6 ms·
Encryption does not help, Apple still is responsible. If Apple intends to let the user store photos in iCloud (or send by imessage) encrypted, they either have
by ashildr 5y ago
Encryption does not help, Apple still is responsible.
If Apple intends to let the user store photos in iCloud (or send by imessage) encrypted, they either have to keep the keys, so they can decrypt and scan the photos or or to keep the user from uploading incriminating content.
Apple found a third way: they will only get to reconstruct the keys if the user uploads too many pictures triggering alarms.
- adambatkin 5y agoSource? I am not aware of a law in the US that requires Apple to actively scan images, or to store them unencrypted (or keep copies of the keys).
- hef19898 5y agoThe US aren't the only government with a stake in that. And countries like China, Saudi, the Emirates have a lot of leverage. Financially and diplomatic. Heck, Facebook bowed to Myanmar just to get the users there.
- nicce 5y agoEvery cloud infrastructure holder is required for doing that. Closing an eye does not take a duty away. You must be actively pursuing that. Encryption would start flood of new laws https://www.govinfo.gov/app/details/USCODE-2011-title18/USCODE-2011-title18-partI-chap110-sec2258A/summary https://www.govinfo.gov/app/details/USCODE-2011-title18/USCO...
- ryanlol 5y agoThose laws do not exist (yet?). You can’t justify this as a compliance measure for legislation that does not exist.
- nicce 5y agoYes, but current laws also restrict storing images as E2E encrypted, so there is dilemma?
- ryanlol 5y agoWhere are you getting this from? That’s simply not true. It’s perfectly legal to “store images as E2E encrypted”
- nicce 5y agoEncryption itself is not illegal, but it might make harder to comply other legal requirements. I have just heard this many times, and now I read the whole law (curse me). It says on 2258Af part especially that there is no requirement to find evidence of CSAM material all the time. However, if NCMEC especially shares some information about visual depictions and asks to stop redistribution, then provider is required to comply in some cases. For example if they share hashes and these should be stopped. To be able to stop this data, then search is required and complying this with E2E encryption is not possible.
- pseudalopex 5y agoPlease show where those legal requirements have been applied to E2E encrypted files.
- skinkestek 5y agoTarsnap exists so either it is legal when done right or tarsnap is a walking dead and I haven't heard anything to that effect from any credible source.
- nicce 5y agoI guess that service slightly goes out of the scope for active scanning, because it is for general backup, not a cloud especially for photo sharing and storing.
- skinkestek 5y agoAnd that is my point: by tying oneself to the mast, denying oneself the access to navigate after the sweet sweet sound of user data, it becomes possible to sail straight past the sirens. Today this is less about physically tying management and physically putting wax in the crews ears and more about technically and legally making oneself unable to touch the juicy juicy customer data.