6 ms·
Severe loss of marketshare? It wouldn't even register. I don't like the feature. Putting this on the client device is dubious and should never have made it pas
by defaultname 5y ago
Severe loss of marketshare? It wouldn't even register.
I don't like the feature. Putting this on the client device is dubious and should never have made it past the brainstorming stage.
Having said that, technology companies, big and small, are bound in the US to do this. By law. If anything Apple was by far the laggard of the bunch (with reporting counts magnitudes lower than peers, despite a larger customer base). As I said in another comment, no company can protect you from your government.
Much has been made about it being on device, which while a serious optics issue...the hot takes being given on here are manifestly absurd. Like, literally the company that holds all of your data, all of your passwords, all of your info and you need to invent slippery slopes to imagine up what they "might" do?
If they want to have their way with your data, they could have been doing it for decades.
They should never have announced two very different systems at the same time. Contrary to some of the insincere claims given in this very thread, there is massive disinformation and confusion about them. In the end I feel like 98% of the "the end is nigh!" comments are by long time Apple detractors who just see this glorious opening.
And while I still hope that Apple says "Mea culpa, we're just going to scan on the ingress to iCloud Photos", whatever they do in a month this is going to be completely forgotten.
- cm2012 5y agoYeah, I dislike Apple and want them to have less marketshare, but I doubt they will even lose 1% of revenue over this.
- pseudalopex 5y ago> Having said that, technology companies, big and small, are bound in the US to do this. By law. Other companies scan their servers instead. And what law banned E2E encryption?
- 29083011397778 5y agoThis actually enables Apple to apply end-to-end encryption, while still complying with US CSAM laws. Users' content is scanned for CSAM, and is encrypted before leaving their phone. Whether one considers E2E encryption worth it if the content is still scanned before being encrypted is an exercise left to the reader. This potentially means all of iCloud, not just photos, could start to use E2E encryption as well - which is fantastic.
- strangeattractr 5y agoSo if we submit to having all our content scanned by them they'll even give us E2EE on iCloud? I guess they really do care about our privacy.
- deleted 5y ago[deleted]
- pseudalopex 5y agoLeaking information to Apple makes it not E2E. What law do you think banned real E2E encryption?
- dpkonofa 5y agoThere's no leak of content. None of your content ever gets sent to Apple...ever.
- pseudalopex 5y ago"safety vouchers, which contain a visual derivative of the image, such as a low-resolution version"[1] And I said information. The hash matching is information. [1] https://www.apple.com/child-safety/pdf/Security_Threat_Model_Review_of_Apple_Child_Safety_Features.pdf#page=13 https://www.apple.com/child-safety/pdf/Security_Threat_Model...
- dpkonofa 5y agoYou edited your response because I specifically used the word "content" because that's what you used...
- pseudalopex 5y agoI did not. The person I replied to said content. Not me.
- vimy 5y ago
- mdoms 5y agoThis is misinformation.
- TheTester 5y agoHow is this misinformation a opinion yes and perhaps too much of an hyperbole but you should read what misinformation is before commenting?
- Terretta 5y ago> Putting this on the client device is dubious Putting it server side is categorically worse. Putting it in the client SDK for iCloud (architecturally speaking) rather than on cloud storage or in the OS is clearly the better correct technical choice, tying surveillance’s hands in a way server side or OS would not. Most every client SDK routinely checks content before upload, it’s a best practice. Careful examination suggests this was engineered better than that practice. (Note: even tech trade posts such as LWN, Stratechery, or Daring Fireball trying to write well about this need to sit down a minute and have how it actually works walked through for them, as do many in this community.) FWIW, I agree with much of the rest of your post except the rationale for low reporting counts.
- lordlic 5y agoNo, architecturally there's no reason to do it on the client side. You're uploading a photo to iCloud, encrypted with a key that Apple controls. The only reason to use even a little bit of battery power to do the check on the client, and to do this elaborate song-and-dance around only notifying Apple if there are a certain number of positive matches, is that it creates the (false) impression that Apple couldn't just check your photos on the server side if they wanted to. It's basically engineering with the goal of creating a perception of privacy rather than actual privacy. I don't really care that much about Apple policing what you upload to iCloud, but this disingenuous architecture does annoy me a bit, and there's also the added insult of having a device in your pocket that by design works against its owner (reminiscent of "treacherous computing"). These problems would go away if they just did the check on the server side.
