46 ms·
Apple Has Opened the Backdoor to Increased Surveillance and Censorship
- xyst 5y agoI am beginning to wonder if this was the plan all along. Back in 2013 via the Snowden leaks, it was revealed Apple was associated with the NSA domestic surveillance program, PRISM. It appears they (NSA and Apple, et al) pulled out due to the level of negative PR. After 8 years, the intelligence community and tech companies figured out they could sell their surveillance through a thinly veiled effort to “protect X group” (in this case it was children).
- szc 5y agoSorry, but I do not believe that is what the leak revealed. There was a slide that indicated that data from Apple and other companies was now part of the PRISM program. I am not trying to deny or refute Snowden's whistleblowing. I think it is highly likely that PRISM exists. What I dispute are the speculations that the companies listed are complicit. The 2012 date is quite suspicious - it is precisely the same year that a new Apple datacenter in Prineville came online. Facebook also has a datacenter. Literally next door. Facebook also appears on those slides. I am not sure who else is also now in the area. I wonder where all of the network cables go? I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. The NSA has previously tapped lines (AT&T), but they made the mistake of doing it inside the AT&T building. Google "Room 641A at 611 Folsom Street, SF". That is where "beam splitting" was done. This eventually leaked out. The NSA isn't stupid, I doubt they wanted to repeat that sort of discovery. The best way to keep something from being discovered is to not let people know. This is why I think it is believable and likely that the companies listed on the slides have no idea what has been done. I will also note that PRISM and "beam splitting" are a rather cosy coincidence. I think it is most likely that PRISM is implemented without the knowledge of anyone except the NSA and in Prineville there is some "diversion" of network cabling to a private facility that is tapping the lines.
- alfiedotwtf 5y ago> I wonder where all of the network cables go? Remember the smiley face in the slide deck?
- szc 5y agoI do not. It would be helpful to enumerate the specifics of this rather than to play the role of a cheshire cat and say nothing. (I am independently looking for this, but cannot currently confirm)
- alfiedotwtf 5y agoSorry, I thought it was part of the collective. ICYMI: https://slate.com/technology/2013/10/nsa-smiley-face-muscular-spying-on-google-yahoo-speaks-volumes-about-agency-s-attitude.html https://slate.com/technology/2013/10/nsa-smiley-face-muscula...
- szc 5y agoThanks. This can be entirely explained if the NSA had already performed a "solar winds" supply chain attack on the vendor that supplied the TLS encrypt / decrypt endpoints. Is the vendor of that hardware known or discoverable? Google would have no idea the traffic could be intercepted. The NSA could use the Smiley face, perhaps with a nudge, nudge, wink, they are now a "supplier of data" on slides.
- lmm 5y ago> I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted. If you want even basic PCI-DSS compliance then links between racks must be encrypted (and a rack that uses unencrypted links must be physically secured). And properly implemented TLS or equivalent (which is table stakes for a company that takes this stuff at all seriously) can't be broken by the NSA directly (and if it could be then everything would be hopeless). Thus the MUSCULAR programme where the NSA put their own equipment in Google's datacenters - that's really the only way you can do it. Remember how the legal regime in the US works with National Security Letters. Companies can be, and are, required to install these backdoors and required to keep their existence, and the existence of the letter itself, secret. Of course Google, Apple, Facebook, every other company with a significant US presence is in receipt of one of those letters and has installed backdoors - the NSA aren't stupid, what else would those laws and their funding be for?
- sneak 5y agoThey didn't pull out. Apple discloses over 30,000 customers' data each year without a warrant under PRISM (aka FISA 702) as disclosed in their own transparency report (listed under "FISA orders"). PRISM is just the internal NSA name for it. It continues unabated.
