Apple defeats liability for not scanning iCloud for CSAM
blog.ericgoldman.org
blog.ericgoldman.org
For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has even extended to fictional CSAM such as AI generated stories and pictures. As an aside, if that gets extended to political speech or other non-CSAM materials that are determined to be undesirable, that's a big concern. I can imagine that a conservative state could pass a law banning all porn because they claim it could encourage illegal activities such as prostitution, rape, or CSA.
On the CSA side, you rarely hear about arrests (they happen but less than CSAM). There doesn't seem to be any real push for educating and protecting kids before it happens. Ironically, the groups doing the most to educate and implement protective strategies are the ones who have been involved in abuse scandals in the past (Churches, Scouts, etc). Even then, a lot of it is just getting clearances, which doesnt prevent people who where not caught or were first timers. Offenders get put on a list/map. This is sort of a half approach. If they are still a threat, they shouldn't be released. Yet if you comb the list and see some of the results, they don't all seem to fit with CSA. I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.
It seems like these laws are more about peddling to the publicist and lawmakers fantasy of incrementally extreme punishment rather than taking a appropriate, data driven, and level-headed approach that actually protects kids. Otherwise they will just keep pushing ham-fisted low-hanging "fixes" like required scanning and IDs to access the internet.
The same technology/access used for CSAM identification can find copyrighted files, materials that don't support current government, etc. Full E2E encryption seriously raises the cost of mass surveillance, and why the US government fights it at every turn going back 30 years.
Also you can do one and the other ... at the same time. E.g. suicides of kids/teenagers (<= 19) in Germany in 2025: 216. That is, compared to the population in this age group, 1.38 per 100'000. In the USA that ratio is 9.4 in the age-group 15-19 and 2.3 in the age group 10-14.
And keep in mind, the total deaths by firearms in Germany in 2024 was "just" 168 (we have 1/4th of the US population, in the US police forces alone killed more people ... the total number of 44'000 firearms deaths in USA/2024 is even more staggering). Even if I multiply the 168 by 4 for the population difference ... then 672 vs. 44'000 is still a point of shame for the USA.
So in Germany, we do BOTH better regarding firearms AND regarding health services on kids. And if the USA truly would try MAGA they'd actually copy good results from other countries. So a real-MAGA-person must be against liberal firearms distribution AND for better social health work with teenagers.
BTW, the USA ideology of "the population needs arms to fight a corrupt state" is laughable. When you had your armed religious sects clash with the state, then the state always won. They still have more and better weapons and armor. On the other side, if you look how east-europe shed off their socialist regimes 40 years ago, than nowhere was an armed general population involved. So one can conclude that private firearms may as well be highly regulated and diminshed.
Well, most of Europe simply has banned guns in the hands of civilians instead, so that's some data as well.
The only reason why the US is so extremely lax on firearms is because people keep blathering on about how guns are the last line of defense against a tyrannical government - and yet, what do the most rabid of these people do? Vote in and defend a literal tyrant.
The detectives assigned to this work tend to not last long, and the horrific nature of the crime affects them.
Like all rape, it’s a combo of control and dopamine. The church and Boy Scout leaders leveraged their societial influence and power to compel compliance and even loyalty from their victims. Boy Scouts as an organization inserted itself into existing power structures like church, police and other institutions. It’s difficult for a 11 year old victim to make an accusation about a beloved community figure. They also tend to find ways to make their victims feel complicit. Even if people come forward, they are hard cases to try and exposes young victims to public shame. Many of these people plea to lesser crimes to protect the victim.
I wasn’t a victim thank god, but a Boy Scout leader at my parish was a serial molester who abused dozens or hundreds of children. I learned about it years later and realized that some of my friends were almost certainly victims — in his case everyone in authority just blew it off
This doesn't mean I agree with active scanning of things like iCloud, effectively making everyone a suspect, but counter to what people here seem to think it really might help prevent CSA.
I was curious about this. I did find some research here: https://www.suojellaanlapsia.fi/en/post/csam-users-in-the-da... (2021)
That paper states
> Traditional research on individuals who use CSAM is often inherently biased as it has focused primarily on convicted and known offenders.
and appears to be directly trying to avoid that bias, which is good to see.
Isn't there still some bias here though? They only got answers from 1. people who were using a dark web search engine with ads, 2. felt the need to click a "Help us to help you" link, 3. were willing to discuss the topic with strangers on the web. Only (3) was (almost) acknowledged in the Limitations section.
They concluded that "Many CSAM users are not just viewers" and, while "many" could mean any number, I think readers would probably take it to mean something like 30% (shown in graphs) which isn't indicated by their data.
Furthermore, the "not just viewers" conclusion is from a question about "seeking direct contact with children through online platforms". I'm not sure why they didn't more directly ask if respondents took action towards abusing children, with the inspecific "direct contact" qualifier and very specific qualifier "through online platforms". I wonder what the results would have been if they removed "direct" and "through online platforms" from the question.
Admittedly I don't know a lot about statistical techniques! Has there been other research, or do you know what the police agency was basing their explanation on?
Or as the Dothraki put it, “it is known”.
It is technical possible that in small villages there is only a single Boy Scout leader and no other adults, who then spend a lot of time alone with children. In my experience however, after school activities involving children also generally involve several adults. That makes it a major structural issue among the adults if they fail to detect a problem like hundreds of victims, and the more common remedy would be to train people, apply some form of screening, and change routines that limit risk and encourage reporting in case of inappropriate behavior.
In addition, having trained people that regular meet and talk to children can help detect situations even when they happen in peoples home, like having school employees training in detecting signs of CSA.
You have been mildly brainwashed.
It would be best if that episode lead you to study a bit of psychology but instead you chose to believe.
Like any belief it's a combo of control and dopamine. The feeling of belonging to a group and being righteous within that group hits so hard that it takes hard explicit effort to screen your perception of its effects.
