9 ms·
Apple's CSAM would scan your offline photos. Google scanning photos you upload to their cloud seems fine to me. Not a slippery slope.
by dharmaturtle 5y ago
Apple's CSAM would scan your offline photos.
Google scanning photos you upload to their cloud seems fine to me. Not a slippery slope.
- fleddr 5y agoVery much a slippery slope. Their cloud doesn't mean its their content. If said content is public, I mostly agree, but not if its private. When I hire a storage box and put stuff in it, I don't own the storage box. Yet still it cannot be searched by anyone, not the company nor the authorities, unless there is a credible criminal suspicion.
- dharmaturtle 5y agoThe storage owner can have a terms of service - i.e. you can't store flammable material/liquids. They also probably reserve the right to enter your unit to perform repairs.
- fleddr 5y agoRight, and to keep this analogy consistent, do storage owners routinely open all storage units, then open up all your boxes and search through them to check for flammables?
- kevin_thibedeau 5y agoThey don't give out free storage. If you aren't paying with money you're paying with something else and you have no expectation of privacy when you agree to terms that say as such.
- dharmaturtle 5y agoNo, but that's primarily due to a lack of interest/manpower. They (probably) reserve the right to ensure that you aren't doing things that are against their TOS. There's (probably) no right to privacy.
- jrockway 5y agoI guess the question is, if someone emails you an archive of jpg files to share on your public website, will you? Without looking at them? I think that would be crazy. When they end up being CSAM or whatever, you're the one that will go to prison for possessing them, not the person that sent them to you.
- bvxhl 5y agoSo, after Google/YouTube have been aided in growth by the safe harbor clause, they now think that site owner responsibility is not such a bad thing after all? Sounds more to me that they are pulling up the ladder to impede competitors.
- _notathrowaway 5y agoI belive this is a really good take on the matter, and somehow you are the first person I see bringing it up.
- not2b 5y agoThe EFF has raised this issue repeatedly (that stringent requirements on content filtering will be an advantage to the large players who can afford to do it).
- judge2020 5y agoIt's very likely you only start getting 'requests' from 3-letter agencies asking you to scan content once you reach some large mass of hosted content, especially since the technology for even doing so is locked up, with NCMEC and Microsoft being the arbitrators for who gets to use it: https://www.microsoft.com/en-us/PhotoDNA/CloudService https://www.microsoft.com/en-us/PhotoDNA/CloudService
- fleddr 5y agoThat's why I made the distinction between public hosting and a private album. For public files, I fully agree with you. For private ones, not at all.
- jodrellblank 5y ago> "Apple's CSAM would scan your offline photos." No it wouldn't. It would only scan photos you upload to their cloud. "This feature only impacts users who have chosen to use iCloud Photos to store their photos. It does not impact users who have not chosen to use iCloud Photos. There is no impact to any other on-device data." and "Does this mean Apple is going to scan all the photos stored on my iPhone? No. By design, this feature only applies to photos that the user chooses to upload to iCloud Photos, and even then Apple only learns about accounts that are storing collections of known CSAM images, and only the images that match to known CSAM. The system does not work for users who have iCloud Photos disabled. This feature does not work on your private iPhone photo library on the device." - https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
- dharmaturtle 5y agoYou're right - I misremembered. Kinda wish HN would let me edit.
- Kerbonut 5y agoYou are spreading misinformation. I don’t know if on purpose or ignorance. https://www.cbsnews.com/news/child-sexual-abuse-scans-apple-push-back/ https://www.cbsnews.com/news/child-sexual-abuse-scans-apple-... They were very much planning to scan all photos on the device independent of iCloud. It was going to be another phase of the rollout. It was going to be in iOS 15.x and they backpedaled.
- md_ 5y agoI think that's just imprecision on the part of noted tech news outlet CBS. Apple clearly documented that this was only for iCloud uploaded photos, and indeed the technical description makes clear that this is only designed to work with uploaded photos: https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni....
- 5y ago
- Tagbert 5y agoIf they implement it, Apple's CSAM would scan your photos as they are being uploaded. Not really “offline”.
- GeekyBear 5y ago>Apple's CSAM would scan your offline photos. Apple's plan was to to scan photos that you uploaded to iCloud, only. Even that plan was canceled. Google, however, still does scan everything in your account and has been doing so for the past decade. For instance, this article from 2014: >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-led-to-a-mans-arrest-for-child-porn-was-not-a-privacy-violation/ https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
- md_ 5y agoAs does Dropbox, Aol, Yahoo, Microsoft, Facebook, etc, etc. Whether this is good or bad is a topic for fair debate, I think, but it continues to astound me both how little people are aware of this and that, in comparison, Apple's relatively privacy-preserving approach generated so much flak.
- ipaddr 5y agoApple iCloud is in that list. And you still need to scan local photos on the phone?
- bri3d 5y agoIt's better for a customer to scan images locally, on the phone, prior to upload. By doing this, the device can then encrypt images and store them in the cloud service. In this way the cloud service can be "CSAM sharing free" but never needs the symmetric keys to decrypt private images, period, for any reason. The only thing this adds to the threat model is mistrust for false positives in scanning engine - but in even the worst case scenario here (forged false positives), you're still ahead of the Google model, where the same forged false positives would be extremely likely to result in a full account review rather than review of specific images. Everything about "the device looking at your photos" is tinfoil hat, because the device is already looking at your photos, they're decrypted in RAM! All of the threat scenarios about "Apple adds a secret government backdoor that downloads your photos and sends them to the FBI" are already equally possible today!
- jgalt212 5y agoBut the default is to upload. On my phone, I had upload off, and then it got turned on again (not by me). The same thing happened with Google Assistant. I had it off, but then it mysteriously tried to start assisting me again.