Apple defeats liability for not scanning iCloud for CSAM

(blog.ericgoldman.org)

444 points | by speckx 1 day ago

24 comments

  • giantg2 1 day ago
    Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA.

    For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has even extended to fictional CSAM such as AI generated stories and pictures. As an aside, if that gets extended to political speech or other non-CSAM materials that are determined to be undesirable, that's a big concern. I can imagine that a conservative state could pass a law banning all porn because they claim it could encourage illegal activities such as prostitution, rape, or CSA.

    On the CSA side, you rarely hear about arrests (they happen but less than CSAM). There doesn't seem to be any real push for educating and protecting kids before it happens. Ironically, the groups doing the most to educate and implement protective strategies are the ones who have been involved in abuse scandals in the past (Churches, Scouts, etc). Even then, a lot of it is just getting clearances, which doesnt prevent people who where not caught or were first timers. Offenders get put on a list/map. This is sort of a half approach. If they are still a threat, they shouldn't be released. Yet if you comb the list and see some of the results, they don't all seem to fit with CSA. I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.

    It seems like these laws are more about peddling to the publicist and lawmakers fantasy of incrementally extreme punishment rather than taking a appropriate, data driven, and level-headed approach that actually protects kids. Otherwise they will just keep pushing ham-fisted low-hanging "fixes" like required scanning and IDs to access the internet.

    • Hasz 23 hours ago
      Because it isn't about CSAM, IMO. You see this with plenty of social issues, notably firearms ownership. The claim is we will restrict/license/outlaw xyz for the kids, but really, a data-drive approach would have focused on different things entirely (eg additional behavioral health services for kids, suicide prevention etc)

      The same technology/access used for CSAM identification can find copyrighted files, materials that don't support current government, etc. Full E2E encryption seriously raises the cost of mass surveillance, and why the US government fights it at every turn going back 30 years.

      • nativeit 20 hours ago
        When did we aggressively legislate against, search for, monitor, investigate, and prosecute owning firearms?
        • throwaway17824 20 hours ago
          I'm taking a guess at what the OP meant, but people focus on assault rifles and high-capacity magazines. Supposedly most incidents and deaths are caused by handguns. They're more affordable, and easy to discretely keep on your person. A data-driven policy would focus on them first, but it's easier to rile up the public about AR-15s so we keep doing the less-effective thing.
          • MBCook 18 hours ago
            Things that feel useful instead of are useful.

            We're not allowed to use data or experts. They’re untrustworthy and out to trick us.

            • LanceH 7 hours ago
              > They’re untrustworthy and out to trick us.

              When politics is involved, there is a lot of truth to this.

            • timr 12 hours ago
              Everyone loves the experts that repeat what they like to hear. The ones that don't are obviously quacks.
          • belorn 11 hours ago
            When we say that handguns cause more deaths than assault rifles, is that normalized towards ownership?

            Data and statistics is as always dependent on how and what you measure.

            • giantg2 8 hours ago
              What I could find was that there are estimated to be about 350-500 million firearms in the US. The closest thing to a breakdown was 30-50 million semi-auto rifles, and probably close to a 60/40 split handgun to long gun over time (article shows trends). Murders per year using rifles and shotguns were less than 600 combined. Handguns accounted for over 6000.

              So the number of hanguns is maybe something like 20% higher than long guns, but murders using handguns are 10x higher than with long guns.

              https://www.thetrace.org/2023/03/guns-america-data-atf-total...

              https://ucr.fbi.gov/crime-in-the-u.s/2019/crime-in-the-u.s.-...

              • belorn 8 hours ago
                Rifles are problematic as a single category since that involves hunting rifles. We can look at machine guns as a category that is neither rifle or handgun, and with limited use in hunting.

                That said, the death rate of machine gun ownership may still be lower than handgun ownership, with a possible explanation being that it is easier to buy a handgun compared to a machine gun. A further jump into the data would then explore who are the buyer demographic of a handgun compared to a machine gun, and how machine guns compare to handguns in locations where both has similar restrictions on those who buy them.

                An other avenue to explore would be to look at purchases of ammunition to determine which guns are actually in use for non-murder purposes. Hunting ammunition for example may show a much more common use than guns used for non-hunting purposes, and thus have a lower murder rate per shot. Machine guns and handguns might share a much more similar profile in that regard, possible normalized towards how much ammunition each use in a target range.

                • galangalalgol 7 hours ago
                  Relatively inexpensive plastic semiauto pistols, ruger is overrepresented, are purchased in small batches by people either pressured into it or who make their living marking them up and reselling to people who couldn't pass the background check. The majority of those sales go through a small number of known registered firearms dealers. The straw buyers are the ones breaking the law, but the dealers who knowingly selling to them aren't. There should be some policy fix, but the best I've seen is a state that limited purchases to 3 per month per person. It drastically slowed the flow into those groups driving up prices as old ones were recovered from crime scenes etc. Money and macro also has a good episode where they talk about how neighborhood beautification worked better than gun control for this type of violence. The scary rifles get used by the mentally ill because they look scary, and the large number of deaths at once combined with the inability to control your risk and the more privileged socioeconomic class of those harmed makes it more visible.
                • yonaguska 5 hours ago
                  Full auto handguns are quite popular now despite being effectively illegal.
                  • throwaway-blaze 2 hours ago
                    This is simply untrue, there are no full auto handguns legally sold to the public. Semiautomatic yes. And yes, some guns are way too easy to convert to full auto.
                • lacunary 7 hours ago
                  just to be clear, it appears you're making up studies, results and explanations for results all in one go, is that right?
            • SuperNinKenDo 10 hours ago
              Not to get too off track, but it's actually an interesting case in that it's one of those where weighting for prevalence of ownership wouldn't matter for the purpose of discovering the more effective measure. If you did something to restrict handguns you would prevent more death than restricting other firearms.

              Also, not that it has any bearing on what I said, but I'm decidedly pro-gun for any repliers who want to follow up on this tangent.

              • inigyou 9 hours ago
                If it's weighted by ownership then banning one type of gun would increase the ownership of other types of guns, maybe not solving the problem.
          • forshaper 19 hours ago
            One might wonder about why ceramic plates are controlled in Connecticut or New York.
            • philipkglass 19 hours ago
              It looks like Connecticut first enacted body armor regulations in 1998, the year after the North Hollywood police shootout with a pair of heavily armed and armored men:

              https://en.wikipedia.org/wiki/North_Hollywood_shootout#Weapo...

              It's hard to find 1998 news articles about it now, but I would guess that the law was a reaction to this high profile crime.

          • austhrow743 15 hours ago
            Most deaths doesn't necessarily mean most deaths that people care about.
          • kelnos 14 hours ago
            Are handgun deaths predominantly murder, or are they mostly accidents? If the latter, then I don't think it's odd to go after AR-15-type weapons, which usually end up killing people during mass shooting incidents.
        • kaliqt 6 hours ago
          This entire time. It’s a gradient and it has been getting worse annually. But the firearms tracking is only for regular people not criminals, funny that, it aligns with the problem OP outlines: it has nothing to do with helping and everything to do with controlling and subduing those who have the ability to stop them.
        • wang_li 19 hours ago
          The second militia act of 1792. Though that required you to have a gun. Which in some fashion required monitoring. In modern times many states require you to have a permit to own a firearm and states regularly prosecute people without a license. In Washington state they have laws about safe storage and the police can come into your house to inspect your storage solution without if someone calls them and says you aren’t storing it properly. There’s a constant stream of cases fighting these laws in court. In the 2025-2026 SCOTUS term there were 14 petitions for cert.

          https://scotus2a.com/

        • boredatoms 15 hours ago
          Most countries do
      • kryogen1c 20 hours ago
        epsteins case tells you how much the US political class cares about SA and CSA happening in the US.
        • ryandrake 20 hours ago
          Yea, until at least one non-ringleader Epstein party participant goes to jail, I'm not going to believe the US actually gives a shit about protecting children.
          • throwaway85825 20 hours ago
            Every president since Clinton protected epstein too, it's not a partisan thing.
            • myko 8 hours ago
              always with the "both sides" stuff, meanwhile trump literally provided girls to Epstein through Mar-A-Lago
          • derektank 19 hours ago
            There’s no concrete evidence that anyone besides Epstein (and by extension Maxwell, who assisted Epstein) actually abused children. Besides the testimony of Virginia Giuffre, nobody else has claimed they were sexually assaulted as minors (Sjoberg was groped by Prince Andrew at Epstein’s home when she was in her early 20s). And neither the FBI nor the Palm Beach PD found physical evidence of such or communications between Epstein or others indicating this was going on.

            Why would you expect anyone else to go to jail under those circumstances? Proving guilt beyond a reasonable doubt seems very unlikely

            • cogman10 5 hours ago
              > Why would you expect anyone else to go to jail under those circumstances? Proving guilt beyond a reasonable doubt seems very unlikely

              It's actually pretty easy to prove guilt in the US. But it becomes a lot harder the longer the distance from the crime. In particular, witnesses die or leave. Heck, investigators die or leave which makes discovery for the perpetrator even harder on the FBI.

              Further, the bar for civil litigation is lower than criminal. The FBI refusing to prosecute means that victims have a very hard time pursuing civil cases even if the FBI were to lose their case. The FBI has way more evidence that a victim can have.

              The most non-nefarious but still shitty reason I can think of for why the FBI hasn't gone to trial is because they know each of these cases will be long and expensive because of the perpetrators. That's caused them to collect way more evidence than they would have if this were just a normal person.

              Funny how the FBI is only careful and pensive when perpetrators are rich.

            • ryandrake 17 hours ago
              I'd at least expect there to be an investigation, based on the huge volume of information that already exists. Unless we believe that the files are just 3 million pages of casserole recipes and that the people who visited just went to play Settlers of Catan.
            • ipaddr 17 hours ago
              There is if someone would follow the money trail. Plenty of hard facts to reach a guilty outcome. And over half of the papers haven't been released. If someone motivated comes to power there is a good chance.
              • blackqueeriroh 16 hours ago
                Where are the hard facts about this? If you know them why haven’t you shared them?
            • dartharva 15 hours ago
              Just in case someone might mistake this comment to imply there wasn't actually a large-scale CSA-as-a-service business happening on his island - FBI has officially declared the number of minor victims to be over a thousand: https://www.justice.gov/opa/media/1407001/dl

              It was an industrial-scale racket. It is impossible for that kind of number of victims to be just for one person or group's recreation.

              • austhrow743 15 hours ago
                I think you linked to the wrong document, unless you're taking "Epstein had over ten thousand pornographic videos and images" as "there were over one thousand minor victims" which doesn't follow as a logical conclusion.
                • antonvs 10 hours ago
                  Two quotes from the link they posted:

                  > The files relating to Epstein include a large volume of images of Epstein, images and videos of victims who are either minors or appear to be minors

                  > Consistent with prior disclosures, this review confirmed that Epstein harmed over one thousand victims. Each suffered unique trauma. Sensitive information relating to these victims is intertwined throughout the materials.

                  The second quote doesn’t explicitly say “minor victims”, but the whole document is focused on that, mentioning that “One of our highest priorities is combatting child exploitation and bringing justice to victims.”

                  • austhrow743 9 hours ago
                    I read the whole thing twice because I was fairly sure I missed something the first go around and still missed that second quote. My reading comprehension is atrocious. Thanks and sorry dartharva.
            • TheOtherHobbes 4 hours ago
              There's plenty of concrete evidence. But - for some reason - Trump's government has refused to release it, defying multiple legal judgements.
      • mschuster91 21 hours ago
        > The claim is we will restrict/license/outlaw xyz for the kids, but really, a data-drive approach would have focused on different things entirely (eg additional behavioral health services for kids, suicide prevention etc)

        Well, most of Europe simply has banned guns in the hands of civilians instead, so that's some data as well.

        The only reason why the US is so extremely lax on firearms is because people keep blathering on about how guns are the last line of defense against a tyrannical government - and yet, what do the most rabid of these people do? Vote in and defend a literal tyrant.

        • derektank 19 hours ago
          >The only reason why the US is so extremely lax on firearms is because people keep blathering on about how guns are the last line of defense against a tyrannical government

          No, it’s because the right to own firearms is very explicitly stated in our constitution and the constitution requires an extreme super majority to update. A 50%+1 majority is all that’s required to ban civilian ownership of guns in most parliamentary systems, not so in the US. The culture is downstream of the law.

          • xethos 17 hours ago
            > the right to own firearms is very explicitly stated in our constitution

            The right to bear arms does not necessarily mean firearms. Arms doesn't necessarily even have to include firearms, and America is already pretty damn strict about certain armaments, such as sub-machine guns.

            Americans are allowed to have certain firearms, sometimes, in some places. I'm not sure how one squares that with the blanket statement from the American constitution that Americans have the right to bear arms, unless it's simply an impossibly poorly-informed citizenry

            • modo_mario 12 hours ago
              > and America is already pretty damn strict about certain armaments, such as sub-machine guns.

              Not one but you're really validating their slippery slope fears and claims there.

            • kelnos 14 hours ago
              You can personally interpret the US constitution however you want, I suppose, but the only interpretation that matters is that of the Supreme Court. And they have held over and over that 2A includes a right to many different kinds of firearms.

              I feel like you're the one who is poorly informed?

              (For the record, I am in favor of strong gun control laws, but your statement just ignores reality.)

            • redeeman 10 hours ago
              and this is very clearly unconstitutional. "shall not be infringed" is very very plain and simple
              • inigyou 9 hours ago
                Yep, alongside "Congress shall make no law" which says it's fine for anyone who isn't Congress to infringe your free speech, or for Congress to do it in any way that isn't making a law.
                • WarmWash 5 hours ago
                  The system does not work like that, hah. This is the kind of logic sovereign citizens use..."I'm traveling, not driving, so I don't need a license!"

                  At the end of the day, judges have the ability to clear away silly logic like that, it's part of their job.

                • redeeman 6 hours ago
                  thats very very obviously not how it works or was intended. then they could just come up with "rules" that are not laws, and then rules say cannot have arms.

                  all these insane and VERY OBVIOUS attempts to bypass the constitution should result in official doing it be put in jail FOREVER

                  • inigyou 6 hours ago
                    Who's going to put them in jail? Their best friends?
              • myko 8 hours ago
                The 2A was created for states to maintain their own troops, what is now the modern national guard - hence "well regulated militia"

                SCOTUS bastardized this original intent. It's shameful.

                • giantg2 8 hours ago
                  What you miss is that US Code defines militia as the explicit militia that you mention, but also the implicit militia. That implicit militia includes others not in the national guard.

                  It's also worth mentioning that most states have similar language to the second amendment, including states whose constitutions were implemented prior to the bill of rights, lending to the credence that this is a right of the people, and not of the state. The 10th amendment was supposed to be for the rights of the states.

                  https://www.law.cornell.edu/uscode/text/10/246

            • Spooky23 14 hours ago
              The more… enthusiastic gun people among us think that the national firearms act (which strictly regulates automatic weapons) is an abomination.

              It’s unique in that it’s the only right that aligns with business marketing. Peddling fear, mostly to insecure men, has sold hundreds of millions of guns.

              The fetishized nature of modern gun culture killed, in addition to people, a lot of shooting sports and hunting.

              • deejaaymac 13 hours ago
                What a strange take.

                I grew up in a small hunting town (I'm in my early 30s), where most high school boys (most girls didn't hunt, but some did) had a rifle and/or shotgun in their truck, mounted against the inside back of the cab where you could see it plain view.

                We had 0 homicides from guns in the 19 years I lived there, there was 1 suicide by gun that I know of.

                Many of us grew up hunting to feed our family. This is in Colorado.

                I shot my first pistol around the age of 5.

                I accidentally went to 7th grade with ammo in my pocket because we were hunting that morning. I went to the principal, he told me just to put the ammo in my locker.

                With that being said, you'd be hard pressed to find a group of townspeople more respectful of guns.

                It's not a gun problem, it's a culture problem.

                Not saying that there's not "insecure men" out there that are the victim of marketing, etc, but a lot of us grew up with guns and see them as a tool.

                • lesostep 9 hours ago
                  My mom grew up in a small town (village? settlement even?) like that (surrounded by nature, lots of hunting, animals can wonder in town) in a country where guns weren't free.

                  Every family still had a rifle, getting license isn't that hard when you could answer questions about your intentions.

                  No handguns though, not very useful for self-defense or wildlife. I believe mom made and shot her first arbalest around 6-7 yo though.

                  Similar cultures, but one of them allows for outsiders to screen potential gun owners, and the other doesn't. Which, I believe, is the point – there always will be mentally unwell or ill-intentioned people. There should be a way for a small town to revoke the trust of allowing weapons in their hands.

                • Spooky23 7 hours ago
                  I think we’re closer than you think. I grew up in a similar place - my school had a rifle and trap team. Great place to grow up. I’d often go out for the first they day turkey season and miss school.

                  Reality is shooting sports licensing churns significantly and has for many years - the people doing it get older every year. Some of the stats look better becuase many states offer more deer tags to fewer hunters.

                  There is a huge culture problem. Army LARPing and conspiracy move guns. Legal arbitrage makes the retail channel a haven for smuggling. Marketing lands heavily on that and politics. The sportsman (and often conservationist) is a relic notion.

                • antonvs 10 hours ago
                  > see them as a tool.

                  Yes, a tool for killing. You’re respectful of guns, but where’s your respect for life?

                  • grosswait 6 hours ago
                    Respectful of liberty. A spear is also a tool for killing. Respect for life is not an expectation of the tool.
          • phoghed 19 hours ago
            Or just a reinterpretation of a single line of the constitution.
            • plagiarist 18 hours ago
              Oh, SCOTUS doesn't radically reinterpret the Constitution in that direction. Or, perhaps maybe it does, but nobody's bought Clarence the right RV yet.
        • jaharios 20 hours ago
          > Vote in a literal tyrant.

          Tyrant? You may disagree with him, but he got in through the system. Now if he doesn't get out that is another story.

          • mallets 17 hours ago
            Being a tyrant has little to do with term limits or office duration.
            • Ntrails 10 hours ago
              A couple of dictionary checks suggest some set of:

              - Ruler who is unrestrained by law or constitution

              - A usurper of sovereignty

              - Ruler who uses power oppressively or unjustly

              Obviously b) is not applicable as per GP. He has also been constrained by the supreme court and others multiple times in this term, which suggests a) is a stretch. c) probably a fair accusation, though I'm not sure I would agree.

          • one33seven 12 hours ago
            Hitler was elected too (not saying he is Hitler)
            • Gareth321 11 hours ago
              Hitler was not elected Chancellor by the German public. Germany had/has a mixed-member proportional system, meaning that coalitions may form after everyone votes President Paul von Hindenburg appointed Hitler as Chancellor on 30 January 1933 after negotiations among conservative politicians who believed they could control him. The Nazi Party was the largest party, but it won only 33.1% of the vote in the final free Reichstag election of November 1932 and never secured a popular majority. Once appointed, Hitler exploited emergency powers and political intimidation to dismantle democratic institutions and convert his government into a dictatorship.

              During his political ascent he used his Brownshirts - a large, organised paramilitary force - to assault political opponents, break up rival meetings, intimidate voters, and fight street battles, helping destabilise the Weimar Republic and suppress opposition.

              • greedo 4 hours ago
                Your comment implies that Hitler seized power despite a lack of popularity. The historical record shows that Hitler was wildly popular in Germany, even up to the end of WW2.
        • psd1 11 hours ago
          > Well, most of Europe simply has banned guns in the hands of civilians instead, so that's some data as well

          No, that's some bullshit. How do you think we eat pheasant and rabbit and venison? Show me a pheasant farm and I'll show you forty acres of unfenced woodland littered with empty cartridges.

