BY ZACHARY MARGULIS-OHNUMA
Apple announced a remarkable program last week to crack down on “CSAM” — child sexual exploitation material, also known as child pornography — on its hardware. At first glance, the program, which hopes to protect privacy while flagging child porn on Apple’s iCloud service, seems like a step away from Apple’s historical commitment to privacy, even in the face of law enforcement needs. But Apple is under immense pressure to report illegal CSAM on its systems and the solution announced last week seems to be a way to do it that is calculated to maximize privacy protection. Aspects of it will continue to drive law enforcement crazy.
Remember that Google has long scanned your email to find and report child pornography, leading to full searches and prosecutions like the one upheld in U.S. v. Ringland, 966 F.3d 731 (8th Cir. 2020). But that scanning takes place in the cloud, i.e. after illegal material leaves a user’s device en route to another user or for storage on Google’s servers. The Ringland case upheld Google’s email scanning as a private search, and therefore beyond the protection of the Fourth Amendment (which bars most warrantless government searches). Google, Apple, and other service providers are required under 18 U.S.C. Sec. 2258A(a) to report illegal child pornography they become aware of to the National Center for Missing and Exploited Children (NCMEC), which maintains a database of all known child pornography.
But they are not required to look for it.
For the first time, Apple announced it will be looking for CSAM on your iPhone. The approach in iOS 15 is very different from Google’s. Apple won’t look at your photos once they are in the cloud. Instead, it will download NCMEC’s entire database of hash values for known child pornography onto your phone as part of your operating system. When you use iCloud Photos, before uploading a photo, the operating system will compare your photo against known child pornography. If there are more than 30 matches, it will disable your account and report the photos to NCMEC. For people who use iCloud for CSAM, that may lead to a law enforcement search warrant, arrest, prosecution, and federal prison.
At the same time, Apple’s announcement is much more solicitous of privacy rights than what other companies do. Facebook makes no pretense of protecting user privacy — of the 21.7 million reports of CSAM made to NCMEC in 2020, more than 20.3 million were from Facebook. Half a million were from Google and only 265 were from Apple. Apple is relatively transparent about its technology, providing detailed papers about how it will work that are easy to find. By doing the matching on device, the process remains far more under the user’s control than emails sent through Gmail: if you do not want your phone to scan your images, just turn off iCloud photos on your device. Apple’s humans can only become involved if your phone tries to upload more than 30 images that match the NCMEC database.
Apple’s new measures strike a balance between privacy and enforcement. They come as no real surprise to internet lawyers like Legal Aid’s Adam Elewa, who, as a former ZMO Law associate, tried cases involving alleged child pornography on Apple devices. “Apple has never categorically opposed collaborating with the government in turning over user data, and has intentionally declined” to let users encrypt their iCloud data to accommodate law enforcement.
The upshot of Apple’s announcement is that users will no longer be able to use iCloud photos to store CSAM. The crackdown will lead to a handful of prosecutions and raises important Fourth Amendment questions that may be used by the defense. If you suspect you are under investigation for possession of child pornography on an Apple device, call our office for further information.
Photo by Designecologist from Pexels