There was some reporting that Apple does server-side CSAM scanning, but based on the volume of matches they report, it must be extremely limited.
Apple never said it this way, but many people assumed that Apple designed this client-side scanning system so that they could then encrypt iCloud data with client-side keys, which would provide end to end encryption for customer backups… and prevent any server-side scanning. This is likely what Matthew is referring to.
With the attention I don't see how Apple can delay taking some action here. A new external liability that can be attacked in different ways. Either they need to level up the CSAM scanning server-side to increase compliance, or they need to reimplement the client-side approach. The latter approach is probably much better from their perspective for various reasons.
Ultimately, they might have been better giving this a lower profile overall and effectively have sought public attention of law enforcement to provide some cover. The authorities are going to get this in some fashion eventually.
For reference:
> According to NCMEC, I submitted 608 reports to NCMEC in 2019, and 523 reports in 2020. In those same years, Apple submitted 205 and 265 reports (respectively). It isn't that Apple doesn't receive more picture than my service, or that they don't have more CP than I receive. Rather, it's that they don't seem to notice and therefore, don't report.
https://www.hackerfactor.com/blog/index.php?/archives/929-On...