https://www.bbc.com/news/technology-51207744
https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
It was a mistake to announce it in isolation as seen by this blowback because most people don’t understand or care about the actual details and just loudly complain.
Similar to the dismissal of the privacy preserving Bluetooth exposure notifications. Dumb knee-jerk dismissals imo that end up with worse outcomes for everyone.
You can pick
a) no backups
b) iCloud backups with E2EE and privacy preserving CSAM scanning as suggested by Apple (private set intersection, half client side, half server side)
c) iCloud backups, unencrypted, with CSAM scanning server side (like all other cloud services)
I know what I'd choose!
d) encrypted offline backups that never touch iCloud
I don't use iCloud for anything at all. Any sort of client-side scanner seriously compromises my privacy for no good reason. I am not a criminal. I don't deserve to be treated like one.
Is this a given?
There was some reporting that Apple does server-side CSAM scanning, but based on the volume of matches they report, it must be extremely limited.
Apple never said it this way, but many people assumed that Apple designed this client-side scanning system so that they could then encrypt iCloud data with client-side keys, which would provide end to end encryption for customer backups… and prevent any server-side scanning. This is likely what Matthew is referring to.
With the attention I don't see how Apple can delay taking some action here. A new external liability that can be attacked in different ways. Either they need to level up the CSAM scanning server-side to increase compliance, or they need to reimplement the client-side approach. The latter approach is probably much better from their perspective for various reasons.
Ultimately, they might have been better giving this a lower profile overall and effectively have sought public attention of law enforcement to provide some cover. The authorities are going to get this in some fashion eventually.
For reference:
> According to NCMEC, I submitted 608 reports to NCMEC in 2019, and 523 reports in 2020. In those same years, Apple submitted 205 and 265 reports (respectively). It isn't that Apple doesn't receive more picture than my service, or that they don't have more CP than I receive. Rather, it's that they don't seem to notice and therefore, don't report.
https://www.hackerfactor.com/blog/index.php?/archives/929-On...