Assuming this is correct (I only followed a couple of links, but it would be the EU planning to mandate content scan for CSAM on all e-mail and messaging platforms, after making it legal/optional already to do so earlier this year), I guess this answer the question of why Apple released their tech.
While it made little sense on iCloud Photos, they can add the exact same client-side scanning to iMessage and keep it (mostly) e2ee.
Certainly not judging the merits of this, such mandates would be the end of e2ee via third party companies (there seems to have been a concerted worldwide effort around that), but at the very least, I can see the impetus from Apple's point of view to release this right now.
Just like WhatsApp 'conveniently' integrated Google Drive backups by default. That is why it's funny to see the fake outrage of WhatsApp's team over this.
Meh. Compared to 10 years ago we still live in a bright future where e2ee is available to everyone who needs it. Yeah, you might need to enable some options (like in Telegram) or disable some other options (like iCloud in iMessage), but it's still there.
Even with this on-device CSAM thingy, Apple knows less about you than they did 10 years ago and random staffers at FAANG can't just go and spy on their spouses (the way they could not that long ago).
Disabling iCloud doesn't enable e2e as the other end of your conversation still has iCloud on by default and is escrowing your chat plaintext to Apple.
Apple has access to all of the plaintext iMessages for almost all devices/conversations and can turn them over to the USG at will.
For those unfamiliar, as I was, it appears iCloud backup is enabled by default. I think the above statement about iMessage not being e2e in practice is very fair.
Note that even if you disable iCloud/iCloud Backup, all of your iMessages will still be leaked unencrypted to Apple via the phone on the other end of the conversation that still has iCloud Backup enabled.
This option is transparent to the user and easy to change. Also, anyone who has done IT support will appreciate that yeah regular users actually want / need backups enabled by default, it's often a life saver for them.
And the mere fact it's a default makes it a significant problem when discussing it as a popular and widespread E2E messenger. It would be more borderline if it was a required configuration choice with no default that clearly disclaimed the ramifications.
Even then, you have the issue that you are not the only person with a copy of the conversation. Your partner - or partners - has it too. Does Apple require some kind of pre-conversation negotiation to determine how the conversation will be stored in the backups? Or at least provide some kind of warning if a person with backups disabled gets in contact with somebody with backups enabled?
I don't disagree with you about backups, but how useful they are is completely irrelevant in this context for several separate reasons.
Users need backups to protect from a device loss scenario. Apple needs to have keys for that to work. They also can’t rely on key derivation because users forget their Apple ID passwords all the time.
It is relevant because this requirement necessarily conflicts with strong e2ee. And since Apple is designing devices for end users that don’t necessarily even know or care what e2ee is, it seems completely reasonable to have defaults that will optimize for the problems that are relevant for the majority of users (losing decide and forgetting your password) while making strong e2ee a few clicks away to those who need it (and understand associated tradeoffs).
While it made little sense on iCloud Photos, they can add the exact same client-side scanning to iMessage and keep it (mostly) e2ee.
Certainly not judging the merits of this, such mandates would be the end of e2ee via third party companies (there seems to have been a concerted worldwide effort around that), but at the very least, I can see the impetus from Apple's point of view to release this right now.