You are a victim because you failed to accept reality.
Meanwhile the real pedos are rich people vacationing in well known places.
Now for real: People often do not care a lot about child abuse. It does not affect them as it happens in private where they do not see it. CSAM however does affect them as it makes the abuse visible and shows something deemed reprehensible. In a lot of ways people see themselves being witness (even indirect by purely hearing about it) to CSAM as the victim rather than the children who are harmed in the making and by redistribution.
My cynical opinion is that it is a lot more about social norms and feelings arising from the violation of these norms rather than the harm done through the violation of children.
This isn't entirely true. In much of the Western world – outside the US – CSAM (or equivalent legal terms such as "child pornography", "child abuse material", "child exploitation material", etc) can include text, drawings, AI-generated imagery, etc, which no child was abused to create, indeed the child depicted in it may be entirely fictional. Canadian law goes so far as to treat material which "advocates or counsels" the commission of CSA as CSAM - which the Supreme Court of Canada insisted (in the 2001 case of R v Sharpe) doesn't include mere political advocacy for its legalisation (as in e.g. the NAMBLA Bulletin), although some will question whether that insistence actually cashes out in practice.
Now, as a father of school-aged children, I find the whole idea of groups like NAMBLA rather abhorrent – but, I'm hesitant about the government making it illegal for people to express abhorrent ideas, because there are likely ideas which you or I hold which somebody out there considers abhorrent.
You might want to look up if that's actually true. It might be. It might also be a lie to hide the real reason why they are registered.
Talk about tainted for life.
I make this point on HN each time it comes up: Dealing with actual CSA requires actual people going to investigate actual reports of children's living conditions out in the real world, not "scanning digital files". Seems obvious when you say it like that, but the alternative seems to still score heavily on the political scale. Ironically, spending more money on "scanning digital files" takes away from resources that could prevent those digital files from being created in the first place, so all the additional time, money, and effort towards combatting CSAM is time, money, and effort specifically _not_ working against stopping CSA. It's categorically _not_ protecting the children.
Teachers, in Australia at least, have mandatory reporting where any kind of abuse is suspected. The heart-breaking irony is that the resources to investigate the reports are so scarce that they can only respond to reports where the child's life is in immediate danger.
Caveat: the above was true a few years ago, I genuinely don't know if it's still true. What I do know is that 'social work' isn't suddenly a high paying job, so I doubt resource availability has changed much.
There is no easy answer to this. It's entirely nuance.
That's exactly what happens. CSAM has two parts to it.
The first is the known and most horrific videos of CP out there. These aren't shared, instead only hashes are used to determine if the image/video matches. It's next to impossible to get an mis-hit on that.
The second is nudity and age detection AI. Apple has this on their devices, but warns the user before sharing not reporting.
It normally takes more than one hit to get flagged for investigation. At that point law enforcement are informed and take over.
The majority of investigations are children sending naked pictures of themself to their friends.
So it is absolutely being used as the purpose to protect children and it's amazing how many people don't realise how it works when they are very transparent about it.
Of course it is not without its issues that need to fixed. For example providers will just ban the person before it's determined if they broke a law or not.
If there's a person committing abuse against a child, usually a family member in their own household, there's no story there. They (hopefully) get arrested, get a minor mention in the media if that, and life moves on.
If, on the other hand, they send CSAM using a platform, device or protocol, then clearly the makers of that technology failed to uphold their sacred duty to protect the child. If most CSAM cases happen using a few major technologies (and they will, because societies tend to standardize on what technologies they use for communication), the technologies get blamed for the problem they supposedly enable.
If you dislike the technology for other reasons (the distrust of corporations from left-leaning politicians, censorship allegations on the right, a moral panic about the impact of smartphones on children's mental health), you can use people's misunderstanding of statistics to exaggerate the CSAM problem, blame the tech, and gain some notion of control over it in a way that is politically palatable to citizens.
It's worth saying explicitly that centralization doesn't have much to do with this. We've seen similar stories play out with bicycles, Walkmans, pagers, AI, heavy metal and Uber rapes. They were different moral panics, but the mechanic was roughly the same. I think the situation wouldn't change much if we all used PGP-encrypted email over personal mail servers to communicate.
An exception that proves the rule is the moral panic over CSA in primarily-catholic countries, notably relating to abuse committed by catholic priests, which are statistically no more likely to commit it than anybody else. As the influence of the Church on government policy is a hotly-debated topic in those countries, CSA is suddenly an issue that people can use to further their political causes.
- Prosecutors want to go after it because it is much easier to prove than CSA.
- Authoritarians want to go after it because it gives them a chance to get things like ID checks accepted by the public.
- People who genuinely want to prevent CSA focus on it because a large amount of CSAM is made by serial abusers - so capturing producers can prevent future abuse. Additionally, they believe (with good reasons) that CSAM consumption is a gateway to CSA and CSAM production for many people. Further, finding CSAM can be a way to identify and rescue children from abusive situations.
- CSA survivors may advocate for it often feel traumatized not just by the abuse, but by the fact that people might be continuously viewing that abuse.
- Going after it winds up creating digital forensics specialists and task forces, which creates a special interest group within police departments which wants to continue focusing on CSAM but is not set up to do anything about CSA.
I would recommend the podcast Hunting Warhead to anyone interested in learning more about this.
> yet almost nothing seems to be done to prevent CSA
> On the CSA side, ... [t]here doesn't seem to be any real push for educating and protecting kids before it happens.
This is a mighty wide brush you are painting with. When I was growing up, from very early (elementary school), we had "health class" where the teacher would teach you things about your body and health. This also included who is allowed to see you naked and/or touch your private parts. They also explained how to get help if someone what touching you inappropriately. That effort seems pretty active to me. > I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.
Urinating in public late at night is an interesting category of inprobably CSA-labeled behaviour. It should be treated with kid gloves -- the context matters.My school did not cover that (but at least my parents did).
