Apple publishes a CSAM FAQ to address misconceptions and concerns about photo scanning
Apple has responded to misconceptions and concerns about its photo scanning announcements by publishing a CSAM FAQ - answering frequently asked questions about the features. Source: Apple .
Context & Ripple Effects
Apple had already acknowledged internal concern about the feature, framing it as necessary for child protection in a memo responding to employee misunderstandings. The FAQ is Apple’s first sustained public effort to turn that internal rationale into a user-facing explanation.
The related coverage also identifies a limit to that response: the earlier FAQ left questions about potential government pressure unresolved. Later reporting shifts the issue from one document to an ongoing communications and assurance effort.
First-order effects
- Apple gives users and critics a formal reference point for concerns about its photo-scanning features, while retaining its child-safety rationale.
- The FAQ does not resolve the government-pressure concern identified in related coverage, keeping Apple’s safeguards—not merely its explanations—at the center of scrutiny.
Second-order effects
- Apple’s communications burden expands beyond the FAQ: staff were later warned to prepare for questions, and Apple said an independent auditor would review the system in its response to privacy concerns.
- The episode makes the rollout process part of the product debate; related analysis argues Apple pursued child-safety measures without enough outside expert input while tied to its iOS release schedule.
Third-order effects
- Privacy-sensitive platform features are likely to face a higher expectation of independent review and expert consultation before launch, rather than relying on post-announcement documentation to establish trust.
- If that expectation holds, Apple and other platform operators will have to treat governance and public explanation as release requirements for safety features that touch personal data.
The trend: Safety-focused platform features are increasingly judged on the credibility of their governance and rollout process, not only on their stated purpose.
Related: Apple · CSAM · Apple’s internal memo on photo-scanning concerns · Apple’s FAQ and government-pressure questions · Apple’s planned independent review
Related Coverage
- View article TechCrunch
- View article AppleInsider
- Facebook's Former Security Chief Discusses Controversy Around Apple's Planned Child Safety Features MacRumors
- Apple defends tech for detecting child abuse images amid privacy concerns Silicon Republic
- View article iMore
- Apple tries to clear the air over its CSAM photo-scanning child protection technology SiliconANGLE
- Apple Says It Won't Let the Government Turn Its Child Abuse Detection Tools Into a Surveillance Weapon Gizmodo
- Apple says it will refuse gov't demands to expand photo-scanning beyond CSAM Ars Technica
- Apple Publishes FAQ for Their New Child Safety Features (PDF) Daring Fireball
- Apple says it will not allow governments to use its CSAM detection system for other images, but assurance doesn't go far enough MediaNama
- Apple confirms existing iCloud Photos will be scanned for child abuse SlashGear
- Apple responds to outcry over controversial photo-scanning policy Trusted Reviews
- Apple Answers Some Important Privacy-Related Questions in New CSAM FAQ iPhone Hacks
- Apple's child safety moves stir praise and protests Axios
- Apple Publishes CSAM FAQ to Deal With Questions Surrounding Its Botched Launch Redmond Pie
- Apple issues new FAQ regarding photo scanning in its Expanded Protections for Children iDownloadBlog.com
- Apple Posts FAQ About its CSAM Scanning in iCloud Photos The Mac Observer
- Apple says it won't expand controversial CSAM technology Computerworld
- Apple confirms CSAM detection only applies to photos, defends its method against other solutions 9to5Mac
- Apple Responds to Privacy Concerns Regarding Child Abuse Detection Features WinBuzzer
Discussion
-
@alexmartin
Alexander Martin
on x
New: Apple has responded to concerns that its CSAM detection system could be used to detect things other than abuse images. Source, Page 5: https://www.apple.com/... cc @rossjanderson @sjmurdoch @pwnallthethings https://twitter.com/...
-
@jonathanmayer
Jonathan Mayer
on x
Apple's answer about government demands is difficult to reconcile with its litigation position against FBI & DOJ. Just 5 years ago, Apple swore in court filings that if it built a capability to access encrypted data, that capability would be used far beyond its original context. …
-
@josephfcox
Joseph Cox
on x
In a call today with Apple, we asked if China demanded Apple deploy its CSAM or a similar system to detect images other than CSAM (political, etc), would Apple pull out of that market? Apple speaker said that would be above their pay grade, and system not launching in China.
