Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apple’s acquiescence to the Russian government’s demand to remove this app was predicted when it first came to light. Exactly at the same time as Apple was assuring world+dog that it would never acquiesce to governmental pressure to extend and expand the scope of its CSAM scanning tool on user’s devices.


Have they ever explained why the csam would be implemented? Apple bends just fine if the government is powerful enough and the marketplace is big enough, see China.


In their defence (I say this with some trepidation), if they want to see their products in another country, then they need to play by that countries rules. Regardless of how we in the west feel about those rules.

If a Chinese company came to the US or EU and ignored US or EU rules and lawful directives from government, we would quite rightly be up in arms about that.

With regards to CSAM, I think the same applies. After all the CSAM issue only exists because the US government has decided that invasive monitoring is the only way to counter CSAM.

I note that no other western country takes such an authoritarian approach to CSAM, an approach that seems to be primarily driving by evangelist Christian keen on outlawing sex in general. As oppose to actually helping victims of CSAM.


> In their defence (I say this with some trepidation), if they want to see their products in another country, then they need to play by that countries rules.

I understand your trepidation in saying it. That is simply a fact of reality as it stands and how businesses operate under the current incentives, not a value judgement.

However, it makes me think that liberal democracies should play hardball. The USA already has the Foreign Corrupt Practices Act [0] and the UK the Bribery Act 2010 [1], which hold their own businesses and citizens criminally liable for business-related corruption in a foreign country. Also, many countries apply universal jurisdiction for crimes such as child abuse [2].

Maybe liberal democracies should start applying a similar set of rules to businesses who are licenced to operate within their country, forbidding them from performing certain types of tasks (e.g. ideological censorship) for any government.

I am well aware of how incredibly complex a law of this kind would need to be, but let businesses choose – if they want to operate in the EU, USA, UK, etc. then they need to play by the no political repression rules worldwide. Would losing the markets of repressive regimes not be worth it? Well, they're free to move their headquarters to those countries and lose the liberal democratic market.

[0] https://en.wikipedia.org/wiki/Foreign_Corrupt_Practices_Act

[1] https://en.wikipedia.org/wiki/Bribery_Act_2010

[2] https://en.wikipedia.org/wiki/Universal_jurisdiction


I don't think liberal democracies care about these freedoms, other than as a rhetorical stick to hit countries that "illiberal" with. E.g. imprisonment of Julian Assange, removal of Trump from twitter, Atlantic Council as official part of FB content moderation team (w/ the probably-not-coincidental) subsequent removal of pro-Venezuela and far left groups.

(Plus also IMO being banned from FB and Twitter are materially much more harmful to a political movement than being banned from an app store. EDIT: Maybe not, since per other comment it was being used to organize election results.)


Yes, I agree there is much hypocrisy amongst those in power regarding this issue, and liberal democracies as such do not "care" about freedoms.

But then, why do they have laws punishing corruption in a foreign country? And why do they care if one of their citizens travels to a foreign country and performs a sexual act which, while not technically a crime at the current location, would be a crime back home?

Whether the motivation of these rules is purely utilitarian ("We don't want our businesses to get good at corruption, in case they start bringing it back" or "It's easier to catch active paedophiles having this option"), honestly moral ("Corruption/sex tourism is a scourge for developing countries, we must do anything to stop it") or even cynically electoral ("Let's look tough on crime to win votes"), any of these three options could be applied to a law against collaboration with repressive regimes.

In particular, given the dependence of our economies on the likes of Alphabet, Apple, Facebook, etc. and the increased power of China, I think that the utilitarian motivation should be enough. We don't want businesses that are so entrenched in our day-to-day to be so cozy with repressive authoritarian regimes which may sooner than later start to apply their own requirements on how businesses should operate in other countries if they want to have access to their own lucrative market.


Interesting points.

If I were to hazard cynical guesses, I'd say anti-corruption drives are genuine, in that corruption hurts American business interests, and anti-sex-crimes stuff is convenient to intelligence services who use sexual transgressions as black mail (e.g. Alexander Acosta explaining why he cut a sweet-heart deal for Epstein: "I was told Epstein 'belonged to intelligence' and to leave it alone").


Democratic leaders will care about it if it earns them votes at the polls.

But I agree that the government's themselves don't give a rats arse about this stuff, as long as they can keep winning elections.


Following laws in countries that one is operating is expected.

However, following laws that contradict one’s marketing materials will lead to some understandable questions about those “values”.


I think avianlyric is suggesting Apple didn't have a choice, and that US gov is compelling them to add the CSAM features. Which seems likely to me.