Because it is nearly always someone we know. Someone who we just cannot imagine would ever do such a thing, even when the evidence is glaringly obvious. And I suspect that the fraction of the population diddling kids in real life is breathtaking, and nobody really wants to face that head on. Too uncomfortable.
I could just be overly cynical today. But given my own experiences and other people I've known throughout my life, I really believe it is very common.
Before abstinence and birth control, CSA prevention should be the primary goal of sex ed in schools, especially before high school. (Though on birth control [1] and probably STIs as well the US is not doing well.)
[1] https://www.plannedparenthoodaction.org/issues/sex-education...
If you provide the government a platform to do So, they'll do Y if you wait long enough
That's not to say it's acceptable if illegally produced.
We have issues in the UK. So far they've banned 'rape' porn. And now they're talking about 'barely legal'
None of this seems to be based on any statistics showing this is actually harmful in any way.
for the UK, there has been a massive shift to prevent this kind of stuff.
anyone who even volunteers with children or vulnerable adults needs to be screened. Charities are required to have policies for dealing with vulnerable people safely.
but to the point, Apple halfarse CSAM reporting.
Whatsapp which doesn't do "CSAM scanning" reports in one hour more CSAM than apple does in a year. From memory meta (instgram, facebook and whatsapp) reported millions of cases of CSAM for 2021, compared to apple's ~250 (not thousand, just 250)
for facebook its automated scanning, but for whatsapp, its just design. its really obvious how to report a message/image. in imessage, its impossible, there is no mechanism to long press/select/other a message.
Now, Facebook are bastards in virtually every way, but for whatsapp at least, they have made GUI changes that have real positive impact on CSAM protection.
Apple has not.
They made some noise about hashing, but thats invasive and ironically noisier than having user reports.
as far as i am aware, that is common practice in many countries. the problem is that screening is typically a quick check of "has this person been suspected or arrested for something involving minors already" and perhaps a few questions on a piece of paper. its not like they give everyone volunteering for a fieldtrip an extensive 1:1 with a psychologist and an mri. any predator who has not previously been caught will easily pass screening.
>From memory meta (instgram, facebook and whatsapp) reported millions of cases of CSAM for 2021, compared to apple's ~250 (not thousand, just 250)
easy enough to explain. instagram and facebook are social media with billions of public posts. whatsapp is in a similar enough boat, with large (up to 1000 participants?) facebook-like groups of otherwise strangers and a lot of marketing and inertia for social-media-like use.
i imagine instagram is a majority of it. it's disgusting on there.
on the other hand, apple is not a social media company nor facilitates large group chats (imessage goes up to 32 participants).
i doubt adding an easier UX for reporting would make a material difference in the number of reports apple submits because you're typically already talking with people you know when using imessage.
Peripheral to your comment, there is an argument against AI generated CSAM that no one seems to be making so allow me. AI will do the same for CSAM as it has already done for copyright laundering. That is, it will enable its distributors to train their models on real CSAM while obscuring the training material. A legal regime that permits unrestricted distribution of AI generated CSAM incentivizes actual abuse as a source of training material. If one opposes legal prohibitions on free speech grounds, then at a minimum there should be an audit requirement incumbent on AI generated CSAM distributors to document their process in sufficient detail as to establish that they haven't used actual CSAM for training, similarly to the way porn distributors are required to document that their models are of legal age.
>that many of the people actually arrested are arrested for CSAM and not CSA
So there are, or there aren't arrests?
Also you hear about CSA arrests all the damn time. If anything it's underplayed in the media somewhat when they're a specific people.
Even ADP in iCloud sends the hashes of the plaintext to Apple, non-e2ee. This allows them to see who has unique files, and when, and the networks of users to which they spread, and when.
Second, detecting CSAM leads to its producers who are by definition abusers. Here’s a nice article in Wired about the digital forensics of cracking down on a CSAM ring with some interesting details about the role played by crypto, and abusers’ misconceptions about it: https://www.wired.com/story/tracers-in-the-dark-welcome-to-v...
With that said, I agree that a lot of political concern for this is a smokescreen for a creating more surveillance. “think of the children!” has the flavor of a rhetorical trump card.
These are utterly anathema to huge chunks of society, especially American society. It's more and more clear, from the scope of the Epstein Files, just how much of American society and government has been influenced specifically to enable easy access to children by rich white men. Even beyond that, the entire right wing would instantly catch fire if we actually required effective sex education. Especially age-appropriate sex education going right down to kindergarten (yes, kindergarten: the better children that age understand what's normal and safe, the better they can communicate when someone is doing things to them that are not that...and I only stop at kindergarten because AFAIK that's the earliest mandated schooling still). Similarly, the right wing desperately wants to have absolute control over their children—treat them as property—so giving children rights that even parents have to respect will get them to oppose absolutely everything.
Plus, as other sibling comments have already noted, the real desire here is for ubiquitous surveillance. CSAM is just the excuse they use.
It's all about surveilling the masses and keeping them under control. Children are merely one of the political weapons they use to make the masses accept any proposed solution, no matter how Orwellian. You're not against protecting children from drug trafficking, money laundering, child molesting terrorists, are you?
Compared to this, CSA is much harder. Every case is different. You have to do due diligence. And it is extremely hard to proactively detect them. Careful criminals will destroy all evidence. The number of case itself is smaller. And there is a good chance to lose in the court and for prosecutors this is a clearly risky move. Good ol' criminal investigation is expensive. There is a structural reason not to prioritize them.
The whole incentive structure is broken. The only thing to fix this is external pressure, but even it does not work these days. Exposing CSA is a rare event but media needs constant, sensitive headlines so they tend to treat CSA and CSAM like the same thing. Hence external pressures do not work, and even worse those work in a wrong way. This creates a bad feedback loop.