-
@josephfcox
Joseph Cox
on x
Also said system has things in place such as Apple having the inability to add hashes itself to the hash list, the sourcing of the hash list (NCMEC), Apple having one operating system globally and not per country.
-
@jasonaten
Jason Aten
on x
@stephenrobles @reckless @jcenters They've now made it explicit: “The system does not work for users who have iCloud Photos disabled. This feature does not work on your private iPhone photo library on the device.” https://www.apple.com/...
-
@stephenwarwick9
Stephen Warwick
on x
@reckless They did it just doesn't fit your narrative 😂
-
@reckless
Nilay Patel
on x
@StephenWarwick9 Where does that say local hashing is disabled?
-
@secparam
Ian Miers
on x
How would Apple not be able to add things to the hash list/ change which list they use? NMEC would need to publish some root hash of their list and Apple would have to bind it into their client software in a way even they couldn't change. Thats a tall order. https://twitter.com/.…
-
@joshbal4
Josh
on x
you know an announcement went well when you have to publish a 6 page follow-up pdf https://twitter.com/...
-
@stephenwarwick9
Stephen Warwick
on x
@reckless “This feature does not work on your private iPhone photo library on the device”, not carrying water, just basic reading comprehension 😂
-
@reckless
Nilay Patel
on x
@StephenWarwick9 The system comprises a local component and a cloud component. Disabling the cloud component does not require the local component to stop generating hashes. You don't _know_ this. Don't carry their water for them by guessing.
-
@snowden
Edward Snowden
on x
Apple's new iPhone contraband-scanning system is now a national security issue. They just openly admitted they have no answer for what to do when China comes knocking. Hard to understate how disastrous this new system is for iPhone security. Tim Cook needs to intervene. https://t…
-
@antoniogm
Antonio García Martínez
on x
Apple claims a one in a trillion failure rate. I'm dubious. No false positive rate is that low, and they have no way of accurately modeling the real-world rate across billions of users. Their match-thresholding scheme helps, but that too is a knob with a net false-positive rate. …
-
@arossp
Aaron Ross Powell
on x
Apple makes a ton of money selling to the Chinese market, and so it's more likely than not that they'll rationalize opening their CSAM surveillance system to Xi Jinping if he threatens kicking them out of China if they don't. https://twitter.com/...
-
@stephenwarwick9
Stephen Warwick
on x
@reckless If this needs to be explained more to the *checks notes* Editor in chief of The Verge I don't know what to tell you 😂😂😂
-
@stephenwarwick9
Stephen Warwick
on x
@reckless “The system does not work for users who have iCloud Photos disabled.” https://www.apple.com/...
-
@stephenwarwick9
Stephen Warwick
on x
@reckless The system = CSAM scanning including local hashing. Come on dude you're not even trying 😂 but as I said it doesn't fit your narrative so why would you
-
@riana_crypto
Riana Pfefferkorn
on x
Also if this is so privacy-protective and Apple's so proud of it, where's the letter from Tim Cook? Remember the open letter to Apple's customers he published at the outset of the Apple vs. FBI fight? https://www.apple.com/... Tim! Call me maybe!
-
@aral
Aral Balkan
on x
immediately and to issue a statement reaffirming their commitment to end-to-end encryption and to privacy as a fundamental human right. https://ar.al/... #apple #privacy #humanRights #personhood (2/2)
-
@reckless
Nilay Patel
on x
@StephenWarwick9 Who? Quote it.
-
@snowden
Edward Snowden
on x
The last time China stamped an inappropriate demand for access, @Apple sold out their users out. To quote them: “While we advocated against iCloud being subject to these laws, we were ultimately unsuccessful.” (LINK1: https://www.reuters.com/... LINK2: https://t.co/...) https://t…
-
@evacide
Eva
on x
@josephfcox So all that a government has to do is pressure/threaten/compromiseNCMEC instead of Apple? I do not feel better.
