No. The logic was never “if there’s a match the image is uploaded”. The device never knows if there’s a match. Under the process Apple described, an extra packet of data is attached to every iCloud upload. If there are enough matches, Apple can decode those packets to get a low-res thumbnail, which they then check against a second perceptual hash. The process doesn’t work on arbitrary images on your device, it’s specifically designed for iCloud uploads.
Also at the point that the image hash matches, Apple thinks it is CSAM (and it probably is). Doing it locally lets them avoid storing it, which they definitely do not want to do.
The whole point of the CSAM stuff was that it would allow for end to end encryption while not turning Apple’s ecosystem into preferred tool of child pornographers.
Apple poorly communicated the feature, then the EFF put out a deliberately misguided written hitpiece that conflated parental controls with CSAM, and started an online freak out. The “privacy activists” won, and your data is sitting on Apple servers with Apple’s managed encryption keys outside of your control today.
In their proposal they would scan your files on device, which is fundamentally different. Initially they would not run the scanning when icloud upload was disabled but how long would that last for?
Phrases like “it would not be doing any scanning on-device” don’t have any precise meaning. Scanning is a series of operations including hashing and cryptographic calculations plus a voucher upload and decryption. All of the former operations are happening on the device, only the latter happens on the server. So in fact a significant fraction of the scanning is indeed happening on your device. And this two-computer design isn’t being used to preserve your privacy: it’s designed this way solely to prevent you (the device owner) from knowing whether your files match the database. Without that requirement, the system would be much simpler: it would download a hash database and simply send a notification to iCloud whenever (a sufficient number of) local files hash to values matching the database.
> Does macOS 12.3 and beyond phone home with details of images and documents you open in Preview?
There is no similar context with Apple’s previous CSAM scheme. The device is unable to check for a match and then upload the photo if there’s a match. The scheme only works because it operates on iCloud uploads.
[1] https://mspoweruser.com/macos-big-sur-has-its-own-telemetry-...
However with many of these services if you try to kill them, they come back. If you delete them sometimes it will literally break your OS.
Example, if you remove the ocsp daemon, you can’t start any program on your computer.
I think this is a worrying development. Until now our computers were actually ours. Now they're controlled by the vendor, and looking over our shoulder.
I think using the user's own device to spy on them (whatever the reason!) is a big red line to cross. And puts this stricter control over the OS in a different perspective than just "security". I think either thing that plays into it is that Apple is now a content provider (Apple music and TV+). So they have another reason to keep us out to protect their DRM.
But anyway, good security should not have to imply trusting the vendor implicitly. Give us the ability to add our own signing key for files we want to modify, just like secure boot on Windows allows adding custom keys..
It's hard to argue that this "debacle" was not materially driven by the media, which did not accurate report the system's privacy protections, either because they did not understand them, or because they did not care to.