Google's Unannounced Update Scans All Your Photos
forbes.com
forbes.com
Is that really a lesson learnt?
Didn't Google already know what the reaction would be, before they consciously (given it's a significant launch) decided to do it that way?
Why would they care about a little blogger noise?
This leads to loss of revenue, maybe small maybe not. Ie if google is paired with some mentality and/or actions of current US government, US phones and all internet-enabled electronic products everywhere outside of US should be viewed with same scrutiny Huawei was treated previously, with very similar actions.
Or, antitrust laws that can break them into smaller units, recognizing that strict monopoly is not the only market failure scenario. That would be good too.
I think that is just called "government".
It's true that government is vulnerable to capture, but from that it does not follow that government is bad. It is more logical to conclude that the problem is unbounded personal enrichment allowing individuals to catapult themselves above the law. Corporations are the Roman Legions of the 21st century.
Corporations are also vulnerable to capture, after all, and that is their default condition. Why should we not treat powerful conglomerate corporations with the same skepticism as governments, or armies? Their internal structure is an inefficient command economy, why is this not also treated as a problem? Their scale, diversification, and entrenchment, have all allowed them to escape the regulatory power of market competition.
The problem isn't the wealth. The problem is the power.
The correlation between wealth and power is even stronger in countries where government is weak, and it is thus the function of government to prevent wealth from obtaining unchecked power. It is no wonder that wealth would seek to destroy government. That we appear to be losing this fight does not invalidate its importance.
You may have your choice of oligarchs to buy your car from, but what they will never allow you is the choice to compete with them on a level playing field. A cartel can allow internal competition, but they will all cooperate to crush upstarts.
It's government that interferes with competition, not "oligarchs" or "cartels." Otherwise I could buy a Chinese EV. The only way the "oligarchs" and the "cartels" can interfere with my decision is by using their wealth to capture and subvert the government.
Again: the problem is the power.
My 2c is that this style of on device monitoring to warn users/children is an expected evolution of parental content monitoring tools for the llm era.
Graphine is right. As open source it would be much better. Privacy and trust concerns would be easier to check and give the opportunity to make tools that empower parents and children to decide how they should moderate content on their devices.
Perhaps some communities are very worried about nudity where others are more concerned about hate speech. Having the choice on what to detect and how, or if, to act would be helpful.
https://news.ycombinator.com/item?id=43203303
https://security.googleblog.com/2024/10/5-new-protections-on...
I got this after the Forbes tab had sat open for a few minutes. Gotta love the modern web.
I hate how modern society all but requires a smartphone running either Android or IOS. I am very happy that something like GrapheneOS (mentioned in the article as well) exists, and allows me to have a smartphone without fully joining either cult and trusting everything those megacorps push. I hate that this is such a vulnerable position to be in.
The article opens with no problems on my Librem 5 running desktop Firefox with NoScript.
I don't mind paying Google for a piece of hardware quite as much as I do running their OS without anyone looking out for the user's privacy. The hardware transaction is much more straightforward and transparent (although by no means perfect).
Before this I used a Ubuntu Phone, and that was fine, but like a dumbphone, you can't use any 'official app store sanctioned' apps with it, which has become really cumbersome these past few years. If using PureOS means I can't install banking apps and government auth apps, then that is a non-starter. I wish that wasn't the case, but it is.
(The article threw this error on my Linux desktop in Firefox by the way.)
Useless error there is no developers console available without developer access.
And it was the Worst Thing Ever according to hackernews and the internet at large.
Now when Google does it, it's just fine and dandy.
You’re criticising them for something they did not do, did not intend to do, and designed a system that worked in an entirely different way… just because they could do it differently to what they actually proposed doing.
If they wanted to do it that other way, they could have just done it that other way in the first place and saved themselves a lot of effort.
No, this is not true. There is nothing stopping open-source software from pushing malicious updates.
But you are avoiding my main point. You are criticising Apple for something they haven’t done and had no plans to do.
Two things stop it: (much simplified) oversight by the community and a possibility to fix the code.
> You are criticising Apple for something they haven’t done and had no plans to do.
The do participate in the enshittification (https://pluralistic.net/2025/02/26/ursula-franklin/ and https://news.ycombinator.com/item?id=43243075), so my only expectation is that they won't do what's best for the users. In addition, they removed many features requested by the users like the headphone jack.
In general, the less you trust in a company, the better. Free software allows to decrease the trust in the vendor by watching the code and forking whenever you have to.
No, that’s not right either. You should really read their white paper, it’s very interesting and not at all what people assumed it was like.
> "it was the issue of it reporting content outside of your control at all, which again, this Google thing doesnt seem to do."
All the big cloud providers [Google, Microsoft, Facebook] report abusive imagery sent to their clouds to the authorities (search for annual NECMEC reports), except Apple. The others slurp up unencrypted data (Facebook photos, Google Drive, Microsoft OneDrive) and scan it and report on it, and nobody [on HN] says anything. Apple was trying to do a more privacy-preserving approach and it seemed like they might be pushing it to the client upload code so they could offer fully encrypted storage where they couldn't scan photos on their side, and a couple of years later they did, they announced optional Advanced Data Protection[2] which fully encrypts iCloud photos among other things.
