So I did something over the weekend I've been putting off for probably two years: I turned off iCloud Photo Library on my phone. Not because of storage costs (though $2.99 a month for 200GB is exactly $2.99 more than I want to pay for something I resent). I did it because of the CSAM scanning thing Apple announced a couple weeks back, and because of what happened this week around it.
Quick recap for anyone who missed it, since I know not everybody reads Apple blogs for fun the way I apparently do: Apple said it's going to start scanning photos before they get uploaded to iCloud, matching them against a database of known child abuse imagery using something called NeuralHash. The matching happens on your device. If enough images cross a threshold (Apple's said around 30, though they've been cagey about the exact number), a human reviewer at Apple looks at them and, if it checks out, it goes to NCMEC and then to law enforcement.
On paper this sounds fine, even good. Nobody is pro-child-abuse-imagery, obviously. The problem is the mechanism, not the goal. You're putting a scanning system on a billion phones that runs against a database nobody outside Apple and NCMEC gets to audit. Today it's CSAM hashes. What happens when a government asks Apple to add a different hash list? Apple says it'll refuse. I believe that they believe that. I do not believe Apple gets to make that call unilaterally for every country it operates in, especially the ones where "government asks nicely" isn't really how it works.
This past Thursday, over 90 organizations, digital rights groups, policy people, security researchers, sent Apple an open letter asking them to drop the plan entirely. The Center for Democracy and Technology organized it. Ninety is not a small number of people signing something like that. These aren't randoms either, it's the EFF, ACLU, a pile of university security labs. When that many serious people say "hey, this is a bad precedent," I tend to think it's worth listening to even if you don't agree with every word of the letter.
I'll admit my personal reasoning is dumber and more selfish than the policy arguments. I just don't want photo-matching software running on my phone, full stop, no matter how narrow the scope is today. I've had an iPhone since the 3GS. I like the hardware, I like not thinking about my phone, that's the whole pitch of the ecosystem. But this is the first time in probably a decade of using Apple stuff that I felt like the thing in my pocket was reporting on me instead of working for me. Doesn't matter that I have nothing to hide. It's the "before your photo leaves the device" part that gets me, not the after.
So: iCloud Photo Library, off. I moved about 40GB of photos to a local folder on my Mac and I'm going to figure out something with either Backblaze or just a second drive I keep in a shoebox, which, yes, I recognize is a worse backup strategy than iCloud in every practical sense. I'm doing it anyway. Call it a protest that inconveniences nobody but me.
Small unrelated aside, but it's been that kind of week for anyone paying attention to how companies handle your data: T-Mobile confirmed their breach affects something like 47 million people, current and former customers and even people who never signed up but applied for credit once. I checked, my SSN wasn't in what got exposed as far as I can tell from their notice, but a bunch of my identifiers were, which is its own kind of unsettling in a totally different way. Two completely separate stories, Apple scanning your stuff on-device with good intentions and T-Mobile leaking your stuff off a server with no intentions at all, but they landed in the same week and I couldn't stop thinking about them side by side. One is a company being too careful with access to your data in a way I don't trust. The other is a company being not careful enough. Neither one made me feel great about where all this is heading.
Anyway. Photos live on my laptop now. It's 2021 and I'm backing up to an external drive like it's 2009. Progress is not always a straight line.