          Observe! https://worldpopulationreview.com/country-rankings/gun-owner...

          • consp 10 hours ago
            My guess is the person is drawing from one country and applying it to all. The rules are varied all over the EU. e.g. You can buy pheasant, rabbit and venison at the butcher shop where I live. No hunting required, which you can do but requires a special permit, next to the weapons permit for the shotgun and is very limited in scope.
            • psd1 5 hours ago
              I'll wager that rabbit and that pheasant that you see skinned and cleaned in the shop were shot by a man in a field. I'm open to counterexamples, so let me know what your butcher tells you.

              I like your attitude of charity - we should not rush into judgement. But mschuster91's comment said:

              > most of Europe simply has banned guns in the hands of civilians

              This is bullshit. GP must be aware that they are profoundly ignorant on the topic, so why are they holding an opinion, let alone posting it? Should we tolerate bullshit on HN?

        • wang_li 19 hours ago
          No part of Europe has “simply banned guns”. Some countries have stricter policies but it’s possibly to own a gun in every country. Some countries are famous for gun ownership, eg switzerland that expects men to keep their militarily issued gun in the home.
          • kelnos 14 hours ago
            I'd be a lot more comfortable with gun ownership in the US if we could require every owner to have military-level firearms training and certification.
            • eecc 14 hours ago
              Well, that was the whole point of the 2A: effective preparedness.

              But gun manufacturers ragebaited this exceptionally effective marketing campaign around their products and here’s where you folks stand

      • holgerschurig 8 hours ago
        The thing is that a society does not always do only ONE thing. You mentioned that there are better ways to protect kids. But maybe they cost more (e.g. banning firearms is dead cheap, while setting up a structure with lots of psychologists specialized in teenager problems is really expensive).

        Also you can do one and the other ... at the same time. E.g. suicides of kids/teenagers (<= 19) in Germany in 2025: 216. That is, compared to the population in this age group, 1.38 per 100'000. In the USA that ratio is 9.4 in the age-group 15-19 and 2.3 in the age group 10-14.

        And keep in mind, the total deaths by firearms in Germany in 2024 was "just" 168 (we have 1/4th of the US population, in the US police forces alone killed more people ... the total number of 44'000 firearms deaths in USA/2024 is even more staggering). Even if I multiply the 168 by 4 for the population difference ... then 672 vs. 44'000 is still a point of shame for the USA.

        So in Germany, we do BOTH better regarding firearms AND regarding health services on kids. And if the USA truly would try MAGA they'd actually copy good results from other countries. So a real-MAGA-person must be against liberal firearms distribution AND for better social health work with teenagers.

        BTW, the USA ideology of "the population needs arms to fight a corrupt state" is laughable. When you had your armed religious sects clash with the state, then the state always won. They still have more and better weapons and armor. On the other side, if you look how east-europe shed off their socialist regimes 40 years ago, than nowhere was an armed general population involved. So one can conclude that private firearms may as well be highly regulated and diminshed.

        • giantg2 8 hours ago
          Banning firearms isn't "dead cheap" if you have 400 million in existence. The enforcement would cost a lot, even if you didn't perform a mandatory buyback program. Germany doesn't have an outright ban on guns, but strict regulation. Running the regulation costs money.

          A note about copying - you have to look at the culture to see if how things will work. Germany has vastly different socioeconomics than the US, and socioeconomics are major factors in crime and homicide. Not to mention the percentage of people who own guns and are pro-gun are vastly different. Applying the same regulations in the US will take decades for criminals to no longer have many guns and then they will switch to knives and screwdrivers as we see in the UK, which has about dowluble the violent crime rate as the US after accounting for differences in the stats (somewhat culturally/socioeconomically similar). So it might make the gun numbers better, but it won't solve the real drivers.

          The best approach would be to address the underlying factors and causes of all violence while still allowing freedoms for the 44% who do not support stricter regulation.

          • KaiserPro 7 hours ago
            > will switch to knives and screwdrivers as we see in the UK

            London, with a population of ~8 million has the same murder rate as new Orleans, which is 300k people. Not as in x murders per 100k, but as in total murders in a city.

            In terms of knife crime the USA has a slightly _higher_ rate of knife crime than the UK. Bear in mind the UK counts attacks with knifes as knife crimes, where as the states only appear to include death by knives.

            Which means that even if you took away gun deaths (~70% of all us homicides) you're still more likley to be stabbed in the USA compared to the USA.

            • giantg2 4 hours ago
              If we want to compare cities to New Orleans, then you might as well compare them them to Birmingham. Even with firearms being banned you have a murder rate of 28/100k vs 40/100k. Violent crime between the cities is actually equal at 55/1k.

              Yeah, stabbing deaths UK vs US is about half (175/70M UK vs 1600/350M US). But if comparing at the national level, 360/100k US vs 1200/100k UK.

              So it really comes down to each person's systems thinking approach and which stats they care about.

              • KaiserPro 3 hours ago
                > 360/100k US vs 1200/100k UK.

                Sorry but 1200 knife deaths per 100k means the annual rate would be 840,000 murders a year.

                last year the total number of murders in the UK was ~600 which is .86 per 100k

                (far less than the _gun_ related homicides in the US: https://www.pewresearch.org/short-reads/2026/04/28/what-the-...)

                The reason why I was talking about knife homicides specifically is that comparing knife crime between the us and the uk is hard. the UK systematically records crimes where knives are involved at a national level, the USA doesn't really.

                But brum has a murder rate twice that of the national average. Even so its not 28/100k its around 1.25/100k which is still just over a quarter of the _national_ gun homicide rate of the entire USA.(~4.3/100k)

                The point is, the UK is demonstrably less murderous than the USA. Even the UKs most murderous city is safer than Sanjose, which accordign to the stats I can find has a 3.2/100k murder rate.

          • master-lincoln 7 hours ago
            > Applying the same regulations in the US will take decades for criminals to no longer have many guns and then they will switch to knives and screwdrivers as we see in the UK

            That seems like a thing to pursue rather earlier than later if it takes so long to bear fruits. Knives and screwdrivers are at least only used for close-up combat.

            >The best approach would be to address the underlying factors and causes of all violence while still allowing freedoms for the 44% who do not support stricter regulation.

            To have the money for that you would need abolish capitalism I guess...

            • giantg2 4 hours ago
              "Knives and screwdrivers are at least only used for close-up combat."

              Most firearms murders are similarly close-up.

    • Spooky23 21 hours ago
      The CSAM issue is both very real and abused by politicians. When I did some work with a police agency, it was explained to me that there’s a pattern of escalation with people and they tend to accumulate collections and many escalate to actual behavior.

      The detectives assigned to this work tend to not last long, and the horrific nature of the crime affects them.

      Like all rape, it’s a combo of control and dopamine. The church and Boy Scout leaders leveraged their societial influence and power to compel compliance and even loyalty from their victims. Boy Scouts as an organization inserted itself into existing power structures like church, police and other institutions. It’s difficult for a 11 year old victim to make an accusation about a beloved community figure. They also tend to find ways to make their victims feel complicit. Even if people come forward, they are hard cases to try and exposes young victims to public shame. Many of these people plea to lesser crimes to protect the victim.

      I wasn’t a victim thank god, but a Boy Scout leader at my parish was a serial molester who abused dozens or hundreds of children. I learned about it years later and realized that some of my friends were almost certainly victims — in his case everyone in authority just blew it off

      • xyz1234999 13 hours ago
        > there’s a pattern of escalation with people and they tend to accumulate collections and many escalate to actual behavior

        I was curious about this. I did find some research here: https://www.suojellaanlapsia.fi/en/post/csam-users-in-the-da... (2021)

        That paper states

        > Traditional research on individuals who use CSAM is often inherently biased as it has focused primarily on convicted and known offenders.

        and appears to be directly trying to avoid that bias, which is good to see.

        Isn't there still some bias here though? They only got answers from 1. people who were using a dark web search engine with ads, 2. felt the need to click a "Help us to help you" link, 3. were willing to discuss the topic with strangers on the web. Only (3) was (almost) acknowledged in the Limitations section.

        They concluded that "Many CSAM users are not just viewers" and, while "many" could mean any number, I think readers would probably take it to mean something like 30% (shown in graphs) which isn't indicated by their data.

        Furthermore, the "not just viewers" conclusion is from a question about "seeking direct contact with children through online platforms". I'm not sure why they didn't more directly ask if respondents took action towards abusing children, with the inspecific "direct contact" qualifier and very specific qualifier "through online platforms". I wonder what the results would have been if they removed "direct" and "through online platforms" from the question.

        Admittedly I don't know a lot about statistical techniques! Has there been other research, or do you know what the police agency was basing their explanation on?

        • inigyou 9 hours ago
          FYI you are shadowbanned. Did you write this comment with AI? If you did, that's why.
          • xyz1234999 7 hours ago
            No... does it look like I did somewhere? Ah well...
            • john_strinlai 6 hours ago
              it didnt seem like ai to me. more likely its because it is a brand new account. a vouched comment or two clears it up.
      • wickedsight 13 hours ago
        This is correct. Also, the people who produce CSAM usually don't just stop, so tracking down material, especially new and unknown, is one of the most important ways to stop active abuse. Also because the material is actual proof and many (C)SA cases fail due to lack of exactly that.

        This doesn't mean I agree with active scanning of things like iCloud, effectively making everyone a suspect, but counter to what people here seem to think it really might help prevent CSA.

        • giantg2 4 hours ago
          I completely get tracking CSAM to get to the creator to stop the abuse. But how does that work for fictional works that are considered CSAM?
        • inigyou 9 hours ago
          > the material is actual proof

          How do you square this with fictional material being illegal?

          • paulryanrogers 6 hours ago
            IIRC, courts in the US ruled it's legal to produce entirely fictional art depicting children in explicit scenes, so long as no real minors were involved in production.
            • giantg2 4 hours ago
              Just Google "arrested for AI generated CSAM" and you will find tons of cases, including police officers as perps. Looks like the Protect act of 2003 make it illegal if basically looks real enough (cartoon ok, AI generated realism is apparently not).
      • lstodd 20 hours ago
        > When I did some work with a police agency, it was explained to me that there’s a pattern of escalation with people

        You have been mildly brainwashed.

        It would be best if that episode lead you to study a bit of psychology but instead you chose to believe.

        Like any belief it's a combo of control and dopamine. The feeling of belonging to a group and being righteous within that group hits so hard that it takes hard explicit effort to screen your perception of its effects.

        You are a victim because you failed to accept reality.

      • belorn 9 hours ago
        Lets look at this specific situation. Was there regulation that dictate/encourage screening and education for organizations that work with children? How many adults were there in the organization and on activities with this scout leader? How much involvement had parents? Was there any adult in the children environment that was trained to detect CSA, for example school personal?

        It is technical possible that in small villages there is only a single Boy Scout leader and no other adults, who then spend a lot of time alone with children. In my experience however, after school activities involving children also generally involve several adults. That makes it a major structural issue among the adults if they fail to detect a problem like hundreds of victims, and the more common remedy would be to train people, apply some form of screening, and change routines that limit risk and encourage reporting in case of inappropriate behavior.

        In addition, having trained people that regular meet and talk to children can help detect situations even when they happen in peoples home, like having school employees training in detecting signs of CSA.

    • manoDev 22 hours ago
      CSAM is the perfect trojan horse to undermine privacy everywhere. No politician and no company can oppose it on the grounds of protecting privacy before having the reputation ruined.

      Meanwhile the real pedos are rich people vacationing in well known places.

      • inigyou 9 hours ago
        Are you sure? Can't they say "yeah pedophilia is fucked up but reading all our emails is also fucked up"?
        • LanceH 7 hours ago
          > reading all our emails is also fucked up

          Why? are you hiding something in your email?

          • inigyou 7 hours ago
            Nobody actually believes "nothing to hide, nothing to fear" but it's short for "I don't have the energy to deal with this when it's unlikely to actually create any consequences for me in particular"
    • basilikum 20 hours ago
      To play devil's advocate: child abuse is usually a crime without direct evidence. CSAM is child abuse but the perpetrator films their crime as evidence. Everyone else who obtains and keeps this material also holds evidence against themselves as the possession of it is the crime.

      Now for real: People often do not care a lot about child abuse. It does not affect them as it happens in private where they do not see it. CSAM however does affect them as it makes the abuse visible and shows something deemed reprehensible. In a lot of ways people see themselves being witness (even indirect by purely hearing about it) to CSAM as the victim rather than the children who are harmed in the making and by redistribution.

      My cynical opinion is that it is a lot more about social norms and feelings arising from the violation of these norms rather than the harm done through the violation of children.

      • skissane 20 hours ago
        > CSAM is child abuse but the perpetrator films their crime as evidence

        This isn't entirely true. In much of the Western world – outside the US – CSAM (or equivalent legal terms such as "child pornography", "child abuse material", "child exploitation material", etc) can include text, drawings, AI-generated imagery, etc, which no child was abused to create, indeed the child depicted in it may be entirely fictional. Canadian law goes so far as to treat material which "advocates or counsels" the commission of CSA as CSAM - which the Supreme Court of Canada insisted (in the 2001 case of R v Sharpe) doesn't include mere political advocacy for its legalisation (as in e.g. the NAMBLA Bulletin), although some will question whether that insistence actually cashes out in practice.

        Now, as a father of school-aged children, I find the whole idea of groups like NAMBLA rather abhorrent – but, I'm hesitant about the government making it illegal for people to express abhorrent ideas, because there are likely ideas which you or I hold which somebody out there considers abhorrent.

        • basilikum 19 hours ago
          Fictional erotica portraying fictional children is not CSAM. There is no child abuse taking place as there is no child in the first place.

          Conflating the two is 1. wrong as a matter of fact and ethics and 2. a great injustice to the victims of child abuse.

          This is exactly what I wrote about in the second part of my comment. People see themselves as the victim of CSAM or proclaimed CSAM through being witness to it. In fictional works there is no child who could be the victim showing very clearly what these people are really about. They are not primarily concerned about children being exploited but they do not like the existence of such material as them deem it offensive to themselves.

          CSAM is a very real crime; including cases where real children are not physically harmed but get sexualized through the composition of the material. It is a crime because it violates children, not because it is offensive to societal norms.

          • ikeboy 6 hours ago
            Thomas Alan Arthur is currently serving 40 years in a US prison. He was convicted of publishing fictional text stories and two cartoon style drawings. (Note that he was accused of assault decades ago, which apparently factored into his sentence, but he was not charged or convicted of that.)
          • skissane 19 hours ago
            > Fictional erotica portraying fictional children is not CSAM. There is no child abuse taking place as there is no child in the first place.

            That’s your definition, but it isn’t the definition many authorities/activists/etc use.

            And I’m not defending their definition, merely pointing out it is a real live definition in active use

            • basilikum 19 hours ago
              To clarify, I am aware you are objectively describing the legal situation. I am not making a legal, but an ethical argument. We seem to be agreeing.

              There is even a Wikipedia article about the legality. It's quite complicated in a lot of places because people really like to ban it but it very much is free speech or protected artistic expression in countries that have these concepts: https://en.wikipedia.org/wiki/Legal_status_of_fictional_porn...

              To be clear fictional pornography about real children has to be distinguished from fictional characters. Even when the depiction is purely fictional. Sexualizing real children is unacceptable.

        • throwaway85825 20 hours ago
          Not every problem can be fixed by making it illegal.
    • miki123211 11 hours ago
      CSA doesn't neatly fit into a narrative.

      If there's a person committing abuse against a child, usually a family member in their own household, there's no story there. They (hopefully) get arrested, get a minor mention in the media if that, and life moves on.

      If, on the other hand, they send CSAM using a platform, device or protocol, then clearly the makers of that technology failed to uphold their sacred duty to protect the child. If most CSAM cases happen using a few major technologies (and they will, because societies tend to standardize on what technologies they use for communication), the technologies get blamed for the problem they supposedly enable.

      If you dislike the technology for other reasons (the distrust of corporations from left-leaning politicians, censorship allegations on the right, a moral panic about the impact of smartphones on children's mental health), you can use people's misunderstanding of statistics to exaggerate the CSAM problem, blame the tech, and gain some notion of control over it in a way that is politically palatable to citizens.

      It's worth saying explicitly that centralization doesn't have much to do with this. We've seen similar stories play out with bicycles, Walkmans, pagers, AI, heavy metal and Uber rapes. They were different moral panics, but the mechanic was roughly the same. I think the situation wouldn't change much if we all used PGP-encrypted email over personal mail servers to communicate.

      An exception that proves the rule is the moral panic over CSA in primarily-catholic countries, notably relating to abuse committed by catholic priests, which are statistically no more likely to commit it than anybody else. As the influence of the Church on government policy is a hotly-debated topic in those countries, CSA is suddenly an issue that people can use to further their political causes.

      • 0dayz 11 hours ago
        Sorry but I'm intrigued, what was the moral panic about bicycles and Walkman?
    • basilikum 20 hours ago
      > I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.

      You might want to look up if that's actually true. It might be. It might also be a lie to hide the real reason why they are registered.

      • dijit 20 hours ago
        on the flip side, imagine if it's true and everyone immediately suspects that you're a pedophile trying to appear innocent.

        Talk about tainted for life.

      • teaearlgraycold 18 hours ago
        What’s up with the cop that cited them for that?
        • dijit 18 hours ago
          in my limited experience with the law, they tend to really go for you if you aren't the kind of person who enjoys breaking the law.

          It's almost like they can spot an easy target.

          Deal drugs and conduct yourself violently in society, sit with a gang and destroy property... Police seem to have a hard time with you.

          Push someone over who is threatening to knock your teeth out when you're walking with your wife and kids... that's an assault charge, because naively you explained what happened to the police, and they're going to make sure you see the inside of a court room for it.

          • BloodyIron 18 hours ago
            Quotas?
            • dijit 18 hours ago
              Dunno, probably just easier to “catch” people who think that they are good people, they think the police is on their side.
              • WarmWash 5 hours ago
                People who chronically are in trouble with the cops pretty quickly learn the police are working against them.

                Regular people having a bad moment think they can just explain everything to the police and they'll go "Ah, sorry mate, we misunderstood and you can go home now"

          • teaearlgraycold 17 hours ago
            Don't talk to the police!
    • BLKNSLVR 15 hours ago
      The lowest of the low hanging political points scoring fruit will be picked.

      I make this point on HN each time it comes up: Dealing with actual CSA requires actual people going to investigate actual reports of children's living conditions out in the real world, not "scanning digital files". Seems obvious when you say it like that, but the alternative seems to still score heavily on the political scale. Ironically, spending more money on "scanning digital files" takes away from resources that could prevent those digital files from being created in the first place, so all the additional time, money, and effort towards combatting CSAM is time, money, and effort specifically _not_ working against stopping CSA. It's categorically _not_ protecting the children.

      Teachers, in Australia at least, have mandatory reporting where any kind of abuse is suspected. The heart-breaking irony is that the resources to investigate the reports are so scarce that they can only respond to reports where the child's life is in immediate danger.

      Caveat: the above was true a few years ago, I genuinely don't know if it's still true. What I do know is that 'social work' isn't suddenly a high paying job, so I doubt resource availability has changed much.

      There is no easy answer to this. It's entirely nuance.

      • EagnaIonat 14 hours ago
        > Seems obvious when you say it like that,

        That's exactly what happens. CSAM has two parts to it.

        The first is the known and most horrific videos of CP out there. These aren't shared, instead only hashes are used to determine if the image/video matches. It's next to impossible to get an mis-hit on that.