Dark patterns aside, it's in your control whether to upload data to companies, so 'reporting content outside your control' is deliberately misrepresenting it.
[1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
[2] https://support.apple.com/en-gb/guide/security/sec973254c5f/...
That’s what I find most frustrating about the reaction to this. This was a sophisticated, privacy-preserving process that represented a genuine step forward in the state of the art and there was an interesting argument to be had about whether it struck the right balance. But it was impossible to have that argument because it was drowned out by an overwhelming amount of nonsense from people guessing incorrectly about how it worked and then getting angry about their fantasies.
You had to provide multiple confirmed matches to the cloud before the human verifier could decrypt any of the images sent. They weren't scp:ing images to a share for all employees to see ffs.
Of course, you could argue some people that choose to not use iCloud would not get that last bit, but considering they're turning it on by default (and even turning it on whenever you switch devices even though you restore a backup with it off), I'd say that would be a tiny minority of their customers.
Also, since we're on the subject of "unannounced scanning of all photos", Apple went and did it anyway, same as Google turning it on by default but claiming it's only to look for "landmarks" LOL :) https://news.ycombinator.com/item?id=42533685
It was not. The device was incapable of determining matches and the process only applied to photos being uploaded to iCloud.
> Also, since we're on the subject of "unannounced scanning of all photos", Apple went and did it anyway, same as Google turning it on by default but claiming it's only to look for "landmarks" LOL :) https://news.ycombinator.com/item?id=42533685
They did not. The landmark process works in an entirely different way for an entirely different purpose.
You needed to have multiple (exact count undefined) confirmed matches before anything was sent anywhere.
And even then "Apple employees" would only see a "reduced quality" (Can't remember the actual wording) version of the images. Basically just enough for them to determine if there's something actually illegal in there.
You'd have to be the unluckiest person in the world to get 5 false matches against actual verified child abuse imagery. And even then you'd just slightly inconvenience a human checker.
Now they're doing it in the cloud for every image you upload unless you turn on Advanced Data Protection. Just like every provider.
I think I'm literally one of the very few people in the world who actually read and understood the white paper - and I have the downvotes to prove it :)
What counts as inappropriate? And who decides.
According to US supreme court: "I know it, when i see it"
Google's move of installing the app without my permission makes me distrust the company even more. And they did the same thing again with "Android System Key Verifier" which has a different purpose, but they should have asked for my consent. My reaction: uninstalled both apps and turned off auto-updates. I thought I owned my smartphone.
One espionage scandal after another: first Pixels send their location even without location sharing to Google, then several attempts to add some AI crap with completely closed-source implementation and who-knows-what-it-does.
Does anybody use it? Will I have a hard time migrating from Pixel's stock Android?
The reality is that it's an app that offer's some on device models to detect nsfw content. Apps can choose to use those models instead of having to implement it themselves and I think that's kind of it. There's no scanning, there's no uploading, the article is even pulling quotes from a random forum that claims it's listening to your microphone and reading your contacts. The gap between what's written and reality is really ridiculous.
There's a discussion to be had around Google's ability to update software on our phones without our control, absolutely. But that's not what this article is doing, and wont lead the majority to that topic. This article is like reading a conspiracy website, it's a flashy headline with a kernel of truth, but just leads to dangerous behavior, like all the people installing stub apks from GitHub to keep this from installing.
> But do consider that the other 50% may have significantly different preferences on this matter
Or am I reading it the wrong way? 50% of people want to get those pics? That's either news to me, or I run in different circles than you do.
Either way, I don't feel that I'm evangelizing about it, I'm not telling everyone that they should do what I'm doing. I'm merely telling my experiences and what I've done.
From that they infer that women might actually like a feature that blurs out dicks automatically (at least, more than men would).
From that they infer that your expressed dislike of that feature means it's likely you're a man.
From that they infer that you're not used to thinking like a woman, and encourage you to try doing that to see if you think it makes Google's actions make more sense.
(now, the real question - did I get "whooosh"ed, or did you?)
EDIT: To be honest, I don't particularly like the sarcasm of @tetromino_'s comment and I don't think your original comment deserved a response like that. But seeing two responses apparently totally miss @tetromino_'s point was too much for me to ignore.
I am assuming once the alternate OS is flashed, there is no way of going back to the original? Or would a factory reset get the original back?
Though if you want the real Google ecosystem back, instead of going back to stock, try reflashing LineageOS and add in the MindTheGapps zip. MindTheGapps includes the real Google Play Store and other components, just like most Android phones. The LineageOS flashing directions for your phone should mention when and how to do that. You'll have a phone with Google, but without BS apps that you can't delete (aside from simple phone, sms, contacts, camera, etc apps), and should run faster.
They don't release security updates, but updates to scan your fotos are ok.