- szc 5y agoFISA orders are written by a Judge. Only judges can write these, this is the literal definition of a warrant. Warrants require specifics - Person X, person Y. These are enumerable. There is paperwork. PRISM, based on the data available, is all about consuming data WITHOUT a warrant -- vacuuming data associated with identities that are not associated with ANY identities subject to a court order. Violating laws and possibly (USA) constitutional rights in quite a few ways. PRISM likely exists. I ask of "sneak" to confirm their assertion that "PRISM == FISA orders" is true. Please present this "evidence" and the evidence of connection. If you cannot you are, by default, distributing mis-information, bad logic or at worst tying to mislead. (my naive searching suggests that "sneak" is definitely not in a position to make these claims)
- deleted 5y ago[deleted]
- sneak 5y agoJudges can write lots of orders but that doesn't make them search warrants which are defined by the US constitution as requiring probable cause. FISA court orders are not search warrants. FISA Amendments Act (FAA) section 702 is the legal basis claimed by the NSA in a secret interpretation by the FISA court as the basis for PRISM targeted collection without search warrants, including US persons/citizens. It's on Wikipedia if you don't believe me: https://en.m.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act_of_1978_Amendments_Act_of_2008 https://en.m.wikipedia.org/wiki/Foreign_Intelligence_Surveil...
- juanani 5y agoI can't figure it out, are you a corp shill or gubmint? Dang allows both if they are playing our side so this is truly confusing. Can't tell where they've pinned you, jeez they probably give out degrees for that level mental gymnastics.
- robertoandred 5y agoAfter EFF got so many things wrong in their first clickbait article about this, does anyone expect this one to be any better?
- hmsshagatsea 5y agoWhat did they get wrong?
- shuckles 5y agoAbout 2/3rds of their original letter was spent characterizing the system to warn kids about dick pics with on-device inference as an iMessage backdoor, which literally nobody serious believes.
- tzs 5y agoMore astounding was the privacy issue they raised with it, which I've not seen raised by anyone else. Let's review how this feature works. It is only on if parent's explicitly enable it for their child's phone when they set up the child's phone for parental controls. If it is on, images sent to the child's phone are scanned using a ML system to recognize sex images. When such an image is found, the child is given a screen that warns that the image contains content that may be harmful to the child, and may be an image of someone who did not consent to having it sent. The child is asked if they want to reject the image or view it. If the child elects to view it and is 13-17 they are shown a blurred version of the image and that is the end of it. If the child elects to view it and is under 13, they get another screen that says that if they view it their parents will be notified because the parents want to be able to check to make sure the child is safe. They are again asked if they want to reject it or view it. If they reject it, that's the end of it. If they view it they get a blurred version and the parents are notified. The privacy issue the EFF has with this? If I send your 12 or under child a dick pic and they elect to view it knowing that their parents will be notified and see a copy of the image, my privacy might be violated because I did not consent to the child's parents being told I'm sending their child dick pics or to the parents seeing my dick pic. I wonder what the EFF's opinion would be if I sent a dick pic to a 12 year old whose device does not have parental controls, but the kid decided to show it to the parents. Has the child violated my privacy? If we are in a state that has a civil law against nonconsensual image sharing would the EFF help me sue the child?
- hamburgerwah 5y agoGuarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.
- amazingman 5y agoI guarantee you they won’t. My guarantee is at least as good as yours.
- fsflover 5y agoYour guarantee is worse, because Apple has shown themselves as pro-copyright and pro-scanning.
- handrous 5y agoI doubt iOS devices contain enough pirated material on-disk, on average, to make that worth any part of the cost (money, reputational).
- swiley 5y agoMost iOS device probably don't contain any child pornography either.
- hypertele-Xii 5y agoDidn't iMusic or whatever upload users' personal high quality files to cloud, to stream them back in lower quality, and then deleted the originals from the users devices? I remember something like that making the news. Imagine being a musician and Apple deletes your originals to stream your own music back to you in low quality.
- daenz 5y agoAn Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.
- 88840-8855 5y agoI don't want to be that guy, but for this job there were lining up 300 more people. Nobody except of a tiny group of nerdy guys (including myself, ofc) is against this apple csam move. Just ask your parents or your non-tech friends if it's "ok" to scan people's phones to find those "bad pedophiles" in order to jail then up for the rest of their life. You will be surprised how much support Apple's initiative has in the broad public. And that's why apple made this move. They don't really care for the 3% of people who we belong to. They do it because they know they will have the public and political support.
- enw 5y agoEveryone I asked understood the potential for misuse it introduces.