        The second is nudity and age detection AI. Apple has this on their devices, but warns the user before sharing not reporting.

        It normally takes more than one hit to get flagged for investigation. At that point law enforcement are informed and take over.

        The majority of investigations are children sending naked pictures of themself to their friends.

        So it is absolutely being used as the purpose to protect children and it's amazing how many people don't realise how it works when they are very transparent about it.

        Of course it is not without its issues that need to fixed. For example providers will just ban the person before it's determined if they broke a law or not.

        • basilikum 8 hours ago
          What you are describing is indiscriminate mass surveillance. There is absolutely nothing stopping Apple or whoever maintains that listof hashes from putting things other than child abuse on there, like dissident memes for example.

          It also requires devices to run this spyware without a way to disable it. The natural consequence of this is to ban everything but government approved, restricted OSes and to outlaw devices capable of running anything but these. Mandatory CSAM scanning is part of the war on general computing and privacy.

      • Thlom 5 hours ago
        Children also need to understand that they have been abused and know who they can talk to for them to be able to report abuse to a trusted adult. Unfortunately that requires children to learn about sexuality and autonomy which for some reason conservatives think is abuse to teach children.
        • WarmWash 5 hours ago
          Part of the problem is that the topic is so radioactive, that coming forward with a story of abuse, and the legal/media circus that follows, really puts the abuse center stage in people's view of you. Most people absolutely do not want their most defining attribute to be "person whose family member raped them", even if it comes with extreme sympathy and understanding.

          For many, probably most victims, they just want to forget about it and let it vanish into the past, and ideally someone else who was abused by that person comes out and has them jailed.

    • elil17 12 hours ago
      My thought is that many different stakeholders have reasons to focus on CSAM:

      - Prosecutors want to go after it because it is much easier to prove than CSA.

      - Authoritarians want to go after it because it gives them a chance to get things like ID checks accepted by the public.

      - People who genuinely want to prevent CSA focus on it because a large amount of CSAM is made by serial abusers - so capturing producers can prevent future abuse. Additionally, they believe (with good reasons) that CSAM consumption is a gateway to CSA and CSAM production for many people. Further, finding CSAM can be a way to identify and rescue children from abusive situations.

      - CSA survivors may advocate for it often feel traumatized not just by the abuse, but by the fact that people might be continuously viewing that abuse.

      - Going after it winds up creating digital forensics specialists and task forces, which creates a special interest group within police departments which wants to continue focusing on CSAM but is not set up to do anything about CSA.

      I would recommend the podcast Hunting Warhead to anyone interested in learning more about this.

    • guerrilla 23 hours ago
      In Sweden we're going to literally have Minority Report style pre-crime registries for potential child molesters. We already have one for potential domestic abusers. Fuck this country. I need to get out of here before it gets worse.
      • hansvm 22 hours ago
        Say what now? What criteria do they use to scan the populace and create a pre-crime registry of any kind?
        • SiempreViernes 9 hours ago
          Probably there's only two criteria: "are you in any way foreign" or "do you vote for the left", that's the sort of government Sweden has these days.
      • wredcoll 18 hours ago
        What? Since when? What are you talking about?
      • Scroll_Swe 5 hours ago
        And get ready for more refugees when the left wins... 2015 here we go again. Öppna era hjärtan...

        I won't leave. I was born here, and my ancestors were too and this is my beautiful country.

    • gradschool 3 hours ago
      > This has even extended to fictional CSAM such as AI generated stories and pictures.

      Peripheral to your comment, there is an argument against AI generated CSAM that no one seems to be making so allow me. AI will do the same for CSAM as it has already done for copyright laundering. That is, it will enable its distributors to train their models on real CSAM while obscuring the training material. A legal regime that permits unrestricted distribution of AI generated CSAM incentivizes actual abuse as a source of training material. If one opposes legal prohibitions on free speech grounds, then at a minimum there should be an audit requirement incumbent on AI generated CSAM distributors to document their process in sufficient detail as to establish that they haven't used actual CSAM for training, similarly to the way porn distributors are required to document that their models are of legal age.

    • twothreeone 1 day ago
      I think it's similar with other liability issues, e.g., when a company happens to "lose" customer data through a breach. They will be on the hook for not having certain audits and certifications at regular intervals. Practically never will anyone be feeling any pain due to absolute disregard for basic common sense precautions to prevent issues in the first place. So usually, the pattern is that issues that can be outsourced to insurance will be handled by compliance departments - which don't care about the actual problems, just that the fallout from them is "managed" accordingly.
      • giantg2 1 day ago
        That's actually a little funny. I work in compliance and we regularly work with the teams to improve processes that enhance security. I will say though, that the outsourced work that we send to consultants has the same sort of result you describe.
    • throwaway2037 20 hours ago

          > yet almost nothing seems to be done to prevent CSA
      
          > On the CSA side, ... [t]here doesn't seem to be any real push for educating and protecting kids before it happens.
      
      This is a mighty wide brush you are painting with. When I was growing up, from very early (elementary school), we had "health class" where the teacher would teach you things about your body and health. This also included who is allowed to see you naked and/or touch your private parts. They also explained how to get help if someone what touching you inappropriately. That effort seems pretty active to me.

          > I personally know of 1 who took a leak across from a playground at 2am walking home from the bars and was put on the sex offender registry because it was within 500'.
      
      Urinating in public late at night is an interesting category of inprobably CSA-labeled behaviour. It should be treated with kid gloves -- the context matters.
      • rationalist 19 hours ago
        > This also included who is allowed to see you naked and/or touch your private parts. They also explained how to get help if someone what touching you inappropriately. That effort seems pretty active to me.

        My school did not cover that (but at least my parents did).

    • KaiserPro 7 hours ago
      > yet almost nothing seems to be done to prevent CSA.

      for the UK, there has been a massive shift to prevent this kind of stuff.

      anyone who even volunteers with children or vulnerable adults needs to be screened. Charities are required to have policies for dealing with vulnerable people safely.

      but to the point, Apple halfarse CSAM reporting.

      Whatsapp which doesn't do "CSAM scanning" reports in one hour more CSAM than apple does in a year. From memory meta (instgram, facebook and whatsapp) reported millions of cases of CSAM for 2021, compared to apple's ~250 (not thousand, just 250)

      for facebook its automated scanning, but for whatsapp, its just design. its really obvious how to report a message/image. in imessage, its impossible, there is no mechanism to long press/select/other a message.

      Now, Facebook are bastards in virtually every way, but for whatsapp at least, they have made GUI changes that have real positive impact on CSAM protection.

      Apple has not.

      They made some noise about hashing, but thats invasive and ironically noisier than having user reports.

      • john_strinlai 5 hours ago
        >anyone who even volunteers with children or vulnerable adults needs to be screened

        as far as i am aware, that is common practice in many countries. the problem is that screening is typically a quick check of "has this person been suspected or arrested for something involving minors already" and perhaps a few questions on a piece of paper. its not like they give everyone volunteering for a fieldtrip an extensive 1:1 with a psychologist and an mri. any predator who has not previously been caught will easily pass screening.

        >From memory meta (instgram, facebook and whatsapp) reported millions of cases of CSAM for 2021, compared to apple's ~250 (not thousand, just 250)

        easy enough to explain. instagram and facebook are social media with billions of public posts. whatsapp is in a similar enough boat, with large (up to 1000 participants?) facebook-like groups of otherwise strangers and a lot of marketing and inertia for social-media-like use.

        i imagine instagram is a majority of it. it's disgusting on there.

        on the other hand, apple is not a social media company nor facilitates large group chats (imessage goes up to 32 participants).

        i doubt adding an easier UX for reporting would make a material difference in the number of reports apple submits because you're typically already talking with people you know when using imessage.

        • KaiserPro 5 hours ago
          I just looked it up, its the ncmec.org annual report, the one I am referencing is from 2024, not 2021. I mis remembered

          Apple reported 250 items

          Instagram 3.1million whatsapp 1.1 million facebook 8.8million tiktok 1.3 million snapchat 1.1million

          Look I hate meta, more than you would know. But apple have very little excuse here. Even Anthropic reported more CSAM than them. I get your point about group vs 1:1, but frankly that holds only a tiny amount of water. Even if you did want to report it, you can't, not through apple at least. And if you did report it to the police, there is a high chance you'll loose your phone for use as evidence.

          • john_strinlai 5 hours ago
            >Apple reported 250 items

            Instagram 3.1million whatsapp 1.1 million facebook 8.8million tiktok 1.3 million snapchat 1.1million

            those numbers seem absolutely in line with what i would expect when comparing the largest social media platforms on the planet and a company that does 0 social media and extremely limited group sharing.

            it seems very strange to me to put any blame apple here when its just a statistics game. billions of image posts = millions of reports. simple as.

            and anyways, if i received CSAM from one of my phone contacts im going directly to the local police, skipping the apple -> ncmec -> state -> local pipeline. i think most people would be in the same boat.

            a report button is useful when you don't know the identity of the perpetrator. but when you do know them, you should be going to actual law enforcement, not hoping your report eventually gets routed to the right agency.

            • KaiserPro 2 hours ago
              Sorry but this is denial. I know I'm not going to change your mind, however:

              > it seems very strange to me to put any blame apple here when its just a statistics game. billions of image posts = millions of reports. simple as.

              Apple's platform hosts billions of messages and photos. It is the Paedophile’s choice for distributing images and videos. The problem for us is Apple's halfarsedness in tackling this leads to clientside scanning or backdoors in encryption. They are not doing anything at all to stop this, and compared to whatsapp of all fucking apps, they are doing nothing.

              • john_strinlai 18 minutes ago
                >I know I'm not going to change your mind

                you might if you could back up statements like "apple is the pedos choice for distributing images and videos" with any sort of data.

                but you wont be able to, because it's not true.

                and, again, apple is 1:1 transmission. a report button practically worthless because you know who is distributing the CSAM in that case. dont be lazy and go to the police.

                instagram, facebook, whatsapp is 1:many transmission with strangers. a report button makes a lot of sense there.

    • seanmcdirmid 19 hours ago
      CSAM laws in many jurisdictions include computer generated or hand crafted media that do not pre-require CSA at all. The idea is that deviance leads to CSA, and by cracking down on CSAM, we are preventing CSA.
      • brabel 10 hours ago
        This is such a slippery slope. It amounts to thought police. You did not actually cause any harm, but thought of doing something. Where do we stop ? If I fantasize about my pretty coworker without her consent, am I a rapist now? What if I make a sketch of her naked? Is that a crime? What if I ask AI to remove her clothes from a real picture? Even if I just immediately delete it?? I guess that there’s different levels to each “offense”, and at one level it does become criminal, but it’s hard to unequivocally decide where.
      • teaearlgraycold 18 hours ago
        The US constitution should require proof of harm to a living thing as a prerequisite for criminal charges.
    • Cthulhu_ 12 hours ago
      Theory besides what others have said: remove the supply and you affect the demand. That's the theory anyway, I'm not sure it works like that; to make a parallel, punishing drug users didn't affect dealers/supply networks.
    • hn_acker 20 hours ago
      > There doesn't seem to be any real push for educating and protecting kids before it happens.

      Before abstinence and birth control, CSA prevention should be the primary goal of sex ed in schools, especially before high school. (Though on birth control [1] and probably STIs as well the US is not doing well.)

      [1] https://www.plannedparenthoodaction.org/issues/sex-education...

    • rootusrootus 21 hours ago
      > On the CSA side, you rarely hear about arrests (they happen but less than CSAM).

      Because it is nearly always someone we know. Someone who we just cannot imagine would ever do such a thing, even when the evidence is glaringly obvious. And I suspect that the fraction of the population diddling kids in real life is breathtaking, and nobody really wants to face that head on. Too uncomfortable.

      I could just be overly cynical today. But given my own experiences and other people I've known throughout my life, I really believe it is very common.

      • brabel 10 hours ago
        I thought it had never happened around me in my whole life, but my sister recently told me that when she just in primary school, a friend of my dad gave her a lift and while she was in the car, inserted his fingers on her. Like WTF! I really had no idea this could have happened in my environment. I guess it probably happened more than I know to others too uncomfortable to say anything, took my sister 30 years to say something.
        • pixl97 7 hours ago
          I've talked to so many women about their sexual abuse that it seems harder to find someone that has not been abused. What's worse is how many people are involved in covering it up, keeping it hidden, and ensuring the perpetrators are never caught.
    • inemesitaffia 23 hours ago
      >if that gets extended to

      If you provide the government a platform to do So, they'll do Y if you wait long enough

      • inigyou 9 hours ago
        Not everything is a slippery slope. Many things are, but you have to prove each specific case, not cite the general existence of slippery slopes.
    • ribosometronome 1 day ago
      One is far easier to prove. If the government could continuously monitor our actions "Is this CSA?" they might very well be pushing for that, too.
    • one33seven 12 hours ago
      It is not about CSAM, it's about scanning our data. If it were about kids safety there would be lots of people in jail
    • summerlight 3 hours ago
      There is a pretty simple yet disappointing reason. CSAM is much easier to investigate and prosecute. You got evidence, you prosecute. Almost guaranteed conviction. You can even enforce big tech to implement proactive monitoring systems.

      Compared to this, CSA is much harder. Every case is different. You have to do due diligence. And it is extremely hard to proactively detect them. Careful criminals will destroy all evidence. The number of case itself is smaller. And there is a good chance to lose in the court and for prosecutors this is a clearly risky move. Good ol' criminal investigation is expensive. There is a structural reason not to prioritize them.

      The whole incentive structure is broken. The only thing to fix this is external pressure, but even it does not work these days. Exposing CSA is a rare event but media needs constant, sensitive headlines so they tend to treat CSA and CSAM like the same thing. Hence external pressures do not work, and even worse those work in a wrong way. This creates a bad feedback loop.

    • setgree 9 hours ago
      First, I think it’s likely that you hear more about one than the other because you read websites like Hacker News and are not (I assume) an FBI agent or someone else who works on this stuff. A public defender I know would say that child abuse of all sorts is ever-present and relevant to their work, unfortunately.

      Second, detecting CSAM leads to its producers who are by definition abusers. Here’s a nice article in Wired about the digital forensics of cracking down on a CSAM ring with some interesting details about the role played by crypto, and abusers’ misconceptions about it: https://www.wired.com/story/tracers-in-the-dark-welcome-to-v...

      With that said, I agree that a lot of political concern for this is a smokescreen for a creating more surveillance. “think of the children!” has the flavor of a rhetorical trump card.

    • NordStreamYacht 19 hours ago
      These laws are a pretext to remove anonymity on the internet and insert backdoors into everything.
    • matheusmoreira 18 hours ago
      It's not about children. It was never about children. How many politicians have gotten caught in Epstein's island by now?

      It's all about surveilling the masses and keeping them under control. Children are merely one of the political weapons they use to make the masses accept any proposed solution, no matter how Orwellian. You're not against protecting children from drug trafficking, money laundering, child molesting terrorists, are you?

    • benj111 11 hours ago
      I'd like to know the link between availability of csam and CSA. There seems to be an assumption that the former causes the latter.

      That's not to say it's acceptable if illegally produced.

      We have issues in the UK. So far they've banned 'rape' porn. And now they're talking about 'barely legal'

      None of this seems to be based on any statistics showing this is actually harmful in any way.

      • inigyou 9 hours ago
        If they ban "barely legal" the next thing will be "barely not barely legal" and they'll ban that, and they'll have "barely not barely not barely legal" and so on...
    • superxpro12 14 hours ago
      Yeah DUH. its a trojan horse to eliminate any privacy in the populace, except for the government and elites, of course. They get privacy. You dont. How else are they going to maintain control over the populace?
    • nsonha 15 hours ago
      I don't know how to say this and not sound like a CSAM or CSA offender but CSAM policing sounds too much thought policing to me, if you wanna police CSA just go and do it, don't police what people have in their mind.
    • rationalist 23 hours ago
      > ones who have been involved in abuse scandals in the past (Churches, Scouts, etc)

      And those groups still have lower rates of abuse than Schools which do a lot less training and enforcement of youth protection policies.

      Children are still safer in Scouts and churches than in schools.

      Just about every kid goes to school though, so people just prefer to sweep that under the rug and focus on targeting organizations they are not a part of or disagree with because they're easier to demonize and make fun of.

      I work with kids, and I've had to take the Scouts and Catholic Church's youth protection training. They are both free to take online if anyone wants to check it out.

      • fluoridation 23 hours ago
        >And those groups still have lower rates of abuse than Schools

        Is that in absolute terms, or per child who frequents the establishment?

        • rationalist 20 hours ago
          > rates

          So something like 1 per 100,000; which of course is still 1 too many.

          (The other comments in other branches seem to prove my point. I am not defending any institution by the way. No one should be covering up crimes and/or allowing criminals to victimize people further.)

          • fluoridation 20 hours ago
            "Rate" is an ambiguous word. Molested children per year is a rate just as molested children per total children is.

            >something like 1 per 100,000

            What is this? What number are you citing, and where are you getting it from?

            • rationalist 19 hours ago
              I've never heard anyone say that a rate is ambiguous.

              It seems like you're trying to be disingenuous, first with "rate", now with my clearly-arbitrary example of rate.

              > something like

              • fluoridation 19 hours ago
                A rate is just a ratio between two quantities. You've never heard speed defined as the rate of movement?

                I might have interpreted your example as such if not for the "one too many" comment. It's strange to throw out a completely fictitious figure and then lament it as if it's real.

                • godwinson__4-8 16 hours ago
                  who is fighting windmills now? :P

                  see how your patience has been rewarded... no good deed goes unpunished. he will never produce an actual figure. look at his other replies. such a victim complex. on behalf of the catholic church. regarding their sexual abuse of minors. what more is there to say?

                  • rationalist 10 hours ago
                    > he will never produce an actual figure.

                    > It's strange to throw out a completely fictitious figure and then lament it as if it's real.

                    You two are insufferable.

                    Anyway:

                    If you do an online search, the first results you may get, say how hard it is to compare. Here is one comparison that I did find:

                    https://actheologian.com/2025/04/22/comparing-child-abuse-ra...

                    Please note, this is not where I got my figures years ago, as I no longer have access to that source.

                    > Public Schools ~450 per 100,000

                    > Boy Scouts ~100–200 per 100,000

                    > Protestant Churches Likely 1–5 per 100,000

                    > Catholic Church (Priests Only) ~1 per 100,000

                    Also note, something like 90% of the Boy Scout sexual abuse cases were prior to the 1970s before they started mandating adults to take youth protection training. Today, the Boy Scouts and Catholic Church have some of the most comprehensive youth protection traing around, way better than any schools' youth protection training according to educators that I've talked with.

                    Good riddance. Go sharpen your ideological axes somewhere else.

              • phoghed 18 hours ago
                No, it seems more like you are being disingenuous. All you have to do is drop a link to the rates you’re referring to. Instead you’re just arguing semantics. Where’s the receipts?
                • rationalist 18 hours ago
                  > something like

                  I thought adding "for example" at the end was just unnecessary redundancy, but I guess I was wrong.

                  I still don't understand why the other person is trying to cross-examine me on the definition of "rate" or whatever though. That is the person arguing semantics, not me... (Same with you, except you're going one step further and trying to gaslight me.)

                  I'm curious, do you have something against churches and/or Scouts?

                  • phoghed 8 hours ago
                    No, you said explicitly that kids are sexually assaulted at a higher rate in schools than they are in churches or scouts.

                    You clarified that you mean per 100,000 children more are likely to be sexually assaulted in schools.

