6 ms·
No. Why would you think that? It goes against everything they have stated and the designs of the software. They are heavily focused on keeping all of that on
by dev_tty01 5y ago
No. Why would you think that? It goes against everything they have stated and the designs of the software. They are heavily focused on keeping all of that on device.
- nkozyra 5y agoWell other than the proposal specifically outlined in this post, that is. (Pardon if I missed the sarcasm)
- nyanpasu64 5y agoI tested OCR with Wi-Fi disabled and it still functions. Is Visual Look Up (and Live Text) purely offline, phoning home with CSAM reports, or an offline preview of future technology which phones home with CSAM reports?
- nojito 5y agoEverything is done on device. Which is different than others who choose to do scanning on their servers.
- tylersmith 5y agoAnd if the filter thinks the image is positive for CSAM it sends it to Apple, correct? Otherwise there's literally no point.
- JimDabell 5y ago> And if the filter thinks the image is positive for CSAM it sends it to Apple, correct? No. The logic was never “if there’s a match the image is uploaded”. The device never knows if there’s a match. Under the process Apple described, an extra packet of data is attached to every iCloud upload. If there are enough matches, Apple can decode those packets to get a low-res thumbnail, which they then check against a second perceptual hash. The process doesn’t work on arbitrary images on your device, it’s specifically designed for iCloud uploads.
- agildehaus 5y agoWhy can't they just scan iCloud uploads on-server then? Why does anything need to be done on-device?
- xanaxagoras 5y agoThe theory is they were going to use this tech to finally enable E2EE iCloud Photos and reactionary privacy absolutist psychopaths who didn't understand how it works -- such as myself -- made a big ruckus and spoiled everything. Also at the point that the image hash matches, Apple thinks it is CSAM (and it probably is). Doing it locally lets them avoid storing it, which they definitely do not want to do.
- JimDabell 5y agoThis scheme is obviously designed to work when Apple has no direct access to the photos. Because of this, there is a lot of speculation that Apple plans on making iCloud photos encrypted. This scheme would continue to work in that situation, whereas the on-server approach would fail. However that’s just speculation, Apple haven’t announced anything.
- modeless 5y agoThat speculation is pretty out there considering that there have been no barriers to them doing true end-to-end encryption of iMessage backups, but they have chosen not to for many years despite marketing iMessage as "end-to-end" encrypted. Reportedly at the direct request of the FBI. https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
- Spooky23 5y agoThey almost certainly do. Every major provider does, and even some enterprises. The whole point of the CSAM stuff was that it would allow for end to end encryption while not turning Apple’s ecosystem into preferred tool of child pornographers. Apple poorly communicated the feature, then the EFF put out a deliberately misguided written hitpiece that conflated parental controls with CSAM, and started an online freak out. The “privacy activists” won, and your data is sitting on Apple servers with Apple’s managed encryption keys outside of your control today.
- devwastaken 5y agoBy definition information must phone home somehow. How else is apple's spy department going to know if there's a "visual match"? Local scanning doesn't mean anything, it's an excuse to impliment the feature that will be changed later on anyways. That's how the slippery slope of precedent works.
- xanaxagoras 5y agoI don't think it's far fetched at all, that they'd do that without mentioning it. It certainly phones home when you open Preview [1], what's another little ping when you're looking at CSAM or whatever else they've been instructed to look for? The recent debacle made it clear enough to me that the their privacy reputation is little more than carefully curated marketing, and they're likely under tremendous pressure from lawless alphabet agencies to ramp up surveillance. I wouldn't put anything past a 3 Trillion dollar company, that's quite an empire to protect. [1] https://mspoweruser.com/macos-big-sur-has-its-own-telemetry-privacy-nightmare/ https://mspoweruser.com/macos-big-sur-has-its-own-telemetry-...
- KyeRussell 5y ago> The recent debacle [...] It's hard to argue that this "debacle" was not materially driven by the media, which did not accurate report the system's privacy protections, either because they did not understand them, or because they did not care to.
- xanaxagoras 5y agoMaybe. My awareness of it primarily came from this and other tech-minded sites, I'm not exactly sure what the media was saying about it. I understood the privacy protections but still found the features positively horrifying. I stopped using an iPhone and I stopped using iCloud on all devices because of that announcement.
- aunty_helen 5y agoThere is some reprieve by using a good firewall or even an off device firewall. However with many of these services if you try to kill them, they come back. If you delete them sometimes it will literally break your OS. Example, if you remove the ocsp daemon, you can’t start any program on your computer.
- GekkePrutser 5y agoAlso, Apple is making it virtually impossible to make changes to the OS now with the sealed system volume. We as the operator have no workable way of making changes there. You can do the whole bless thing but you have to boot into several modes several times. For every update. Otherwise it won't even boot. I think this is a worrying development. Until now our computers were actually ours. Now they're controlled by the vendor, and looking over our shoulder. I think using the user's own device to spy on them (whatever the reason!) is a big red line to cross. And puts this stricter control over the OS in a different perspective than just "security". I think either thing that plays into it is that Apple is now a content provider (Apple music and TV+). So they have another reason to keep us out to protect their DRM. But anyway, good security should not have to imply trusting the vendor implicitly. Give us the ability to add our own signing key for files we want to modify, just like secure boot on Windows allows adding custom keys..