- 2pEXgD0fZ5cF 5y ago> Nobody except of a tiny group of nerdy guys I think you oversimplify this by a lot. No, Apple reputation won't be severely damaged by this move immediately. But I do believe that those "nerdy guys" did a lot to push the Apple brand, and a big part of that push was due to security and privacy. Until recently Apple was always the "privacy brand" and it was hard to argue against it without going the full FSF route of argumentation. This is no longer the case and I'm sure this will deal some damage over time, even if it only starts with the "screeching voices" of the (nerdy) minority. Maybe not directly to their revenue, but certainly to their reputation. Nothing wrong with shaving off a bit of the prestige of working at Apple ;) > I don't want to be that guy, but for this job there were lining up 300 more people. This is the case for many jobs that don't come close to the holy "working at Apple".
- deleted 5y ago[deleted]
- zxcb1 5y agoReasonably, there are other criminals using iDevices, why stop at this? Even pre-crime police work may be feasible with AI and advanced pattern recognition.
- Grollicus 5y agoLooking into the future with AI and advanced pattern recognition does not work for the stock market, why would it work anywhere else?
- MomoXenosaga 5y agoPre crime police work would be social services. But increasing funding for those are not popular with conservatives and libertarians.
- PikachuEXE 5y agoReminds me of anime Psycho-Pass Prevent crime from happening by checking your vitals to predict the probability of committing crimes
- carom 5y agoThis is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender. EFF lost a lot of credence to me after the Best Buy case. They made this big fuss about how Geek Squad employees were agents of the state for reporting CSAM on a customers hard drive, while doing a requested file recovery. When searched, the defendant had CSAM on 5 different devices. The case was dismissed on a technicality. Never did the EFF mention this. Never did they say they were defending a gynecological doctor who had CSAM on 5 devices. Nope, it was spin city. Now here we are. Apple has made a privacy preserving anti-virus scanner. It does not upload unknown files as Windows Defender does, it does not scan everything. It scans your photos, for known CSAM images, when you are using iCloud backups, in order to comply with the law that they must scan their hosting services for CSAM. It has a more narrow scope than an anti-virus scanner, and a bigger societal benefit. We seem to have taken the idea that sometimes bad things are promoted through "think of the children" to mean we must oppose anything involving the protection of children. Our greatest fear in this is the government using a national security letter to search for banned ISIS memes? Let's address that slippery slope when we come to it, and let's note that we do not see Windows Defender or similar doing the same. This is great, I hope it puts a bunch of pedos behind bars.
- bathtub365 5y agoThis analogy only works at a superficial, technical level. When a virus scanner finds a virus, it alerts me and I can either quarantine or delete it. It’s up to me to decide if what it’s found is actually a virus, or a false positive. When Apple's tool thinks it’s found the material it’s looking for, the assumption is that I am a pedophile who collects CSAM.
- bitwize 5y agoRather than oppose a measure to protect children because of the fear of a few false positives, why can't you accept the fact that the societal benefit outweighs the potential risk? A few innocent men might be condemned to rot -- or be murdered -- in prison, but Apple has developed a system that mostly protects your privacy and could save the lives of potentially millions of children around the world. The rights of a few harmed innocents must be balanced against the greater societal good. (/s in case you were wondering)
- MomoXenosaga 5y agoI don't get people. It's not fucking E2E encryption when it is being scanned. That's just trying to change what encryption means.
- nicce 5y agoWhile this true, you can’t say that it is worse than current state. (Only server side encryption, plaintext in the eyes of Apple)
- markenqualitaet 5y agoIt is worse tho. The surveillance apparatus doesn't care much about your actual words and images, but your associations and relations. This makes finding needles much more efficient and pre-encryption exfiltration circumvents user added measures, like third party iCloud encryption. And I am pretty sure this will be baked into the OS deeper than your VPN/DNS's reach. Opening up this side channel isn't undone by trusting some "icloud deactivation". Much less in your mind.
- nicce 5y ago> Opening up this side channel isn't undone by trusting some "icloud deactivation". If you can't trust that, then you can't trust the whole OS and all this speculation has been as valid as any given time.
