7 ms·
The difference between what's on the "client" vs what's on the cloud has been virtually diminished in the last few years with everything doing a cloud backup by
by sn_master 4y ago
The difference between what's on the "client" vs what's on the cloud has been virtually diminished in the last few years with everything doing a cloud backup by default. Active content scanning and reporting to authorities been there for nearly a decade at least with several high profile cases every year since.
https://www.businessinsider.com/police-say-a-google-tip-about-child-abuse-led-to-arrest-2014-8 https://www.businessinsider.com/police-say-a-google-tip-abou...
https://cbs4indy.com/news/indycrime/muncie-man-arrested-on-child-porn-charges-after-google-submits-report-to-ncmec/ https://cbs4indy.com/news/indycrime/muncie-man-arrested-on-c...
https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html https://www.nytimes.com/2022/08/21/technology/google-surveil...
- Malcx 4y agoI can assure you 99% of my data/files never see the cloud other than as encrypted containers for backup. That's good practice for most business is it not?
- sgt 4y agoWhat do you have to hide? This makes us very suspicious. /s
- Malcx 4y agoI know you're /s but it's not even about privacy, it's the cost of mitigation after $cloud_service_x has a data breach and we then have to assign resources to account for _our_ clients data etc.
- therufa 4y agothis is a terrible argument. Would you enjoy going to the toilet when a certain group of people (like your neighbours) could watch you doing your "business"?
- sneak 4y agoI can assure you that 99% of people and businesses do not operate that way, and that people you communicate with, buy from, and sell to, are all sending your data effectively unencrypted to the cloud.
- Malcx 4y agoGdpr means data out of my control is someone else's liability. If they want to play fast and loose, that's their look out.
- matthewdgreen 4y agoPeople engaged in this debate often say "content scanning has been ubiquitous on private data for years", as though this is true for all cloud content since 1776, 1990, or even 2008. I want to stress that cloud content scanning is extremely new and opinionated decisions about scanning private content are actually more recent (and much less unanimous than implied above.) Microsoft publicly released PhotoDNA only in 2009, and even at that time its use was very limited. A few cloud services adopted it for cloud-uploaded files, which (back then) tended to have a clear UX distinction from private content (in the sense that users either knew they were making a public post, or at least had to make an affirmative decision to upload each piece of content.) Even during this time, some providers only enforced CSAM detection on content explicitly shared with others, while some were more vague about their policies. Still others refused to scan much at all. As an HN reader you may have known this scanning was in place, but in reality it was sporadic and very few platforms made public efforts to engage with customers and explain whether or what they were actually scanning. (For a contrasting example, see Apple's very public messaging efforts around CSAM scanning from 2021.) Today's big private messaging platforms like Facebook Messenger, WhatsApp, WeChat and iMessage didn't really come on the scene until around 2011. Excepting Chinese platforms, most of these messaging platforms do not employ content scanning for private messages. Perhaps the major exception to this rule is Facebook Messenger, which made the (IMHO thoughtless) decision to add CSAM content scanning across its entire network, and didn't bother to make a distinction between "public" and private messaging. But even Facebook has clearly reconsidered this hasty decision, given that they're planning to deploy default E2E encryption for Messenger (as they already do for WhatsApp), and have publicly opposed adding content scanning to that system. Meanwhile transparent smartphone backup systems like iCloud Photos are even newer, and have not always scanned private backup data. (See again Apple's public attempt in 2021 to deploy this scanning, which failed due to customer pushback.) TL;DR: content scanning is a relatively new technology that only had relatively limited deployments, sometimes only on public data or data explicitly uploaded. It was deployed relatively quietly so that "society" never really had the opportunity to have a public debate about whether or where it should be deployed. For better or worse, we are now having that debate. I think it is very unhelpful to imply that this is some long-deployed technology that all providers have always used on private data, because that's (1) not really accurate, and (2) short-circuits the debate and implies that we've already made an important decision.
- newZWhoDis 4y agoTrue, but we should have fought “cloud scanning” then as well. Governments have no right to compel companies to engage in policing activities like this.
- sn_master 4y ago> Governments have no right to compel companies to engage in policing activities like this. It's called privatization of tyranny and it's been going on forever. Companies like to do it to get closer to the government to get less regulation or government contracts.