14 ms·
Apple already scans iCloud Mail for CSAM, but not iCloud Photos
- h3cate 5y agoDidn't the US government recently start scanning messages for Covid misinformation?
- websites2023 5y agoNo. https://apnews.com/article/fact-checking-369404345862 https://apnews.com/article/fact-checking-369404345862
- h3cate 5y agoAh you must not of heard of Edward Snowden
- LegitShady 5y agoThis is a strawman "fact check". They disprove something that was never alleged to seem as if they're fact checking when in fact they're just trying to protect politicians trying to get corporations to intrude into your speech and privacy. What was said was the DNC was trying to get the text message providers to monitor the text, not that the DNC could read your text messages. The text message providers can absolutely monitor your texts. https://www.politico.com/news/2021/07/12/biden-covid-vaccination-campaign-499278 https://www.politico.com/news/2021/07/12/biden-covid-vaccina... >Biden allied groups, including the Democratic National Committee, are also planning to engage fact-checkers more aggressively and work with SMS carriers to dispel misinformation about vaccines that is sent over social media and text messages. It was never "the DNC can read your texts".
- smoldesu 5y agoNot sure why you're being downvoted when this is a proven privacy issue. It's not about democrats v. republicans or iPhone vs Android, it's about our leadership as a whole, and what kinds of powers they have. The fact that our government even has access to our private communications should feel like a conflict of interests, especially in a nation that prides itself on freedom.
- LegitShady 5y agobecause people are so polarized the idea of engaging corporations to intrude on your private messages is ok if its your 'team'. People never seem to realize what they're setting up are mechanisms and agreements that will facilitate further interventions. The mechanisms will be used against everyone, forever. This is just further increasing the centralization of power behind politicians who never deserve it and who use it on people with no power to resist, no matter whose team they're on. or they realize and are so pre-occupied with their team they don't care, which is sad and short sighted.
- aomobile 5y agoGood to get these reminders that our data is in fact not private and that our computers have other owners than us..
- istingray 5y agoOpen source hardware and software is the only sustainable path forward. Perhaps that DIY processor fab discussion is worth a re-read. Edit: HN Discussion of open source phones: https://news.ycombinator.com/item?id=28164208 https://news.ycombinator.com/item?id=28164208 HN Discussion of open source laptops: https://news.ycombinator.com/item?id=28266315 https://news.ycombinator.com/item?id=28266315
- aomobile 5y agoI mean what if apples search decides that I am suspicious? Will they unlock my keychain and give all my logins to some police or worse random people somewhere to check my stuff? Very disappointing indeed
- JKCalhoun 5y agoI don't believe Apple can unlock your Keychain. It requires your biometric (touch/face) to unlock from the Secure Enclave.
- shuckles 5y agoPer the threat model most of the people on here seem to be buying into, Apple can do whatever they want in an iOS update, including sending iCloud Keychain secret keys to a server they control.
- zepto 5y agoThe threat model people are buying into here is that Apple can’t do what they want today, but if they deploy this CSAM detector, only then will they be able to do whatever they want.
- istingray 5y ago"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.
- jeroenhd 5y agoI've honestly always interpreted their privacy activism that way. Apple acts as the warden of your data. Backups are encrypted for your privacy, but they hold a copy of the key. Traffic is obfuscated through fake Tor, but they manage the network. iMessage seems safe enough, but the source code is tightly sealed away, only accessible to Apple's eyes. It's still a valid way to advertise the company because I trust Apple more than I trust Google or Microsoft, who are Apple's biggest competitors. I'd much rather use Apple's cloud integration than Google's or Microsoft's within their operating systems as well. But don't think they don't have any data on you. Apple knows about as much about you as Google, but Apple keeps the data to themselves instead of selling access to advertisers. Always consider the possibility that the Apple four years down the line might not have the same ideals as the Apple of today or yesterday. We've seen Microsoft slide from a "you pay money, we give you software" to a "free software if you hand us your data" model and there's no reason why Apple couldn't choose to do the same.
- istingray 5y agoWell said, appreciate the long term perspective and summary of what you see across backups, fake Tor, and closed source iMessage. Good point about changing of Apple leadership. Tim Cook has said that 10 years from now he won't be the Apple CEO. That means someone new is coming in. I purchased a Linux-first System76 laptop and will switch out my other iDevices. It's not just about Apple - any sort of closed source software/hardware just seems unsustainable long term. Having "trust" in organizations seems misplaced.
- JKCalhoun 5y agoMore than "the customer", Apple is, in the end, beholden to government and its laws, whims, etc. Until a company is more powerful than the government I'm not sure how anyone can have an absolute assurance of privacy from a corporation.
- YPPH 5y agoThe clear distinction being that iCloud Mail scanning doesn't happen on device. For my part, all Apple needs to do is move CSAM scanning to the cloud. No service provider can be expected to keep images of child abuse on their servers. Apple would join myriad cloud service providers in scanning for and reporting such material. My problem is the use of my own device to run the scan. It's a waste of system resources. Presumably, a trivial software update down the line could expand its ambit to locally stored files. And we have the issue of Apple being compelled to run searches for non-CSAM hashes.