- markenqualitaet 5y agoWith this argument you can dissolve anything in "why even bother?". In the real world it very much makes a difference, if the breach of trust is secretly implementing a side channel, or secretly using a documented one. The latter e.g. can maybe by activated "by accident" plausibly, but having a backdoor at all is hard to justify. And for a company like Apple, the size of a breach of trust matters for financial incentives.
- zionic 5y ago
- lovelyviking 5y agoPushing Spyware Engine is literally abuse to all people including children and it's much worse then any problem they would claim to fight. Even if you believe them. By this move people are indoctrinated with the idea that being watched by someone big and powerful is Ok. They learn to accept such abuse and what can be worse for any safety of anyone than learning that? If one is serious about any safety one should learn to walk away from such abuse first just like with any other abuses. It is an attempt to legalize such Spyware Engine installation. Nothing more. The story is just to sell this move using emotional response from naive people. Because high emotions is when people do poor thinking for the long term consequences. Think about Vendetta and consequences of it. Those people should be educated what the real abuse is and they should teach their children to recognize it because abuse by Apple is already there and it is much worse then the problem they claim are trying to solve. People need to understand that it will get much worse with the time.
- koopmenistan 5y agoSo this one time I was tasked to verify a complaint of child pornography and image the infrastructure for evidentiary purposes, if necessary. It was the first time I’d ever been exposed to it as a naïve operations kid at a hosting provider. Imagine my surprise and horror to find that not only was the complaint accurate, it led to a completely polished thumbnail site on par with PornHub. Boom, right there, no login. No nothing. Five high, seven wide thumbnails. No two of the same child. A complete search engine based on Solr that could filter the thousands of images by age of the victim. By the number of adults participating in the rape. A threaded comment section on each image where people discussed children in their neighborhood and their fantasies of abducting them. An erotic literature section where parents wrote about how they’ve been sexually attracted to their children since changing their first diaper. I’ll never forget a photo of two men brutally raping a girl of about 9 or 10, because it was one of the highest voted on the site. One of the comments, which I still remember when I close my eyes at night, simply said “its better when they cry”. It’s been eleven years and I’ve seen and dealt with much more of it since then, and I still weep to this day thinking about the pain inflicted on those children, the pure evil of those who enjoy it, and even the design and engineering team who bafflingly put their skills toward building that nadir of human achievement. Tell me again what “the real abuse” is and educate me, please, because you sound pretty confident that the frighteningly common story I just told isn’t that big of a deal. I can’t believe anyone sane would compare going through your photo collection, even egregiously, to the rape and exploitation of children and think, yeah, you know, based on my value system door number one is the “much worse” injustice. Your opinion is fucking sickening and the exact type of detached inhumanity that is poisoning this industry top to bottom.
- nbzso 5y agoLet me tell you my perspective as a screeching minority long time Apple user. You may be right. We as professionals that evangelized a lot of people for Apple, don't have power or influence over core target of Apple of today. Yep. But I can assure you that I personally, as my colleagues will do everything in our powers to hurt Apples public image and brand, to give real information to our clients, friends and families. To educate people why smartphone convenience is slavery to the Tech Lords and how in the future all this data will shape a Digital ID in Social Credit System which will render peoples freedom obsolete. To all apologists, Apple employees and shareholders who will hold their stock after this, I have a simple message: F*ck You. No. Seriously. Go to hell. You are created and supported the monster which will eat you at the end.
- goekydoeky 5y agoWow. The misalignment of priorities and character deficiencies one requires to actually type this message and mean it is simply breathtaking. Talk to someone, please. You are unwell if this message is genuine. Even if you grant every argument against this system it’s still just poking through your photos at the end of the day. Get angry enough to tell people “go to hell” about half the planet being on fire or something, anything but technical policy that ultimately matters quite little against other challenges we face as a species.
