Apple Beats CSAM Liability Claim, But Judge Warns Lawmakers Must Act

Apple Defeats Liability for Not Scanning iCloud for CSAM

Apple Beats CSAM Liability Claim, But Judge Warns Lawmakers Must Act

Apple successfully defeated a lawsuit claiming liability for not scanning iCloud for CSAM, relying on Section 230 immunity. Although the court ruled in Apple's favor, Judge Wise expressed deep concern that current laws fail to protect victims and urged legislators to create explicit mandates. The decision highlights the critical tension between maintaining end-to-end encryption for user privacy and the urgent need to combat the distribution of child sexual abuse material.

Those children are the collateral damage of our ineffective legal landscape. They deserve better.
  1. giantg2

    Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA.

    For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has even extended to fictional CSAM such as AI generated stories and pictures. As an aside, if that gets extended to political speech or other non-CSAM materials that are determined to be undesirable, that's a big concern. I can imagine that a conservative state could pass a law banning all porn because they claim it could encourage illegal activities such as prostitution, rape, or CSA.

    On the CSA side, you rarely hear about arrests (they happen but less than CSAM). There doesn't seem to be any real push for educating and protecting kids before it happens. Ironically, the groups doing the most to educate and implement protective strategies are the ones who have been involved in abuse scandals in the past (Churches, Scouts, etc). Even then, a lot of it is just getting clearances, which doesnt prevent people who where not caught or were first timers. Offenders get put on a list/map. This is sort of a half approach. If they are still a threat, they shouldn't be released. Yet if you comb the list and see some of the results, they don't all seem to fit with CSA. I personall […]

  2. amazingamazing

    It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level.

    Apple could easily not do this stuff and it may even be easier to not.

  3. djoldman

    I am not a lawyer.

    There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example:

    * A: physical sexual abuse of children. B: possession or distribution of CSAM

    * A: drug trafficking or tax evasion. B: structured cash withdrawals

    The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A.

    It's my understanding that conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person: one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people.

    It's my understanding that one can be convicted of structured withdrawals that are not driven by, linked to, or in any way related to anything nefarious.

  4. majorchord

    IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.

    Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.

  5. JSR_FDED

    The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections.

    As sad as this is, end to end encryption means no CSAM scanning.

    As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too.

    This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

  6. jobs_throwaway

    A win for privacy and freedom

  7. Schlagbohrer

    I have to point out that the united states absolutely does not, under any context, care about the health and wellbeing of children. If they did they would have good, easy to access free healthcare and support for families including parental leave, as well as a good public school system that served every single child adequately.

  8. St0n3d

    “Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

    Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

    The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)

  9. KolibriFly

    A court should not quietly create a general duty to inspect everyone's private files because a provider could theoretically detect illegal content

  10. ryanisnan

    As the creator of mediaden.ca[1] I’ve thought about this. Client side scanning is maybe marginally better than server side scanning, but both paths lead to privacy rot.

    Governments need to catch criminals, but they shouldn’t do it at everyone else’s expense.

    1. https://mediaden.ca

More from this day

2026-07-21