And those groups still have lower rates of abuse than Schools which do a lot less training and enforcement of youth protection policies.
Children are still safer in Scouts and churches than in schools.
Just about every kid goes to school though, so people just prefer to sweep that under the rug and focus on targeting organizations they are not a part of or disagree with because they're easier to demonize and make fun of.
I work with kids, and I've had to take the Scouts and Catholic Church's youth protection training. They are both free to take online if anyone wants to check it out.
What evidence do you have of this? The only sources I can find that would even vaguely support your claim switch to talking about physical abuse in schools, or sexual assault committed by fellow students.
To be clear, we're discussing the sexual assault of children by adults here. We're not talking about physical abuse, nor are we talking about assault by fellow students.
Is that in absolute terms, or per child who frequents the establishment?
Why are you making apologies for (Catholic) church sex abuse? Because you are a member and you took a training? Yikes.
Apple could easily not do this stuff and it may even be easier to not.
> It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.
I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare quotes there because I don't think that political or religious dissidents would find that the same or similar technology used to discover and persecute them is "privacy preserving". And that's really the problem with Apple here. They provided a model for scanning for any kind of message or material while purportedly maintaining privacy.
Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?
If not, I'll happily stand corrected, but please share sources.
Addenda:
- Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...
- Paper breaking the hash: https://arxiv.org/abs/2111.06628
Edit: The second one is the wrong paper. I’ll find and link the correct one tomorrow. Keeping the link for transparency.
Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.
So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.
I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have
https://www.hackerfactor.com/blog/index.php?archives/931-Pho...
That box has been open for years now.
Big brother is already watching what you do on your Android device.
> A Dad Took Photos of His Naked Toddler for the Doctor. Google Flagged Him as a Criminal.
https://www.nytimes.com/2022/08/21/technology/google-surveil...
Google reported him to the police based on a single false positive.
To add insult to injury, even after the police contacted Google to tell them that they had cleared him of wrongdoing, Google refused to restore access to his account.
> The father uploaded photos of his son’s genitals, which were also backed up on his Google cloud, to the health care provider’s messaging system as requested.
And no, this particular article about Google attempting to have innocent parents arrested was published before Apple even discussed scanning images users manually uploaded to their publicly accessible web album on iCloud.
Very different than trying to narc out users to the authorities.
The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069
That's a new version. The one that as announced the same time as client side scanning to block uploading CSAM to iCloud worked like this.
1. It could be enabled on a child's device by the parents. It was not on be default.
2. If the child received a sexual image (not necessarily just CSAM...if an adult sends a dick pic to a child that is not CSAM but would have been flagged) the image is blocked, the child is notified, told their parents are worried the image may harm them, and asked if they still want to see it.
3. If the child says no, they do not want to see it, that is the end of the matter.
4. If the child says that they do want to see it and they are at least 13 they are shown the image and that is the end of the matter.
5. If the child says that they do want to see it and they are under 13, they are again told that they parents are concerned, and that if they view it their parents will be notified, and asked if they still want to view it.
6. If they say no that is the end of the matter.
7. If they say yes they see it but the parents also are notified and will be able to see it.
This should have been pretty uncontroversial, but there were objections on the grounds that if someone say sends their dick pic to your under 13 child and the child goes all the way through to step 7 and decides to view it, that is a violation of the sender's privacy because that message was only intended for the child.
This mode is probably best understood as "if someone texts me a dick pic, please blur it". I don't think there's any reasonable objection to this.
Notifying the parents even requires that the child acknowledge that's what's going to happen.
And the reporting was still gated through Apple employees; there was no mechanism for the government to expand the scope without Apple’s knowledge.
I understand that people don’t like the idea of their personal hardware being complicit in treachery, but when considered from a purely functional perspective, apple’s proposal was no different to what Google and others were already doing.
Accidental false positives could lead to horrific outcomes up to and including oh look bob got shot by the cops for resisting.
It was possible to produce apparently matching innocuous images and then poison people's machines with them.Oops did you click on that picture of a tree have fun with the cops. Like an advanced form of swatting.
Although inspired by a desire to find CSAM Apple could be forced to scan for ANYTHING by repressive regimes including America and China.
Although initially targeting images client side scanning of messages is a pretty obvious next step. Again obvious good motivation exists and is completely justifiable who doesn't want to stop the next mass shooting or terrorist attack... and then we can basically use it to find people critical of the regime. Do remember we are presently prosecuting a political figure for a picture of sea shells and a guy in texas is rotting in prison for distributing political literature.
Including Europe. Europe is ruled by people who think 1984 was an instruction manual.
European citizen surveillance is something i oppose, but at least it's balanced by a robust bill of human rights. America's surveillance state does not have that balance, because America wrote a bill of rights but didn't bother with the follow-through.
Kindly don't use my continent as a punching bag, thanks.
Edit: There are some rare competent managers who will stop the enquiry before even asking the engineers.
No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.
And therapists are legally mandated to report you if you told them you viewed or possessed CSAM.
> Across most states, viewing CSEM alone is generally not a mandated-reporting trigger; reporting becomes obligatory when disclosures involve an identifiable child being abused or used to produce material.
> California’s CANRA imposes a distinct duty to report electronic access (download/stream) with identifying patient information, upheld against privacy challenges based on compelling state interest.
[0] https://www.psychiatrictimes.com/view/mandatory-reporting-ch...
Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines:
"Apple says users can have up to 20 CSAM images on their phone before they'll tell police"
You might not like pictures that way but honestly I think more important in procescuting CSAM is to go after the large sources of CSAM generation. Its trafficing in East Asia, and in Europe. I think weirdly America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures. Abuse definitely happens in the US but making policy decisions like this produces bad policy.