- nbzso 5y agoSeriously? Breathtaking? Talking to someone? Is astonishing to me how "smart" and "educated" people are lost in meaningless details of technological implementation when we are witnessing assault on privacy and personal space on a global level. Let me help you understand something important: Sitting in comfort and relative security cannot give you a real life perspective of long term impact of this system. The long term effect will be the normalization of surveillance state. You don't need people to "See something, say something" you just trust a corporation working with database provided by third party (governments) without any form of public oversight. Without open source software and with proven record of abuse (see China servers case) and proven record of exploits (see NSO/Pegasus). And I have to talk to someone?:) Please, grow up. I have lived part of my life under communistic regime. The political language of personal invasion under the name of "common good" was the public mantra and abuse of the system was a everyday reality. When secret services are taking away your mother on a "signal" received from "trusted procedure" created under the wisdom of the Party Elites you cannot do anything. Trust me.
- gary17the 5y agoA question to you legal experts out there: if a potential CSAM match is found during client-side scanning, but such a match has not yet been confirmed by an Apple employee to actually be CSAM, does Apple have the option, legally speaking, to SIMPLY DELETE the "gray-area" content in-place (just like a regular virus scanner), instead of sending it to Apple for further analysis? Someone performs "an implication by malicious actors attack" on your iPhone/iPad and the injected content simply gets deleted. You take a (false positive) photo with your iPhone/iPad - and it simply disappears (making you retake). No private content is ever sent anywhere, no horrible accusation is ever made, no CSAM ever gets uploaded to iCloud. Simple. Why doesn't Apple do that?
- occamrazor 5y agoI think that the FBI/NCMEC wouldn’t allow the use of the hashes for this. A criminal could load its image collection, one by one, and see which images are deleted. The result is a collection of images that are “FBI safe”.
- gary17the 5y agoBut this strongly suggests that the entire Apple/NCMEC initiative is a "suveillance-and-arrest" system first and foremost (preserving hash secrecy at the cost of user privacy), while the goal of "stop-known-CSAM-distribution-in-iCloud" (developing an in-house CSAM database at the cost of scanning effectiveness) being secondary.
- occamrazor 5y agoThis seems to come from the NCMEC, not from Apple. I remember another thread (can’t find the link) from someone explaining how difficult it was for them to get access to PhotoDNA and the relative hashes.
- samrolken 5y agoIt seems like this system was designed specifically so that this would be impossible, and such a feature would go against what seem to be design goals of this system. They went through the trouble of making this whole “private set” matching so that the client does the matching but doesn’t know the result of the matching. Only the server can (once enough matches are made that the key is available).
- gabrielblack 5y agoMy opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking for dissidents: I look for people that have a photo of Tiananmen Square protests on their pc, for example; - for espionage: I have the hash of some documents of interest, so all the PCs with that kind of documents could be a valuable target; - profiling people: you have computer virus sample on your PC -> security researcher/hacker; I think that the system is prone to all kind of privacy abuse. 4. this could be part of the previous point, but, because I think it's the final and real reason for the existence of that system, I give to this point its own section: piracy fight. I think that the one of the real reason is to discourage the exchange of illigal multimedia material to enforce copyrighs. For the listed reasons, I think that is a bad idea. Let me know what are you thinking about.
- aborsy 5y agoI agree!
- simonh 5y agoOf course it would be possible to implement content search, profiling and reporting mechanisms for such content, but this seems to be a singularly bad platform for that sort of search. The image profiles are part of the OS so there's no mechanism to deliver image profiles separately for different countries. Also when the threshold number of matching images is reached, the matches are reported to a manual reviewer at Apple not a government. It only checks images on upload to iCloud photo storage. So of course each of these limitations of the system could be changed, but you'd really need to change all of them and at that point you've created a completely different system. There's no simple change to this system that would suddenly turn it into a snitch for e.g. China or Saudi Arabia. I've seen exactly the same objections raised every time any kind of device content search has become mainstream. Back in the 90s it was virus checking (Do you trust the AV company? What if they were bribed by the content companies?), full device indexing and search (Do you trust the OS vendor? What if they're in league with the government?). I'm very surprised this didn't blow up when Apple implemented ubiquitous image text recognition. Maybe it did. AV and device indexing mechanisms, which are ubiquitous, seem like a far more vulnerable target for such requirements. So I don't really buy the slippery slope argument. In theory any government could pass a law requiring any company operating in it's jurisdiction to do anything, with an implementation suitable to that actual purpose. Of course this mechanism is motivated by laws in the US so it's a perfect example of exactly that, and it's a completely new system not a slippery slope subversion of an existing one. The real slippery slope here is legislative, not technical and I think that should be far, far more concerning. I do think the legal and moral questions about this mechanism are legitimate. I think it would make more sense for Apple to scan photos in their cloud storage on the cloud storage rather than on upload. I understand there are theoretical privacy benefits to users from this implementation but the optics of having user's devices snitch on them are all wrong.
