4 ms·
Photos are currently encrypted e2e already so Apple does not have the access server side to create the hash unlike their competition who chews their customers d
by LexGray 5y ago
Photos are currently encrypted e2e already so Apple does not have the access server side to create the hash unlike their competition who chews their customers data for machine learning. https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303
- kemayo 5y agoYou've misread that page -- the table just refers to content being stored in an encrypted form, even if Apple still possesses a key. There's a list below it of fully end-to-end encrypted content, which doesn't include Photos.
- LexGray 5y agoTrue enough. Apple does have the key. Well then instead the answer is that they are having you pay the CPU and energy cost instead of wasting twice the energy decrypting and hashing your photos server side.
- dwaite 5y agoYou were sort of both right. Apple has the keys in escrow across several HSMs separate from the cloud hosting environment. Nothing within iCloud can actually see the content, but there are processes to get access to a particular account for various reasons (such as government order). There is a separation of permissions as well as hardware-generated audit logs. Reportedly the HSM systems were specifically manipulated to not be extensible via software updates. So it is E2E with a separate key escrow system, which Apple (wisely) does not attempt to call E2E. Apple couldn't implement the PhotoDNA-based scanning other providers have done because Apple would need access to the escrowed keys for each user photo uploaded.