Does iCloud rehost the photos to other people I don't really know because I use andriod tbh. If they are being rehosted (I assume to members of your contacts) that can be problematic but I think honestly the issue a lot more complex than just protect the children which the source of critic is a lot attacks against apples are coming from
The US has the largest pornography industry in the world by a massive margin, and the largest consumption of online pornography per capita
Meanwhile should we be surprised that CSAM production is higher in countries like the Philippines that have very weak digital policing, abject poverty, high numbers of street children etc?
In some countries it is as far as I’m aware
If Apple's interests sometimes align with ours then great. I'll take it. But don't attribute to this ~5 trillion dollar company some kind of altruism.
Altruism or not, I've found that their interests almost always align with mine when it comes to privacy.
> In a court filing Friday, Apple said continuing the lawsuit now poses “too significant a risk” of exposing the anti-exploitation and threat intelligence efforts needed to fend off the very adversaries involved in the legal dispute.
> “When it filed this lawsuit nearly three years ago, Apple recognized that it would involve sharing information with third parties. However, developments since then have reshaped the risk landscape associated with sharing such information,” the Cupertino device maker said.
I mean, iOS has never been open source so Apple has always practiced security through obscurity. It doesn't seem unreasonable that they'd be concerned about this. Idk, seems like a nothingburger but maybe I'm wrong.
Dropping the case is great for Apple's obscurity, but terrible for enforcing the security of iOS users that are still vulnerable to Pegasus malware. Now NSO Group is not threatened or deterred, which is the worst of all worlds for iOS security.
At least on Desktop we have usable Linux, but on the phones there is literally nothing usable because thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.
Yes its possible to make Andoid spy on you a little less, but even for tech savvy person its damn inconvinient and Google making platform worse with every single release.
Thanks to Google "security" I can use my banking apps on 9 years old device with 6 years outdated firmware, but not on GrapheneOS.
I've been using GrapheneOS for years and that hasn't been my experience. There are two financial apps that don't work for me, and that's it. Pretty much everything else I use is fine. But, to be fair, I'm very scrupulous about my apps and tend to avoid installing an app for every little thing that wants me to.
With only one brief exception, all of my financial institution's apps have worked fine, too, including some banks I see drive-by complaints about on here.
Anyone curious should refer to the tracker: https://privsec.dev/posts/android/banking-applications-compa...
Sometimes, all you need is a Web browser. I personally don't want any "apps" on my phone that aren't basic utilities.
I am aware some banks in Europe require 2FA on a mobile device. Short of switching banks, my answer to that is a cheap or e-waste Googled Android phone that stays at home and serves that sole purpose.
Some banks limit functionality on web apps, which is annoying.
More importantly, many refuse to provide a decent 2FA other than push notifications inside the app or SMS, which is insecure and EU has mandated its phaseout.
The thing that works for me is to pretend to be clueless and get an old hardware OTP generator, but those are susceptible to impersonation attacks on the bank side.
I also need to maintain my own nextcloud, photo sync infrastructure and backups.
Its inconvinient. This is exactly what I talking about.
[1] https://discuss.privacyguides.net/t/no-longer-neccesary-to-s...
They probably use E2EE just so they don't have to respond to court orders and such.
Like OP said, Apple isn't perfect nor will they ever be, but they do prioritize privacy better than most.
Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)
161 points by Logans_Run on Feb 14, 2025 | 69 comments
https://news.ycombinator.com/item?id=43047952
Apple silently uploads your passwords and keeps them (lapcatsoftware.com)
170 points by ingve on Nov 1, 2024 | 127 comments
And whenever your privacy contradicts their control over "your" device, you are also out of luck, e.g., you can't have Ublock Origin on an iPhone. Relevant discussion: https://news.ycombinator.com/item?id=44804921
Except ublock, which can't do what it does the way it normally does, for the same reason you can't have any plugin inspecting realtime activity and doing scriptlet injection.
You can have ad blocking. You can't have plugins with that kind of low level access to your browser activity.
You can prefer something that allows dangerous behavior as a trade-off for greater capabilities, but you can't deny it's a safety trade-off where Apple picked what's safer.
They're pro-privacy when it serves them financially.
But they are until they are actually defeated. I would rather plan for failure. We are in a global climate where court rulings can be ignored.
They might be slightly better than some others (horray!) but given their ecosystem it is still the worst platform if you value any form of freedom. Depending on apple for your privacy is ignorance at best.
Look up the "iCloud Keychain" API:
For years Apple has let and helped Facebook, TikTok, Tinder etc. track users even after you delete an app, even ACROSS DEVICES and DEVICE RESETS.
There's no way to even SEE what data the apps have stored on your device & iCloud account on iOS, only through the macOS Keychain Access app. Even then you can't be sure that that's all that being stored.
They temporarily changed course and wiped iCloud Keychain data when deleting apps, but only during a single beta of iOS some years ago, and then reverted to the way it is now.
This scores so many points in favor of privacy intruding corporations that it puts Apple far from being the paragon of privacy they pretend to parade as.
It's a real flaw that they should've fixed a long time ago, but your conspiratorial framing makes it seem like Apple colluded with Facebook et al. to end run their own privacy protections, while ignoring the fact that Apple's App Tracking Transparency feature has cost Facebook billions.
2. Why in't there any UI in iOS yet to view and delete that data without using those apps, asking them nicely, and trusting them to do it?
3. Why aren't users informed about apps storing data that will carry across app reinstalls, device reinstalls, and to all your other devices?
2. Why would there be? Apple building a UI for people to accidentally fuck up their apps sounds like the exact kind of thing Apple would never do on iOS.
3. Users are already informed when an app wants to track them. Beyond that, having an app store data so that it carries across reinstalls and to all my other devices is what I would expect my apps to do. If I uninstall an app and reinstall it later, I want it to pick up where I left off, not with a blank slate.
People understood this settlement to mean Apple was spying on their conversations and selling them to advertisers, when it seems to have more to do with people accidentally triggering Siri. But people don’t care about this kind of nuance or actually tallying up all the ways Apple is pro privacy against rare issues like this one. It’s all just tribalism at the end of the day.
