Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares...
No, i'm sure people would still make a fuss. Perceptual hashes are required to prevent criminals from slightly changing pixels within CSAM photos to avoid detection.
I think everyone knows why perceptual hashes are being used. I'm not sure how you're certain that people would make a fuss. Almost all of the discussion I have seen surrounding this has spent a tremendous amount of time dwelling on the risk of false positives.
Do you produce most email attachment in your inbox yourself? Do you produce most photos on your iCloud yourself? The point is anti-virus (purposed) hash upload is different from your private iCloud content hash upload.
I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64 Linux, en-US) using a Burp proxy. Here is the function that does it: https://searchfox.org/mozilla-central/source/toolkit/compone...
Here is the about:config tweak to turn it off: browser.safebrowsing.downloads.remote.url
Here is an example request: POST https://sb-ssl.google.com/safebrowsing/clientreport/download...
Content is Protobuf-encoded payload containing:
- full path to the mailbox including the username and "secret" random profile name (e.g. /home/jenda/.thunderbird/ioi8uk0k.tbtest/Mail/hrach.eu/Inbox)
- SHA-256 of the file
- attachment file name (e.g. 10-test-blahblah.pdf)