† Really "CSAM", since there's no way to verify nor ensure it's only scanning for CSAM. What they are building is a prohibited content scanner, and what it will scan for is whatever governments would like it to scan for.


Well do you have a copy of Apple's marketing material from Russia saying that won't censor the app store if compelled to do so by the Russian government?

It not reasonable to hold Apple to pledges they've made to western customers, when talking about a service provided to non-western customers.

As much as we wish it wasn't true, the scope for providing privacy is substantially greater in the west than it is elsewhere.


> Well do you have a copy of Apple's marketing material from Russia saying that won't censor the app store if compelled to do so by the Russian government?

Создавая продукты Apple, мы прежде всего заботимся о том, чтобы защитить вашу личную информацию и предоставить вам контроль над ней. [0]

Which translates to:

When we create Apple products, our primary concern is to protect your data and give you control over it.

[0] https://www.apple.com/ru/privacy/


> It not reasonable to hold Apple to pledges they've made to western customers, when talking about a service provided to non-western customers.

I think it's reasonable: We hold people account across borders for serious violations (extraditions), so it's completely reasonable to hold a company accountable for its serious violations outside of the country that you're buying from.

No-one is forcing Apple to support those countries with oppressing citizens either.


> With regards to CSAM, I think the same applies. After all the CSAM issue only exists because the US government has decided that invasive monitoring is the only way to counter CSAM.

No it hasn't. There is no legislation that the government passed or enforces that says Apple must scan people's private data on their devices for CSAM. Apple decided to do that all on their own.


The specific approach isn't in law. But the requirement to scan photos stored in the cloud is.

On this specific point I think reasonable to believe that Apple want to E2E iCloud photos, and their stated approach to CSAM is how they'll achieve E2E iCloud photos, while remaining compliant with the requirement to scan for CSAM they might be hosting.

Now there's a very strong argument to be made that Apple have made an appalling trade-off here, prioritising E2E over not doing on device scanning. But it's a trade-off that's only happened due to the requirement for CSAM scanning.

An interesting approach Apple could take, is apply E2E iCloud photos in Europe, and continue with on server scanning (and no E2E) for the US.


> But the requirement to scan photos stored in the cloud is.

This is categorically false. The law is very clear. Known CSAM must be reported. There is no obligation to search for it. The law explicitly exempts service providers from having to search for anything in a paragraph aptly named “protection of privacy”.

The text of the law: https://www.law.cornell.edu/uscode/text/18/2258A


> On this specific point I think reasonable to believe that Apple want to E2E iCloud photos

Here's the thing: if they wanted this they should have said so, because until then I'm not going to make this assumption. I can only make decisions on information I have, not on wishful thinking.


But I read from that guy mike Hearn , the early Bitcoin dev that it's like a reverse search. They check the csam database and compare to what is in your files, sounds good at first, but, big concern is...what if governments start to add other, unrelated data to get rid of people who cause political friction and other undesired elements as per their government policies?


> what if governments start to add other, unrelated data to get rid of people who cause political friction and other undesired elements as per their government policies?

That's possibly the most inefficient way anyone can imagine. If they can control Apple, they can just tell them to search Mail.app and Photos.app. What you are proposing is a Rube Goldberg machine.

And I'm 99% certain various agencies are already reading all your emails, with or without Apple's help. They are not hiding that they are spying on Swedish citizens, with the help of our intelligence services. Pretty sure they spy on you as well.


> what if governments start to add other, unrelated data to get rid of people who cause political friction and other undesired elements as per their government policies?

This is exactly what's going to happen, especially in countries like Russia and China. Children are just the perfect political weapon to make people accept the system.


Of course Apple is going to play by the rules of the jurisdictions they want to sell their products in. That's why their reassurances that they would never bend to government pressure on their CSAM plans were so worthless.


everybody can use "i was only following orders" as defense in court


Try "I was only following the law". I seriously doubt any court would punish you for sincerely trying to follow the law to the best of your ability.

Russia is a sovereign nation, with the right to rule as they wish. If you're not happy with there way of life, then I would encourage you to contact your democratic representatives and tell them to either apply greater pressure to the Russian government to live up to our ideals, and follow our laws; and if that fails, declare war.


Presumably to protect children.

The cynic in me believes this was either or both of these:

---

- Marketing ploy. The new iMessages app allows for scanning of the sent and received pictures for nudity and notifies parents if parental controls are enabled.

This is supported by the very large order of iPhones apple made for this year, roughly 90 million iirc.

- Bending the definition of E2EE, that is, enabling them to bend to governments "without breaking" their privacy "stance". Meaning that it is entirely possible to scan for content provided the government targets without losing E2EE. Effectively creating a special class of back window, where one can take a peek without the ability to execute arbitrary code.