- jnwatson 5y agoThe point was so they wouldn't need to see the plaintext of the photos on their servers. Somebody needs to invent a FHE (fully homomorphic encryption) CSAM algorithm, so that Apple could scan encrypted photos for badness on the cloud.
- rfd4sgmk8u 5y agoNot Cool, now we can enforce all kinds of arbitrary censorship on encrypted data. Be careful what you wish for.
- dhosek 5y agoAlso, the Apple system allows for a way of verifying matches to screen for false positives which the encrypted approach would not.
- YPPH 5y agoAre photos uploaded to iCloud encrypted client-side? I suggest the answer is in the negative, given the ability to look at them on the web, and the ability to reset your iCloud password using 2FA. These suggest Apple has a copy of the decryption keys, which I'm happy for them to use to scan files I have stored on their servers, for CSAM, or, within reason, anything.
- amznthrwaway 5y ago
- gonn 5y agoCorrect me if I'm wrong, but I find the idea of people sending this kind of materials via email to be asking for trouble, to put it mildly.
- JKCalhoun 5y agoWhile I agree, law enforcement in the U.S. is supposedly bound by the "expectation of privacy" where, I think we can all agree, we ought to have an expectation of privacy when we send an email directly to one of our contacts. Of course Google and Gmail (as an obvious example) are not law enforcement so they can specify the terms of privacy when you sign up, scan your email if they wish, etc.
- Retric 5y agoInteresting, I don’t have an expectation of privacy when it comes to unencrypted emails. Likely due to them being regularly scanned and archived at work etc.
- xunn0026 5y ago> I think we can all agree, we ought to have an expectation of privacy when we send an email directly to one of our contacts. We ought. But in my country I once received a piece of physical mail from a more important institution in a more special (but not shady) country and the mail literally arrived open. I realised this is how people under communist regimes must have felt.
- Terretta 5y agoIn the U.S., “the Fourth Amendment permits the warrantless searching of mail entering or leaving the United States…. Congress specifically has authorized the warrantless search of mail at the border, although some of those provisions place restrictions on the reading of correspondence. See, e.g., 19 U.S.C. § 1583(a)(l) (permitting warrantless search of mail of domestic origin transmitted for export … and foreign mail transiting the United States”)…”
- Terretta 5y ago
- AbjectFailure 5y agoSomething wasn’t squaring between the claims that Apple has already been scanning iCloud Photos for years, that Apple reports hundreds of instances of CSAM while Facebook reports millions, and that Apple knows they have a major CSAM problem. Good to find out the problem was with the first one. I wonder if the “you know they already do this server-side, right?” people feel the slightest bit chastened.
- diebeforei485 5y agoIt definitely makes sense to scan things that are passed around - mail is an example of that, and Gmail [and also Facebook, Twitter] scan for this, along with scanning for computer viruses, and in some cases (public posts) copyrighted content. It makes absolutely no sense to scan people's photos that they aren't sharing with anyone else. Why are they bothering with scanning people's photo backups at all? With the exception of "shared photo albums", I don't see why they're doing this.
- Retric 5y agoYou can view other peoples iCloud photos. https://macpaw.com/how-to/icloud-photo-sharing https://macpaw.com/how-to/icloud-photo-sharing
- diebeforei485 5y agoI'm aware of shared photo albums. It's reasonable to scan those, but most photos are not in shared albums.
- skoskie 5y agoIf I were permitted to put something on your server that could put you in legal jeopardy, wouldn't you want to know what I'm putting on your server?
- diebeforei485 5y agoI'm not sure it would put me (as a provider) in legal jeopardy. You'll need a cite for that, and you don't have one. Providers only need to take action if they have been made aware about it, and are not required to proactively scan. See [1] 18 USC 2258A, relevant part below. (f) Protection of Privacy. Nothing in this section shall be construed to require a provider to— (1) monitor any user, subscriber, or customer of that provider; (2) monitor the content of any communication of any person described in paragraph (1); or (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b). Or here's another cite in plain English- ... for CSAM, to hold platforms liable, the government would have to prove that they did not take action when they knew federally illegal content was on their sites. The law doesn’t create an obligation for platforms to go out and proactively monitor... [2] [1] https://www.law.cornell.edu/uscode/text/18/2258A https://www.law.cornell.edu/uscode/text/18/2258A [2] https://freedomhouse.org/article/qa-social-media-regulation-and-perils-section-230-reform https://freedomhouse.org/article/qa-social-media-regulation-...
- shoulderfake 5y agoApple doesnt give a shit about the children, this is such a simple and transparent play. If they did, the kids wouldn't still be assembling their phones in China.
- throwawaymanbot 5y ago“Govt misuse”…Period. The infrastructure of survellience seems to have been laid out for a while. iStasi is a new Apple product.