Google S Unannounced Update Scans All Your Photos One Forbes
https://www.forbes.com/sites/zakdof...rts-scanning-your-photos-without-any-warning/ Google’s Unannounced Update Scans All Your Photos—One Click Stops It By Zak Doffman, Contributor.Zak Doffman writes about security, surveillance and privacy. Feb 28, 2025, 12:02pm EST Your photos are now being scanned getty Republished on February 28 with Google and user response to this photo scanning furor, and more information on the system update warnings. You may recall Apple’s un-Apple-like moment a few weeks ago, when users discovered their photos were being scanned by Apple Intelligence to match landmarks.
Users had not been told, and it caused a furor with security experts. Google is now going through something of the same. And again, it’s not the technology, it’s the secrecy. Apple’s Enhanced Visual Search sends parts of photos to the cloud to match against a global index of points of interest.
It’s very privacy-preserving, but as crypto expert Matthew Green complained, “it’s very frustrating when you learn about a service two days before New Years and you find that it’s already been enabled on your phone.” Google’s awkward moment relates to its SafetyCore, an Android system update that enables on-device image scanning that could do all kinds of things, but is currently focused on blurring or flagging sensitive content. It’s seemingly even more private than Apple’s Enhanced Visual Search, given that it’s all on-device. So we’re told.
But when a technology is installed and enabled on our phones without warning, the after-the-fact assurances that it’s all fine tend to be met with more skepticism than would be the case if it was done more openly. That’s the same issue as Apple’s. The X post that kicked off this SafetyCore furor warned “Google had secretly installed this app on various android devices without users permission.
It can reportedly scan through your photo gallery and occupies 2gb of space.” I have covered SafetyCore before, pointing out that its use to secure Google Messages would be a welcome addition to Gmail, shifting security scanning from Google’s servers to a user’s phone. But that doesn’t change the lack of openness point. GrapheneOS — an Android security developer — provides some comfort, that SafetyCore “doesn’t provide client-side scanning used to report things to Google or anyone else.
It provides on-device machine learning models usable by applications to classify content as being spam, scams, malware, etc.
This allows apps to check content locally without sharing it with a service and mark it with warnings for users.” But GrapheneOS also points out that “it’s unfortunate that it’s not open source and released as part of the Android Open Source Project and the models also aren’t open let alone open source… We’d have no problem with having local neural network features for users, but they’d have to be open source.” Which gets to transparency again.
Google says that SafetyCore “provides on-device infrastructure for securely and privately performing classification to help users detect unwanted content. Users control SafetyCore, and SafetyCore only classifies specific content when an app requests it through an optionally enabled feature.” Per ZDNet, the issue is that the “Google never told users this service was being installed on their phones.
If you have a new Android device or one with software updated since October, you almost certainly have SafetyCore on your phone.” As with Apple, “one of SafetyCore’s most controversial aspects is that it installs silently on devices running Android 9 and later without explicit user consent.
This step has raised concerns among users regarding privacy and control over their devices.” Google emphasizes that while SafetyCore brings the architecture to scan your photos, the scanning itself is done separately, for example with the Sensitive Content warnings rolling out this year, and that it’s all done on device. As for the secrecy, Google told me “Google System services automatically updates your device with security, bug fixes, and new features. Some updates are delivered via system services in separate Android packages.
This maintains privacy, security and data isolation following the principle of least privilege because permissions are not shared with other functionality. As part of Google’s continuous investment in transparency of its products, we added binary transparency to these Google system APKs.” SafetyCore was covered in November when it was released, but it hasn’t generated any real media attention until now.
Google did provide an overview of its development capabilities at the time, and it separately promoted the upcoming sensitive content warnings coming to Google Messages, similar to Apple’s on-device content safety. But the issue this has highlighted is different. There’s a user nervousness around what all the clever new tech is doing on our phones, and with Google maybe more than most, the delineation between on and off device is often lost. There’s a trust issue that comes from the publicity around tracking and data harvesting that won’t quickly fade.
Google stresses that users remain in control, that they can disable or uninstall SafetyCore and they don’t need to enable the on-device scanning when it comes. I suspect there needs to be some more PR around the privacy and the benefits of the new functionality, or trigger-happy users will read the coverage and switch it off. Per one tech forum this week: “Google has quietly installed an app on all Android devices called ‘Android System SafetyCore’.
It claims to be a ‘security’ application, but whilst running in the background, it collects call logs, contacts, location, your microphone, and much more making this application ‘spyware’ and a HUGE privacy concern. It is strongly advised to uninstall this program if you can.
To do this, navigate to 'Settings’ > 'Apps’, then delete the application.” If you “don’t trust Google,” because as ZDNet points out, “just because SafetyCore doesn’t phone home doesn’t mean it can’t call on another Google service to tell Google’s servers that you’ve been sending or taking ‘sensitive’ pictures,” then you can stop it. You can find the option to uninstall or disable the service by tapping on ‘SafetyCore’ under ‘System Apps’ in the main ‘Apps’ settings menu on your phone.
