Experts Warn Apple's CSAM Scanning System Lacks Crucial Accountability

Security researchers argue that Apple's newly announced iCloud photo scanning system lacks necessary accountability mechanisms to verify its safety. They warn that without cryptographic transparency, the privacy claims surrounding the CSAM detection tool remain unproven.

Apple announces a new system for iOS 15 that scans iCloud photos for Child Sexual Abuse Material (CSAM) by comparing user images to a database provided by the National Center for Missing and Exploited Children (NCMEC). The company promotes this tool as a way to combat child exploitation while preserving user privacy, stating that Apple personnel only review images if a user's account triggers a substantial number of matches.

However, security researchers point out a critical flaw in this design, noting that there is no way for users or the public to independently verify the properties of the images Apple scans for. This lack of transparency regarding both Apple's scanning protocol and NCMEC's internal processes makes the company's bold privacy and security claims ring hollow, turning a well-intentioned system into a potential public safety hazard.

To address these significant concerns, the experts suggest implementing specific cryptographic mechanisms that increase public confidence in the system. While these technical solutions do not fix every issue associated with the photo reporting proposal, they demonstrate that building a more secure and accountable system is both necessary and entirely possible.

Read More at the original source →