-
@malwarejake
Jake Williams
on x
Oh, is Apple deploying different versions of iOS in different countries now? Because otherwise, this statement seems a bit disingenuous... https://twitter.com/...
-
@malwarejake
Jake Williams
on x
First, I find it beyond belief that Apple lacks the technical capability to add hashes. But my bigger concern is NCMEC. They now hold the keys to one of the world's largest surveillance platforms. But I'm sure their security is top notch and they'll never be compromised, so... ht…
-
@ncweaver
Nicholas Weaver
on x
@josephfcox Someone needs to ask the same question of Microsoft with Windows Defender.
-
@ryu3824796630
@ryu3824796630
on x
@josephfcox Every iPhone user needs to do the uncomfortable thing and give up their iPhone and boycott Apple. I will.
-
@antoniogm
Antonio García Martínez
on x
The Apple system, complex as it is in the details, is well-designed and keeps user privacy top-of-mind. That said, the use of ‘perceptual hashing’ to do image matching raises the possibility of false positives, something with potentially dreadful consequences in CSAM policing. ht…
-
@riana_crypto
Riana Pfefferkorn
on x
AFAICT, some civil society folks got a briefing from Apple 1 day before Thursday's announcement, and that was it. They touted the 👍 they got from prominent cryptographers, so the lack of even the usual pat phrase “in consultation with stakeholders from civil society” stands out.
-
@riana_crypto
Riana Pfefferkorn
on x
It's clear that Apple didn't consult any civil society orgs. No civil liberties or human rights input. Privacy, freedom of expression, LGBTQI+ issues, orgs for homeless queer youth, none of it. If they had, they'd be touting that (even if they ignored everything the orgs said).
-
@nash076
@nash076
on x
The technology can be used for a wide range of scanning and cataloging beyond child abuse (including policing for copyright violations), but Apple pinky swears it would never do that. And as we all know, Apple always keeps its word. https://arstechnica.com/...
-
@jonathanmayer
Jonathan Mayer
on x
Apple's new FAQ on CSAM detection is disappointing. The document uses misleading phrasing to avoid explaining false positives. And the FAQ says little about how Apple will ensure the hashes are only CSAM and the same for all users. This is marketing. https://www.apple.com/...
-
@tim
Tim Bradshaw
on x
“Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government's request to expand it.” (2/2) One to keep for the record. https://www.apple.com/...
-
@dsilverman
Dwight Silverman
on x
Apple CSAM FAQ addresses misconceptions and concerns about photo scanning https://9to5mac.com/... via @benlovejoy
-
@tim
Tim Bradshaw
on x
Apple responds to “slippery-slope” privacy concerns over CSAM tool: “We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future...” (1/2)
-
@normative
Julian Sanchez
on x
As I said last week, IF you just look at the system in isolation, assume it's implemented exactly as intended & frozen in stone, maybe it's fine. But I don't think that's a terribly smart way to think about it.
-
@bergmayer
John Bergmayer
on x
This will be true if and only if iCloud Photos are fully encrypted, and right now, they are not. Apple has policies and systems in place to secure your iCloud images but it does still have the ability to see them if it wants to, or is ordered to https://twitter.com/...
-
@carnage4life
Dare Obasanjo
on x
One can assume there are tens to hundreds of millions of CSAM images in iCloud based on extrapolation of how much storage they've announced is used by the service (8M terabytes) and reporting rates from other services (e.g. FotoForensics says 0.056%). So they must do something.
-
@carnage4life
Dare Obasanjo
on x
The question from a privacy perspective is whether Apple keeping the “we won't look at your content on the server” promise by creating a precedent where “we look at content on your phone instead” is better or worse for customer privacy?
-
@carnage4life
Dare Obasanjo
on x
Apple has also historically made a privacy promise that they can't (actually they won't since they can decrypt your data) look at your content in iCloud. They're between a rock and a hard place. So they've chosen to keep their privacy promise by scanning content on users phones.
