That's not how this works. A system-level background process is not going to be 'concluded upon' by random readers on the internet.
The only thing you should have written is: "a process made a connection, but I don't know what the process is for or what the connection is for, and I do not know how to investigate it". Your readers could then conclude a bunch:
- You use little snitch
- But you don't really know how noisy an OS can be
- Noise seems scary to you
- But you don't know why
- And you don't know how to find out
You could have made your position more credible by doing some extremely basic tests, like checking for strings inside the binary, or finding out what frameworks and libraries it is linked to. That's 2 built-in commands you can run as a normal user, with no arguments or ordering to think about. But if you did that, your position wouldn't be what it is.https://sneak.berlin/20210202/macos-11.2-network-privacy/
I'm not interested in projecting credibility, only disseminating facts for analysis.
> Apple Has Begun Scanning Your Local Image Files Without Consent
Begun? Nope, ancient process and system that has been there for many major releases.
Consent? Definitely gave consent, both at the macro and the micro level. You can't actually get up and running or use Finder unless you gave that consent, because it's the first thing that you have to do when you boot up for the first time.
So both of your key statements are measurably false, and your blog is riddled with fantasies and propositions that don't have the facts to back them up.
It is interesting to understand what this call is for and what the mediaanalysisd daemon is actually doing/sending, but just triggering LittleSnitch while browsing local documents I'm not sure is enough to draw a direct connection. Correlation perhaps, but honestly I think before making the claim that Apple is sending specific document information to their servers, it'd be better to get something a bit more concrete.
Checking with just activity monitor on the mediaanalysisd process and its network traffic while browsing through pictures, the sent/received data is bytes in size; I'm not in a position to do a proper network capture, but already I question what those few bytes are and if it's really related to my media browsing activities or just background noise. There is a fairly significant amount of received traffic (like close to 200 GiB) compared to the sent traffic (13 GiB), so I'm not quite convinced that this correlates to media scanning.
Passing psgrep with mediaanalysisd to lsof shows a lot of fairly normal background processes/daemons like webkit, AppleSupport, the AppStore, etc., so I find myself thinking it's more a general process despite the name, but far more research of actual packet data is needed.
The only mistake I think you've made is that I think your conclusion is premature to connect file browsing to this daemon, as it seems to handle a lot of stuff besides the implication that it scans documents or that it's specifically related to CSAM.
Basically, more information is needed in my opinion.
Edit: Changed "feel" to "think" in 2nd to last text block to correct my own language issue.
I didn't make that claim, because I have not RE'd mediaanalysisd to know precisely what it's doing.
The strings in the binary suggest it does face and animal detection, and processes some sort of "blacklist". As I mentioned, I don't use Photos.app or iCloud so I'm not sure how any of my media would be eligible for analysis. I was literally viewing images in the Finder via spacebar QuickLook (not even in Preview) when it hit the network for the first time. Maybe it's downloading models? Maybe it's sending analytics? Maybe it's sending perceptual hashes? Who knows?
I'm hoping that this post causes someone with the time and skills to do an in-depth RE of the binary to take a closer look at precisely what is happening with regards to images that are not eligible for processing in Photos.app or iCloud.
If you disabled SIP and deleted iCloud and Photos, not much would change. Your media panel widgets would break since they depend on access to the library functions (even if there are empty), but mediaanalysis would still work for all your image renderers. You might think "well that is wasteful, I never use this feature", but you forget that the product was not designed for your personal taste and use case, but for a much broader market. A market where a crapload of money is made every day and a selling point is that there isn't a whole lot to fiddle about with for users.
Your article states that Apple is scanning your files and points to network traffic as evidence for this, combining in your summary that Apple scans the data and then tries to reach Apple owned APIs. You spend a non-trivial amount of the article discussing the CSAM plans Apple had, and making it very clear that Apple never said it wouldn't scan and send files/data to law enforcement.
Your article builds a case that Apple is exfiltrating data, be it document information, media analysis, etc, outside of the local machine; I find it difficult to accept this was not the intent based on how the article is structure, the bullet points, and the summary.
> I was literally viewing images in the Finder via spacebar QuickLook (not even in Preview) when it hit the network for the first time.
Yes, this is likely LiveText and other OCR features done live on the M1/M2 models: https://developer.apple.com/documentation/visionkit/enabling...
There is a lot of live processing done with the M1/M2 boards even without iCloud/Photos.
I understand you think your article presents an objective and curious item that asks the reader to investigate more, but I and other people in this topic are telling you this is not the way your article is understood and interpreted, and we've pointed out how the other conclusion was reached based on your article. An inquisitive article with a call to action would be just that, as other commenters have already posted:
- I see this daemon trying to reach out to Apple APIs
- At this time, I was doing this
- I have not investigated the binary or network traffic
- I find this interesting, but I have not yet drawn a conclusion on it
- I invite others to comment on it more
If the article was presented like that, you wouldn't have so many comments here stating that they find your conclusion premature and misunderstanding your intention.
If your intent is really to call for investigation, I would suggest that you add an addendum section to the article clarifying your goals and purpose, as it seems that overwhelmingly readers are not taking this interpretation.
It's shallow alarmism.
At the very least, it's a bug. At worst, it's covert surveillance.
The system could be behaving exactly as it should be, but because you failed to do any research before drawing any conclusions, you've decided there are only two explanations when many more could be possible.
You consent when you agree to use their software. The information is encrypted and stays on your device. One of many notices over the years is here: https://www.apple.com/ios/photos/pdf/Photos_Tech_Brief_Sept_...
And, they've been analyzing your local image files for over a decade for numerous OS purposes.
> The media erroneously reported this as Apple reversing course.
The article you are quoting (whose author you infer has poor reading comprehension) is from December 2022. CSAM was put on pause in 2021. They have announced as of last month it is no longer being developed.
You criticize Lily's ability to understand Apple's statements, and yet:
> At the beginning of September 2021, Apple said it would pause the rollout of the feature to “collect input and make improvements before releasing these critically important child safety features.” In other words, a launch was still coming. Now the company says that in response to the feedback and guidance it received, the CSAM-detection tool for iCloud photos is dead.
Is this a lack of reading comprehension? Or did you just not read it at all?
> Today, Apple scanned my local files and those scanning programs attempted to talk to Apple APIs, even though I don’t use iCloud, Apple Photos, or an Apple ID.
> This is your first and only warning: Stock macOS now invades your privacy via the Internet when browing [sic] local files, taking actions that no reasonable person would expect to touch the network, with iCloud and all analytics turned off, no Apple apps launched (this happened in the Finder, via spacebar preview), and no Apple ID input. You have been notified of this new reality. You will receive no further warnings on the topic.
You are inferring (and I'm using the term infer to be very charitable) Apple is sending data to its servers based on the media it analyzes. It's clear that packets are coming in the form of GET requests (406B/s) not outbound requests (6B/s). IIRC that API endpoint is for searching to process your input before actually searching your local machine to get Siri suggestions and what not.
> Integrate this data and remember it: macOS now contains network-based spyware even with all Apple services disabled. It cannot be disabled via controls within the OS: you must used third party network filtering software (or external devices) to prevent it.
I'd call their advertising network-based spyware, but this isn't. And you absolutely can disable these features.
I trust you will update the article now.