> Although Apple does not explicitly disclose it in its consumer-facing privacy documentation, a small proportion of Siri recordings are passed on to contractors working for the company around the world. https://www.theguardian.com/technology/2019/jul/26/apple-con...
Regardless of how you feel towards Apple, this sort of data should be siloed in a way that makes it impossible to share with undisclosed third-parties. It also should not be shared anywhere until Apple can confirm that PII and other sensitive information was redacted from the data, which they did not. It generally points to a laissez-faire attitude towards personal data that is hard to abdicate without seeing the Siri server-side code or retention architecture, which is why Apple settled to avoid revealing the extent to which they retain and share data in a class-action discovery process. The settlement is a mea-culpa without admitting to wrongdoing or proving fundamental security.
The lawsuit was entirely avoidable if Apple didn't play fast-and-loose with production databases. It'll be a black eye for anyone that points to Apple's whitepapers as an example of their commitment to security - some retention simply doesn't get documented by Apple.
So once there’s a profit motive for violating your privacy, the justification for eroding your privacy will proceed. It’s really the inertia of Apple starting out as privacy-compatible that makes them hesitant to throw that away.
These companies are liars. I do not trust liars. It has served me well.
Quite a lot of the labor issues in Apple's supply chain we found out because Apple found them and included them in their annual report on these and other supply chain issues.
Apple is on the side of making money, and the privacy claims are mostly marketing. The entire stack is closed source, which means it is difficult and expensive to independently verify any of the claims made. What's more, the "auto update" universal backdoor means that Apple can forcibly push a user-hostile "feature" like client-side scanning when it wants or is compelled to by a state actor.
There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example:
* A: physical sexual abuse of children. B: possession or distribution of CSAM
* A: drug trafficking or tax evasion. B: structured cash withdrawals
The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A.It's my understanding that conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person: one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.
It's my understanding that one can be convicted of structured withdrawals that are not driven by, linked to, or in any way related to anything nefarious.
This isn't necessarily the case in the US, though I believe only for drawings. AI-generated CSAM probably wouldn't fly in a court of law.
Regardless, it's a naive conception of a system of law to think of it as a utilitarian system of restitution in contexts of "this individual harmed this individual". In fact, that would fall under the category of a "tort" rather than a "crime". The law is just as much about enforcing social mores and norms as it is about dealing with individuals harming each other. Hence why locales like Canada outlaw all forms CSAM, even fictional ones. The victim taken is to be society itself. The possession of this material, implicitly entailing enjoyment of it, is so gross a violation of society's norms and mores that it becomes elevated to a legal matter.
This shouldn't be the case in a society that supposedly values liberty.
As well as possession. I don't actually know if those are different for CSAM, but I would assume so because they are for drugs.
> Non-consented distribution of sexual images (eg: revenge porn) is also a crime.
There is very compelling empirical evidence that this causes actual harm (suicide ideation in a very big fraction of the victims), even if it is fictional, so here there is no question about the harm.
I can't wrap my head around how AI-generated imagery is evidence of child sexual abuse (CAS). How are you abusing a real child by generating an image of a fake one?
[1] https://rainn.org/get-the-facts-about-csam-child-sexual-abus...
(a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
(1)
(A)depicts a minor engaging in sexually explicit conduct; and
(B)is obscene; or ...
(b)...
(c)Nonrequired Element of Offense.—
It is not a required element of any offense under this section that the minor depicted actually exist.
It is not a required element of any offense under this section that the minor depicted actually exist.On top of that, while there are different types of child abusers, the worst ones almost invariantly collect CSAM to the point of hoarding. So it really isn’t that bad of a proxy.
The root comment is implying that legalizing or decriminalizing csam would somehow help with prosecution of child abuse? I’m kind of speechless. Csam IS child abuse. The fact that there are consumers encourages producers to, well, produce!
There have been a handful of convictions based on fictional content, but usually the defendants also possessed real CSAM so there wasn't much point in contesting the charges over fictional images.
> The PROTECT Act includes prohibitions against obscene illustrations depicting child pornography, including computer-generated illustrations, also known as virtual child pornography. Previous provisions outlawing virtual child pornography... had been ruled unconstitutional... The PROTECT ACT attached an obscenity requirement under the Miller test or the variant test noted above to overcome this limitation.
Which, if I'm reading it right, means that GP was correct in saying "conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person"
Also, in regard to the fictional CSAM depictions that stuff is still wending its way through the courts.
- Structured transactions are illegal because we put a minimum on the amount of cash that has to move before government financial surveillance applies. The alternative (at least, one acceptable to the state) would be that the government knows every transaction you make[0] no matter the size. Since we don't want that, it has to be illegal to lie about the size of a transaction. Furthermore, the harder it is to get away with structuring your transactions, the more legible the financial system becomes and the easier it is to catch drug dealers.
- Pedophiles have not stopped possessing or distributing CSAM to reduce their legal liability. Actually, this argument ignores the main reason why pedophiles store and trade CSAM around in the first place: it's specifically to scare victims into silence and revictimize those who tell the cops. In fact, this is why we stopped calling it "child porn" and started calling it "child sexual abuse material" - because it is specifically material designed to sexually abuse children by way of it's mere existence.
If you're a "no touch" pedophile (they do exist!) that's still trading real CSAM around, well... Congratulations, Nobuhiro Watsuki, award-winning author of the hit samurai manga Rurouni Kenshin, you're still doing the dirty work for the full-contact pedo who recorded the damned thing.
As for drawn child porn, involving fictional characters (i.e. not CSAM), it is legal in certain jurisdictions. Notably, America, where the 1st Amendment errs on the side of creative expression[1]; and Japan, the thinking man's Epstein Island, where... I actually don't know why the fuck Japan is so weirdly tolerant of all this sick lolicon trash. Hell, Watsuki didn't even get cancelled when it came out he had 100 DVDs worth of actual CSAM.