It should be noted that given that the model is fast and can run with minimal impact (thank god for accelerators on SOCs /s), it could in theory run in realtime as part of the display pipeline, further removing restrictions like requiring that the content is downloaded with the images and iCloud sync is enabled.

---

But all of that is pure speculation from a random netizen.


They say it is their responsibility, they don't want to be hosting and serving this content. They have mentioned it's their moral obligation, and they're just playing catch up to other providers.

The story that keeps getting mentioned is that Facebook reports about 55k images a day, Google reports about 1500/day, whereas Apple was reporting 250 a year.


You do understand that icloud is a private storage platform which is fundamentally different from Facebook/Instagram which are used for publicly sharing photos?


Okay? I don't work for Apple, and I'm not making any judgement or sharing my opinion, just answering the question that was asked in a way that I hope was objectively factual with little editorialising.

I will state though that Google Photos has in-servers CSAM detection, and Dropbox. You can have your own opinion about all of that.


Perhaps they don't want people to use their devices for child abuse? Radical idea I know.


If we’re engaging in straw-man arguments, why don’t they just force such detectors directly in safari? And in your camera feed? That should solve issue even faster, so why stop at half measures?


It's not a straw man to say that Apple is scanning for CSAM because they don't want CSAM. It may be naive or wrong, but it's not a "straw man".

The stated reason they do it this way is to protect privacy. Presumably a lot more people would complain if they scanned the camera feed.


Don't stop there! What about terrorists, drug dealers and the organized crime?! We need to stop those, too!


I bet if those crimes were proliferating at the rate that CSAM is, a lot of people would be pursuing more active counter measures


Is there data to show thay CSAM proliferating at a different rate than those crimes?


Well it's hard to say how much of the growth is growth in detection/reporting versus growth in underlying crime, but it's worth noting that each transmission of CSAM is considered a separate crime. I.e. even if actual sexual assault remains steady, the nature of the internet (virality and community creation) sort of pushes CSAM transmission upwards. The internet is designed to spread content that people want, CSAM is sadly just that.


What do you mean by CSAM proliferating? Do you have evidence already that CSAM's image database is being used in a much wider scope than Apple is claiming?


We are already trying to stop those, so that's some weird sarcasm. But scanning photos is not a very efficient way to stop drug dealers, they don't tend to take photos of their stash I think.



You’re not wrong, it could be as simple as that. What’s got some people up in arms isn’t that.

The police in America have proven repeatedly that they will ignore individual freedoms to look indiscriminately for people doing bad things.

Apple creates a tool that enables pattern matching without consent. But they promise they won’t use it for more than CSAM, and that only they will hold the keys.

Okay so imagine that your HOA enacts a rule they’re now allowed to review all of your purchases by comparing known hashes used by drug lords to determine if you are cooking meth in your basement. And if they find a match, without your knowledge, they will report you to the police who will have a defensible justification for a warrant to come enter your house and look for meth lab stuff. Sounds fine as long as you have nothing worth hiding right? Might as well let them just go through everyone’s house preemptively looking for meth labs and skip the hash checking right? Oh you don’t support that leap? Don’t worry, others do.


The police will only be involved after their scanner has found 30 matches and Apple’s reviewer has manually concluded that it actually is CSAM, so I don’t see how the police is really relevant?

If HOA means home owners association, I don’t see the connection. They can’t influence Apple either.


Its the thin end of the wedge argument, and the fact that your property 'the phone' is spying on you and reporting you to the police.


> * Apple’s reviewer has manually concluded that it actually is CSAM*

There is no manual review of the image by Apple employees. What is viewed is a derivative image, which is scaled down and blurred. It would be trivial for someone to use legal pornographic images and put it through a NeuralHash collision generator, which upon viewing the scaled down derivative image, would look like CSAM.


If that’s what you’re worried about, then if people have physical control over your phone they could just upload CSAM to your FB or Google photos from it.


I said nothing about physical control. WhatsApp and other apps automatically download images that are sent to them. Scammers and those who commit fraud or phishing attempts don't have physical access to their victims electronic, yet they're able to get victims to download and run malicious code all of the time.

There's also the fact that iOS exploits are so plentiful that they're cheaper than Android exploits.


Still, why not send actual CSAM then, so that they are actually caught? Getting them into review just causes them inconvenience. Remember, only the flagged images will be reviewed, and only they could ever be sent to law enforcement, so it wouldn't even reveal their private photos or anything like that.


> Still, why not send actual CSAM then, so that they are actually caught? Getting them into review just causes them inconvenience.

