logoalt Hacker News

St0n3dtoday at 3:31 PM3 repliesview on HN

“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)


Replies

EmbarrassedHelptoday at 8:31 PM

A mandatory client side scanning system with an opaque database filled with unverifiable entries would render many of the protections provided by ADP meaningless. Its was insane that Apple was even considering such an idea in the first place.

kyralistoday at 3:46 PM

Also, Apple's E2E iCloud encryption vastly predated the NeuralHash efforts.