Apple defeats liability for not scanning iCloud for CSAM
Apple defeats liability for not scanning iCloud for CSAM, but the judge was not pleased – Amy v. Apple
Apple 在不扫描 iCloud 中儿童性虐待材料(CSAM)的诉讼中胜诉,但法官对此表示不满——Amy v. Apple 案
This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files. Apple’s maneuvers confused the public and seemed like an embarrassing unforced error for Apple. It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.
本案涉及苹果公司对其私有 iCloud 存储中用户上传文件的处理方式。苹果公司没有采用 PhotoDNA 来扫描托管文件中的 CSAM,而是创建了自己的专有替代方案 NeuralHash,但该方案显然效果不佳。因此,苹果公司在云存储中扫描 CSAM 的努力出现了“大转弯”,转而为 iCloud 文件实施了端到端加密。苹果的这些举措令公众感到困惑,看起来像是苹果公司一次尴尬的非受迫性失误。这也招致了来自政府和原告(包括 CSAM 受害者)的压力,他们更倾向于苹果公司此前自愿展示并愿意采取的更具干预性的手段。
This lawsuit represents a full-scale attack on Apple and Section 230. “Plaintiffs allege that Apple’s failure to implement any known CSAM detection is a design defect because Apple can safely implement readily available features to prevent the spread of known CSAM but has continuously failed to do so.” The court dismisses the third amended complaint, which tees this case up for the Ninth Circuit, where (as usual) anything could happen.
这起诉讼代表了对苹果公司和《通信规范法》第 230 条的全面攻击。“原告声称,苹果未能实施任何已知的 CSAM 检测机制属于设计缺陷,因为苹果本可以安全地实施现成的功能来防止已知 CSAM 的传播,但却一直未能这样做。”法院驳回了第三次修订后的起诉状,这使得本案将进入第九巡回上诉法院,在那里(像往常一样)任何事情都可能发生。
The court reiterates that Section 230 applies to the plaintiffs’ claims: First, Plaintiffs’ claims treat Apple as a publisher or speaker of the CSAM content that animates Plaintiffs’ injuries. Fundamentally, Plaintiffs contend that Apple has elected to permit users to disseminate and share third-party CSAM content when it could have—and, in their view, should have—used readily available technology to prevent the distribution of child pornography depicting the Plaintiffs in this putative class. The duties Plaintiffs seek to invoke “spring[ ] from the defendant’s status as publisher,” and consequently, “immunity applies.” Second, immunity also applies because “the means to avoid liability requires [Apple] to act as a publisher.” As a result, Apple is entitled to complete immunity under § 230.
法院重申,第 230 条适用于原告的诉求:首先,原告的诉求将苹果视为导致其伤害的 CSAM 内容的发布者或传播者。从根本上讲,原告认为苹果选择允许用户传播和分享第三方 CSAM 内容,而苹果本可以——且在他们看来应该——使用现成的技术来防止传播描绘本案原告群体的儿童色情制品。原告试图援引的义务“源于被告作为发布者的身份”,因此,“豁免权适用”。其次,豁免权同样适用,因为“避免责任的手段要求 [苹果] 采取发布者的行为”。因此,苹果有权根据第 230 条获得完全豁免。
Citing Doe 1 v. Meta, the court says: Plaintiffs’ injuries are the direct result of the actions of third parties who used iCloud to share CSAM, a use Apple neither explicitly condones nor prevents (even assuming—as alleged in the TAC—that Apple was aware of the use of iCloud for this purpose)….though Plaintiffs allege that Apple knew that its tools were likely to be used to distribute child pornography (as confirmed by the internal Apple text messages at the center of this case), under the current state of the law, Apple is still entitled to immunity under § 230—irrespective of that general knowledge.
法院援引 Doe 1 v. Meta 案指出:原告的伤害是第三方使用 iCloud 分享 CSAM 的直接结果,苹果既没有明确纵容也没有阻止这种使用(即使假设——如第三次修订起诉状中所述——苹果知晓 iCloud 被用于此目的)……尽管原告声称苹果知道其工具可能被用于传播儿童色情制品(本案核心的苹果内部短信证实了这一点),但在现行法律下,苹果仍有权根据第 230 条获得豁免——无论其是否具备这种普遍认知。
The case reaches its inevitable denouement of a win for Apple. However, Judge Wise remains troubled about its implications. She expresses her uneasiness in stronger-than-normal terms: As it stands, nothing in the law prevents any company, including Apple, from utilizing available technology or creating new technology to identify and report child pornography stored and distributed on their traditional servers or through their cloud services. Conversely, there is no law that obligates companies to proactively do so. Undoubtedly any such legislation would come at a cost of at least some loss of privacy for millions of people. But if lawmakers expected that companies would take steps to prevent their products from being used for storing and distributing child pornography based on something short of a legal imperative, this case, like many others before it, demonstrates the inadequacy of that approach.
本案最终迎来了苹果胜诉的必然结局。然而,怀斯(Wise)法官对本案的影响仍感到不安。她以比平时更强烈的措辞表达了她的忧虑:就目前而言,法律没有任何规定阻止包括苹果在内的任何公司利用现有技术或创造新技术,来识别和举报存储并分发在其传统服务器或云服务中的儿童色情制品。反之,也没有法律强制要求公司主动这样做。毫无疑问,任何此类立法都将以牺牲数百万人的部分隐私为代价。但如果立法者期望公司在没有法律强制要求的情况下,采取措施防止其产品被用于存储和分发儿童色情制品,那么本案就像之前的许多案件一样,证明了这种做法的不足。