Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I agree that the idea of the AG bringing felony charges against Apple employees because of their approach to dealing with CSAM is pretty far-fetched. But the article you're referring to [0] is correct to point out that Apple will be silently exfiltrating unencrypted data from its users' devices to be reviewed by its employees, meaning that they'll be viewing arbitrary content from Apple users' devices without their knowledge or consent. That's not speculation, it follows directly from Apple's explanation of how the system will work, with the only safeguard being Apple's purported one-in-a-trillion false positive rate for the on-device scanning that causes the data to be sent to Apple.

[0] https://www.hackerfactor.com/blog/index.php?/archives/929-On...



You are confusing encryption with access to encryption.

Apple ALREADY has access to all you icloud photos. Period. How do you think they offer them to you via website and various sync services.

So they can encrypt them at rest or in transit, but their KMS or whatever gives them access ALREADY to these very same photos.

This illustrates I think how bad this convo has been from the HN side. A lot of bad info out there on this which makes the totally overblown responses even worse.

Heads up - your phone ALEADY uploads photos to iCloud if you let it, and those photos are accessible by Apple ALREADY.


While logical to assume, that's not a given. I think some of us want to believe that the keys to those said images are uploaded encrypted to the cloud. And the ability to sync between devices just means adding more keys to your account. So unless you know something we don't, it's not 100% that they sit unencrypted on Apple's servers, or that they have the keys to decrypt them.

It is sound judgement tho, to assume that they do.


They are explicit about this.

"iCloud content may include email, stored photos, documents, contacts, calendars, bookmarks, Safari Browsing History, Maps Search History, Messages and iOS device backups. iOS device backups may include photos and videos in the Camera Roll, device settings, app data, iMessage, Business Chat, SMS, and MMS messages and voicemail. All iCloud content data stored by Apple is encrypted at the location of the server. When third-party vendors are used to store data, Apple never gives them the encryption keys.

Apple retains the encryption keys in its U.S. data centers. iCloud content, as it exists in the customer’s account, may be provided in response to a search warrant issued upon a showing of probable cause, or customer consent."

So unless you doubt apples own guide - they maintain the keys and will provide this info in response to govt requests.

They handled requests for 31,000 accounts in the last 6 months based on their reporting and provided data in 85% of those situations.


The AG bringing felony charges isn't far-fetched its ridiculous. Does anyone think a trillion dollar company with a giant legal staff hasn't vetted this in a hundred different ways? They are probably going country by country to validate legality. It will not be implemented anywhere they don't find that it is 100% legal.


The irony - my guess is many countries will require this or block e2ee. The idea that govt or public is against this seems unlikely




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: