5 ms·
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iClou
by new299 5y ago
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos.
I really dislike this statement. It's likely designed to be "technically true". But it's been reported elsewhere that they do scan iCloud content:
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-icloud-photos-for-child-abuse-images/ https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
Perhaps they scan as the data is being ingested. Perhaps it's scanned on a third party server. But it seems clear that it is being scanned.
- shuckles 5y agoMy understanding based on piecing together the various poorly cited news stories is that Apple used to scan iCloud Mail for this material, and that’s it.
- new299 5y agoIf you have references to also help me piece this together I'd find that really helpful.
- selsta 5y ago> Last year, for instance, Apple reported 265 cases to the National Center for Missing & Exploited Children, while Facebook reported 20.3 million According to [1] it does seem like Apple didn't do any wide scale scanning of iCloud Data. [1] https://www.nytimes.com/2021/08/05/technology/apple-iphones-privacy.html https://www.nytimes.com/2021/08/05/technology/apple-iphones-...
- new299 5y agoIf they weren't doing any scanning why would they find any to report? The data is encrypted as rest so... why would they find any to report. This clearly doesn't include search requests [1]. iCloud has perhaps 25% of the users of Facebook. Of that 25% it's not clear how many actively use the platform of backups/photos. iCloud is not a platform for sharing content like Facebook. So how many reports should we expect to see from Apple? It's unclear to me. So, I'm not saying the number isn't suspiciously low. But it doesn't really clarify what's going on to me... [1] https://www.apple.com/legal/transparency/pdf/requests-2018-H2-en.pdf https://www.apple.com/legal/transparency/pdf/requests-2018-H...
- shuckles 5y agoForbes had the only evidence based reporting where they cited a court case where Apple automatically detected known CSAM in attachments to iCloud Mail: https://www.forbes.com/sites/thomasbrewster/2020/02/11/how-apple-intercepts-and-reads-emails-when-it-finds-child-abuse https://www.forbes.com/sites/thomasbrewster/2020/02/11/how-a... Everyone else is making inferences from a chance to their privacy policy and a statement made by a company lawyer.
- zepto 5y agoThat link doesn’t confirm that they have already been doing it. Just that they changed an EULA.
- dwaite 5y agohttps://www.forbes.com/sites/thomasbrewster/2020/02/11/how-apple-intercepts-and-reads-emails-when-it-finds-child-abuse/ https://www.forbes.com/sites/thomasbrewster/2020/02/11/how-a... My interpretation is Sophos got it wrong (they don't give a quote from the Apple Officer involved and manage to have a typo in the headline). Apple does scanning of data which is not encrypted, such as received and sent email over SMTP. They presumably at that time were using PhotoDNA to scan attachments by hash. This is likely what Apple was actually talking about back at CES 2020. They may have been also scanning public iCloud photo albums, but I haven't seen anyone discuss that one way or another.