                    Usually when someone has a belief like this, it’s grounded by something that they read or learned somewhere. Where did you learn this? Why aren’t you sharing the source with everyone else so they can learn it too?

                    But there’s still nuance there that you’re ignoring as well. We could say that rate should be examined per hour because a kid will spend 30 hours per week at school vs a few hours per week at scouts or church. Without your source though, we have no idea what the rates are, if they are what you say, if there’s even a significant difference, etc.

                    Now you’re trying to act like a victim because people want clarity on what exactly you mean and where you learned it.

                    Nobody is “gaslighting” you, just give the receipts.

                    • rationalist 8 hours ago
                      > just give the receipts.

                      Just read my last comment I posted two hours before you posted yours?

                      > you’re ignoring as well.

                      You're assuming facts not in evidence.

                      > We could say that rate should be examined per hour because a kid will spend 30 hours per week at school vs...

                      "Don't worry Timmy, even though you were molested at school, because you're forced to go there every (week)day and spend more time there than church, Boy Scouts, etc, you statistically had less of a chance per hour of being molested."

                      Per hour makes zero sense.

                      Do you have something against churches or scouts? I can't imagine why you are being ao convoluted otherwise.

                      > Nobody is “gaslighting” you, just give the receipts.

                      I already gave the "receipts". Stop trying to gaslight me.

                      ...

                      FYI everyone else: the Boy Scouts has a "two deep" leadership policy, meaning no private one-on-one contact between youth and adults. That's why 90+% of cases were from over 50 years ago. And don't believe everything you read on reddit, because I saw one comment where someone claimed they were abused as a kid by their troop manager... No one who actually was a Scout would call their Scoutmaster a "troop manager". It almost certainly was someone who was ideologically opposed to Boy Scouts. (If someone can teach me how to use reddit's aweful search function to find that comment, I'll gladly provide that "receipt".)

                      • phoghed 4 hours ago
                        > I already gave the "receipts". Stop trying to gaslight me.

                        Not to me and not when I asked. And you just applied waaaay more effort than it would have taken.

                        > Don't worry Timmy, even though you were molested at school, because you're forced to go there every (week)day and spend more time there than church, Boy Scouts, etc, you statistically had less of a chance per hour of being molested.

                        No, but as a parent it becomes part of your risk assessment when deciding if you want your kid to become an altar boy.

                        • rationalist 4 hours ago
                          > you just applied waaaay more effort than it would have taken.

                          I have no idea what you mean by that. I'm guessing it's some kind of jab that didn't land.

                          > as a parent it becomes part of your risk assessment when deciding if you want your kid to become an altar boy.

                          "Timmy, remember when I told you that you should keep your private parts private, to only let the doctor touch them while wearing gloves during at the doctor's office, and to let me know if anyone touches them, tries to touch them, stares at them, or asks to see or touch them; to let me know right? That still stands. The robe goes over your clothes, you don't need to undress at church or at school. And do you remember how if someone tells you to keep a secret from me, and it's not something like a birthday surprise for me, that you should tell me. God is not going to be mad at you if you do what's right, God will be mad at someone if they try to take advantage of you, no matter what their position is."

                          Yes, everything has a risk assessment. Singling out a more rare risk shows that you have a bias. It has been very obvious for a while that you and a few other users have a bias. I don't know why, but I hope you heal or get better/smarter.

                          Being ganged up on by you all is tiring. Anyone who doesn't have a bias can see this comment chain for what it is. I'm going to move on with my life, and if you want to be happier with your lot, you should too.

                          Best regards, rationalist

                      • fluoridation 7 hours ago
                        >No one who actually was a Scout would call their Scoutmaster a "troop manager".

                        I was a scout and I natively speak Spanish, so I never learned what the ranks are called in English (and after nearly 30 years I've pretty much completely forgotten them in Spanish too, if I'm being honest). Are you going to call me a liar too?

                        • rationalist 4 hours ago
                          Wow, you all do not stop. You've been grinding your ax so long now, it could cut a hair. If you were a Scout, you would know your ax should not be that sharp.
                          • fluoridation 4 hours ago
                            Not an answer to my question. If you feel ganged up on, perhaps it's time to stop posting.
                            • rationalist 3 hours ago
                              No, I'm not going to call you a liar since you didn't specify the Boy Scouts of America and there are 100+ Scouting programs in different countries across the world.

                              The Boy Scouts of America program has only been in English until just last year (they just released the Spanish version of their Handbook last year, and now they have a Mandarin version too). Anyone who doesn't know the world "Scoutmaster" and claims to have been in the Boy Scouts of America, is very odd... I'm only calling those people liars.

                              Holy moly. If you thought I was calling you a liar, perhaps you should stop posting. But if you want to continue to grind your ax, since you asked me a question, I'll ask you one: do you have a bias?

                              • fluoridation 2 hours ago
                                Redundant question. Everyone has biases.
      • snozolli 23 hours ago
        And those groups still have lower rates of abuse than Schools

        What evidence do you have of this? The only sources I can find that would even vaguely support your claim switch to talking about physical abuse in schools, or sexual assault committed by fellow students.

        To be clear, we're discussing the sexual assault of children by adults here. We're not talking about physical abuse, nor are we talking about assault by fellow students.

        • pixl97 6 hours ago
          Ya I personally don't believe it myself. Schools have legal demands on reporting. Every church I had went to when I was young covered CSA up and ensured the perpetrators were never brought to justice.
          • rationalist 4 hours ago
            Flat earthers do not believe the world is round, yet it is. Feel free to read my comment I posted hours ago, with a link.
            • pixl97 2 hours ago
              I mean, the earth isn't exactly trying to hide that it is round, religious criminals are.
      • godwinson__4-8 23 hours ago
        Does the school work to cover it up to the same extent? Are people across the school in on it? Are the rates of abuse higher on a per capita basis?

        Why are you making apologies for (Catholic) church sex abuse? Because you are a member and you took a training? Yikes.

        • schrodinger 22 hours ago
          Where did you see apologies?

          I read it basically as “schools are even worse than churches and scouts yet are overlooked,” nothing apologizing for the churches.

          • godwinson__4-8 20 hours ago
            "demonization" of the church?

            Ironic phrasing, given the Catholic Church wants authority to decide what is demonic while acting like demons. Why is the comment so plainly aggrieved? Is the Catholic Church a victim here?

            Even as your sanitized claim, where is the evidence?

            It doesn't exist.

            • schrodinger 20 hours ago
              I'm not a Catholic (nor religious at all), and do question whether schools truly are worse than churches in terms of how children are treated.

              But that's not the point. You made up a quote I didn't say ("demonization"), and accused the former poster of doing something they weren't: defending the church.

              Saying that schools are worse yet ignored is not defending the church. It may also be incorrect, but that's a separate assertion.

              • godwinson__4-8 20 hours ago
                That was in the comment that started this chain. Are you using an alt? I'm not sure why this is so hard for you to follow. If I were you I would take a breath and read the chain again.

                Here I'll help you:

                > Just about every kid goes to school though, so people just prefer to sweep that under the rug and focus on targeting organizations they are not a part of or disagree with because they're easier to demonize and make fun of.

                In what world is that useful to your sanitized claim? Is it not an obviously underhanded apology for the conduct of the church? Is the aggrieved nature of this really lost on you?

                • fluoridation 20 hours ago
                  Buddy, you are fighting windmills. You should go lie down.
          • xboxnolifes 22 hours ago
            HN is very anti-religion. It turns off their brain when they see it and leads to these kinds of responses.
            • rationalist 17 hours ago
              Some HN users probably are, but not all, and I doubt not a majority. A majority might not be religious, but not being religious does not automatically mean anti-religion. There are occasionally comments that show an espousal of a god that do get upvotes.

              Calling someone's god, an "imaginary friend" is probably a trait of someone very anti-religious though. I haven't read all the different religious texts, but I highly doubt any of them call their god a friend. Perhaps Jesus could be considered friendly, but I don't think the Bible says that a Christian must consider Jesus as their friend. I think it's more like how parents should be parents and not friends. I imagine in most if not all relgions, gods should be gods and not friends.

            • godwinson__4-8 20 hours ago
              Please tell me which part of your brain is engaged when you converse with your imaginary friend?

              Is that really the best reply you could conjure? Maybe you can produce some evidence absolving the Catholic Church here? Or are you also an apologist for institutions that call themselves sacred engaging in systemic sex abuse?

              • pixl97 6 hours ago
                While I am as anti religious as you, probably not the best discussion method.

                Instead ask them if their church ever taught them anything on how to prevent sexual abuse, in both children or adults. Quickly you'll find the apologist for the church saying it's not the churches job even though they are in charge of children and vulnerable adults almost all the time.

    • sneak 15 hours ago
      It’s nothing to do with CSAM and all about surveilling who has which files and when, and who they send them to.

      Even ADP in iCloud sends the hashes of the plaintext to Apple, non-e2ee. This allows them to see who has unique files, and when, and the networks of users to which they spread, and when.

    • danaris 23 hours ago
      The problem is, the things that would actually prevent CSA require things like "giving children rights", "widely mandating effective age-appropriate sex education even for young children", and "admitting that it's mostly not scary strangers doing it."

      These are utterly anathema to huge chunks of society, especially American society. It's more and more clear, from the scope of the Epstein Files, just how much of American society and government has been influenced specifically to enable easy access to children by rich white men. Even beyond that, the entire right wing would instantly catch fire if we actually required effective sex education. Especially age-appropriate sex education going right down to kindergarten (yes, kindergarten: the better children that age understand what's normal and safe, the better they can communicate when someone is doing things to them that are not that...and I only stop at kindergarten because AFAIK that's the earliest mandated schooling still). Similarly, the right wing desperately wants to have absolute control over their children—treat them as property—so giving children rights that even parents have to respect will get them to oppose absolutely everything.

      Plus, as other sibling comments have already noted, the real desire here is for ubiquitous surveillance. CSAM is just the excuse they use.

      • throwaway89864 23 hours ago
        Somehow, even something as simple as "age-appropriate sex education going right down to kindergarten" would tend to end up "special interests education from vocal minority groups."
        • danaris 22 hours ago
          To be clear, I recognize that there is zero chance of genuine effective age-appropriate sex education being mandated in the foreseeable future in the US, nor has there been any such chance at any time in the past. I'm merely noting some of the things that would actually be helpful measures in combating CSA if it were possible to implement them.

          You're absolutely right that, even if such a mandate had already existed, it would've been erased or co-opted by right-wing groups by now.

          • throwaway89864 21 hours ago
            Yep, will end up right-wing groups, or same-sex groups.
            • danaris 13 hours ago
              To be even clearer, genuine effective age-appropriate sex education absolutely includes education on what it means to be trans, gay, bi, ace, and every other part of the queer rainbow, and that all of these things are just as good and normal as being straight, cis, etc.

              Take your bigotry and stuff it.

      • KolibriFly 11 hours ago
        [flagged]
    • Kalibr 14 hours ago
      Arresting for CSAM is easy and brings in a lot of money. It’s a slam dunk case for just possession. Investigating and prosecuting people for CSA takes a lot of manpower and time for single case and not nearly as profitable. As usual, follow the money.
  • amazingamazing 1 day ago
    It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level.

    Apple could easily not do this stuff and it may even be easier to not.

    • avidiax 1 day ago
      > It is crazy people think apple isnt on the side of privacy.

      > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.

      I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare quotes there because I don't think that political or religious dissidents would find that the same or similar technology used to discover and persecute them is "privacy preserving". And that's really the problem with Apple here. They provided a model for scanning for any kind of message or material while purportedly maintaining privacy.

      • bayindirh 1 day ago
        > It proved that it was technically feasible, and was "privacy preserving".

        Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?

        If not, I'll happily stand corrected, but please share sources.

        Addenda:

        - Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...

        - Paper breaking the hash: https://arxiv.org/abs/2111.06628

        Edit: The second one is the wrong paper. I’ll find and link the correct one tomorrow. Keeping the link for transparency.

        • comex 1 day ago
          The paper you linked doesn’t reveal blurred versions of the images being hashed. It does train a classifier to determine which of 1,000 ImageNet classes an image belongs to, which “achieved a top-1 test accuracy of 4.34%”.
          • bayindirh 1 day ago
            Then, that’s the wrong paper. I’ll find it and link it as a reply to this comment. Probably tomorrow morning.
        • yogorenapan 1 day ago
          > to reveal blurred version of the images being hashed

          Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.

          So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.

          I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have

          • soulofmischief 1 day ago
            It starts at a broad understanding and ends with people permanently giving up their right and ability to keep rogue corporate governments in check.
        • duskwuff 18 hours ago
          There's actually been some work to reverse the original PhotoDNA hash, with much more precise results than for Apple's NeuralHash:

          https://www.hackerfactor.com/blog/index.php?archives/931-Pho...

          https://anishathalye.com/inverting-photodna/

        • esnard 9 hours ago
          Could this be the correct link?

          https://arxiv.org/abs/2412.06056

      • GeekyBear 1 day ago
        > I feel that Apple open pandora's box with the client-side scanning.

        That box has been open for years now.

        Big brother is already watching what you do on your Android device.

        > A Dad Took Photos of His Naked Toddler for the Doctor. Google Flagged Him as a Criminal.

        https://www.nytimes.com/2022/08/21/technology/google-surveil...

        • letmevoteplease 1 day ago
          This is not client side. Images just sitting on your Android phone are probably safe (although Google could push an update at any time). Your images get scanned when you back them up, send them over RCS, etc. I have even seen criminal cases originating from reverse image search - anything that touche the servers of the big tech companies, except apparently Apple, will be scanned using questionable AI and against a secret list to Protect the Children.
          • GeekyBear 1 day ago
            This is an image that he did not send off of his device to anyone except his doctor's office, yet Google reached into his private data and scanned it anyway.

            Google reported him to the police based on a single false positive.

            To add insult to injury, even after the police contacted Google to tell them that they had cleared him of wrongdoing, Google refused to restore access to his account.

            • izacus 1 day ago
              Stop making stuff up man, the image was uploaded to Google Photos servers.

              > The father uploaded photos of his son’s genitals, which were also backed up on his Google cloud, to the health care provider’s messaging system as requested.

              • GeekyBear 1 day ago
                Did he set up his device to upload his private data to Google, or did Google create an OS that automatically sent everyone's private data to their AI server for scanning without explicit consent?
                • izacus 23 hours ago
                  Google Photos does ask you for consent when you run it.

                  (It is, granted, a bit pushy about it and will ask multiple times when you run it with an intrusive dialog.)

                  • GeekyBear 23 hours ago
                    Informed consent would require Google to inform you that their AI server will scan every photo you take with your device and report you to the police if it should detect (or hallucinate) something it doesn't like.
                    • dghlsakjg 21 hours ago
                      On page 83 of subsection 14 of paragraph 3 of the consent document you agree to by using "google" as a verb, or by viewing any website they have a tracking pixel on there is a link to a policy which mentions that they retain the right to scan any and all of your photos for advertising targeting purposes, and further, if you read page 27 of the sub agreement mentioned in upside down white on white text in the main TOS they describe advertising purposes as: "Anything we want to do, in perpetuity, for any reason, and without any right of redress".

                      It's right there plain as day in the TOS. I don't know how people can use these products without understanding the contract they locked themselves into. /s

              • wildfireday2 1 day ago
                [dead]
          • inigyou 9 hours ago
            You shouldn't trust any Android phone not running GrapheneOS or similar.
        • xboxnolifes 22 hours ago
          I'm pretty sure this article if from after Apple introduced (floated the idea of?) client-side scanning. I'm not sure it really bolsters the idea that it's been open for years.
          • GeekyBear 17 hours ago
            You do know that we are discussing something that Apple talked about doing, but never did vs. something that Google has been doing for years?

            And no, this particular article about Google attempting to have innocent parents arrested was published before Apple even discussed scanning images users manually uploaded to their publicly accessible web album on iCloud.

        • trvz 1 day ago
          Google is not Apple. Apple customers expect the higher standard.
          • brokenmachine 15 hours ago
            Well, there's a lot of things you can expect from Apple customers.
      • inigyou 9 hours ago
        Engineers tend to be too people-pleasing. When someone from management asks "can you scan devices for CSAM without violating privacy?" the answer should not be "hmm... well... maybe if we did it this way it could work". The answer you should give us "no" or to hedge your bets "I don't think so". Same to the government and the court. In particular a court isn't asking for a statement of objective reality whether it's possible, they're asking whether you think you could do it.
        • notnullorvoid 5 hours ago
          People pleasing is a component for some, some also like the technical challenge. The biggest factor though is that as a software engineer "No" is basically never an accepted answer (even from management with an engineering background). They'll either counter with "we need to do X, so find a way", or they'll move along the line to the next person until they get an answer they were looking for.

          Edit: There are some rare competent managers who will stop the enquiry before even asking the engineers.

      • trollbridge 1 day ago
        I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help.

        Very different than trying to narc out users to the authorities.

        • Zak 1 day ago
          There were two different technologies. One was client-side scanning for known CSAM, which created a huge backlash and is described here: https://educatedguesswork.org/posts/apple-csam-intro/

          The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069

          • tzs 21 hours ago
            > The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial [...]

            That's a new version. The one that as announced the same time as client side scanning to block uploading CSAM to iCloud worked like this.

            1. It could be enabled on a child's device by the parents. It was not on be default.

            2. If the child received a sexual image (not necessarily just CSAM...if an adult sends a dick pic to a child that is not CSAM but would have been flagged) the image is blocked, the child is notified, told their parents are worried the image may harm them, and asked if they still want to see it.

            3. If the child says no, they do not want to see it, that is the end of the matter.

            4. If the child says that they do want to see it and they are at least 13 they are shown the image and that is the end of the matter.

            5. If the child says that they do want to see it and they are under 13, they are again told that they parents are concerned, and that if they view it their parents will be notified, and asked if they still want to view it.

            6. If they say no that is the end of the matter.

            7. If they say yes they see it but the parents also are notified and will be able to see it.

            This should have been pretty uncontroversial, but there were objections on the grounds that if someone say sends their dick pic to your under 13 child and the child goes all the way through to step 7 and decides to view it, that is a violation of the sender's privacy because that message was only intended for the child.

            • duskwuff 18 hours ago
              One of the more recent changes is that anyone can now enable a version of this functionality, even if they aren't set up with a child account. (It's under Settings > Messages > Sensitive Content Warning.) In this mode, it behaves similarly to the over-13 mode described above; no one is notified, whether the user chooses to view the image or not.

              This mode is probably best understood as "if someone texts me a dick pic, please blur it". I don't think there's any reasonable objection to this.

            • Zak 20 hours ago
              I have a hard time imagining any significant number of people objecting based on the sender's privacy. An adult sending explicit images to a child is a crime in most jurisdictions. A child doing it with a recipient under 13 is a concerning behavior the parents need to address.

              Notifying the parents even requires that the child acknowledge that's what's going to happen.

              • fwip 18 hours ago
                Presumably they were worried about misclassified images, or images sent by other kids.
                • themaninthedark 13 hours ago
                  The above proposed system could get ugly...

                  Family A enables system.

                  Kid B sends dick pic to Kid A.

                  Kid A decides to view it, Apple notifies and makes it viewable to Parents A.

                  Parents A are now guilty of possessing CSAM. (Distributed by Apple for extra fun)

          • EmbarrassedHelp 23 hours ago
            The controversial part is having the system enabled by default with age verification required to turn it off, and having the system impact non-Apple/Google apps. The UK for example wants Apple and Google to forcibly enable nudity blocking on all devices in the UK, and they want the system to bypass app/DRM security to scan all content visible on a device.
          • simondotau 19 hours ago
            While I didn’t agree with Apple’s approach, there is a subtle but IMHO critical nuance that is often forgotten about the client side scanning. It was only generating fingerprint material which Apple could decrypt and scan, alongside original images sent E2E encrypted to Apple servers. If the image wasn’t sent to Apple, the fingerprint wasn’t either.