- LexGray 5y agoApple gets hung up on weird stuff. Likely doing work phone side was an environmental argument. The amount of energy used to decrypt server side to create the hash was marginally larger than the amount used by the phone pre-encryption with cost of transmitting. (Bonus that the energy and CPU was paid for by the client). The result for either location is identical.
- Terretta 5y ago
- slg 5y agoTech folks drastically overestimate how much the average person cares about privacy. Plenty of people believe that the Facebook and Instagram apps are recording audio 24/7 and target you ads based on the speech the apps hear. That doesn't stop people from using the apps. A few years ago some of the most famous people in their world had their iClouds accounts hacked and had their naked photos leaked. That is a lot of people's worst fear. People literally commit suicide over this sort of thing. It didn't hurt the iPhone's market share. People largely don't care.
- wintermutestwin 5y agoIMO, people largely DO care. If you ask the average Joe - is online privacy important to you, the majority would obviously say yes. Why then don't they stop using FaceCrook? 1. The penalty of social ostracism due to the network effect. This is a severe punishment to most humans - particularly in today's socially disconnected world. Without these apps, a large # of people would not have any contact with much of their social circle - including family. 2. Learned helplessness. I think that many people have just given up. Even if they knew how to fight for their privacy, they see time and time again that money always wins.
- lordlic 5y agoA better way of saying it would be that they just don't care that much. Most people care in theory about taking care of the environment, but that doesn't mean that they're willing to tolerate even 1c/gal higher fuel taxes. Most people care in theory about taking care of the poor but balk at the personal economic consequences of doing so. People have different priorities and when one consistently loses out to the others that means that they largely DON'T care about it.
- chillwaves 5y agoIf privacy was a selling point to buy Apple, then it will be a selling point to buy a competitor. Who knows how much it will matter in the end? But it is hard to argue it doesn't matter.
- eecc 5y ago
- argvargc 5y ago> Severe loss of marketshare? It wouldn't even register. Disagree. Something this ludicrously intrusive, over-reaching, reckless and trust-destroying is a dealbreaker for exactly the demographic of technology enthusiasts who influence others purchasing. It may not be instantaneous, but it would certainly propagate. It's anecdotal, but I know zero people who are NOT reconsidering even lifelong loyalty to Apple over this. It's just too crazy big a wrong, it's like the company just had a nuke go off inside it and is trying to pretend nothing happened. They may as well have announced a partnership with Trump to put MAGA engravings on all future products, and then in the ensuing furore say they "regret the confusion", whilst carrying on with it regardless. Though I suppose in that scenario they'd at least be targeting a significant market. The same can't be said for the size of "sign me up for software-automated police raids" market. A market whose naiveity-induced initial "size" would rapidly shrink after the first few innocents went down, as they absolutely would. I mean depending on the targets chat software preferences, could a malicious actor potentially ruin an Apple iOS users life just by sending them an image? There are many troubling scenarios one could imagine. In fact, there is nothing but troubling scenarios. It's not a can of worms so much as a wormhole, blasting an endless stream of worms at the speed of light. I'm left not just questioning Apple's leadership, but - honestly - their mental faculties. Really. No innocent person wants to walk around with an automated snitch in their pocket - I mean, hacking? Bugs? Oversights? Just the overall preponderance of fear that every millisecond you walk around with this thing, it - and its parent corporation and all the depersonalised machinations that go along with it - could be busy organising a blithely mistaken police raid on your family? Say, because someone you've never met, sent you a message on that new chat app you forgot you installed, that autosaves all media to your iCloud? Or because someone stole the spare phone you keep in a drawer at work, used it for God-knows what and you didn't even notice it was gone? Or, maybe your teenage son got sent something from his teenage girlfriend who unbeknownst to any of them had her phones images uploaded and subsequently catalogued and flagged? Or any number of other entirely plausible scenarios that provide the very reason we have law enforcement protocols and procedures for reporting crimes and that are complex, nuanced and have evolved over hundreds of years and mountains of cases into a massive structure that exists primarily to protect the innocent from exactly this kind of freaking crazy shit? And Apple expects people to pay them to carry the weight of all that around with them?
