I can’t help but feel this dovetails with the CSAM-scanning work that Apple canned last year.
I was always under the impression that ultimately they were doing that work because they needed some mitigations for the fact that iPhoto backups meant people were storing CSAM on Apple’s servers. If they were serious about privacy, that would be a big big problem for them —- hard to say no when the government comes knocking with a legitimate warrant, so they needed a solution that would let them preempt that scenario.
Now they are storing hashes for every file, so they no longer need to do on-device scanning.
If they were serious about E2E, of course everything would be encrypted.
There is no reason why they shouldn't store only hashes of the encrypted data, or, in fact, not store hashes at all, except -
1) data deduplication, which only saves Apple money
2) storing hashes and thus enabling govt and LE intrusion by mass scanning of content through matching hashes
Neither of these options is good for consumer privacy, and I would expect better from a company that is supposedly about privacy.
I would also be interested to know if they are still doing the perceptual hashing, because that would actually still fit in with their language about storing hashes, because AFAIK they didn't specify what kind of hashes they are storing.
I can’t help but feel this dovetails with the CSAM-scanning work that Apple canned last year.
I was always under the impression that ultimately they were doing that work because they needed some mitigations for the fact that iPhoto backups meant people were storing CSAM on Apple’s servers. If they were serious about privacy, that would be a big big problem for them —- hard to say no when the government comes knocking with a legitimate warrant, so they needed a solution that would let them preempt that scenario.
This is a much better solution.