            And the reporting was still gated through Apple employees; there was no mechanism for the government to expand the scope without Apple’s knowledge.

            I understand that people don’t like the idea of their personal hardware being complicit in treachery, but when considered from a purely functional perspective, apple’s proposal was no different to what Google and others were already doing.

        • pavon 1 day ago
          That is what they actually deployed. They were planning on performing client-side scanning of all images uploaded to iCloud for CSAM and reporting it to the authorities, but backpedaled after public push-back.
        • michaelmrose 1 day ago
          The original proposal was to use a visual hash designed to identify known bad CSAM images even if cropped or otherwise edited. Your computer would scan all your stuff for these images and report you to apple who would report you to the cops. This presented a number of issues.

          Accidental false positives could lead to horrific outcomes up to and including oh look bob got shot by the cops for resisting.

          It was possible to produce apparently matching innocuous images and then poison people's machines with them.Oops did you click on that picture of a tree have fun with the cops. Like an advanced form of swatting.

          Although inspired by a desire to find CSAM Apple could be forced to scan for ANYTHING by repressive regimes including America and China.

          Although initially targeting images client side scanning of messages is a pretty obvious next step. Again obvious good motivation exists and is completely justifiable who doesn't want to stop the next mass shooting or terrorist attack... and then we can basically use it to find people critical of the regime. Do remember we are presently prosecuting a political figure for a picture of sea shells and a guy in texas is rotting in prison for distributing political literature.

          • soundnote 20 hours ago
            > Apple could be forced to scan for ANYTHING by repressive regimes including America and China.

            Including Europe. Europe is ruled by people who think 1984 was an instruction manual.

            • psd1 10 hours ago
              Europe is a fractal mix of polities ruled by a constant flux of elected representatives, and consequently exhibits political behaviour from a wide range of constituencies. Each citizen agrees, presumably, with some policies and disagrees with others, then they vote as best as they are able - which is not very, since every large electorate in the world falls short of adequate political competence. Some of those people vote for authoritarians, which i consider a shame but which is also true in your closest democratic nation.

              European citizen surveillance is something i oppose, but at least it's balanced by a robust bill of human rights. America's surveillance state does not have that balance, because America wrote a bill of rights but didn't bother with the follow-through.

              Kindly don't use my continent as a punching bag, thanks.

      • ribosometronome 1 day ago
        The Pandora's box was already open and essentially no one noticed nor was there immense pushback that resulted in the features being removed. Photo scanning was already happening for both Android and Apple for the purpose of image search.
      • winningChild 1 day ago
        [dead]
      • FireBeyond 1 day ago
        I still also totally don't get their policy.

        Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines:

        "Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

        • xphos 1 day ago
          Imagine you have pictures of someones baptism and the kid was nude. Is it CSAM? I think the program would have to say use but morally I'd say no. The issue with client scanning is it has to assume the worst, or they are than liable. If its the person has 20+ different baptism of nude babys well huh that actually might be CSAM because the context of how that concentrated photos implies but even than its hard what if that person actually has 20 God Children its less crazy than one thinks... Especially if they have multiply phones from a single baptism.

          You might not like pictures that way but honestly I think more important in procescuting CSAM is to go after the large sources of CSAM generation. Its trafficing in East Asia, and in Europe. I think weirdly America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures. Abuse definitely happens in the US but making policy decisions like this produces bad policy.

          Does iCloud rehost the photos to other people I don't really know because I use andriod tbh. If they are being rehosted (I assume to members of your contacts) that can be problematic but I think honestly the issue a lot more complex than just protect the children which the source of critic is a lot attacks against apples are coming from

          • nylonstrung 1 day ago
            > America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures

            The US has the largest pornography industry in the world by a massive margin, and the largest consumption of online pornography per capita

            Meanwhile should we be surprised that CSAM production is higher in countries like the Philippines that have very weak digital policing, abject poverty, high numbers of street children etc?

            • dgellow 1 day ago
              The US is pretty extreme, you have at the same time easy access to all the pornography you want (unless you’re in states that require age verification), and also a very prude culture. It’s not the only place with such contradictions though
              • RajT88 23 hours ago
                Texas is particularly wild to me as a midwesterner. All the bibles and megachurches and all that and... They have strip clubs freaking everywhere! Really weird zoning laws as well - I recall seeing a strip club across the street from an Office Depot, next to a deli. The suburbs where I live, you have to go to a seedy part of town so you feel good and ashamed about it. lol

                Some TV shows rightfully take aim at this contradiction (recently: The Hunting Wives).

                • brokenmachine 15 hours ago
                  My uninformed guess as a non-murican would be that it's just zoned as a business.

                  I doubt there would be a special zoning category exclusively for strip clubs.

                • dgellow 20 hours ago
                  That’s hilarious!
            • mothballed 1 day ago
              The age of consent in the PI was like 14 until a couple years ago when they changed it to roughly match international norms, in their culture it was considered consensual rather than abuse until very recently.
              • FireBeyond 22 hours ago
                You can get married with parental or a judge consent at any age in Mississippi, New Mexico, and Oklahoma.

                You can get married at 15 in Hawaii and Kansas.

                You are "grandfathered" into sexual consent (not as in "marital rape" but "no longer statutory rape") when you do so.

                So we may not want to be lording it too much on "international norms", particularly given that most of the marriages that happen at those ages are not "young couple got pregnant" but "older man in conservative/religious community".

          • d1sxeyes 1 day ago
            The proposed mechanism was hash matching against known CSAM images, so the baptism photos would not trip the filter because they wouldn’t be hash matches.
            • wildfireday2 1 day ago
              But AI algorithms actually deployed by other cloud services do not. You’d hope that they wouldn’t flag a baptism or bris photo but currently fielded systems are flagging doctor-patient medical photos and have ruined lives, so.
          • dgellow 1 day ago
            > Imagine you have pictures of someones baptism and the kid was nude. Is it CSAM?

            In some countries it is as far as I’m aware

        • fortran77 1 day ago
          The practical problem is, without a threshold, they'd have an order of magnitude more false positives than 'real' detections, making the system useless.
      • mmmlinux 1 day ago
        Is it different than telling your therapist something in confidence and then finding police waiting for you in the lobby.
        • arcticbull 1 day ago
          Yes, in the sense that you have a legal doctor-patient privilege that binds what they can share with whom. There's not really an Apple cloud user privilege.

          No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

          • AlexandrB 1 day ago
            A better analogy is a storage locker. AFAIK police need a warrant to search "your" storage locker even though it's on someone else's property. I don't see why data in the cloud should be any different. Pre-emptively scanning everyone's data is equivalent to officers rummaging through all the storage lockers in a facility "just in case" they find something illegal.
            • d1sxeyes 1 day ago
              It’s a bit more like requiring you to submit to a weapons pat down before you go to your locker I think.
          • busterarm 1 day ago
            > No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

            And therapists are legally mandated to report you if you told them you viewed or possessed CSAM.

            • Dylan16807 1 day ago
              No matter how or why? That seems like a terrible mandate.
              • mothballed 1 day ago
                They are mandated to report child abuse. It is the same story with doctors, if an abusive parent brings in a child for care they learn never to give the kid healthcare again after the doctor reports it. It is rooted in good intentions but the effect is it means abused children never get to see doctors, therapists, get a half-ass minimal homeschool instead of going to school, etc so that mandated reporters never enter the picture.
                • Dylan16807 1 day ago
                  Reporting abuse the client was involved in has a compelling reason. That's different from hearing their client saw a picture of the abuse of a total stranger.
                  • RajT88 23 hours ago
                    > That's different from hearing their client saw a picture of the abuse of a total stranger.

                    I get it, actually. It's totally possible the picture in question was not known to authorities prior. That's called due diligence to look into it.

                    Adults not looking into things or following up on things are how the system fails children if you read some accounts of people who were abused by their guardians. Horrifying stuff.

                    • Dylan16807 22 hours ago
                      It could theoretically help to flag those images. But that kind of submission should be anonymous. It shouldn't ruin the ability for someone to get therapy.

                      Mandatory reporting makes sense for situations you are connected to. And even then there's presumably good reasons not everyone is a mandatory reporter. This goes way beyond that, mandatory reporting once removed for someone that doesn't know a single person involved.

                      Hell, reporting someone for that doesn't even guarantee the images get looked into! If they didn't save history they're probably not feeling like going back to the site to demonstrate. Similar if it was sent against their will and they deleted it right away.

              • busterarm 1 day ago
                > No matter how or why? That seems like a terrible mandate.

                Honestly shocked that anyone would even say this, but even giving you the benefit of the doubt here -- the one case where I could imagine this might not happen would be if you're a police officer investigating such cases. But they also have their own therapists dedicated/trained in police-specific issues.

                • Dylan16807 1 day ago
                  Even if someone went browsing for it, yes that's illegal but there's no benefit in their therapist reporting them for just visiting terrible websites.

                  But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.

                  • busterarm 1 day ago
                    I think you're demonstrating incredibly poor judgment here. CSAM is a crime with real victims. Even if your patient came across it innocently, someone is out there intentionally distributing it and that needs to be investigated.
                    • AnthonyMouse 1 day ago
                      Have you considered the implications of what you're saying?

                      A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something they've discovered is also used for CSAM.

                      You think it's a good thing for the therapist to be required to report this? Should they report that the patient admitted to viewing CSAM with no context so the whistleblower gets investigated and arrested, or should they provide the context -- that the patient is about to expose the corruption of the government receiving the report?

                      For that matter, consider what it does when someone is actually a pedophile. They find out that if they try to seek therapy to address their perverse attraction to kids, the therapist isn't allowed to keep their confidence and they'll be arrested, so instead of seeking professional help, they keep abusing kids. Is that the result we wanted? There is a reason doctor-patient confidentiality was a thing.

                      • mothballed 1 day ago
                        I used to have a good friend that was a stripper (I promise, I wasn't the client...). Some of her biggest customers were people that wanted therapy without the paper trail of going to a licensed therapist. This is a big thing for pilots as well, since their health records and mental care are intensely scrutinized. A stripper will provide comfort, verbal relief, and physical love for $100 hour you can tell them anything and their reputation is bad enough no one will bother to believe them if they say something bad about you.
                        • gausswho 1 day ago
                          Makes you wonder if there's a strip-joint where they're all licensed therapists, but non-practicing.
                      • busterarm 1 day ago
                        Well, in the jurisdictions that I care about the courts and lawmakers have already decided this and the legal requirement is to report.

                        If its your license to practice on the line you know what choice you're going to make.

                        • rootusrootus 23 hours ago
                          Therapy will become progressively more useless as people avoid it because therapists are required to report anything they hear which might be a crime.
            • freehorse 1 day ago
              That's not generally true. From [0]

              > Across most states, viewing CSEM alone is generally not a mandated-reporting trigger; reporting becomes obligatory when disclosures involve an identifiable child being abused or used to produce material.

              > California’s CANRA imposes a distinct duty to report electronic access (download/stream) with identifying patient information, upheld against privacy challenges based on compelling state interest.

              [0] https://www.psychiatrictimes.com/view/mandatory-reporting-ch...

    • mikenew 1 day ago
      Apple is on the side of privacy if it serves their marketing. Which is why they would rather build and normalize CLIENT SIDE CONTENT SCANNING so they can continue to market iCloud as "secure and private".

      If Apple's interests sometimes align with ours then great. I'll take it. But don't attribute to this ~5 trillion dollar company some kind of altruism.

    • SXX 1 day ago
      Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

      At least on Desktop we have usable Linux, but on the phones there is literally nothing usable because thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

      Yes its possible to make Andoid spy on you a little less, but even for tech savvy person its damn inconvinient and Google making platform worse with every single release.

      Thanks to Google "security" I can use my banking apps on 9 years old device with 6 years outdated firmware, but not on GrapheneOS.

      • Pfhortune 1 day ago
        > hanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

        I've been using GrapheneOS for years and that hasn't been my experience. There are two financial apps that don't work for me, and that's it. Pretty much everything else I use is fine. But, to be fair, I'm very scrupulous about my apps and tend to avoid installing an app for every little thing that wants me to.

        • inigyou 8 hours ago
          My experience is the same as yours. Even several financial apps work. And why shouldn't they? It's a safer OS to do finances than any other. Apps that blacklist Graphene are either data-stealing or just misguided.
        • handedness 17 hours ago
          My experience is the same as yours, and I run a huge number of apps for work purposes. A few have required disabling exploit protection but otherwise work fine.

          With only one brief exception, all of my financial institution's apps have worked fine, too, including some banks I see drive-by complaints about on here.

          Anyone curious should refer to the tracker: https://privsec.dev/posts/android/banking-applications-compa...

      • drnick1 1 day ago
        > thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

        Sometimes, all you need is a Web browser. I personally don't want any "apps" on my phone that aren't basic utilities.

        I am aware some banks in Europe require 2FA on a mobile device. Short of switching banks, my answer to that is a cheap or e-waste Googled Android phone that stays at home and serves that sole purpose.

        • SXX 1 day ago
          A lot of banks in UK and EU simply dont offer web access at all.
          • fsflover 1 day ago
            But you can switch to one that does.
            • nextos 1 day ago
              It's sadly becoming harder. I've been playing that game for quite long and hope to stick to web apps, but still.

              Some banks limit functionality on web apps, which is annoying.

              More importantly, many refuse to provide a decent 2FA other than push notifications inside the app or SMS, which is insecure and EU has mandated its phaseout.

              The thing that works for me is to pretend to be clueless and get an old hardware OTP generator, but those are susceptible to impersonation attacks on the bank side.

            • SXX 1 day ago
              Yes I can, but then I wont be able to use some of very convinient fintech services.

              I also need to maintain my own nextcloud, photo sync infrastructure and backups.

              Its inconvinient. This is exactly what I talking about.

      • anonymars 23 hours ago
        WhatsApp insists on having access to your contact list. Pro-privacy, it ain't. It's still a Meta product.
      • Cider9986 1 day ago
        > Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy.

        They probably use E2EE just so they don't have to respond to court orders and such.

        • cataphract 1 day ago
          Like when Google got tired of handling geofencing warrants.
          • inigyou 8 hours ago
            For the uninitiated: Google stopped hosting your location timeline on its servers just because it kept getting orders to search or reveal it.
    • selicos 1 hour ago
      Their level is set where it best feeds their revenue. Their security plays equally as well into their walled garden.
    • Sephr 22 hours ago
      Apple has degraded privacy online through Safari's cookie-preferential storage partitioning (i.e. site capabilities are penalized for using private localStorage instead of cookies), requiring sites to occasionally leak data over the network for multi-subdomain same-site web applications. These applications can privately share local state offline in Firefox and Chrome but usually serve the lowest common denominator, so many webapps use cookies to support Safari.

      They're pro-privacy when it serves them financially.

    • tjoff 10 hours ago
      To me it is crazy people go out of their way to defend apple in this area.

      They might be slightly better than some others (horray!) but given their ecosystem it is still the worst platform if you value any form of freedom. Depending on apple for your privacy is ignorance at best.

    • kevin_thibedeau 20 hours ago
      They aren't. They're on the side of making money and using backroom deals with the DOJ to avoid antitrust regulation. This is how a broken image hashing tool was surreptitiously installed on every iPhone.
    • cryo32 1 day ago
      Indeed.

      But they are until they are actually defeated. I would rather plan for failure. We are in a global climate where court rulings can be ignored.

    • daveisfera 23 hours ago
      I agree but sadly that's eroding. They're starting to let advertisers into the walled garden and it's becoming too big for them to ignore it. That will only get worse and then one day Uncle Sam will walk in with a big check and things will change.
    • LatencyKills 1 day ago
      I was an engineer at both MS and Apple. At Apple, privacy was baked into every new feature from the start. At MS, the privacy component was glued on at the very end, if ever.

      Like OP said, Apple isn't perfect nor will they ever be, but they do prioritize privacy better than most.

    • Isamu 1 day ago
      Privacy is a natural fit for Apple in that they make money on discrete devices, but services have grown tremendously. That’s where the erosion of privacy happens.

      So once there’s a profit motive for violating your privacy, the justification for eroding your privacy will proceed. It’s really the inertia of Apple starting out as privacy-compatible that makes them hesitant to throw that away.

    • an0malous 1 day ago
      I said this in another thread a while ago, and one of these people who thinks Apple isn’t on the side of privacy cited a lawsuit they settled around Siri listened to conversations: https://www.scientificamerican.com/article/apple-settles-cla...

      People understood this settlement to mean Apple was spying on their conversations and selling them to advertisers, when it seems to have more to do with people accidentally triggering Siri. But people don’t care about this kind of nuance or actually tallying up all the ways Apple is pro privacy against rare issues like this one. It’s all just tribalism at the end of the day.

      • bigyabai 23 hours ago
        This is also a misunderstanding of the case, though. The suit wasn't filed because of accidental Siri triggers, it was filed because Apple never informed users that third-party contractors would be listening to retained recordings of accidental invocations. From the original Guardian report:

        > Although Apple does not explicitly disclose it in its consumer-facing privacy documentation, a small proportion of Siri recordings are passed on to contractors working for the company around the world. https://www.theguardian.com/technology/2019/jul/26/apple-con...

        Regardless of how you feel towards Apple, this sort of data should be siloed in a way that makes it impossible to share with undisclosed third-parties. It also should not be shared anywhere until Apple can confirm that PII and other sensitive information was redacted from the data, which they did not. It generally points to a laissez-faire attitude towards personal data that is hard to abdicate without seeing the Siri server-side code or retention architecture, which is why Apple settled to avoid revealing the extent to which they retain and share data in a class-action discovery process. The settlement is a mea-culpa without admitting to wrongdoing or proving fundamental security.

        The lawsuit was entirely avoidable if Apple didn't play fast-and-loose with production databases. It'll be a black eye for anyone that points to Apple's whitepapers as an example of their commitment to security - some retention simply doesn't get documented by Apple.

    • amelius 1 day ago
      Apple may be on the side of privacy, but since they are competing everybody out of the market with their slick consumer products they actually form a threat to privacy since now the government has to only implement a backdoor at one vendor.
      • macintux 1 day ago
        I have a suspicion that Google and Android aren't going to just vanish.
    • Razengan 23 hours ago
      > It is crazy people think apple isnt on the side of privacy.

      Look up the "iCloud Keychain" API:

      For years Apple has let and helped Facebook, TikTok, Tinder etc. track users even after you delete an app, even ACROSS DEVICES and DEVICE RESETS.

      There's no way to even SEE what data the apps have stored on your device & iCloud account on iOS, only through the macOS Keychain Access app. Even then you can't be sure that that's all that being stored.

      They temporarily changed course and wiped iCloud Keychain data when deleting apps, but only during a single beta of iOS some years ago, and then reverted to the way it is now.

      This scores so many points in favor of privacy intruding corporations that it puts Apple far from being the paragon of privacy they pretend to parade as.

      • nozzlegear 19 hours ago
        It's misleading to claim that Apple has "let and helped Facebook, TikTok, Tinder etc. track users [...]" using the keychain API. The persistence you're talking about, which those companies exploit, is a side effect of how the API works, not an intentional surveillance feature. Furthermore, it's not some special API that those big companies made a deal with Apple to get access to – any iOS dev can use it.