Because that requires possessing illegal images, while legal pornography that also happens to cause a hash collision with NeuralHash doesn't.

Again, no one at Apple is reviewing the source image. They're reviewing obfuscated derivative images, and then informing law enforcement if they suspect they're illegal images.

What law enforcement then does is get warrants for all of the accused's electronic devices and raids their home and workplace in order to collect evidence.

It's another version of SWATing. Sure, eventually the authorities might find out that the accused isn't actually a mass shooter or holding hostages, but by then the damage is already done.


Why would the police raid you based on blurry versions of completely legal images?

And are you really saying that the images Apple reviews are so blurry that they can’t review them? That seems like a very stupid system.

In any case, your scenario sounds pretty far fetched. Even if it actually works, I wouldn’t say it’s a major blocker.


> Why would the police raid you based on blurry versions of completely legal images?

Because they have a reasonable suspicion that they're illegal images, and it's quite literally job of the police to collect evidence to determine whether or not a suspect can be charged with a crime or not.

> And are you really saying that the images Apple reviews are so blurry that they can’t review them? That seems like a very stupid system.

Are you saying that Apple built a system that can detect CSAM, and then chose to build a system for distributing and viewing said illegal material, considering that the acts of distributing and viewing CSAM are both very, very illegal?

Again, it isn't Apple's job to determine what's CSAM or not, that's the job of the police and courts. Apple's obligation is to report what they believe could be CSAM to authorities, who will take the investigation from there.


>Are you saying that Apple built a system that can detect CSAM, and then chose to build a system for distributing and viewing said illegal material, considering that the acts of distributing and viewing CSAM are both very, very illegal?

I'm saying that I'm pretty sure they will not turn you in to the police for possession of child porn without being damn sure that's what it is. How do you think the other FAANGs do it? I have never heard of anyone falsely reported for CSAM by Facebook for example, have you? Why would it be different for Apple?

I really don't think you are being honest about this.


There's a world of difference between someone creating a NeuralHash collision and spamming people's iMessage with false positives and actually taking the device and uploading CSAM to the cloud.


Well yes, spamming your iMessages would be pointless.


They can insist that if they are in the phone rental business and the ownership of the phone on their balance sheet, not if they're in the phone sales business. If you sell a product, it's pretty much illegal to control what people can and can't do with it. They can still control usage of iCloud which is a service they're renting out.

Of course they don't care about CASM to switch their business model to do this legally... And their valuation will crash if their balance sheet expands so much and management would be fired.


Of course you can have terms of use for things you sell, I don't know why you would think otherwise.

In this case it IS linked to iCloud though, as you probably know. Images are only scanned on their way to iCloud, and they won't be scanned if you don't use iCloud.


I don't think anyone who is arguing against this capability, myself included, actually believes that it will only ever be used on photos destined for iCloud, especially if state authorities start pressuring Apple to start scanning everything.


That's because people don't understand how technology works.

They think this is some kind of new system that gives Apple new access to things. It's not. They access they have here is nothing compared to what they have always had.

They can and do scan all your messages and photos already, locally, for features such as photo classification and making reminders from emails.

Apple could spy on anything they want, without this system. And this system is an incredibly impractical way to spy on people.

It's also pretty obvious that they wouldn't tell us if they were planning to spy on us, they would just do it.

In short: I have no idea if Apple spies on us, but I can say for certain that they will not use this system for it.


Terms of use are totally different - they allow you to sue a person if they use it againt the terms, and your ability to sue based on them is going to be very limited. Putting in the TOE of a car: " you are not allowed to drive kids in it" will not be enforceable.

In this case the company retains direct control over your property, and changed what it does after you bought it and paid for it.


I really don’t understand why americans are so obsessed with “my property”. I guess it’s a cultural thing.


I am not american, and I dont understand this obsession of American companies making of retaining control of items they already don't down, because they sold them.

I think having these for-profit busybodies butting in how you can live your life is a great threat to invidividual liberty.


How does this threaten your liberty?


You know how posting nudes gets you banned from social media, or gets your google account banned and you loose access to all your files on Drive?

The same will happen with physical devices that you bought - a car, an electric bike, a smart coffee machine. Imagine a car detecting you are smoking dope, or taking an issue with your trip to the abortion clinic.

You think it's not gonna happen, its too absurd? I just had to sign a 42 page lisence agreement to ride a bike.


Nothing in the new Apple scanner relates to what you are talking about. There is a absolutely no limitation on storing and transmitting porn and other types of nude material, as long as it’s legal.

You can even store copyrighted porn, they won’t try and stop you.

If a car could detect if the driver was smoking dope that would be excellent. I don’t think you have the right to drive around blunted.


