Not on iCloud. They have all the content already encrypted on your phone. Can’t fingerprint after that. Them adding this as an on device process is due to that.
And the fact that Apple has been talking about privacy all this time (and rightly so) means their past mitigations makes this more painful. Any other vendor could just do it on the server, add a line to their Privacy Policy and nobody would know.
This is false. Up until now, iCloud photos are encrypted in transit and in store but can be decrypted with Apples own key. There is no e2ee.
Apple has been talking a lot about putting all ML and data handling on your own device so that the data does not need to leave your device without e2ee
This story originally said Apple screens photos when they are uploaded to iCloud, Apple's cloud storage service. Ms Horvath and Apple's disclaimer did not mention iCloud, and the company has not specified how it screens material, saying this information could help criminals.
U.S. law requires tech companies to flag cases of child sexual abuse to the authorities. Apple has historically flagged fewer cases than other companies. Last year, for instance, Apple reported 265 cases to the National Center for Missing & Exploited Children, while Facebook reported 20.3 million, according to the center’s statistics. That enormous gap is due in part to Apple’s decision not to scan for such material, citing the privacy of its users
Comments
Not on iCloud. They have all the content already encrypted on your phone. Can’t fingerprint after that. Them adding this as an on device process is due to that.
And the fact that Apple has been talking about privacy all this time (and rightly so) means their past mitigations makes this more painful. Any other vendor could just do it on the server, add a line to their Privacy Policy and nobody would know.
This is false. Up until now, iCloud photos are encrypted in transit and in store but can be decrypted with Apples own key. There is no e2ee.
Apple has been talking a lot about putting all ML and data handling on your own device so that the data does not need to leave your device without e2ee
I guess you are correct, they are not e2e encrypted. So part of my reasoning does not hold up, they could do this on the server if they wanted.
That I’d prefer to be honest.
Apple does not scan iCloud for csam because they feel that blanket scanning of iCloud violates end user privacy.
That’s the whole reason for their research into differential privacy.
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
Read the original telegraph article cited.
https://www.telegraph.co.uk/technology/2020/01/08/apple-scan...
This confirms the reporting from NYT
https://www.nytimes.com/2021/08/05/technology/apple-iphones-...