Whatever did happen to the on-device CSAM scanning? Is it still coming to iOS?
Whatever did happen to the on-device CSAM scanning? Is it still coming to iOS?
Curious what they're going to do to mitigate that repetitional risk now. Possibly they'll just eat it and say, "look, this is what you fuckers wanted, we tried to solve the problem but you said no."
Not thrilled to see what the next showdown between them and e.g. the FBI is gonna look like. I expect it's not gonna look good in the court of public opinion and that might have unfortunate legislative consequences.
[EDIT] Actually, wouldn't be surprised if they wait until the first high-profile case involving their inability to deliver data on someone who probably is a disgusting scumbag, and use that as cover to go ahead with the local-CSAM-scanning-for-iCloud-uploads, once it's 100% clear what'll happen if they don't and the no-scanning crowd isn't the loudest set of voices anymore.
> First, iCloud users may now take advantage of hardware security keys like YubiKeys. Both NFC keys and plug-in keys are supported.
This is great news! I wonder if this is able to replace Apple's bespoke 2FA system or it's strictly in addition to that.
Edit:
From Apple's announcement:
> Now with Security Keys, users will have the choice to make use of third-party hardware security keys to enhance this protection. This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government. For users who opt in, Security Keys strengthens Apple’s two-factor authentication by requiring a hardware security key as one of the two factors.
If I read that right, it sounds like it's in addition to Apple's 2FA? I'd love to replace Apple's weird 2FA mechanisms, but this is still nice.
On macOS photoanalysisd phones home even when not using iCloud at all, fwiw. Who knows what it is doing?
Lawfully nothing is stopping them, but since pretty much all US cloud services scan files it's clear there are some forces making them to do so. I thought that Apple was able to negotiate a compromise where they scan locally and then they are "allowed" to to E2EE.
Interesting that they proceeding with the encryption regardless.