There's an additional layer to this, though, in that for all the crimes you brought up, there's been a history of active state complicity in the crime:
- The CIA is a drug trafficking gang that happens to moonlight as a government intelligence agency
- A good chunk of elected officials and heads of state in multiple countries were compromised by notorious child trafficker Jeffrey Epstein
- The government doesn't pay taxes. I mean, obviously, they're the ones levying them.
We like to think of law enforcement as a cat-and-mouse game: criminals do a thing and law enforcement tries to hunt them down within the bounds of 4A/5A. The reality is more complicated. There are cases in which governments actively collaborate with organized crime, either because the government is corrupt as sin, or because the criminals are offering the state a way out.
[0] Fun fact: if you use Bitcoin, you're automatically opting into this.
[1] To be clear, while I agree with the American argument, you still shouldn't actually expose yourself to this kind of porn, because you're training yourself to get horny around kids. I shouldn't have to say this, but just because it's not illegal doesn't mean it's safe to use.
As I noted in another comment:
Currently this is explicitly against the law[0]:
(a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
(1)
(A)depicts a minor engaging in sexually explicit conduct; and
(B)is obscene; or ...
(b)...
(c)Nonrequired Element of Offense.—
It is not a required element of any offense under this section that the minor depicted actually exist.
It is not a required element of any offense under this section that the minor depicted actually exist.Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.
Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOSSAD’ED UPON"[0]. This is specially good for me because I know the equivalent to the FBI where is live is too cheap to buy a Cellebrite [1] license.
[0] https://www.usenix.org/system/files/1401_08-12_mickens.pdf [1] https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...
EDIT: I suppose someone could ask about Meta. The reason behind their support for scanning (and removing e2e in facebook msg) is simply regulatory capture. The zucc wishes to have a letter of marque to "protect" your children and remove the "unsafe" competitors.
EDIT2: Used the wrong term, I mixed up exfiltration channel with sidechannel attack.
Watching memory changing on a complex code base without having said code base is near impossible.
1. Run code 2. Watch memory changes 3. Correlate those to real data
If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.
My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy.
What financial gain do they get from this?
A: risk billions in stock value and customer purchases for basically a "thanks" from the gov? One whistleblower would also have the real ability of becoming world famous for "exposing" apple.
B: Get publicity actually resisting the gov and not lying, what is the gov gonna do? I imagine it has and does happen but I also imagine there's a crying tim apple being dragged through it painfully.
Unlike google I just don't see the financial positives for them to do it beyond massive arm twisting. For many companies the risk of destroying their entire value to customers is just not worth it.
The only money in it is mass scale data collection for training data and ads, if they aren't doing that any other method is the opposite of valuable it's a massive liability.
I'm curious as to how well (legally) this "we could modify the app to do it, but nah" approach actually works, and for how long.
From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers.
I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually contain ways to truly lock out the company itself from seeing your data.
Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.
I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could.
And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would take a whistleblower to find out.
> Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.
I agree, it is the best option available. But Apple/Meta are technically lying when they say it's impossible for them to read your messages.
If the company is misleading, any encryption technology is irrelevant anyway.
This is for example why Lavabit chose to go out of business instead of giving up their keys.
Which apple does.
It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc).
The headaches that come from e2e everything are too great for most people.
That's obviously only the case if they aren't also the sole providers of the "ends".
1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.
Another way is to open source it and repeat 2/3/4
The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.
In a technical sense it's absolutely possible. Owning the servers != transferring keys to the servers. Most E2E apps run both client and servers, it's about if they ever had key access.
But when Apple etc. control both ends, their app could always see your data locally because it is the one that encrypts it to upload to the server in the first place. And these companies can receive secret orders from the US government to add backdoors into the local app and there's nothing you can do or say about it, except go out of business (like Lavabit).
As sad as this is, end to end encryption means no CSAM scanning.
As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too.
This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.
Just because we technically can make a privacy destroying drag net does not mean we should. Had phones existed 250 years ago, I have no doubt the founders would have thought it obvious that a cellphone’s contents were your personal papers which could not be freely searched.
An icloud is like a storage locker or a safety deposit box... the owner should go through all your stuff there, just in case you have some CSAM!
Metadata is just tracking info about who, where and with whom... every bartender should take your IDs and log when you came to the bar, who you sat with and how long you talked there.
EU Chat control is like general eavesdropping... every time you sit down and talk with someone, an EU bureaucrat should sit next to you and listen and write down your conversations, just in case.
etc.
Somehow people think that "it's ok if it's on the internet", even when it's stuff they'd never accept in real life.
Personally, I am on the side of privacy, just to be clear.
When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.
If you take a 1000 random people of the street now,how many of them are sharing CSAM via icloud?
If you take a 1000 random politicians, how many of them have corruption scandals? Why not start with them instead, a bodycam and an AI powered microphone that would detect corruption automatically... let them lead as an example, before they apply the laws onto "the rest of us".
Even if the current proponents have no ulterior motive, and in fact live and die having done nothing negative with such power, it does not stop the next group in power from extending and abusing power, don't base laws on temporary trust of politicians.
It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing.
They could do it when people are not at home. There'd no problem, nobody would even notice.
A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?
Absolutely not.
And client side scanning is just as bad as encryption backdoors. There's a good reason Apple was attacked for even considering it: https://arxiv.org/abs/2110.07450
The primary focus should always in preventing the creation of CSAM.
- Comprehensive Sex Ed starting young so kids can identify grooming and seek help from a trusted adult, even if abuse comes from a family member.
- Fixing schools in general so homeschooling isn't as attractive for parents. Keep a tab on home schooled children and identify social isolation.
- Bigger resources for actual honest to god on the ground investigations.
