It wasn’t scanning photos looking for csam, it was computing a fingerprint of every photo that could only be read on the server if 5 of those fingerprints matched known csam.
I can’t see how that is worse than unencrypted photos in the cloud that can be scanned at any time server side.
I can’t see how that is worse than unencrypted photos in the cloud that can be scanned at any time server side.