- occamrazor 5y agoThere is another information leak that I have not seen mentioned in any news report. If an image hash matches the CSAM database, then it is sent to Apple, encrypted and with the “safety voucher”. Apple can decrypt the image only if they receive enough vouchers, and so they claim that they do not have any information about the user in case the number of vouchers is lower than the threshold. But actually they do have information: they know that a user has a specific number of images which are perceptually similar to known CSAM material. This information is not conclusive, but it’s also not nothing. For example, could a court order Apple to release the unencrypted iCloud backups of all users who had at least one match?
- nicce 5y agoThere is strong evidence, that E2EE backups are coming. How about hold our horses until actual release of iOS 15?
- cageface 5y agoWhat is the evidence for this?
- nicce 5y agoIn iOS 15 beta, there is option to recover backup with some authentication key. There is no use for that without E2EE.
- cageface 5y agoIf that was the plan why wouldn't Apple announce that alongside this to avoid the massive PR hit?
- nicce 5y agoThis whole Child Safety feature was not planned to be announced yet. They tried to fix some missleading leaks. My guess is that they are now preparing well to announce everything in September. I don’t want to be mean, but sometimes leaks do more harm than good, espcially when they don’t match what is actually coming. Many people are angry here, the most of them have not read actual technical details. Respected people should be more responsible about what they spread.
- ngcc_hk 5y agoJust a very bad move.
- eplanit 5y agoNot being an Apple fan, I'm enjoying the schadenfreude of watching them destroy the arguably most-favored, though one of the last remaining, qualities of Apple products -- people used to see them as the great protectors of their privacy. It fits, though. They also used to be considered the masters of UI design, and the best at hardware innovation, and in manufacturing. They've mostly destroyed those reputations, as well. It's actually good when old institutions/companies fail, because the opportunities created for others. The problem is that their failure often takes many years (i.e. look at IBM). If only we could accelerate the process across FAANG, the world would then truly be a better place (and their mission statements fulfilled).
- dav43 5y agoThis was the last straw for me. I’ve started looking around at alternatives (iCloud photos, literally no decent alternatives soo ok far to sync 400gb of photos) and have removed iCloud files to sub for just a simple NAS at home with tailscale. I doubt I’ll buy a new iPhone next.
- websites2023 5y agoEFF conflates the CSAM detection and the iMessage safety features in the first paragraph. Disappointing that they can’t make their case with the facts.
- arvinsim 5y agoIf Apple thinks this is a very good feature that will help CP victims, why wasn't it headlined in WWDC?
- FridayoLeary 5y agoWhat they did say was that privacy is a human right. So they are, by their own confession, abusing human rights, albeit to protect another human right. But the irony is striking.
- peanut_worm 5y agoWon’t you please think of the children?! Pinephone is looking awfully appealing lately.
- mensetmanusman 5y agoThis is apple speaking out both sides of the mouth, because they will be punished by China if they don’t implement this. China can submit hashes of political images Xi disagrees with to obtain lists of enemies. The only way to sell this tool to the west is under the banner of protecting innocent children, this is their best shot of squaring the circle.
- new_realist 5y ago“Techno-geeks throw fit upon discovering their devices are not immune to the rule of law.”
- scotuswroteus 5y agohttps://www.eff.org/deeplinks/2016/02/eff-apples-shareholders-meeting-statement-support https://www.eff.org/deeplinks/2016/02/eff-apples-shareholder...
- journey_16162 5y agoClient-side scanning? As in they can scan what is stored offline on a personal computer? Or is it just their cloud?