-
@reckless
Nilay Patel
on x
This is still not Apple explicitly saying “you can completely turn off local hashing of your photos.” The “system” and “this feature” are intentionally vague descriptors. Don't connect the dots for them! Make them say it on the record. https://twitter.com/...
-
@carnage4life
Dare Obasanjo
on x
Developer of FotoForensics is the best I've read on the valid reasons for, yet problematic technical & legal issues with Apple's CSAM detection. Apple has chosen to die on the hill of not doing server side scanning and has chosen an invasive alternative https://www.hackerfactor.c…
-
@profwoodward
Alan Woodward
on x
This sounds a lot like “trust us, we could do it but we promise we won't”. https://twitter.com/...
-
@normative
Julian Sanchez
on x
Apple's put out a FAQ in response to backlash over their new CSAM photo scanning feature. Points out various ways their current design is privacy protective, which is great, but doesn't really alleviate my core concerns. https://www.apple.com/...
-
@howelloneill
Patrick Howell O'Neill
on x
Apple's response to ‘slippery slope’ concerns: “Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government's request to expand it.” https://www.apple.com/... https://twitter.com/...
-
@howelloneill
Patrick Howell O'Neill
on x
It's important, as we're discussing Apple's CSAM tech, to note that saying it's simple to disable iCloud backup skips over everything we know about the way people use software. This doesn't win or lose the argument any which way but it addresses one of Apple's points.
-
@howelloneill
Patrick Howell O'Neill
on x
It's hard to overstate the power of defaults. History shows that vanishingly few users mess with most of them: “For most users, the default value is the only value.” https://blog.codinghorror.com/ ...
-
@jasonaten
Jason Aten
on x
Apple also says that it won't add images hashes to the database, they have to come from NCMEC: “[hashes] are from known, existing images of CSAM that have been acquired and validated by child safety organizations. Apple does not add to the set of known CSAM image hashes.”
-
@jasonaten
Jason Aten
on x
On why Apple is doing this: “In most countries, including the United States, simply possessing these images is a crime and Apple is obligated to report any instances we learn of to the appropriate authorities.”
-
@jasonaten
Jason Aten
on x
That's the most explicit Apple has been on the record that if you turn off uploading to iCloud Photos, CSAM detection doesn't happen. Apple wants to be clear it isn't “scanning” your photo library on your device.
-
@jasonaten
Jason Aten
on x
On the chance it could be forced to expand the scope of the feature: “We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future.”
-
@martinsfp
Martin Sfp Bryant
on x
Apple says it “will not accede to any government's request to expand” use of its device scanning tech. Easy for them to *say* that, and Apple has resisted such demands in the past, but it's understandable why many are wary of the genie leaving the bottle https://www.theverge.com/…
-
@aral
Aral Balkan
on x
Nothing in this FAQ (PDF: https://www.apple.com/...) that Apple has released addresses any of our concerns. It basically boils down to “trust us, don't worry, it'll be fine.” To reiterate what we're asking: Apple must halt deployment of its content monitoring technology (1/2)
-
@kaepora
@kaepora
on x
“Can the CSAM detection system in iCloud Photos be used to detect things other than CSAM?” Again, we get: “No, but actually yes.” 🤦♂️🤦 ♂️ The Electronic Frontier Foundation *has already documented* instances where CSAM lists were expanded to target non-CSAM content. https://twi…
-
@kaepora
@kaepora
on x
“Could governments force Apple to add non-CSAM images to the hash list?” “Apple will refuse any such demands.” — except, they won't. Apple *has already dropped plans for encrypting iCloud backups specifically because the FBI complained*: https://www.reuters.com/... https://twitte…
-
@kaepora
@kaepora
on x
Asking people to disable iCloud Photos in 2021 is not realistic, and Apple knows this. Everyone depends strongly on iCloud Photos not just for sync, but as a critical backup feature for what is often years and years of important photos.
-
@kaepora
@kaepora
on x
Apple just published a FAQ document regarding its content-scanning rollout. Some choice parts: “Does this mean Apple is going to scan all the photos stored on my iPhone?” “No, but actually yes.”🤦♂️ Full FAQ Here: https://www.apple.com/... https://twitter.com/...