To be clear I'm not saying that homeschooling = child abuse, simply there's a lack of the mechanisms to detect it in homeschooling settings.
I'm not entirely convinced that's true. Facebook is a leading reporter of CSAM, much of it sent through Messenger, which only recently got E2EE, and Instagram DM, which briefly had E2EE but no longer does. If I was going to transmit something that could get me in trouble, it certainly wouldn't be via Instagram DM.
Facebook's EU CSAM report is here: https://transparency.meta.com/reports/regulatory-transparenc...
Not true. There is the option of scanning on the device.
There is no back door if nothing leaves your device
> goes against the purpose of having end to end encryption
Most people would consider the "purpose" is to avoid 3rd parties listening in
I think your conspiracy theory needs work, to be perfectly honest with you.
I think it depends on your definition of e2ee and where the "end"s are.
If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?
Once again, someone (in this case, the judge of this case) asks if we can meet in the middle on whether or not private communications are actually private.
To be clear: this is not a limitation of nerds' imagination. This is a limitation of physics. A person is either party to a communication (and thus can decrypt it) or is not (and thus cannot). If you demand Apple scan encrypted photos for CSAM, what you are demanding is that Apple be party to every communication done with an iPhone. There is no middle ground on encryption, there will never be a middle ground on encryption, and I will hold this truth on my deathbed.
There is no "encrypted but crackable" - if the CIA can crack it at all, we're only a few years away from some kid's gaming rig doing the same thing. There is no "secure golden key" - if there was, you could buy it in the same section of Amazon that sells copies of the TSA master key that opens all luggage locks.
Personally, the next time a government demands decryption keys, I think Apple should just set all iCloud photo libraries in that country to public and say "Sorry, your politicians made private photos illegal, take it up with them". Obviously, telegraph this far in advance and give users time to actually delete their cloud-hosted photos first. But definitely do not pretend like you can keep a secret with a government bureaucracy of hundreds of thousands of people.
But then again, Apple also capitulated (good meaning) to the EU on third-party app distribution, so Apple has a lot less of a spine than they let on. At least Google actually stayed out of China.
Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).
The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)
Governments need to catch criminals, but they shouldn’t do it at everyone else’s expense.
What world do you live in?
Most people don’t have computers, those who do, do not regularly backup their photos on them.
In both family and extended family many a cry would be avoided if people paid the 5 bucks it costs to backup their photos before your phone gets stolen or lost.
The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen.
The criminal and disgusting tail end of this type of material deserves the worst of consequences for the perpetrators and all the support in the world for the victims, but these are mostly - you guessed it - poor and unprivileged children from far away places and they certainly can’t put this much pressure on apple
I wrote to the rep and explained my concerns. I wholeheartedly agreed with the intent of the law, but the code was buggy. To my surprise, he wrote back in horror to say he hadn’t considered that and pulled the bill immediately. I’m proud of having done that.
I’m 100% pro yeeting child pornographers into the sun. I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.
The one messy corner of this is the "strict liability" for this type of material. An underage kid can take a nude photo, send it to an adult, and then the adult can criminally liable for just having it, even if he deleted it as soon as he saw it. Either both parties involved in handing something for which there is "strict liability' need to be held accountable, or "strict liability" has to be changed so a person isn't liable if he deletes or reports the material as soon as he first becomes aware of it. And this isn't likely to happen because it would provide a plausible defense for every one criminally charged.
Stories like this give me hope - thank you for sharing
This is weird indeed. These bills are mostly put forward in order to appear tough on crime and secure votes of the naive population ("think of the children"). Pulling the bill is detrimental as it may lead to "pedo supporter" conspiracy spreading among the district.
While on statistics, I wonder, are there reliable statistics about child abuse of different types? Studying correlations with other social metrics, like sex education, liberal/conservative, policies regarding prostitution, and others can provide support for/against decisions.
Not that I hope these will impact people's and governments' choices, but I want to challenge my intuitions.
The real question is what happens when a horny teenager sends another a nude. There definitely have been insane cases where they get stitched up for creating child porn. I don't know if that's the normal outcome today though.
It was not a tool to identify private images as being underage. That’s an impossible task.
Just ask the dad who was investigated for taking pictures of his toddler for the doctor: https://www.koffellaw.com/blog/google-ai-technology-flags-da...
I don’t have any ideas for a solution, but I suspect that the heightened focus on CSAM is really compensating for the fact that we don’t have solutions for revenge porn.
The only way I can see this working is that people in explicit images need to publicly declare their intent for who can see the images (maybe a hash of the image content and the name of the person who can see that content) and then when the courts prosecute revenge porn the intent can be referenced to see if it was meant to be shared or not. There are still issues in that there is no proof that the person being accused of revenge porn actually distributed the images vs the defendant actually sending the images to other, or the image was leaked by a hack.
I think the best thing we can do is try and educate teens on the dangers of revenge porn like we do on the consequences of having sex. We cannot stop teens from having sex or taking nudes, but we can at least try to educate them as best we can.
Yes, poor and unprivileged children can't really defend themselves here, but this is the system working to find some legal mechanism to do what it can, as a more powerful force. Protecting people from exploitation is a good use of government. If this was shot down for legal reasons, OK, the system is working and I hope there is a way to expand protections that fits into our system.
Our legal systems are not built to deal with that mess, and it may hang around your neck for the rest of your life. Unfortunately, the law is very explicit, leaving barely any avenue for the courts to drag us out of the mess, and politicians - even if they are actually interested in the topic in the first place - won't touch that area with a ten foot pole for fear of getting blamed a pedophile themselves.
[1] https://www.n-tv.de/panorama/KI-treibt-Jugendporno-Fallzahle...
I'm aftaid of putting those terms in my search engine, can you please expand those acronyms?
Don't let a classic "think of the children" appeal to emotion short circuit your reasoning.