        It's a real flaw that they should've fixed a long time ago, but your conspiratorial framing makes it seem like Apple colluded with Facebook et al. to end run their own privacy protections, while ignoring the fact that Apple's App Tracking Transparency feature has cost Facebook billions.

        • Razengan 6 hours ago
          1. How many years ago was the iCloud Keychain API introduced?

          2. Why in't there any UI in iOS yet to view and delete that data without using those apps, asking them nicely, and trusting them to do it?

          3. Why aren't users informed about apps storing data that will carry across app reinstalls, device reinstalls, and to all your other devices?

          • nozzlegear 5 hours ago
            1. Rhetorical?

            2. Why would there be? Apple building a UI for people to accidentally fuck up their apps sounds like the exact kind of thing Apple would never do on iOS.

            3. Users are already informed when an app wants to track them. Beyond that, having an app store data so that it carries across reinstalls and to all my other devices is what I would expect my apps to do. If I uninstall an app and reinstall it later, I want it to pick up where I left off, not with a blank slate.

    • fsflover 1 day ago
      Apple is on the side of privacy, except when you want privacy from Apple:

      Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)

      161 points by Logans_Run on Feb 14, 2025 | 69 comments

      https://news.ycombinator.com/item?id=43047952

      Apple silently uploads your passwords and keeps them (lapcatsoftware.com)

      170 points by ingve on Nov 1, 2024 | 127 comments

      And whenever your privacy contradicts their control over "your" device, you are also out of luck, e.g., you can't have Ublock Origin on an iPhone. Relevant discussion: https://news.ycombinator.com/item?id=44804921

      • dd8601fn 1 day ago
        It's telling that these come from people trying to implement tracking and high visibility into user behavior, and complaining that Apple won't let them even though Apple conceptually could.

        Except ublock, which can't do what it does the way it normally does, for the same reason you can't have any plugin inspecting realtime activity and doing scriptlet injection.

        You can have ad blocking. You can't have plugins with that kind of low level access to your browser activity.

        You can prefer something that allows dangerous behavior as a trade-off for greater capabilities, but you can't deny it's a safety trade-off where Apple picked what's safer.

        • inigyou 8 hours ago
          You need detailed access to block ads. Otherwise, ad vendors will hide in whatever access the adblocker doesn't have.
        • anon7000 1 day ago
          Yep, and if you want good Adblock on iPhone use Wipr.
    • goolz 1 day ago
      It is crazy that I do not trust a multi-trillion dollar company who has forced labor in their supply chain to have my best interests in mind? It is crazy to me you would think they do not understand the concept of lip service.

      These companies are liars. I do not trust liars. It has served me well.

      • tzs 20 hours ago
        You mean the company that does hundreds of assessments per year of companies all throughout the supply chain, including surprise spot checks, and forces those it catches violating labor standards to fix the problem and also provide remedies to the affected workers?

        Quite a lot of the labor issues in Apple's supply chain we found out because Apple found them and included them in their annual report on these and other supply chain issues.

    • KolibriFly 11 hours ago
      [dead]
    • drnick1 1 day ago
      > It is crazy people think apple isnt on the side of privacy.

      Apple is on the side of making money, and the privacy claims are mostly marketing. The entire stack is closed source, which means it is difficult and expensive to independently verify any of the claims made. What's more, the "auto update" universal backdoor means that Apple can forcibly push a user-hostile "feature" like client-side scanning when it wants or is compelled to by a state actor.

  • djoldman 1 day ago
    I am not a lawyer.

    There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example:

      * A: physical sexual abuse of children. B: possession or distribution of CSAM
      * A: drug trafficking or tax evasion. B: structured cash withdrawals
    
    The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A.

    It's my understanding that conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person: one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

    It's my understanding that one can be convicted of structured withdrawals that are not driven by, linked to, or in any way related to anything nefarious.

    • ux266478 1 day ago
      > one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

      This isn't necessarily the case in the US, though I believe only for drawings. AI-generated CSAM probably wouldn't fly in a court of law.

      Regardless, it's a naive conception of a system of law to think of it as a utilitarian system of restitution in contexts of "this individual harmed this individual". In fact, that would fall under the category of a "tort" rather than a "crime". The law is just as much about enforcing social mores and norms as it is about dealing with individuals harming each other. Hence why locales like Canada outlaw all forms CSAM, even fictional ones. The victim taken is to be society itself. The possession of this material, implicitly entailing enjoyment of it, is so gross a violation of society's norms and mores that it becomes elevated to a legal matter.

      • engeljohnb 1 day ago
        > The law is just as much about enforcing social mores and norms

        This shouldn't be the case in a society that supposedly values liberty.

        • Exoristos 1 day ago
          There is no _society_ without _social_ mores and norms.
          • engeljohnb 1 day ago
            I'm not denying they exist, I'm saying a society that values liberty shouldn't enforce them by law.
            • RIMR 21 hours ago
              This is an argument I find myself making depressingly frequently to people I thought knew better...
      • voxic11 1 day ago
        For drawings it has to additionally be "obscene" (since obscenity isn't protected by the first amendment). And there is also a specific law that criminalizes even non-obscene realistic computer generated imagery.
        • Manuel_D 1 day ago
          Not quite. There can be more restrictions on the distribution or promotion of obscene material, but mere possession of obscene material is protected by the first Amendment: https://en.wikipedia.org/wiki/Stanley_v._Georgia

          The reason why the Supreme Court upheld bans on possessing CSAM is not because it's obscene, but because it incentivizes abuse of children to produce it.

          • voxic11 1 day ago
            Stanley v. Georgia considered the question from the right to privacy side, not the first amendment. The relevant cases are https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit... and United States v. Williams https://en.wikipedia.org/wiki/PROTECT_Act_of_2003#Supreme_Co...
          • RIMR 21 hours ago
            This is an extremely important point to understand. At face value, it can feel like CSAM should be protected speech, however repulsive. There are no laws against gore videos, though one might argue that death is worse than SA. However, we have substantial empirical evidence that CSAM directly contributes to offending behavior.

            We also acknowledge that participating in pornography requires consent, and that the continued distribution of nonconsensual pornography constitutes a continuing crime against the unwilling subject. Because children have zero legal capacity to consent, CSAM is de facto illegal.

            It misses the point to think that CSAM is illegal because it is "obscene". It isn't illegal because it's disgusting; it's illegal because it's egregiously harmful to children. It's like thinking the bad thing a murderer did was make a mess.

            • rootusrootus 20 hours ago
              > It misses the point to think that CSAM is illegal because it is "obscene".

              Are you sure you're not the one missing the point here? You're replying to the tail end of branch of discussion about AI-generated imagery. Obscene is the only argument that works against it.

        • inigyou 8 hours ago
          How is obscenity defined? "I know it when I see it" i.e. "anything I think doesn't deserve first amendment protection"?
    • goalieca 1 day ago
      Our society is pretty aligned that distribution is another kind of harm. Non-consented distribution of sexual images (eg: revenge porn) is also a crime. Children don’t need to be the ones to press charges in child porn unlike with adults. That’s a good thing.
      • ux266478 1 day ago
        > Our society is pretty aligned that distribution is another kind of harm.

        As well as possession. I don't actually know if those are different for CSAM, but I would assume so because they are for drugs.

        • djoldman 1 day ago
          Meh, I assume "possession" (of drugs) is how the law is worded because otherwise law enforcement would have to catch someone in the act of using or distributing, which must be much harder to do.

          Mere possession of a substance is surely not what society cares about.

      • cataphract 1 day ago
        It surely is, but that doesn't change the fact that many cases are not about distribution and the harm is frequently more of a legal fiction, unless by harm you mean something other than suffering inflicted on the victims. I don't necessarily think it's wrong for society to ban certain acts on purely moral grounds (another example: incest between siblings), but let's not pretend it's something else going on.

        > Non-consented distribution of sexual images (eg: revenge porn) is also a crime.

        There is very compelling empirical evidence that this causes actual harm (suicide ideation in a very big fraction of the victims), even if it is fictional, so here there is no question about the harm.

    • pushcx 1 day ago
      No. In short, in US law, CSAM is a visual depiction of a real-world act of child sexual abuse. Visual depictions like you're describing are covered under a different law, and I'm not aware of it having a short name. There's a good expert thread on this with links to the relevant federal laws here: https://bsky.app/profile/rahaeli.bsky.social/post/3lbt7zkvlq...
      • djoldman 1 day ago
        Currently it is explicitly against the law[0]:

          (a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
            (1)
              (A)depicts a minor engaging in sexually explicit conduct; and
              (B)is obscene; or ...
          (b)...
          (c)Nonrequired Element of Offense.—
          It is not a required element of any offense under this section that the minor depicted actually exist.
        
        
        It is not a required element of any offense under this section that the minor depicted actually exist.

        [0]https://www.law.cornell.edu/uscode/text/18/1466A

        • bsimpson 1 day ago
          I wonder how you'd actually go about prosecuting that. What's the line between crass and illegal?

          People have infantilization fetishes - where they wear diapers and shit. You can certainly imagine someone making a cartoon of that in a sexual way.

          Adults often don't look their ages. John Mulaney famously had a set about resembling a child when he was 29.

          What if someone generated an image that looked like a teenager, but there was a driver's license in the frame that said the person was an adult?

          Real people have ages. Imaginary people are imaginary.

          What about art from the antiquity when what we would call a teenager would have been treated as an adult? Surely someone painted people having sex before "the age of consent" was a well-defined term. Is it illegal to own that painting?

        • inigyou 8 hours ago
          Apparently audio child porn is allowed huh?
    • joshred 1 day ago
      I don't think these are the same. Outlawing CSAM gives law enforcement the ability to shutdown markets and prevent commercial distribution of CSAM. Sexually abusing children is heinous, but sexually abusing children for financial gain is even worse.
      • carljungslabtek 1 day ago
        There are even people involved in commercial distribution of it that claim to not even be interested in children, just in profit or even allegedly “for a sense of community” (someone actually said this after getting caught, he was in his 20s but I can’t remember his name — he might have been one of the red room guys).

        On top of that, while there are different types of child abusers, the worst ones almost invariantly collect CSAM to the point of hoarding. So it really isn’t that bad of a proxy.

        The root comment is implying that legalizing or decriminalizing csam would somehow help with prosecution of child abuse? I’m kind of speechless. Csam IS child abuse. The fact that there are consumers encourages producers to, well, produce!

      • IncreasePosts 1 day ago
        There's also the argument that CSAM can act as a gateway leading people from just being a pedophile in their head, to going out and doing something to some child.
        • MichaelDickens 1 day ago
          Yes, this is an argument that exists. But it's not supported by evidence. It's the same as the old "video game violence should be outlawed because it might cause real violence", which is just as unsubstantiated.
          • ButlerianJihad 1 day ago
            Yeah, that old canard is ridiculous!

            I mean, if there were any truth to it, surely our nation would have seen an uptick, in the past 30–40 years, of new generations picking up guns and just mercilessly mowing down soft targets as if playing GTA.

            Thankfully, that is all confined to fantasy in cyberspace!

            • john_strinlai 23 hours ago
              gta is played all around the world yet only one country is an outlier in mass shootings.

              perhaps there is more to it?

            • Ardon 1 day ago
              Yeah, /your/ nation maybe. I wonder if there's any other reasons that could explain this, especially given the pretty uniform distribution of video games, and the extremely uneven distribution of violence.

              Oh, and everywhere in your nation? At the same time?

              Sorry, I think I have a button.

            • tancop 9 hours ago
              school shootings happen when lonely boys with mental health issues a) have access to guns and b) feel like society failed them and they need to take revenge.

              the first one is the reason why it happens it america more than any other place. other countries also have youth unemployment and social isolation but they show up as bullying in schools or votes for fascist parties instead of mass murder.

              the actual problem is people feeling hopeless, like theres no way they could ever be successful in this world so they want to burn it down. thats why some of them turn violent, when you feel like nothing you can do will make life better the only thing left is making it worse for those you think are responsible, like your classmates or gay/queer people or Jews.

              none of this comes down to video games, feminism, rap music, violent movies, atheism or other cultural "problems" conservatives always like to blame. its a social issue that needs social solutions.

              • cindyllm 8 hours ago
                [dead]
              • inigyou 8 hours ago
                > fascist parties

                you mean anyone who isn't 100% all-in on globalism?

            • ButlerianJihad 1 day ago
              https://youtu.be/g7tII_3WXqo?is=MagnO5GswnVJJltM

              Mother Shares How Video Games Radicalized Her Son to Run Around and Pick up Coins

        • pembrook 1 day ago
          Yes, it’s an argument but there’s zero data to support it, in fact the opposite.

          If this were true then widespread availability of pornography on the internet would have resulted in a massive increase in rape of adult females. When in fact, assault numbers have been on a steady decline for decades.

          • IncreasePosts 1 day ago
            Why would general pornography lead to rape? Most pornography is not rape pornography. Would people watching a bunch of rape pornography lead to more rapes? I don't know, but that seems more likely than general pornography leading to rapes.

            60% of respondents who were found looking for CSAM on the dark web stated that they were fearful that consuming CSAM would lead them to do something to a child in real life: https://doi.org/10.54501/jots.v1i2.29

            • pessimizer 1 day ago
              > Most pornography is not rape pornography.

              I'm not taking a position here, but the total amount of pornography is irrelevant to the argument. If the amount of rape pornography available has increased 500x as the total amount of pornography has increased 5000x, the proportion of pornography that was rape pornography has been reduced by 90%.

              > 60% of respondents who were found looking for CSAM on the dark web stated that they were fearful that consuming CSAM would lead them to do something to a child in real life

              Someone looking for child pornography is somebody looking for child pornography, so their opinion about what the search might lead to seems a bit worthless. There's no reason to assume that they have any insight into what will happen next, but we know for a fact what has already happened.

              That out of the way, though, and assuming that child pornography leads to child abuse, the good pro-pornography case that has been made is that when pornography is suppressed rather than regulated, the 95% of people who are exclusively interested in adult pornography will have to go through the same underground channels that child pornography flows through, thus having the perverse effect of exposing more people to child pornography (or at least obtaining access to it.) If exposure to child pornography causes child abuse, then the suppression of adult pornography would then lead to more child abuse.

            • pembrook 1 day ago
              Does it need to be said that by making all pornography easier to access the internet obviously makes rape pornography more prevalent and easier to access as well?

              Hence your theory should be easily visible in rape statistics, yet it’s the opposite.

              • IncreasePosts 1 day ago
                It would be easily visible or not visible in the rape statistics if the world had a single variable. In any case, even if the world was extremely simple, 'rape porn' could increase rapes, and we could still observe a decrease in rapes if 'general porn' decreased the odds of rape to a larger degree than rape porn increased them relative to the population that consumed each.
                • pembrook 1 day ago
                  Yes exactly my point...so it sounds like you're admitting this "availability of porn leading to action" theory isn't a very good one? And that in fact it leads to less action given it satisfies urges at much lower cost.
    • Manuel_D 1 day ago
      At least in the US, fictional content is legal even if it depicts minors sexually: https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit...

      There have been a handful of convictions based on fictional content, but usually the defendants also possessed real CSAM so there wasn't much point in contesting the charges over fictional images.

      • arijun 1 day ago
        Clicking on a page linked in your article, the PROTECT Act of 2003[1] (passed a year later), I see:

        > The PROTECT Act includes prohibitions against obscene illustrations depicting child pornography, including computer-generated illustrations, also known as virtual child pornography. Previous provisions outlawing virtual child pornography... had been ruled unconstitutional... The PROTECT ACT attached an obscenity requirement under the Miller test or the variant test noted above to overcome this limitation.

        Which, if I'm reading it right, means that GP was correct in saying "conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person"

        [1] https://en.wikipedia.org/wiki/PROTECT_Act_of_2003

        • Manuel_D 1 day ago
          But crucially:

          > However, the court did not reverse its holding in Ashcroft v. Free Speech Coalition as to virtual child pornography which is not obscene under the Miller standard

          • arijun 19 hours ago
            Unless I’m misunderstanding it wrong, any kind of porn would pass the first two prongs of the Miller test: it’s for purient purposes and it has depictions of sexual acts. As for the third prong, I’m sure some porn out there has literary merit, but I would guess the vast, vast majority would not.
          • Exoristos 1 day ago
            > virtual child pornography which is not obscene

            Does it surprise anyone else that this is a legal possibility?

            • rootusrootus 22 hours ago
              I get a little twitchy anytime we have laws based on something like obscenity, which is by definition a moral judgement.
            • inigyou 8 hours ago
              It isn't possible, it's a fig leaf to avoid the law being ruled unconstitutional, but doesn't change the law itself.
    • laughing_man 1 day ago
      It's even worse than that. If you make withdrawals with the intent of evading currency reporting requirements you've committed a crime even if the withdrawals don't constitute structuring.

      Also, in regard to the fictional CSAM depictions that stuff is still wending its way through the courts.

    • kimjune01 1 day ago
      a 17 year old can take a nude selfie and be charged as an adult in possession of CSAM
    • mannanj 1 day ago
      > CSAM (“see-sam”) refers to any visual content—photos, videos, livestreams, or AI-generated images—that shows a child being sexually abused or exploited. Child sexual abuse material (CSAM) is not “child pornography.” It’s evidence of child sexual abuse [1]

      I can't wrap my head around how AI-generated imagery is evidence of child sexual abuse (CAS). How are you abusing a real child by generating an image of a fake one?

      [1] https://rainn.org/get-the-facts-about-csam-child-sexual-abus...

      • ipython 22 hours ago
        what about an AI generated image using the real face of a minor? That can (I would argue will) cause real damage to the real child.
    • mannanj 1 day ago
      A: cyber crimes or other digital crimes. probably applies to many of the other crimes you mentioned too. B: privacy
    • kmeisthax 1 day ago
      I don't think there's a particular connection between indirect enforcement mechanisms and inability to detect the crime, though:

      - Structured transactions are illegal because we put a minimum on the amount of cash that has to move before government financial surveillance applies. The alternative (at least, one acceptable to the state) would be that the government knows every transaction you make[0] no matter the size. Since we don't want that, it has to be illegal to lie about the size of a transaction. Furthermore, the harder it is to get away with structuring your transactions, the more legible the financial system becomes and the easier it is to catch drug dealers.

      - Pedophiles have not stopped possessing or distributing CSAM to reduce their legal liability. Actually, this argument ignores the main reason why pedophiles store and trade CSAM around in the first place: it's specifically to scare victims into silence and revictimize those who tell the cops. In fact, this is why we stopped calling it "child porn" and started calling it "child sexual abuse material" - because it is specifically material designed to sexually abuse children by way of it's mere existence.

      If you're a "no touch" pedophile (they do exist!) that's still trading real CSAM around, well... Congratulations, Nobuhiro Watsuki, award-winning author of the hit samurai manga Rurouni Kenshin, you're still doing the dirty work for the full-contact pedo who recorded the damned thing.

      As for drawn child porn, involving fictional characters (i.e. not CSAM), it is legal in certain jurisdictions. Notably, America, where the 1st Amendment errs on the side of creative expression[1]; and Japan, the thinking man's Epstein Island, where... I actually don't know why the fuck Japan is so weirdly tolerant of all this sick lolicon trash. Hell, Watsuki didn't even get cancelled when it came out he had 100 DVDs worth of actual CSAM.

      There's an additional layer to this, though, in that for all the crimes you brought up, there's been a history of active state complicity in the crime:

      - The CIA is a drug trafficking gang that happens to moonlight as a government intelligence agency

      - A good chunk of elected officials and heads of state in multiple countries were compromised by notorious child trafficker Jeffrey Epstein

      - The government doesn't pay taxes. I mean, obviously, they're the ones levying them.

