Apple CSAM Detection Only Triggers With iCloud Photos Enabled

Apple confirms that its upcoming child sexual abuse material detection system does not scan photos if users disable iCloud Photos. The feature relies entirely on the photo uploading process to flag illegal content.

Apple introduces a new system in iOS 15 and iPadOS 15 that detects known child sexual abuse material (CSAM) on user devices before photos upload to iCloud Photos. The technology works by matching unreadable hashes of known illegal images against a user's local photo library, ensuring that Apple does not broadly inspect personal photos that are not already circulating among criminals.

The system operates automatically and is not an optional feature, but it actively requires iCloud Photos to function. Apple confirms that if a user disables the iCloud Photos feature, the company cannot detect known CSAM images on the device or within standard iCloud Backups. The detection process only triggers when a flagged photo actually uploads to Apple's servers with an attached digital voucher.

Once a user uploads a specific number of flagged photos, Apple interprets the collected vouchers and conducts a manual human review. If the review confirms the presence of CSAM, Apple disables the user account and reports the incident to the National Center for Missing and Exploited Children. Despite assurances that the scanning is strictly limited to known CSAM hashes, security researchers express concerns that this framework could potentially expand to detect other types of content in the future.

Read More at the original source →