Earlier quoted context omitted.
There was an excellent Twitter thread on why they didn't do this: https://twitter.com/alexstamos/status/928740488395608065 The salient bit: > A quick note to everybody who says 'calculate the hash locally': > A) Photo fingerprinting algorithms are usually not included in clients to prevent the development of circumvention techniques. > B) Humans need to review to prevent adversarial reporting. Further down the thread…
It's not a hard problem. Both A & B are bogus reasons. A) Any hash is going to be easily circumvented by anyone who owns Photoshop or any image editor. It's only going to catch those dumb enough not to modify the images, ie. most everyone. Doing the hash server side isn't the big problem though, because if you trust the Facebook App then by default you should trust the Facebook web applications. B) The big problem is…
B) That's a support nightmare; it would be nearly trivial to start submitting false reports from a ton of accounts without establishing a pattern so those accounts could easily be ignored. Regardless, how do you prove that you "own an image" (what does that even mean?) and that it was reported as an "intimate photo" maliciously?
I agree that FB's current solution is really bad, and if it were me, I certainly wouldn't pro-actively send in photos of myself, but I'm at a loss for how they can address A & B.