to scan every photo, citation needed.
Google, on the other hand, has been scanning the entire contents of your account for the past decade.
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect’s Gmail account.
https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
However, Google is scanning everything in your account.
We recently had a thread from a historian whose entire account was suspended after Google scanned all the files in his Google Drive, and didn't like what they saw (files on the history of tanks).
https://support.google.com/accounts/thread/81988101/google-l...
If you want your photos to upload in the background, iCloud Photos is your only choice on iOS. Not so on Android. This makes backing up photos to a server privately on iOS essentially unusable.
This kind of crippling anti-privacy pro-Apple-profits design permeates iOS. You cannot even install an app on your device without giving Apple your billing details and letting them know you installed it, which is used for ads. You cannot get your location without also telling it to Apple. You cannot tell Apple not to track your WiFi SSID's location. You cannot uninstall Apple News, which is filled with user tracking for ads. On and on.
> We recently had a thread from a historian whose entire account was suspended after Google scanned all the files in his Google Drive,
You're comparing iOS to the wrong entity when you compare it to Google instead of Android, but even your comparison to Google is faulty. Your link is about Google suspending an account for files shared publicly, not about Google scanning all the files in that account. Section V.B. of https://www.apple.com/legal/internet-services/icloud/ says that sharing those types of images publicly is also a violation of the iCloud TOS, and Apple has the right to do the same thing. The difference is that Apple will probably handle the customer complaint better, but that is an issue of customer service, not privacy.
Nope. Background App Refresh has allowed any iOS app to update data between the server and client in the background for more than half a decade.
Apple has discussed scanning photos uploaded to the iCloud Photos portion of their cloud service in the future, but nothing is scanned now.
Google has been scanning everything in in their user's cloud accounts for the past decade.
Also, given Google's reluctance to pay human beings to supervise decisions made by their algorithms, I have zero doubt that Google is turning in users when they have a single false positive.
All the other privacy-invading criticisms remain, making iOS an awful choice for privacy.
I still don't know why you're comparing iOS to Google. As I've already explained, that is the wrong comparison. I can use my own services on Android. Apple is planning to scan photos in iCloud (and already does in mail) and only hasn't because their services are still so basic, so it is just as bad as Google in that respect but only temporarily better due to incompetence. My own server does not scan and review photos and never will.
I guess I could have said almost a decade ago.
So, again, Apple only discussed scanning the iCloud Photos portion of their cloud service some time in the future, but NOTHING is being scanned now.
Google, on the other hand, has been scanning everything in your account for the past decade.
Also, documents from the discovery phase of Google's various antitrust trials show that Google has literally pressured device makers to hide the privacy settings from users.
Google also buys a copy of everybody's credit/debit card transaction data so they can spy on your real world purchases as much as they spy on your online life.
A company with surveillance capitalism as it's business model, like Google, will always be motivated to violate user privacy as much as possible.
I don't know why you're still trying to pretend that Google's cloud service is separate from Android while Apple's cloud service is not separate from iOS?
I acknowledged that. The point is that they admitted this is an oversight because they are already scanning iCloud Mail. Their intentions are exactly the same as Google's. They are merely less competent. Apple is also a surveillance capitalist, as I explained in my previous post, giving several examples. iOS even splits the privacy settings of Apple's apps from the privacy settings of all other apps to make it harder for users to control what little Apple lets them control.
> Google also buys a copy of everybody's credit/debit card transaction data so they can spy on your real world purchases as much as they spy on your online life.
Apple gets the exact same information for transactions completed with Apple Pay. Users have to opt in for Google to see this information. Once again, exactly the same.
> I don't know why you're still trying to pretend that Google's cloud service is separate from Android while Apple's cloud service is not separate from iOS?
I already explained why. I don't have to use Google services on Android. iOS ties me to Apple's privacy nightmare. I listed several other examples of Apple data collection on iOS that are unavoidable. Android, even in builds provided by Google, has none of those problems.
Nope.
>Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
https://www.technologyreview.com/2017/05/25/242717/google-no...
Buying a copy of everyone's credit card transaction data, no matter who they bank through, is not even close to the same.
>I don't have to use Google services on Android. iOS ties me to Apple's privacy nightmare.
Nope. Apple's cloud service is every bit as optional as Google's.
The difference is that Google has been scanning everything in Google accounts for the past decade.
Google and Facebook, as the pioneers of surveillance capitalism, are both privacy nightmares.
Yep.
> Buying a copy of everyone's credit card transaction data, no matter who they bank through, is not even close to the same.
As I already explained, the user has to opt in to share that data with Google. The purchase is a deal with the credit card companies to send data that users have opted in to share. https://support.google.com/googlepay/answer/10845853?hl=en
> Nope. Apple's cloud service is every bit as optional as Google's.
You completely ignored my post explaining why they are not. To repeat myself from https://news.ycombinator.com/item?id=28933939:
"You cannot even install an app on your device without giving Apple your billing details and letting them know you installed it, which is used for ads. You cannot get your location without also telling it to Apple. You cannot tell Apple not to track your WiFi SSID's location. You cannot uninstall Apple News, which is filled with user tracking for ads. On and on."
Apple, Google, and Facebook are all privacy nightmares. The difference is that iOS forces that privacy nightmare on its users, while Android does not. Your comparison of Apple to Google is as irrelevant as it is incorrect.
As I have already explained, this has nothing to do with Google Pay whatsoever.
It doesn't matter who issues your card. Google made deals directly with Visa and Mastercard to buy your transaction data.
>as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
Google has gone from spying on everything you do online, to spying on your offline behavior as well.
As for the rest of your errors. I'm afraid that I'm not willing to take the time to correct them individually.
Apple claims to not scan your pictures, but that's unrelated to whether they scan your pictures
You either believe their corporate communications on the subject or you do not.
In reality they probably have a "photoscanner.so / .dylib" that currently is only linked in by the iCloud uploader thing, but at any time could be called in by any other part of the system (or offer exploits new avenues for data exfiltration), which was actually spelled out in their initial announcement (there will be a system API for accessing it).
So they absolutely have the ability to scan photos on your phone; the fact that they don't intend to currently use it outside of the iCloud uploader is totally immaterial to this debate (the thing I don't want on my phone is photoscanner.so or any such capability).
That is completely false. They announced, a week after the initial announcement, that the on-device nudity-detection they planned on implementing in iMessage would also be open to Snapchat and other messaging apps. That doesn't report anything to the police, isn't hash-based, and is done on-device; it just pops up a bypassable warning to allow child users who are part of "iCloud Family Sharing" to avoid seeing things they don't want to see. It has nothing to do with CSAM detection.
I continue to be frustrated by the amount of misinformation on the anti-CSAM scanning side of the debate, including on HN (and it's orders of magnitude worse everywhere else).
Come on, now you're really going off the rails. What we're discussing here is the system Apple has said they have implemented and described. Anything beyond that is hearsay and accusation, for which some evidence would be appreciated. If you're just going to believe whatever you want to, and damn the evidence or what anyone says, go ahead. There's nothing much more to say.