Apple defeats liability for not scanning iCloud for CSAM

436 points · 470 comments on HN · read original →

Points and comments are a snapshot, not live.

A court ruled Section 230 shields Apple from liability for not scanning iCloud for CSAM.

A federal judge dismissed a lawsuit against Apple for not scanning iCloud for child sexual abuse material (CSAM), citing Section 230 immunity. The judge ruled that claims treated Apple as a publisher of third-party content, and that requiring CSAM detection tools like NeuralHash would involve content moderation decisions protected by Section 230. The judge expressed concern that the legal framework prioritizes privacy over protecting CSAM victims, but noted that only lawmakers can mandate scanning. The case is set for appeal to the Ninth Circuit.

The judge highlighted that breaking end-to-end encryption to scan for CSAM would cause significant privacy loss for all users, citing past data breaches like the Fappening. The blog post argues that government efforts to prosecute CSAM creators should be the priority, not weakening encryption.

What commenters are saying

Commenters largely supported the ruling as a win for privacy and freedom, with many praising Apple's privacy stance relative to other tech companies. Some noted that Apple's earlier proposal for client-side scanning opened a Pandora's box by showing technical feasibility, which could be exploited by repressive regimes. Others pointed out that client-side scanning was already happening on other platforms. A few commenters expressed concern about false positives and the potential for the technology to be abused for political surveillance.