      We like to think of law enforcement as a cat-and-mouse game: criminals do a thing and law enforcement tries to hunt them down within the bounds of 4A/5A. The reality is more complicated. There are cases in which governments actively collaborate with organized crime, either because the government is corrupt as sin, or because the criminals are offering the state a way out.

      [0] Fun fact: if you use Bitcoin, you're automatically opting into this.

      [1] To be clear, while I agree with the American argument, you still shouldn't actually expose yourself to this kind of porn, because you're training yourself to get horny around kids. I shouldn't have to say this, but just because it's not illegal doesn't mean it's safe to use.

      • djoldman 23 hours ago
        > As for drawn child porn, involving fictional characters (i.e. not CSAM), it is legal in certain jurisdictions. Notably, America, where the 1st Amendment errs on the side of creative expression

        As I noted in another comment:

        Currently this is explicitly against the law[0]:

          (a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
            (1)
              (A)depicts a minor engaging in sexually explicit conduct; and
              (B)is obscene; or ...
          (b)...
          (c)Nonrequired Element of Offense.—
          It is not a required element of any offense under this section that the minor depicted actually exist.
        
        It is not a required element of any offense under this section that the minor depicted actually exist.

        [0]https://www.law.cornell.edu/uscode/text/18/1466A

    • phoghed 18 hours ago
      [flagged]
      • AnimalMuppet 18 hours ago
        This is probably across the line for being a "personal attack". Those are against site rules. Please don't do this here.
        • phoghed 8 hours ago
          Only if you view autistic people in a negative way. Otherwise it’s just a normal observation. To me it’s a hilarious comment, it’s gems like this that keep me coming back over the years.
  • majorchord 1 day ago
    IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.

    Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.

    • SepiaSapient 1 day ago
      Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere.

      Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOSSAD’ED UPON"[0]. This is specially good for me because I know the equivalent to the FBI where is live is too cheap to buy a Cellebrite [1] license.

      [0] https://www.usenix.org/system/files/1401_08-12_mickens.pdf [1] https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...

      EDIT: I suppose someone could ask about Meta. The reason behind their support for scanning (and removing e2e in facebook msg) is simply regulatory capture. The zucc wishes to have a letter of marque to "protect" your children and remove the "unsafe" competitors.

      EDIT2: Used the wrong term, I mixed up exfiltration channel with sidechannel attack.

      • johnsmith1840 1 day ago
        Side channel is academic at best.

        Watching memory changing on a complex code base without having said code base is near impossible.

        1. Run code 2. Watch memory changes 3. Correlate those to real data

        If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

        • SepiaSapient 1 day ago
          Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment.

          My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy.

          • johnsmith1840 21 hours ago
            Yeah Cletus and Chud aren't getting many secrets but I get the feeling Apple's incentives here are against this.

            What financial gain do they get from this?

            A: risk billions in stock value and customer purchases for basically a "thanks" from the gov? One whistleblower would also have the real ability of becoming world famous for "exposing" apple.

            B: Get publicity actually resisting the gov and not lying, what is the gov gonna do? I imagine it has and does happen but I also imagine there's a crying tim apple being dragged through it painfully.

            Unlike google I just don't see the financial positives for them to do it beyond massive arm twisting. For many companies the risk of destroying their entire value to customers is just not worth it.

            The only money in it is mass scale data collection for training data and ads, if they aren't doing that any other method is the opposite of valuable it's a massive liability.

      • majorchord 16 hours ago
        > sidestep any unpleasantness when they get a subpoena

        I'm curious as to how well (legally) this "we could modify the app to do it, but nah" approach actually works, and for how long.

    • kyralis 1 day ago
      This is based on a faulty understanding of the underlying systems. The risk with this sort of E2E encryption is not that the service provider pinky promises not to decrypt what they have, it's that they promise they will not insert a new key into your circle of trust to subsequently start decrypting things.
      • IshKebab 1 day ago
        I think you've imagined this faulty understanding. There are many mechanisms by which Apple could actually decrypt the data despite pinky promises not to. You listed one. There are others.
        • johnsmith1840 1 day ago
          You're suggesting they purposely put a backdoor into all their custom methods? Why?

          From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers.

          I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually contain ways to truly lock out the company itself from seeing your data.

          Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.

          • IshKebab 1 day ago
            > You're suggesting they purposely put a backdoor into all their custom methods? Why?

            I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could.

            And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would take a whistleblower to find out.

            > Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.

            I agree, it is the best option available. But Apple/Meta are technically lying when they say it's impossible for them to read your messages.

            • johnsmith1840 21 hours ago
              I disagree because these systems are amoungst the most abused in the world. The only way a backdoor realistically exists is if they have code that is prebuilt backdoor that they serve to inviduals upon request.

              As a company you'd be asking for an internal implosion of your company if everything had an additional backdoor in it.

              Any backdoor added is a backdoor the thousands to tens of thousands of advanced hackers are always actively trying to breach. So if they do it they'd be doing it very selectively via special served code.

              It's also the only way they'd stop whistle blowers.

              Now that I say it. That's 100% what they would do. But again it's a crazy high risk almost zero reward action for them. Is the CIA paying apple a bajillion dollars for phones? No so why unless their arm is twisted would they risk billions of dollars for basically no gain?

            • kyralis 22 hours ago
              They are not lying when they say that they cannot read your messages at rest or in transit without actively changing the code so that you start trusting a new key. The keys sync between devices in ways that Apple cannot read.

              This is not bulletproof, because they can potentially change the code to do this - this is what the FBI vs Apple thing was a few years ago was all about.

              • IshKebab 9 hours ago
                > ...without actively changing the code so that you start trusting a new key.

                Yes but the problem is there's nothing stopping them from doing that. If Apple/Meta rely on the argument that they technically cannot read people's messages then they will eventually lose because it's simply not true.

    • slashdave 1 day ago
      Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion).

      If the company is misleading, any encryption technology is irrelevant anyway.

      • majorchord 20 hours ago
        In the US at least, companies can and do receive secret demands from the government to add whatever kind of backdoor they want, and you're not allowed to disclose it in any way, they even order you to preserve any warrant canaries you have implemented.

        This is for example why Lavabit chose to go out of business instead of giving up their keys.

        • inigyou 8 hours ago
          Wasn't it found to be unconstitutional compelled speech?
      • dd8601fn 23 hours ago
        The company can provide secure enclave and allow the architecture to be audited by third parties.

        Which apple does.

        It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc).

        The headaches that come from e2e everything are too great for most people.

      • IshKebab 1 day ago
        Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you.

        That's obviously only the case if they aren't also the sole providers of the "ends".

        • johnsmith1840 1 day ago
          There are actual methods to do this though just not sure anyone does it yet.

          1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.

          Another way is to open source it and repeat 2/3/4

          The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.

          • slashdave 1 day ago
            I seem to recall that Apple provided an audit
          • IshKebab 1 day ago
            How would that work for closed source apps like iMessage and WhatsApp?
    • scosman 1 day ago
      > IMO "end-to-end encryption" simply isn't possible

      In a technical sense it's absolutely possible. Owning the servers != transferring keys to the servers. Most E2E apps run both client and servers, it's about if they ever had key access.

      • majorchord 20 hours ago
        Right... it's one thing to for example, use a third-party MEGA client to upload files so that there's no chance of the company ever being able to see your key (unlike random javascript they might inject into the web version).

        But when Apple etc. control both ends, their app could always see your data locally because it is the one that encrypts it to upload to the server in the first place. And these companies can receive secret orders from the US government to add backdoors into the local app and there's nothing you can do or say about it, except go out of business (like Lavabit).

    • megous 1 day ago
      There's no issue with mega. There are third party apps and as long as you don't login to mega.nz with their website you're fine. And they also have SDK you can use that they'll not be able to control/manipulate without your knowledge.
  • JSR_FDED 1 day ago
    The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections.

    As sad as this is, end to end encryption means no CSAM scanning.

    As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too.

    This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

    • 0cf8612b2e1e 1 day ago
      People can also distribute heinous things through snail mail, but we are not yet at the point where the government reads all letters looking for wrongthink.

      Just because we technically can make a privacy destroying drag net does not mean we should. Had phones existed 250 years ago, I have no doubt the founders would have thought it obvious that a cellphone’s contents were your personal papers which could not be freely searched.

      • timcambrant 1 day ago
        But that's mostly because it's impractical. They do use dogs to sniff for drugs and explosives, so if CSAM smelled or was visible through X-ray then it would probably be a different story. And let's not forget snail mail is by far a more uncommon way to spread that material than the Internet is. The Internet came into broad use just ~15 years after commercial CSAM was openly being sold by mail order in Europe.

        Personally, I am on the side of privacy, just to be clear.

        • projektfu 1 day ago
          If East Germany can, why can't we? /s
      • ajsnigrutin 1 day ago
        More effort should be done to find real-world equivalents of such actions and "think of the children".

        An icloud is like a storage locker or a safety deposit box... the owner should go through all your stuff there, just in case you have some CSAM!

        Metadata is just tracking info about who, where and with whom... every bartender should take your IDs and log when you came to the bar, who you sat with and how long you talked there.

        EU Chat control is like general eavesdropping... every time you sit down and talk with someone, an EU bureaucrat should sit next to you and listen and write down your conversations, just in case.

        etc.

        Somehow people think that "it's ok if it's on the internet", even when it's stuff they'd never accept in real life.

      • izacus 1 day ago
        Police can absolutely open snail mail with an appropriate warrant when investigating traffickers.
        • 0cf8612b2e1e 1 day ago
          With a signed warrant being the key differentiator vs invading privacy by default.
          • izacus 23 hours ago
            I agree, so let's make sure that signed warrant is always required for any kind of access to communications, even _if unencrypted_ like snail mail, SMS or plain text chat client. As well as encrypted.

            So - political solution, not a tech solution.

    • al_borland 1 day ago
      Children are often used as a weapon to erode freedoms, like privacy and speech. Those pushing it rarely actually care about the children.
      • layer8 1 day ago
        While I’m decidedly pro-encryption, I don’t like this argument. If something is the right thing, it would still be the right thing when promoted for the wrong reasons, and if it’s the wrong thing, it’s still the wrong thing even when at present nobody has ulterior motives.

        When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.

        • giancarlostoro 1 day ago
          > not on whether the current proponents happen to have ulterior motives.

          Even if the current proponents have no ulterior motive, and in fact live and die having done nothing negative with such power, it does not stop the next group in power from extending and abusing power, don't base laws on temporary trust of politicians.

          • tzs 20 hours ago
            This suffers from the "proves too much" problem. You are essentially arguing that government should only be given powers that cannot possibly ever be abused or be extended to where they can be abused. It is only an argument against government powers against CSAM because it is an argument against pretty much all government powers.

            Arguments that have any chance of persuading a government not to do something (and the public not to support the government in doing that thing) have to a lot more specific than that.

        • al_borland 1 day ago
          Calling out the ulterior motives can help clear the deck to focus on what is right or wrong, without as much emotional manipulation in the picture.
          • layer8 1 day ago
            One problem with that is that it’s difficult to prove motives. So you’re on shaky and disputable ground. It’s much better to point out how the proposed mechanisms are prone to be misused, which is independent of current motives. Get rid of the shaky ground. Saying “these are disingenuous people proposing this” is exactly an attempt at emotional manipulation, in the sense of an ad hominem fallacy.
        • ajsnigrutin 1 day ago
          So invading the privacy of millions of people, even if it's just automatic scans for some specific thing is a right thing? Does this apply to mandatory drug tests for everyone everywhere? How about drug and weapon seeking drones, doing daily checks in every apartment everywhere? How about mandatory AI powered microphones everywhere that would detect threats, blackmail, any talk about anything illegal, etc.?

          If you take a 1000 random people of the street now,how many of them are sharing CSAM via icloud?

          If you take a 1000 random politicians, how many of them have corruption scandals? Why not start with them instead, a bodycam and an AI powered microphone that would detect corruption automatically... let them lead as an example, before they apply the laws onto "the rest of us".

          • layer8 1 day ago
            You misread what I wrote. My comment is against the argument used, not against what is being argued for. Using the wrong argument diminishes one’s position. I’d prefer the stance against surveillance to not be diminished by such arguments.
      • owisd 1 day ago
        Feels like this has gone completely meta and it's now way more common to see people who don't care about children refusing to support that any proposal that might benefit children under the assumption that nobody cares about children so there must be an ulterior motive.
    • EmbarrassedHelp 23 hours ago
      The judge's comments are extremely disturbing, as she seems to want legislation passed that requires companies to violate user privacy.

      And client side scanning is just as bad as encryption backdoors. There's a good reason Apple was attacked for even considering it: https://arxiv.org/abs/2110.07450

    • SepiaSapient 1 day ago
      Truly being honest, I think CSAM scanning of private comms is ineffective in the long term anyways. Pedophiles aren't stupid, you'll drag a bunch at first but the networks will be reestablished and sharing will be done via sneakernet.

      The primary focus should always in preventing the creation of CSAM.

      - Comprehensive Sex Ed starting young so kids can identify grooming and seek help from a trusted adult, even if abuse comes from a family member.

      - Fixing schools in general so homeschooling isn't as attractive for parents. Keep a tab on home schooled children and identify social isolation.

      - Bigger resources for actual honest to god on the ground investigations.

      To be clear I'm not saying that homeschooling = child abuse, simply there's a lack of the mechanisms to detect it in homeschooling settings.

      • Zak 23 hours ago
        > Pedophiles aren't stupid

        I'm not entirely convinced that's true. Facebook is a leading reporter of CSAM, much of it sent through Messenger, which only recently got E2EE, and Instagram DM, which briefly had E2EE but no longer does. If I was going to transmit something that could get me in trouble, it certainly wouldn't be via Instagram DM.

        Facebook's EU CSAM report is here: https://transparency.meta.com/reports/regulatory-transparenc...

        • rootusrootus 22 hours ago
          Facebook could be catching 99% of those trafficking in CSAM, or 1%, and still be the leading reporter.
    • megous 1 day ago
      I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever.

      It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing.

      They could do it when people are not at home. There'd no problem, nobody would even notice.

      • slashdave 1 day ago
        Kind of a bad analogy (not service related, no associated liability).

        A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?

        • pantalaimon 1 day ago
          > Can the landlord randomly check for criminal behavior?

          Absolutely not.

        • inigyou 8 hours ago
          In Australia, they can.
      • kthinckley 1 day ago
        [flagged]
        • eagle2com 1 day ago
          It is drowning in sarcasm, so I would say yes, it is a joke.
        • theoreticalmal 1 day ago
          The comment above is illustrating why the judge’s decision would be silly in another circumstance. And if it’s silly in that circumstance, it’s silly in the judge’s circumstance as well.
        • Terr_ 1 day ago
          They are being sarcastic.
    • slashdave 1 day ago
      > end to end encryption means no CSAM scanning

      Not true. There is the option of scanning on the device.

      • EmbarrassedHelp 23 hours ago
        Circumventing encryption with client side scanning is on par with requiring encryption backdoors, and goes against the purpose of having end to end encryption.
        • slashdave 22 hours ago
          > on par with requiring encryption backdoors

          There is no back door if nothing leaves your device

          > goes against the purpose of having end to end encryption

          Most people would consider the "purpose" is to avoid 3rd parties listening in

          • eimrine 22 hours ago
            If nothing leaves the device so why to scan it at all? This is what proves your statement about compatibility of scanning and e2ee to be wrong.
      • yason 1 day ago
        Owning your device (instead of the manufacturer, a set of unlisted governments, big software corporations, etc.) means no scanning.
        • pantalaimon 1 day ago
          It also means no banking app will work
          • mothballed 1 day ago
            Banks are probably the most Orwellian surveillance apparatus of all. Almost every time I read an arrest warrant there is a whole section where banking records are used to damn someone. The equivalent level of banking privacy to graphene is roughly walking in to the teller to withdraw a few thousand cash once a month and then paying literally everything with that (or an anonymized crypto).
    • an0malous 1 day ago
      -
      • semiquaver 1 day ago
        The judge’s dicta about protecting children in her pro-privacy ruling upholding existing law “tips their hand” that they are somehow part of a global conspiracy to eliminate privacy?

        I think your conspiracy theory needs work, to be perfectly honest with you.

    • majorchord 1 day ago
      > As sad as this is, end to end encryption means no CSAM scanning.

      I think it depends on your definition of e2ee and where the "end"s are.

      If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?

      • cortesoft 1 day ago
        The locally running application is one of the 'ends' of the end to end encryption.
        • majorchord 1 day ago
          Then in that case I think the previous statement of "end to end encryption means no CSAM scanning" would be false.
  • jobs_throwaway 1 day ago
    A win for privacy and freedom
    • hosteur 1 day ago
      Indeed. And a rare one at that.
  • Schlagbohrer 5 hours ago
    I have to point out that the united states absolutely does not, under any context, care about the health and wellbeing of children. If they did they would have good, easy to access free healthcare and support for families including parental leave, as well as a good public school system that served every single child adequately.
  • KolibriFly 11 hours ago
    A court should not quietly create a general duty to inspect everyone's private files because a provider could theoretically detect illegal content
  • St0n3d 1 day ago
    “Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

    Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

    The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)

    • kyralis 1 day ago
      Also, Apple's E2E iCloud encryption vastly predated the NeuralHash efforts.
    • EmbarrassedHelp 23 hours ago
      A mandatory client side scanning system with an opaque database filled with unverifiable entries would render many of the protections provided by ADP meaningless. Its was insane that Apple was even considering such an idea in the first place.
  • ryanisnan 1 day ago
    As the creator of mediaden.ca[1] I’ve thought about this. Client side scanning is maybe marginally better than server side scanning, but both paths lead to privacy rot.

    Governments need to catch criminals, but they shouldn’t do it at everyone else’s expense.

    1. https://mediaden.ca

  • drnick1 1 day ago
    I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are created, for their own good, of course.
    • slashdave 1 day ago
      > most people don't need cloud backups

      What world do you live in?

      • drnick1 1 day ago
        The world where the operating system on my phone (GrapheneOS) isn't conspiring against me or uploading my files to someone else's computer.
        • kowbell 1 day ago
          Is your phone also made of indestructible materials so it can't break, and magnetically linked to your person so it can't be stolen? Backups exist so you don't lose precious photos/data if you lose the device. Most People™ do not have the technical knowledge to set up a self-owned backup system, and/or will not realize how badly their future selves will wish they had backups if the setup friction for a self-owned solution is too high to conveniently do it right this second.
          • mannanj 1 day ago
            I think we are closing that gap with AI coding tools.

            A growing number of people people today can figure out how to run Fable in a co work session, or codex, and that can indeed set up the self-owned backup system for you along with an alternative trustable cloud backup thats not Apple or Google.

            • jcgl 11 hours ago
              Technical people, maybe. Even if we hypothetically grant that vibe-coded backup systems can be trusted, deploying, using, and maintaining are still hurdles. And there’s absolutely no way that’s all tractable for the vast, vast majority of the population.

              Mind you, an average person probably doesn’t even really know what a server is. And these average people need backups just as much as (probably more than) people technical enough to vibe-and-deploy.

        • slashdave 1 day ago
          That must also be the world where more than a tiny number of people are using GrapheneOS
        • GuB-42 1 day ago
          But you still need backups right?

          For most people "the cloud" is where you backup stuff. If you have a personal backup strategy that doesn't involve the cloud, you are not "most people".

          Doing backups the right way take some skill and investment if you want to do it by yourself. It may involve setting up a NAS, and some discipline with physical media. You have to do your own security too. Most people don't want to do that, so, cloud backup it is.

