Hacker News new | ask | show | jobs
by jkcxn 1768 days ago
By the way they already scan photos that aren’t uploaded to iCloud. I’ve never used iCloud and I can go on the photos app and search for food for example
2 comments

Right, the difference is that now, you can be reported to the authorities for a photo that the CSAM algorithm mistook for child pornography, whereas before the image classifying was purely for your own use.
This is simply a complete falsehood, because photos that are not uploaded are not scanned for CSAM.

Photos for your own use that you do not upload to Apple’s cloud are completely unaffected.

Exactly. They already analysed photos on your phone for search. They don’t in fact do CSAM detection on the photos on your phone.

But why are people only objecting now when they were already doing on-device analysis?

CSAM detection is a complete red herring. It is less of a general purpose scanning mechanism than the search function that was already there.

They're doing on device analysis, but there isn't any process by which an image of a hotdog will be sent to someone else without my knowledge.
Right, but neither is the CSAM code being used to detect anything but CSAM.

If a bit can be flipped to make the CSAM detector go evil, surely it can be flipped to make photo search go evil, or spotlight start reporting files that match keywords for that matter.

There is nothing special about this CSAM detector except that it’s narrower and harder to repurpose than most of the rest of the system.

> ... to make photo search go evil, or spotlight start reporting files that match keywords for that matter.

As your immediate parent has already said: there isn't any process by which an image of a hotdog will be sent to someone else without my knowledge.

Neither "photo search" nor "spotlight" report anything to third parties currently.

No, but a ‘bit flip’ could make them do so just as easily as a ‘bit flip’ could make the CSAM detector do something nefarious.
How are you still not getting this?: "search" and "spotlight" do not have the code to report anything to anyone.