Are they stopping the pictures being taken? Because the actual cloud uploading isn't child abuse, it's 90% the taking and 10% the sharing with other human beings. (Which only applies to the small subset of casm which is child abuse, rather than the majority which is "sexy" selfies)


100% of the CSAM they scan for is child abuse.


Thank you for this. I had a number of HN users insinuate that I was wrong to warn that Apple could expand beyond CSAM scanning and begin scanning for other material. People seemed to take a very firm stance that no, that could never ever ever happen and I'm wrong to even suggest the possibility.

This incident is more than enough for me to remain concerned that that will happen.


More arguments that Apple will go further than CSAM were presented by Snowden: https://news.ycombinator.com/item?id=28309202.


#freeAppStores for everybody!


You are comparing ”apples” to oranges. App store apps are built by third parties whereas CSAM is Apple’s own code and design on OS level, applying on global level. App store apps have been under removal threat in every country for many years if they can be considered as illegal.


So, same for Apple then, which would be under a threat from a government if they do not submit to whatever CSAM requirements, regardless of “pinky swear” promises?


People should start realisizing that they don’t have much control over for their iPhones, never hard. User interfaces are just an illusion. Reversing their black box code is too much work in real time.

We have always had to trust Apple and their word on what they do. There isn’t evidence that they have broken the trust yet, so what gives reason for even more speculation than before?


This article is evidence that Apple has and is continuously willing to bend to demands in dictatorships... That's why people are talking about it here.

Heck, even in democracies it's willing to bend. It's been widely reported that the reason iCloud backups aren't encrypted is to make it easier for the FBI to surveil them, despite there being no American laws forbidding Apple from encrypting the backups.


> This article is evidence that Apple has and is continuously willing to bend to demands in dictatorships... That's why people are talking about it here.

But this has happened for years already with similar ways. What has changed to make this big news? They have blocked many apps in the U.S as well, but it seems to be fine when for the majority it is OK. For example idea of withdrawal of the TikTok was fine for the most, while it was only for political reasons. People pick sides when it is the most suitable for them.

> It's been widely reported that the reason iCloud backups aren't encrypted is to make it easier for the FBI to surveil them, despite there being no American laws forbidding Apple from encrypting the backups.

And yet, Apple made a way to make encrypting possible while avoiding liabilities, and people made their best to not allow that happen. Such an irony. (Looking at CSAM feature. People seems to still ignore the fact, that it changes from server-side encryption into partial E2EE + server side encryption, tooking a way powerful arguments from FBI to not enable encryption on backups)


I’m saying that Apple is going to do what is required by law, there is no speculation.

This is true for booting an app from App Store, because it was required by a government, or looking through your data on your iPhone, due to a requirement from a government.


Apple has to comply with local laws, regardless of who authored the code.


That's not entirely true. Apple is big enough that they can ignore, bend, or even change local laws when it suits them, especially as it pertains to their operations outside the U.S.

It makes one wonder who or what made this demand worth fulfilling for Apple, but it could just as easily be someone incompetent at Apple blindly fulfilling a takedown request from the Russian government because it's in their job description to follow such demands and they didn't realize that a simple app takedown request had significant geopolitical implications. Who knows. Either way, Apple has definitely strayed far from the vision of their 1984-themed commercial back in the day where they shattered big brother with a hammer...


Yes, but they are not forced to add new features, only to remove, which is kinda big difference.



> Apple struck a deal with the government that will show users a prompt when first configuring a device in Russia to pre-install apps from a list of government-approved software. Users will have the ability to decline the installation of certain apps.

Apps you can decline? And uninstall? We are talking about quite different things here. Not to mention every Android with pre-installed bloatware.


I mean, there's some big questions left out there. It says 'certain' apps. Is it all? Or just some?

If you do opt-out, does anybody get notified? Is it reasonable users are concerned somebody might get notified?

There's a lot going on there. And just to point out, this has moved on from saying Apple only removing features, to debating how bad the features they've added are.


It is very uncertain, who has added the word "certain", as quoted statement is just talking about offering:

> users will be offered a choice of applications from Russian developers, which they will be able to choose for further installation on their iPhone or iPad


They can be forced to do either.


The CSAM databases are not Apple's own either.


Apple uses databases from 2 or more child safety organisations.

Specifically to prevent governments from being able to include entries.


What stops governments from requiring that "this one list" is required to be used, regardless of other organisations? Certainly not "Apple TOS".


> Specifically to prevent governments from being able to include entries.

Yes, governments and their intelligence agencies famously don't work together and share information[1].

[1] https://en.wikipedia.org/wiki/Five_Eyes




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: