/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple publishes a CSAM FAQ to address misconceptions and concerns about photo scanning

Apple has responded to misconceptions and concerns about its photo scanning announcements by publishing a CSAM FAQ - answering frequently asked questions about the features. Source: Apple .

9to5Mac Ben Lovejoy

Context & Ripple Effects

Apple had already acknowledged internal concern about the feature, framing it as necessary for child protection in a memo responding to employee misunderstandings. The FAQ is Apple’s first sustained public effort to turn that internal rationale into a user-facing explanation.

The related coverage also identifies a limit to that response: the earlier FAQ left questions about potential government pressure unresolved. Later reporting shifts the issue from one document to an ongoing communications and assurance effort.

First-order effects

  • Apple gives users and critics a formal reference point for concerns about its photo-scanning features, while retaining its child-safety rationale.
  • The FAQ does not resolve the government-pressure concern identified in related coverage, keeping Apple’s safeguards—not merely its explanations—at the center of scrutiny.

Second-order effects

  • Apple’s communications burden expands beyond the FAQ: staff were later warned to prepare for questions, and Apple said an independent auditor would review the system in its response to privacy concerns.
  • The episode makes the rollout process part of the product debate; related analysis argues Apple pursued child-safety measures without enough outside expert input while tied to its iOS release schedule.

Third-order effects

  • Privacy-sensitive platform features are likely to face a higher expectation of independent review and expert consultation before launch, rather than relying on post-announcement documentation to establish trust.
  • If that expectation holds, Apple and other platform operators will have to treat governance and public explanation as release requirements for safety features that touch personal data.

The trend: Safety-focused platform features are increasingly judged on the credibility of their governance and rollout process, not only on their stated purpose.

Discussion

  • @alexmartin Alexander Martin on x
    New: Apple has responded to concerns that its CSAM detection system could be used to detect things other than abuse images. Source, Page 5: https://www.apple.com/... cc @rossjanderson @sjmurdoch @pwnallthethings https://twitter.com/...
  • @jonathanmayer Jonathan Mayer on x
    Apple's answer about government demands is difficult to reconcile with its litigation position against FBI & DOJ. Just 5 years ago, Apple swore in court filings that if it built a capability to access encrypted data, that capability would be used far beyond its original context. …
  • @josephfcox Joseph Cox on x
    In a call today with Apple, we asked if China demanded Apple deploy its CSAM or a similar system to detect images other than CSAM (political, etc), would Apple pull out of that market? Apple speaker said that would be above their pay grade, and system not launching in China.
  • @josephfcox Joseph Cox on x
    Also said system has things in place such as Apple having the inability to add hashes itself to the hash list, the sourcing of the hash list (NCMEC), Apple having one operating system globally and not per country.
  • @jasonaten Jason Aten on x
    @stephenrobles @reckless @jcenters They've now made it explicit: “The system does not work for users who have iCloud Photos disabled. This feature does not work on your private iPhone photo library on the device.” https://www.apple.com/...
  • @stephenwarwick9 Stephen Warwick on x
    @reckless They did it just doesn't fit your narrative 😂
  • @reckless Nilay Patel on x
    @StephenWarwick9 Where does that say local hashing is disabled?
  • @secparam Ian Miers on x
    How would Apple not be able to add things to the hash list/ change which list they use? NMEC would need to publish some root hash of their list and Apple would have to bind it into their client software in a way even they couldn't change. Thats a tall order. https://twitter.com/.…
  • @joshbal4 Josh on x
    you know an announcement went well when you have to publish a 6 page follow-up pdf https://twitter.com/...
  • @stephenwarwick9 Stephen Warwick on x
    @reckless “This feature does not work on your private iPhone photo library on the device”, not carrying water, just basic reading comprehension 😂
  • @reckless Nilay Patel on x
    @StephenWarwick9 The system comprises a local component and a cloud component. Disabling the cloud component does not require the local component to stop generating hashes. You don't _know_ this. Don't carry their water for them by guessing.
  • @snowden Edward Snowden on x
    Apple's new iPhone contraband-scanning system is now a national security issue. They just openly admitted they have no answer for what to do when China comes knocking. Hard to understate how disastrous this new system is for iPhone security. Tim Cook needs to intervene. https://t…
  • @antoniogm Antonio García Martínez on x
    Apple claims a one in a trillion failure rate. I'm dubious. No false positive rate is that low, and they have no way of accurately modeling the real-world rate across billions of users. Their match-thresholding scheme helps, but that too is a knob with a net false-positive rate. …
  • @arossp Aaron Ross Powell on x
    Apple makes a ton of money selling to the Chinese market, and so it's more likely than not that they'll rationalize opening their CSAM surveillance system to Xi Jinping if he threatens kicking them out of China if they don't. https://twitter.com/...
  • @stephenwarwick9 Stephen Warwick on x
    @reckless If this needs to be explained more to the *checks notes* Editor in chief of The Verge I don't know what to tell you 😂😂😂
  • @stephenwarwick9 Stephen Warwick on x
    @reckless “The system does not work for users who have iCloud Photos disabled.” https://www.apple.com/...
  • @stephenwarwick9 Stephen Warwick on x
    @reckless The system = CSAM scanning including local hashing. Come on dude you're not even trying 😂 but as I said it doesn't fit your narrative so why would you
  • @riana_crypto Riana Pfefferkorn on x
    Also if this is so privacy-protective and Apple's so proud of it, where's the letter from Tim Cook? Remember the open letter to Apple's customers he published at the outset of the Apple vs. FBI fight? https://www.apple.com/... Tim! Call me maybe!
  • @aral Aral Balkan on x
    immediately and to issue a statement reaffirming their commitment to end-to-end encryption and to privacy as a fundamental human right. https://ar.al/... #apple #privacy #humanRights #personhood (2/2)
  • @reckless Nilay Patel on x
    @StephenWarwick9 Who? Quote it.
  • @snowden Edward Snowden on x
    The last time China stamped an inappropriate demand for access, @Apple sold out their users out. To quote them: “While we advocated against iCloud being subject to these laws, we were ultimately unsuccessful.” (LINK1: https://www.reuters.com/... LINK2: https://t.co/...) https://t…
  • @evacide Eva on x
    @josephfcox So all that a government has to do is pressure/threaten/compromiseNCMEC instead of Apple? I do not feel better.
  • @malwarejake Jake Williams on x
    Oh, is Apple deploying different versions of iOS in different countries now? Because otherwise, this statement seems a bit disingenuous... https://twitter.com/...
  • @malwarejake Jake Williams on x
    First, I find it beyond belief that Apple lacks the technical capability to add hashes. But my bigger concern is NCMEC. They now hold the keys to one of the world's largest surveillance platforms. But I'm sure their security is top notch and they'll never be compromised, so... ht…
  • @ncweaver Nicholas Weaver on x
    @josephfcox Someone needs to ask the same question of Microsoft with Windows Defender.
  • @ryu3824796630 @ryu3824796630 on x
    @josephfcox Every iPhone user needs to do the uncomfortable thing and give up their iPhone and boycott Apple. I will.
  • @antoniogm Antonio García Martínez on x
    The Apple system, complex as it is in the details, is well-designed and keeps user privacy top-of-mind. That said, the use of ‘perceptual hashing’ to do image matching raises the possibility of false positives, something with potentially dreadful consequences in CSAM policing. ht…
  • @riana_crypto Riana Pfefferkorn on x
    AFAICT, some civil society folks got a briefing from Apple 1 day before Thursday's announcement, and that was it. They touted the 👍 they got from prominent cryptographers, so the lack of even the usual pat phrase “in consultation with stakeholders from civil society” stands out.
  • @riana_crypto Riana Pfefferkorn on x
    It's clear that Apple didn't consult any civil society orgs. No civil liberties or human rights input. Privacy, freedom of expression, LGBTQI+ issues, orgs for homeless queer youth, none of it. If they had, they'd be touting that (even if they ignored everything the orgs said).
  • @nash076 @nash076 on x
    The technology can be used for a wide range of scanning and cataloging beyond child abuse (including policing for copyright violations), but Apple pinky swears it would never do that. And as we all know, Apple always keeps its word. https://arstechnica.com/...
  • @jonathanmayer Jonathan Mayer on x
    Apple's new FAQ on CSAM detection is disappointing. The document uses misleading phrasing to avoid explaining false positives. And the FAQ says little about how Apple will ensure the hashes are only CSAM and the same for all users. This is marketing. https://www.apple.com/...
  • @tim Tim Bradshaw on x
    “Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government's request to expand it.” (2/2) One to keep for the record. https://www.apple.com/...
  • @dsilverman Dwight Silverman on x
    Apple CSAM FAQ addresses misconceptions and concerns about photo scanning https://9to5mac.com/... via @benlovejoy
  • @tim Tim Bradshaw on x
    Apple responds to “slippery-slope” privacy concerns over CSAM tool: “We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future...” (1/2)
  • @normative Julian Sanchez on x
    As I said last week, IF you just look at the system in isolation, assume it's implemented exactly as intended & frozen in stone, maybe it's fine. But I don't think that's a terribly smart way to think about it.
  • @bergmayer John Bergmayer on x
    This will be true if and only if iCloud Photos are fully encrypted, and right now, they are not. Apple has policies and systems in place to secure your iCloud images but it does still have the ability to see them if it wants to, or is ordered to https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    One can assume there are tens to hundreds of millions of CSAM images in iCloud based on extrapolation of how much storage they've announced is used by the service (8M terabytes) and reporting rates from other services (e.g. FotoForensics says 0.056%). So they must do something.
  • @carnage4life Dare Obasanjo on x
    The question from a privacy perspective is whether Apple keeping the “we won't look at your content on the server” promise by creating a precedent where “we look at content on your phone instead” is better or worse for customer privacy?
  • @carnage4life Dare Obasanjo on x
    Apple has also historically made a privacy promise that they can't (actually they won't since they can decrypt your data) look at your content in iCloud. They're between a rock and a hard place. So they've chosen to keep their privacy promise by scanning content on users phones.
  • @reckless Nilay Patel on x
    This is still not Apple explicitly saying “you can completely turn off local hashing of your photos.” The “system” and “this feature” are intentionally vague descriptors. Don't connect the dots for them! Make them say it on the record. https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    Developer of FotoForensics is the best I've read on the valid reasons for, yet problematic technical & legal issues with Apple's CSAM detection. Apple has chosen to die on the hill of not doing server side scanning and has chosen an invasive alternative https://www.hackerfactor.c…
  • @profwoodward Alan Woodward on x
    This sounds a lot like “trust us, we could do it but we promise we won't”. https://twitter.com/...
  • @normative Julian Sanchez on x
    Apple's put out a FAQ in response to backlash over their new CSAM photo scanning feature. Points out various ways their current design is privacy protective, which is great, but doesn't really alleviate my core concerns. https://www.apple.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Apple's response to ‘slippery slope’ concerns: “Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government's request to expand it.” https://www.apple.com/... https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    It's important, as we're discussing Apple's CSAM tech, to note that saying it's simple to disable iCloud backup skips over everything we know about the way people use software. This doesn't win or lose the argument any which way but it addresses one of Apple's points.
  • @howelloneill Patrick Howell O'Neill on x
    It's hard to overstate the power of defaults. History shows that vanishingly few users mess with most of them: “For most users, the default value is the only value.” https://blog.codinghorror.com/ ...
  • @jasonaten Jason Aten on x
    Apple also says that it won't add images hashes to the database, they have to come from NCMEC: “[hashes] are from known, existing images of CSAM that have been acquired and validated by child safety organizations. Apple does not add to the set of known CSAM image hashes.”
  • @jasonaten Jason Aten on x
    On why Apple is doing this: “In most countries, including the United States, simply possessing these images is a crime and Apple is obligated to report any instances we learn of to the appropriate authorities.”
  • @jasonaten Jason Aten on x
    That's the most explicit Apple has been on the record that if you turn off uploading to iCloud Photos, CSAM detection doesn't happen. Apple wants to be clear it isn't “scanning” your photo library on your device.
  • @jasonaten Jason Aten on x
    On the chance it could be forced to expand the scope of the feature: “We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future.”
  • @martinsfp Martin Sfp Bryant on x
    Apple says it “will not accede to any government's request to expand” use of its device scanning tech. Easy for them to *say* that, and Apple has resisted such demands in the past, but it's understandable why many are wary of the genie leaving the bottle https://www.theverge.com/…
  • @aral Aral Balkan on x
    Nothing in this FAQ (PDF: https://www.apple.com/...) that Apple has released addresses any of our concerns. It basically boils down to “trust us, don't worry, it'll be fine.” To reiterate what we're asking: Apple must halt deployment of its content monitoring technology (1/2)
  • @kaepora @kaepora on x
    “Can the CSAM detection system in iCloud Photos be used to detect things other than CSAM?” Again, we get: “No, but actually yes.” 🤦‍♂️🤦 ‍♂️ The Electronic Frontier Foundation *has already documented* instances where CSAM lists were expanded to target non-CSAM content. https://twi…
  • @kaepora @kaepora on x
    “Could governments force Apple to add non-CSAM images to the hash list?” “Apple will refuse any such demands.” — except, they won't. Apple *has already dropped plans for encrypting iCloud backups specifically because the FBI complained*: https://www.reuters.com/... https://twitte…
  • @kaepora @kaepora on x
    Asking people to disable iCloud Photos in 2021 is not realistic, and Apple knows this. Everyone depends strongly on iCloud Photos not just for sync, but as a critical backup feature for what is often years and years of important photos.
  • @kaepora @kaepora on x
    Apple just published a FAQ document regarding its content-scanning rollout. Some choice parts: “Does this mean Apple is going to scan all the photos stored on my iPhone?” “No, but actually yes.”🤦‍♂️ Full FAQ Here: https://www.apple.com/... https://twitter.com/...