Lessons learnt for both Apple and Google in recent weeks then. If you want to turn our phones into AI-fueled machines, then let us know what you’re doing before you do it, and give us the opportunity to say yes or no. Otherwise it fuels fear of the unknown. And if AI is to bed down on our smartphones with access to all our apps and data, then it needs to establish high trust bars and stick to them rigidly.
Meanwhile, the furor around SafetyCore continues to build, with it clearly struggling to shake off the spyware implication of a system app with this underlying function being installed without notice or a specific opt-in/opt-out assurance. “I did not consent to this app being installed, nor was I notified,” complained one Redditor. “And when I found out about this through another source, I couldn’t find this app by using Google Play’s search function. I had to use a link someone else provided to even locate it.
(Some people said they found and uninstalled it through their security settings.) Absolutely obscene. Apparently it’s been added to older devices as well - even crashing some of them.”
People Also Asked
- GoogleNews%20-%20News%20aboutGoogle-%20Overview
- %5BPSA%5DGoogle%u2019sUnannouncedUpdateScansAllYourPhotos%u2014One...
- Google%u2019sUnannouncedUpdateScansAllYourPhotos%u2014OneClick...
- Google%27s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%u2014One...%20-%20Forbes
- Google%27s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%20-%20Democratic...
GoogleNews%20-%20News%20aboutGoogle-%20Overview%3F
Users%20had%20not%20been%20told%2C%20and%20it%20caused%20a%20furor%20with%20security%20experts.%20Google%20is%20now%20going%20through%20something%20of%20the%20same.%20And%20again%2C%20it%u2019s%20not%20the%20technology%2C%20it%u2019s%20the%20secrecy.%20Apple%u2019s%20Enhanced%20Visual%20Search%20sends%20parts%20of%20photos%20to%20the%20cloud%20to%20match%20against%20a%20global%20index%20of%20points%20of%20interest.
%5BPSA%5DGoogle%u2019sUnannouncedUpdateScansAllYourPhotos%u2014One...%3F
But%20when%20a%20technology%20is%20installed%20and%20enabled%20on%20our%20phones%20without%20warning%2C%20the%20after-the-fact%20assurances%20that%20it%u2019s%20all%20fine%20tend%20to%20be%20met%20with%20more%20skepticism%20than%20would%20be%20the%20case%20if%20it%20was%20done%20more%20openly.%20That%u2019s%20the%20same%20issue%20as%20Apple%u2019s.%20The%20X%20post%20that%20kicked%20off%20this%20SafetyCore%20furor%20warned%20%u201CGoogle%20had%20secretly%20installed%20this%20app%20on%20various%20android%20devices%20without%20users%20permission.
Google%u2019sUnannouncedUpdateScansAllYourPhotos%u2014OneClick...%3F
Google%20says%20that%20SafetyCore%20%u201Cprovides%20on-device%20infrastructure%20for%20securely%20and%20privately%20performing%20classification%20to%20help%20users%20detect%20unwanted%20content.%20Users%20control%20SafetyCore%2C%20and%20SafetyCore%20only%20classifies%20specific%20content%20when%20an%20app%20requests%20it%20through%20an%20optionally%20enabled%20feature.%u201D%20Per%20ZDNet%2C%20the%20issue%20is%20that%20the%20%u201CGoogle%20never%20told%20users%20this%20service%20was%20being%20installed%20on%20their%20phones.
Google%27s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%u2014One...%20-%20Forbes%3F
https%3A//www.forbes.com/sites/zakdof...rts-scanning-your-photos-without-any-warning/%20Google%u2019s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%u2014One%20Click%20Stops%20It%20By%20Zak%20Doffman%2C%20Contributor.Zak%20Doffman%20writes%20about%20security%2C%20surveillance%20and%20privacy.%20Feb%2028%2C%202025%2C%2012%3A02pm%20EST%20Your%20photos%20are%20now%20being%20scanned%20getty%20Republished%20on%20February%2028%20with%20Google%20and%20user%20response%20to%20this%20photo%20scanning%20furor%2C%20and%20m...
Google%27s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%20-%20Democratic...%3F
https%3A//www.forbes.com/sites/zakdof...rts-scanning-your-photos-without-any-warning/%20Google%u2019s%20Unannounced%20Update%20Scans%20All%20Your%20Photos%u2014One%20Click%20Stops%20It%20By%20Zak%20Doffman%2C%20Contributor.Zak%20Doffman%20writes%20about%20security%2C%20surveillance%20and%20privacy.%20Feb%2028%2C%202025%2C%2012%3A02pm%20EST%20Your%20photos%20are%20now%20being%20scanned%20getty%20Republished%20on%20February%2028%20with%20Google%20and%20user%20response%20to%20this%20photo%20scanning%20furor%2C%20and%20m...