          It is not a perfect solution, even beyond the privacy considerations, like you can still lose your data by losing your account, but from my personal experience, people lose their data less often now that they have cloud backups.

          • drnick1 1 day ago
            > But you still need backups right?

            I back up files to my own cloud with a Nextcloud integration for Android. That being said, a monthly or so backup of devices via USB/Ethernet, like we used to in the pre-cloud area, would be enough for all intents and purposes. It's not like what people have on their phones is generally very valuable.

            • BeetleB 22 hours ago
              > I back up files to my own cloud with a Nextcloud integration for Android.

              Ouch man. Don't do that. Nextcloud is fairly unreliable.

              > That being said, a monthly or so backup of devices via USB/Ethernet, like we used to in the pre-cloud area, would be enough for all intents and purposes.

              And/or use FolderSync to sync to your PC, and then use a proper E2E system to back up to the cloud.

            • tredre3 22 hours ago
              - People don't need cloud backups

              - People's files aren't valuable

              You're making a lot of claims that are so blatantly false from what I see on my side that I don't know what to make of it. Are you projecting your own needs onto "people"? Or am I the one who's disconnected, and people truly don't care about losing all their photos?

    • yoz-y 1 day ago
      Everybody needs cloud backups for their photos at least.

      Most people don’t have computers, those who do, do not regularly backup their photos on them.

      In both family and extended family many a cry would be avoided if people paid the 5 bucks it costs to backup their photos before your phone gets stolen or lost.

    • poolnoodle 1 day ago
      I gotta say handling my ever growing photo collection is a pain in the ass but I'm just not okay with uploading it to some server I don't control.
  • kristopolous 21 hours ago
    If you're going to be committing a crime, why would you store it in a cloud service?
    • pixl97 6 hours ago
      Because companies love turning things like this on by default.
    • Retr0id 18 hours ago
      Cloud storage is practically the default these days, and most users have no clue where their files are.
  • wbl 1 day ago
    IANAL but I thought the whole reason scanning worked was it wasn't required so there weren't fourth amendment issues.
  • quaddoggy 1 day ago
    Ah, the CSAM saga. Very poorly handled by Apple. Suspect it may have taken Hair Force One off the shortlist of CEO succession.
  • twuopf 1 day ago
    I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me

    The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen.

    The criminal and disgusting tail end of this type of material deserves the worst of consequences for the perpetrators and all the support in the world for the victims, but these are mostly - you guessed it - poor and unprivileged children from far away places and they certainly can’t put this much pressure on apple

    • kstrauser 1 day ago
      I think you’re right, but from another angle. In the state where I lived way back when, a state representative put forth a bill to explicitly make e-CSAM illegal. I guess it was already illegal for print media and this covered a gap in the law about cell phone pics, etc. Thing is, it had no allowance for the age of the picture taker, or even whether the picture taker was the photo subject. If a 16 year old girl took a nude selfie and sent it to her boyfriend, she was a felon.

      I wrote to the rep and explained my concerns. I wholeheartedly agreed with the intent of the law, but the code was buggy. To my surprise, he wrote back in horror to say he hadn’t considered that and pulled the bill immediately. I’m proud of having done that.

      I’m 100% pro yeeting child pornographers into the sun. I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.

      • r3trohack3r 19 hours ago
        > To my surprise, he wrote back in horror to say he hadn’t considered that and pulled the bill immediately. I’m proud of having done that.

        Stories like this give me hope - thank you for sharing

      • egorfine 8 hours ago
        > pulled the bill immediately

        This is weird indeed. These bills are mostly put forward in order to appear tough on crime and secure votes of the naive population ("think of the children"). Pulling the bill is detrimental as it may lead to "pedo supporter" conspiracy spreading among the district.

        • pixl97 6 hours ago
          Eh, it's kinda weird that we're against pedos here in the US, then we elect them.
      • fortran77 1 day ago
        > I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.

        The one messy corner of this is the "strict liability" for this type of material. An underage kid can take a nude photo, send it to an adult, and then the adult can criminally liable for just having it, even if he deleted it as soon as he saw it. Either both parties involved in handing something for which there is "strict liability' need to be held accountable, or "strict liability" has to be changed so a person isn't liable if he deletes or reports the material as soon as he first becomes aware of it. And this isn't likely to happen because it would provide a plausible defense for every one criminally charged.

        • rootusrootus 22 hours ago
          > has to be changed so a person isn't liable if he deletes or reports the material as soon as he first becomes aware of it

          AFAIK that's more or less how it works today as a practical matter. The law recognizes this situation as an affirmative defense, but does not make it impossible to be charged.

          To be an affirmative defense it has to be reported immediately or destroyed, constitute three images or less, and not be sent to anyone [other than law enforcement]. Interestingly, NCMEC doesn't necessarily count for that -- if you find yourself in this situation and you want to report something, call your local police.

          • fortran77 19 hours ago
            We shouldn't rely on selective, "practical" enforcement of the law though.
            • pixl97 6 hours ago
              Yep, especially when even an accusation of CSAM can be life ruining.
        • kstrauser 1 day ago
          IANAL, but the notion of "strict liability" horrified me when I first head of it, and I thought it had to be some kind of a misunderstanding. So we're tossing that "innocent until proven guilty" idea out the window, huh?

          I'm sure smarter people than me have sussed this out and can explain why it's a good thing, but it sits wrong with me. We can put the subject matter aside for a second: I don't think I could convict someone for having something happen to them, regardless of what the law says. Let's say drug possession was a strict liability law (and maybe it is for all I know). Finding a baggy of meth on the corner of a farmer's lot would mean that, technically, he was guilty of possession and had to prove that it wasn't really is. That's nuts. And looping back to the subject at hand, if the only evidence that someone possessed CSAM was their email inbox, without proof that it was solicited? They want me on their jury.

          There should never be a circumstance where someone can't report something that happened to them to the police without a legitimate fear of being arrested. That's bad for the person, and it's bad for society.

          But if their hard drive has folders grouped by age or something, prepare the solar catapult.

          • egorfine 8 hours ago
            > So we're tossing that "innocent until proven guilty" idea out the window, huh?

            We sure do. Legislators who pushed this "strict liability" thing forward were playing "tough on crime" for the audience of naive voters. Now anyone who tries to change this will commit political suicide and achieve the "pedo supporter" title.

    • aljgz 1 day ago
      Are there statistics backing up the "VAST" majority claim?

      While on statistics, I wonder, are there reliable statistics about child abuse of different types? Studying correlations with other social metrics, like sex education, liberal/conservative, policies regarding prostitution, and others can provide support for/against decisions.

      Not that I hope these will impact people's and governments' choices, but I want to challenge my intuitions.

      • mrkeen 1 day ago
        That's the fun of it. Try to find out? Straight to prison.
        • aljgz 1 day ago
          Really sad. I read a lot of psychology. But I've never encountered psychology of child sexual abuse (I know there is if I look it up, but that's my point, it should be shared around, discussed, challenged).

          Why would some adults find kids sexually attractive? Is it abusive/aggressive behavior manifesting itself in sexuality? Or is it sexuality channeled in the wrong direction? If it's the second, is it out of desperation, and would happen less if the culture makes it easier for them to satisfy their needs with adults, or would it happen regardless? On the victim's side, are the shy and less social ones more in danger, or the socially active ones? From my social scientist friends I hear a lot that most child sexual abuse is domestic. What are measures that a society can take to prevent these, without turning the society into a surveillance state, which will ultimately harm everyone more, including the children? What can be done to make sure children speak up, so that such behavior is dealt with at the beginning (and maybe while the more terrible things have not happened yet), and not turn into a multi-year childhood trauma?

          What are signs (and early signs) on the abuser's side and the child's side? How to deal with these signs?

          • ebbi 20 hours ago
            I can't reply with stats, but I sometimes get in a bit of a loop watching the 'pred vs catcher' videos on social media.

            After having watched what would probably be hundreds (across the US and UK), you start to see some patterns on offenders:

            - The ones that are obviously mentally ill/brain development issues - they're adults but act and talk like a child. With some of the interactions with this cohort, some/many don't even realise what they're doing is wrong.

            - The ones that seem ok from a developmental perspective, but are physically undesirable from societal norms and don't have a legal outlet - whether that's because of looks/weight/age/disabilities etc. This is where you see many old married men - probably not being fulfilled at home.

            - The ones that have a fetish for a type and will go to any lengths after not being able to fulfil this legally (this is where, I think, immigrants over-index: they have a fetish for 'white' women, and can't fulfil their desires legally, so try with the most vulnerable)

            - The ones that seem mentally and physically ok, but you can glean from their interactions that they are cold-blooded, ruthless, know what they're doing is wrong. These are the ones that take many calculated steps to cover their trails. When caught, they show barely any regret, and when they do, it's only regret because they were caught.

            Then obviously I think there's a class of them that don't come up on these sites, but we can get a glimpse of it from the likes of the Epstein files. The rich. The famous. The ones that think they can do whatever they want. How pervasive this is in society is anyone's guess, but it seems like there is a dark underworld for this class. A Netflix documentary comes to mind about two boys who were trafficked by their parents to wealthy elites in the UK.

            Obviously what differentiates all of these to people that may sit in one of those cohorts but don't resort to this despicable behavior is some underlying predisposition to predatory behavior.

            • aljgz 3 hours ago
              Thanks, as a software engineer, always a problem solver, who just follows an dreams of solutions to social problems (I've once led a software project for one of these, but not more), breaking down the mega category of abusers into subcategories with mechanics of their actions changes my mindset from useless anger into a problem solving one.
      • IshKebab 1 day ago
        It's probably impossible to get reliable statistics about that given how both groups are trying to keep everything secret. But you can consider how many paedophiles there are vs how many horny teenagers there are. Based on that it would be extremely surprising if he was wrong.

        The real question is what happens when a horny teenager sends another a nude. There definitely have been insane cases where they get stitched up for creating child porn. I don't know if that's the normal outcome today though.

    • Aurornis 1 day ago
      The proposed CSAM scanning used perceptual hashing to try to identify CSAM material known to law enforcement.

      It was not a tool to identify private images as being underage. That’s an impossible task.

      • cortesoft 1 day ago
        It's impossible to do with perfect accuracy, but that doesn't mean it isn't done.

        Just ask the dad who was investigated for taking pictures of his toddler for the doctor: https://www.koffellaw.com/blog/google-ai-technology-flags-da...

      • trollbridge 1 day ago
        I'd say modern AI tools could probably do this pretty effectively. They're very effective at describing anything else about an image. I have a workflow that churns through large amounts of images, describes them, and then looks for things I specifically want (in my case, auction listings that are not described accurately on the auction website).
        • philipkglass 1 day ago
          I need to process a modest amount of imagery (about 25 million images, and growing) for NSFW content and general captioning/description. About 5% of it contains nudity or partial nudity, and about 10% of that 5% contains sexual activity.

          In theory, modern vision language models could classify human nudity and sexual activity very thoroughly. But every model I have tried is reluctant to clearly describe what is notable about sexualized/nude images. The models are deliberately under-exposed to nude and sexualized content during training and further RLHF'd away from generating straightforward descriptions of such images.

          Models also occasionally hallucinate WTF captions for ordinary adult sexual activity. I recently ran a baseline test with frames extracted from adult videos and about 1/3000 frames was mis-captioned as involving a child according to Gemma 4 12b.

    • kccqzy 1 day ago
      I completely agree with you, but I do think that these teens do not have good opsec around these photos. It’s like the revenge porn problem but way worse. A teenager sending a nude selfie to a friend who then later shared these images non-consensually is a much bigger problem than if the same thing happened to adults.

      I don’t have any ideas for a solution, but I suspect that the heightened focus on CSAM is really compensating for the fact that we don’t have solutions for revenge porn.

      • __turbobrew__ 22 hours ago
        There is no good solution to revenge porn. It is impossible to enforce that only a single person has access to an image (physical or digital), and that the person doesn’t redistribute the image.

        The only way I can see this working is that people in explicit images need to publicly declare their intent for who can see the images (maybe a hash of the image content and the name of the person who can see that content) and then when the courts prosecute revenge porn the intent can be referenced to see if it was meant to be shared or not. There are still issues in that there is no proof that the person being accused of revenge porn actually distributed the images vs the defendant actually sending the images to other, or the image was leaked by a hack.

        I think the best thing we can do is try and educate teens on the dangers of revenge porn like we do on the consequences of having sex. We cannot stop teens from having sex or taking nudes, but we can at least try to educate them as best we can.

        • inigyou 8 hours ago
          Isn't the solution to revenge porn just arresting everyone caught doing revenge porn, same as it is now and with most crimes? The law doesn't work like a computer, it doesn't have to work 100% of the time.
    • majorchord 1 day ago
      Children cannot legally consent to most things in most places, especially until near the end of their teen years.
      • pixel_popping 1 day ago
        They can't consent but it does make sense that it's true, I would genuinely bet that more nudes are being shared between 17-year olds than some freak, as this is common to the point where I feel a very large portion of all existing teens have done it.
        • intrasight 1 day ago
          In the near future, when a 17 year old asks her phone to take a nude selfie, the phone will say "no".
          • pixel_popping 1 day ago
            It wouldn't be so bad tbh, would avoid all the leaks and regrets that comes with it. In term of awareness, I would say that a late teen is fully aware of his/her actions but might not calculate consequences properly.
            • inigyou 8 hours ago
              That lack of understanding of consequences is how we get a lot of bad and good things. Like Aaron Swartz downloading JSTOR (relevant today because of the Anthropic fine). He tried to make the world better, he wouldn't have done that if he knew what would happen.
    • alistairSH 1 day ago
      Do you have a citation for that? Sounds plausible, but I'm not sure I've ever seen it stated that way in any of the related media reports on CSAM efforts.
      • mschuster91 1 day ago
        In Germany, the rise in "youth porn" material has been attributed to such kinds of cases where youth send intimate pictures to each other [1].

        Our legal systems are not built to deal with that mess, and it may hang around your neck for the rest of your life. Unfortunately, the law is very explicit, leaving barely any avenue for the courts to drag us out of the mess, and politicians - even if they are actually interested in the topic in the first place - won't touch that area with a ten foot pole for fear of getting blamed a pedophile themselves.

        [1] https://www.n-tv.de/panorama/KI-treibt-Jugendporno-Fallzahle...

        • alistairSH 23 hours ago
          We absolutely have the same problem here in the US. There have been a few (small number) of cases that hit the national or regional news where teens were sharing nudes of classmates, etc.

          I'm questioning the parent post's contention that the "vast majority" of CSAM falls into this bucket.

    • abayedris 21 hours ago
      Just by casually glancing at KMP or VoL, you'd find that even the darknet pedo community itself strongly vilifies actual child abuse (known as "hurtcore"). There's truly no place for people who rape children. They are scum of the earth even in the eyes of the scum of the earth itself.
      • rationalist 20 hours ago
        > KMP or VoL

        I'm aftaid of putting those terms in my search engine, can you please expand those acronyms?

        • inigyou 8 hours ago
          They must be the names of darkweb child porn sites. Abbreviating the names is done so that people who are familiar with the site will know it, but people unfamiliar with the site will not gain any new information or be able to find it. The same is done with private torrent trackers and other piracy groups.
    • dfxm12 1 day ago
      I won't pretend to be so knowledgeable about how so much CSAM is being created, but keep in mind, there are laws against distribution & mere possession, too. Revenge porn is an obvious thing to be mindful of in this context in addition to other types of distribution. Consent to create doesn't imply consent to distribute (probably even to cloud storage) & is completely immaterial to issues of possession if it ends up in some 3rd party's hands. So the scope goes way wider than you're letting on. If you're saying all of these these laws are being abused, like they exist primarily to punish a state senator's daughter's ex-boyfriend, I would ask for something to back that up.

      Yes, poor and unprivileged children can't really defend themselves here, but this is the system working to find some legal mechanism to do what it can, as a more powerful force. Protecting people from exploitation is a good use of government. If this was shot down for legal reasons, OK, the system is working and I hope there is a way to expand protections that fits into our system.

  • m3kw9 1 day ago
    If these judges are so righteous, they should go further and mandate the OS to do mandatory scanning of personal hd.
    • stronglikedan 1 day ago
      It's still a shade of gray to me. If I offered some homegrown cloud storage to my friends, and one of them uploaded CSAM to it, you can bet your ass that I would be arrested for it.
      • polski-g 1 day ago
        Does Sundar get arrested if someone uploaded CSAM to GDrive?
        • rootusrootus 17 hours ago
          The law has exceptions for electronic service providers who report what they find on their storage. If you are operating a service for friends at no charge with no business plan you probably will have to work a bit harder to avail yourself of that exception. Might be best to charge a nominal fee and at least pretend to be doing it as a service provider.
        • izacus 1 day ago
          No, because Google will report it to the law enforcement.
    • dilap 1 day ago
      Don't worry, we'll get there soon enough.
  • unselect5917 12 hours ago
    A perfectly safe panopticon and freedom & privacy will always be at odds.

    Don't let a classic "think of the children" appeal to emotion short circuit your reasoning.

  • kmeisthax 1 day ago
    sigh

    Once again, someone (in this case, the judge of this case) asks if we can meet in the middle on whether or not private communications are actually private.

    To be clear: this is not a limitation of nerds' imagination. This is a limitation of physics. A person is either party to a communication (and thus can decrypt it) or is not (and thus cannot). If you demand Apple scan encrypted photos for CSAM, what you are demanding is that Apple be party to every communication done with an iPhone. There is no middle ground on encryption, there will never be a middle ground on encryption, and I will hold this truth on my deathbed.

    There is no "encrypted but crackable" - if the CIA can crack it at all, we're only a few years away from some kid's gaming rig doing the same thing. There is no "secure golden key" - if there was, you could buy it in the same section of Amazon that sells copies of the TSA master key that opens all luggage locks.

    Personally, the next time a government demands decryption keys, I think Apple should just set all iCloud photo libraries in that country to public and say "Sorry, your politicians made private photos illegal, take it up with them". Obviously, telegraph this far in advance and give users time to actually delete their cloud-hosted photos first. But definitely do not pretend like you can keep a secret with a government bureaucracy of hundreds of thousands of people.

    But then again, Apple also capitulated (good meaning) to the EU on third-party app distribution, so Apple has a lot less of a spine than they let on. At least Google actually stayed out of China.

  • i3ima 1 day ago
    the judge is indeed wise
  • crest 22 hours ago
    You wouldn't hold the postal service accountable for delivering CSAM or a bank for offering storing it a lock box would you? So why should cloud storage services be different? Stop clutching your pearls and welcoming big brother over imagined threats while a real rapist sits in the oval office!
  • VerifiedReports 18 hours ago
    Whatever "CSAM" is...
  • 1saadcodes 23 hours ago
    [dead]
  • Unified-Mentor 13 hours ago
    [dead]
  • economistbob 1 day ago
    Seems like the kids miss their chance at justice because of section 230 allowing platforms the freedom to remove whatever they want but not be responsible for what they keep or amplify. That is the problem with 230. Censorship is permitted and punishing the censor isn't. Twitter and Tiktok are literally microblog platforms that get away with removing good stuff and leaving evil because they "are not a publisher" while the algorithm literally publishes a chosen set of articles to people. Facebook can remove religious freedom material and leave human trafficking groups. Section 230 gives the publishers the cake and the edict too.
    • inigyou 8 hours ago
      Section 230 doesn't provide as much immunity as people think. A platform can still be liable for the choice to amplify something.
    • junon 1 day ago
      You're conflating "what's illegal" with "what a private entity doesn't want". I don't like it any more than you do, but the first is very clear, the second is a bit harder to "solve".