- mindslight 5y ago> are bound in the US to do this. By law I keep seeing this asserted, but there is never any legal citation. What exactly compels a software company to make their software product scan for CSAM? I get that a service provider like cloud storage may need to scan what they themselves are storing to avoid possessing such material themselves. And iCloud could scan uploaded blobs all day to fulfill their legal department's recommendation. But what exactly compels a software developer to include a content scanning function in code they distribute? And does this requirement also apply to the authors of rclone?
- defaultname 5y agoWhat distinction are you making with what I stated? What disagreement is there? Apple only scans photos being uploaded to iCloud photos. Google scans. Facebook scans. Microsoft scans. Even tiny image hosting sites scan. Apple decided to implement this functionality on device, but they could as easily (with much less fanfare and dissent) have placed it on the ingress to iCloud.
- mindslight 5y agoThe distinction is between providing services and providing software. When iCloud scans stored files like Google Drive, nobody complains. It's understandable that risk adverse legal departments have come to the conclusion that doing such things is necessary, to avoid a company being in possession of trivially-discoverable CSAM. And from an individual security perspective, you should consider everything you upload unencrypted to be the subject of similar analysis. If iOS were to encrypt all files before uploading, making any iCloud scanning mostly pointless, Apple would still not be running afoul of any law. Apple is making general software for end users, and encrypting files to upload would be doing the basic user diligence I alluded to. If users end up using the software to do bad things, those specific users are liable and not Apple. As far as I am aware, there is no legal requirement for a software developer to modify their software to perform scanning of content it will process while being run by other people. But this is what is implied when you say that Apple is forced to do this by law. Furthermore if this development was driven by iCloud worrying about legal liability from the combined system, then iCloud should be spun out into a separate company that cannot affect the development of the iOS software.
- alsetmusic 5y ago> Having said that, technology companies, big and small, are bound in the US to do this. By law. Law requires reporting CSAM. They are not required to scan for it.
- defaultname 5y agoUS law makes them responsible for what they host, to a reasonable, discretionary degree. Literally *every* technology company that I know of scans for CSAM for this reason. Apple is only implementing this for photos that go to iCloud Photos for this reason. They are surely not required to scan client devices, and that was a foolishly, ill-considered plan (that I still would wager they will abandon), however they absolutely must scan iCloud Photos unless they were technically incapable of doing this. US law doesn't say "you go to jail if you don't", it says "you face enormous liability if you don't".
- throwaway81523 5y agoI have dedicated and virtual servers at OVH and Hetzner and other companies. I'm quite confident they don't scan for anything on the hard drives. One of the selling points of Scaleway.com's C14 backup product (previous incarnation, don't know about current one) was that the storage was encrypted and that they would delete their copy of the decryption key if you checked a box. If you chose that option, you could not restore your backup without re-entering the key (block of hex digits that you had to copy on making the backup). It wouldn't surprise me if that resulted in the obvious sob stories about lost keys. Those are not US companies but I've never heard of AWS, DO, etc. scanning people's storage either.
- kevin_thibedeau 5y ago> but I've never heard of AWS, DO, etc. scanning people's storage either. Pre-Snowden, that was insourced by the NSA.
- noduerme 5y agoAWS offers encrypted backups, and afaik there's no scanning of anything you put in a bucket, but why trust them? Just encrypt your own backups before uploading them, and keep your own keys. In other words, your storage provider needn't and shouldn't be the purveyor of your backup software. Except with an iPhone, you don't have a choice.
- indymike 5y ago> in a month this is going to be completely forgotten. I'm tossing the mac and iphone because my phone is mine.
- indymike 5y ago> If they want to have their way with your data, they could have been doing it for decades Yep. They just altered that deal. (Darth Vader quote deleted)