Google scanning photos you upload to their cloud seems fine to me. Not a slippery slope.
Google scanning photos you upload to their cloud seems fine to me. Not a slippery slope.
Apple's plan was to to scan photos that you uploaded to iCloud, only. Even that plan was canceled.
Google, however, still does scan everything in your account and has been doing so for the past decade.
For instance, this article from 2014:
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account
https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
Whether this is good or bad is a topic for fair debate, I think, but it continues to astound me both how little people are aware of this and that, in comparison, Apple's relatively privacy-preserving approach generated so much flak.
And you still need to scan local photos on the phone?
The only thing this adds to the threat model is mistrust for false positives in scanning engine - but in even the worst case scenario here (forged false positives), you're still ahead of the Google model, where the same forged false positives would be extremely likely to result in a full account review rather than review of specific images. Everything about "the device looking at your photos" is tinfoil hat, because the device is already looking at your photos, they're decrypted in RAM! All of the threat scenarios about "Apple adds a secret government backdoor that downloads your photos and sends them to the FBI" are already equally possible today!
The massive difference being that they would scan photos on my device. Not on the cloud. On my local device. How is that people consider that better?
The important bit is that Google does not currently have any capability to scan stuff on my phone. This is good. It's my stuff. They have no right to look at my stuff.
Apple proposed to implement tech that could scan stuff on my device, with a promise that they'll only do it when I am uploading stuff. Wait a few years, and some pressure from Authorotarian Government/Corporate Overlords and now the promise is just a promise that they can be easily removed and we can scan all stuff to make sure you're not stealing "content"/spreading "propoganda".
Apple's plan was to have your device conduct the scan and encrypt the scan results so not even they could see them until a threshold of ~30 image matches was reached.
This protects the user from false positives.
Once the 30 image threshold was crossed, the plan was to have a human review before turning someone into the authorities.
I think we all know that Google is not ever going to hire expensive human beings to supervise it's algorithms, so a single false positive would likely see you turned in for kiddie porn.
My point is that the difference between the approach from Google and Apple is that in one case (Google), we have a tech level blockage, it's not currently possible for Google to even do that.
On the other hand (Apple), the "blockage" is policy or "promise". That's far less reliable than the tech just not existing.
There is nothing stopping Google from inserting code to scan everything on your device. They can stick it into the binary blob of closed source Play Store code, and you would have no way of knowing it is there.
Google still does scan everything in your online account and has been doing so for the last decade.
Apple has backed down from even doing that for iCloud Photos.
No it wouldn't. It would only scan photos you upload to their cloud.
"This feature only impacts users who have chosen to use iCloud Photos to store their photos. It does not impact users who have not chosen to use iCloud Photos. There is no impact to any other on-device data."
and
"Does this mean Apple is going to scan all the photos stored on my iPhone? No. By design, this feature only applies to photos that the user chooses to upload to iCloud Photos, and even then Apple only learns about accounts that are storing collections of known CSAM images, and only the images that match to known CSAM. The system does not work for users who have iCloud Photos disabled. This feature does not work on your private iPhone photo library on the device."
- https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
https://www.cbsnews.com/news/child-sexual-abuse-scans-apple-...
They were very much planning to scan all photos on the device independent of iCloud. It was going to be another phase of the rollout. It was going to be in iOS 15.x and they backpedaled.
Apple clearly documented that this was only for iCloud uploaded photos, and indeed the technical description makes clear that this is only designed to work with uploaded photos: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni....
Not sure why they would need to do that. It does open up your phone for scanning and uses beyond what they initially layout.
The whole point of the protocol (as described in the Apple whitepaper) is to allow clients to attest to perceptual hash matches without the server having access to the plaintext.
So, the irony of all of this is that the Apple design is effectively more private than the status quo, but everyone freaks out about it.
Their cloud doesn't mean its their content. If said content is public, I mostly agree, but not if its private.
When I hire a storage box and put stuff in it, I don't own the storage box. Yet still it cannot be searched by anyone, not the company nor the authorities, unless there is a credible criminal suspicion.
I think that would be crazy. When they end up being CSAM or whatever, you're the one that will go to prison for possessing them, not the person that sent them to you.
Sounds more to me that they are pulling up the ladder to impede competitors.
For public files, I fully agree with you. For private ones, not at all.