{"id":34479,"date":"2021-12-17T11:28:42","date_gmt":"2021-12-17T16:28:42","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=34479"},"modified":"2021-12-17T14:21:18","modified_gmt":"2021-12-17T19:21:18","slug":"apple-removes-references-to-controversial-csam-scanning-feature","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/12\/17\/apple-removes-references-to-controversial-csam-scanning-feature\/","title":{"rendered":"Apple Removes References to Controversial CSAM Scanning Feature"},"content":{"rendered":"<p><a href=\"https:\/\/www.macrumors.com\/2021\/12\/15\/apple-nixes-csam-references-website\/\">Tim Hardwick<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=29564300\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/12\/15\/apple-nixes-csam-references-website\/\">\n<p>Apple has quietly nixed all mentions of CSAM from its Child Safety webpage, suggesting its controversial plan to detect child sexual abuse images on iPhones and iPads may hang in the balance following significant criticism of its methods.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2021\/12\/15\/apple-child-safety-csam\">John Gruber<\/a> (<a href=\"https:\/\/twitter.com\/daringfireball\/status\/1471262802828431361\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2021\/12\/15\/apple-child-safety-csam\">\n<p>I wouldn&rsquo;t read too much into this. [&#8230;] I think the CSAM fingerprinting, in some form, is still forthcoming, because I suspect Apple wants to change iCloud Photos storage to use end-to-end encryption. Concede for the moment that CSAM identification <em>needs<\/em> to happen somewhere, for a large cloud service like iCloud. If that identification takes place server-side, then the service <em>cannot<\/em> use E2E encryption&#x2009;&mdash;&#x2009;it can&rsquo;t identify what it can&rsquo;t decrypt. If the sync service <em>does<\/em> use E2E encryption&#x2009;&mdash;&#x2009;which I&rsquo;d love to see iCloud Photos do&#x2009;&mdash;&#x2009;then such matching has to take place on the device side. Doing that identification via fingerprinting against a database of known and vetted CSAM imagery is far more private than using machine learning.<\/p>\n<p>[&#8230;]<\/p>\n<p>Put another way, if governments, authoritarian or otherwise, were able to force Apple (or Google, or Microsoft) to add secret snooping features&#x2009;&mdash;&#x2009;like say finding photos of Tank Man on Chinese users&rsquo; devices and reporting them to the CCP&#x2009;&mdash;&#x2009;to our operating systems, the game is over.<\/p>\n<\/blockquote>\n\n<p>They don&rsquo;t need to force Apple to do anything because Apple never sees the photos in the CSAM databases, only the fingerprints. They would need to compromise two of the databases and infiltrate Apple&rsquo;s human reviewers.<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471265583324880901\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471265583324880901\">\n<p>You can already upload illegal photos to iCloud Drive, and have Apple host them, as long as you encrypt the files yourself first on disk. Nobody can do anything about that, including Apple.<\/p>\n<p>[&#8230;]<\/p>\n<p>It doesn&rsquo;t seem like they&rsquo;re even interested in catching criminals, because they already publicly announced you can &ldquo;opt out&rdquo; by simply not using iCloud Photos.<\/p>\n<p>Consequently, the real goal must be to trick everyone else into giving up their legal rights and their principles.<\/p>\n<p>And once the &ldquo;opt out&rdquo; allows all or most of the criminals to avoid getting caught, is this going to be a bait and switch where they say, &ldquo;Well, we didn&rsquo;t catch anyone, so we have to get rid of the opt out and scan everyone&rdquo;?<\/p>\n<\/blockquote>\n\n<p>Or perhaps the real goal is to avoid wittingly hosting illegal photos. No one is going to blame Apple for hosting encrypted content that it can&rsquo;t read.<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471267795694403589\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471267795694403589\">\n<p>There&rsquo;s not even any reason why there can&rsquo;t be end-to-end encrypted iCloud without scanning, either on device or on the server. It could have and should have happened already.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/gruber\/status\/1471300893446443014\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/gruber\/status\/1471300893446443014\">\n<p>I don&rsquo;t disagree with you on (almost) any of this. But, politics <em>is<\/em> a reason. I think Apple considers it politically unfeasible to do E2EE for photo syncing without throwing some sort of bone to the crowd who think civil liberties should not override CSAM concerns.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471302875846524941\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471302875846524941\">\n<p>Which crowd? I haven&rsquo;t heard a single politician of either party even mention it. Not an issue in the public debate, until Apple made it one.<\/p>\n<p>The most important crowd ought to be the half billion Apple customers. Who weren&rsquo;t clamoring for it either.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/gruber\/status\/1471310672390721537\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/gruber\/status\/1471310672390721537\">\n<p>Politics is hard because it&rsquo;s such a soft science. You can&rsquo;t prove anything. But here&rsquo;s one optimistic spitball: maybe Apple tossed this CSAM proposal out, as a concession to the anti-CSAM die hards. It went over like a lead balloon. Now, they&rsquo;re like fine, we&rsquo;ll wait.<\/p>\n<p>[&#8230;]<\/p>\n<p>And so now they don&rsquo;t say they&rsquo;re going to do it, but don&rsquo;t say they&rsquo;re not going to do it either. They have political cover from both sides so long as it remains in limbo.<\/p>\n<p>[&#8230;]<\/p>\n<p>My read is that they know they fucked up by not designing all of iCloud to be E2EE like iMessages from the get-go. But feel like they can&rsquo;t put that genie back in the bottle.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/12\/14\/tim-cooks-secret-275-billion-deal-with-china\/\">Tim Cook&rsquo;s Secret $275 Billion Deal With China<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/11\/12\/revised-messages-communication-safety-feature-in-ios-15-2\/\">Revised Messages Communication Safety Feature in iOS 15.2<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/07\/apple-delays-child-safety-features\/\">Apple Delays Child Safety Features<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/08\/05\/scanning-icloud-photos-for-child-sexual-abuse\/\">Scanning iCloud Photos for Child Sexual Abuse<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/01\/14\/reminder-imessage-not-meaningfully-e2e\/\">Reminder: iMessage Not Meaningfully E2E<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/01\/21\/apple-dropped-plans-for-end-to-end-encrypted-icloud-backups-after-fbi-objected\/\">Apple Dropped Plans for End-to-End Encrypted iCloud Backups After FBI Objected<\/a><\/li>\n<\/ul>\n\n<p>Update (2021-12-17): See also: <a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1471906703373438984\">Jeff Johnson<\/a>, <a href=\"https:\/\/twitter.com\/GlennF\/status\/1471902597866942472\">Glenn Fleishman<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Tim Hardwick (Hacker News): Apple has quietly nixed all mentions of CSAM from its Child Safety webpage, suggesting its controversial plan to detect child sexual abuse images on iPhones and iPads may hang in the balance following significant criticism of its methods. John Gruber (tweet): I wouldn&rsquo;t read too much into this. [&#8230;] I think [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-12-17T16:28:45Z","apple_news_api_id":"95d1a00c-b2f7-4a74-bc56-6da3e7130a20","apple_news_api_modified_at":"2021-12-17T19:21:22Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AldGgDLL3SnS8Vm2j5xMKIA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2106,1142,31,2078,30,2077,927,355],"class_list":["post-34479","post","type-post","status-publish","format-standard","hentry","category-technology","tag-child-sexual-abuse-material-csam","tag-icloud-photo-library","tag-ios","tag-ios-15","tag-mac","tag-macos-12","tag-photos-app","tag-privacy"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=34479"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34479\/revisions"}],"predecessor-version":[{"id":34490,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34479\/revisions\/34490"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=34479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=34479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=34479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}