4 ms·
Right, and in the interview linked [1] above they state: > The voucher generation is actually exactly what enables us not to have to begin processing all users
by new299 5y ago
Right, and in the interview linked [1] above they state:
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos.
But they do appear to do "something" server-side. It's possible that all data in scanned as it is ingested for example. I dislike this statement, because it's probably technically correct but doesn't help clarify the situation in a helpful way. It makes me trust Apple less.
[1] https://techcrunch.com/2021/08/10/interview-apples-head-of-privacy-details-child-abuse-detection-and-messages-safety-features/ https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
- dwaite 5y ago> But they do appear to do "something" server-side. It's possible that all data in scanned as it is ingested for example. I dislike this statement, because it's probably technically correct but doesn't help clarify the situation in a helpful way. It makes me trust Apple less. The qualifier is "Photos" - different services have different security properties. Email transport is not E2E encrypted because there are no interoperable technologies for that. Other systems are encrypted but apple has a separate key escrow system outside the cloud hosting for law enforcement requests and other court orders (such as a heir/estate wanting access). Some like iCloud Keychain use more E2E approach where access can't be restored if you lose all your devices and paper recovery key. iCloud Photo Sharing normally only works between AppleID accounts, with the album keys being encrypted to the account. However, you can choose to publicly share an album, at which point it becomes accessible via a browser on icloud.com. I have not heard Apple talking about whether they scan photos today once they are marked public (going forward, there would be no need). FWIW this is all publicly documented, as well as what information Apple can and can't provide to law enforcement.
- ec109685 5y agoEven without publicly sharing your iCloud photos, they are accessible on iCloud.com (e.g. you can see your camera role there).
- cm2187 5y agoWhat I don’t understand is that if they announced they would do that scanning server side, the only eyebrows that would be raised is of people who thought they were doing it already. It’s not like if those pictures were e2e encrypted. I still haven’t seen any convincing argument about why searching client side provide any benefit to end users, while being a massive step in the direction of privacy invasion.