Live data from Hacker News

Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

wired.com

221–230 of 407 posts

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#221
post #123

Earlier quoted context omitted.

> - It sets a precedent for uploading nude photos to FB and for them asking for it. Before we reduce this to a slippery slope, what scenario do you envision in which FB could coax its userbase to upload nude photos? I know the OP is about taking a selfie to prove existence. What would FB use as the basis to mandate the general user to send a self-nude? > You need to trust FB to delete the photos when they receive it.…

> Before we reduce this to a slippery slope, what scenario do you envision in which FB could coax its userbase to upload nude photos? The one where FB asks its userbase to upload nude photos[0]. [0] https://news.ycombinator.com/item?id=15651710

That's exactly the topic we're discussing now. Sorry, with "userbase" I meant "general userbase". This initiative they're proposing -- in coordination with a safety group in Australia -- is aimed at revenge porn victims. The general userbase of Facebook aren't in that group.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#222

Earlier quoted context omitted.

they can verify that after they have found a match. if there is no match you gave them no data of interest. if there is a match then they already have that image anyway and you didn't make your privacy situation worse, except maybe telling them that you claim that is you, now allowing them to associate more images was you, but that's probably an acceptable tradeoff if there is actual revenge porn of you out there.

It's not a simple hash. From Alex Stamos: “There are algorithms that can be used to create a fingerprint of a photo/video that is resilient to simple transforms like resizing.” That doesn't make it clear that they are making use of the powerful classifiers that Facebook has, but it's clearly not md5, either. Regardless, I think your point stands.

They could also combine locally computed perceptual hashes of the unwanted images with face recognition of already uploaded regular images on the profile. That combination makes it even less necessary to send nudes to facebook.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#223
I find their claim that the picture will be deleted from their servers at odds with their claim that they will make sure that photo is unique.

I suspect that what they're not saying is that they will keep some signature/hash/data about the photo, which I'm sure they will use for much more than just verifying uniqueness.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#224
post #123

Earlier quoted context omitted.

> - It sets a precedent for uploading nude photos to FB and for them asking for it. Before we reduce this to a slippery slope, what scenario do you envision in which FB could coax its userbase to upload nude photos? I know the OP is about taking a selfie to prove existence. What would FB use as the basis to mandate the general user to send a self-nude? > You need to trust FB to delete the photos when they receive it.…

> If the image is hashed before it reaches FB servers, then it gives every user the power and impunity to attempt to censor via a Content-ID like approach. Another commenter makes a good point that you could still have a human verify the first time a provided hash matches an image. In the current setup, there is a human that verifies the image to be hashed is a nude photo instead of the McDonald's profile picture. In…

The main obstacle that I can think of is: where does that hashing get done? Is it a feature that can efficiently be part of the phone app? Keeping in mind that this is a feature that would only be used by a very, very small part of the general userbase.

Let's assume that it is possible, the other issue that might come up is that the system is still suspect to a sort of denial of service attack, in which a group (for whatever reason) floods FB with purported sensitive images, and FB is flooded with constant takedown requests to review.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#225
post #97

Sure, Facebook might delete your photo when they're done, but they probably won't delete any machine learning models that they trained using it.

wording like this is really tricky (intentionally so!), it exploits our naive notion of digital information as files. One aspect is the machine learning you mention but basically they can also create a new "file" from your image with metadata about your image. Metadata rich enough to render the original image unnecessary. There is no way out of this relatiohship with FB, however they formulate words to comfort you, t…

The more data they keep about these images that they are promising to delete, the more they would make themselves liable to be sued for privacy violation (especially in the EU).

It is a blurred line, but one that most rational companies (=not Uber) would prefer to avoid in the first place by only storing data that is necessary for their main functionality.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#226
post #78

Earlier quoted context omitted.

There was a thread about this on HN -- too lazy to look it up now or repeat some of the longer comments about it. But going into this assuming that FB has no ill-intentions, FB's proposal seems by far the best solution in a world of ugly and terrible solutions. For starters, it's intended for victims of revenge porn, which is a fairly extreme category and one in which the harassment is distinctively aggressive and vi…

https://news.ycombinator.com/item?id=15651710 https://news.ycombinator.com/item?id=15648080 https://www.google.com/search?q=ycombinator+fb+revenge+porn > too lazy to look it up now People doing this frustrates me greatly. You had to type 30 key strokes. ⌘+t "ycombinator fb revenge porn" ↵ and paste the results back. How many people are going to read your comment? Maybe 10% of them want to read those links. You spared…

I sometimes misunderestimate how long it'll take me to write out my thoughts or how much time I'll have before I need to get back to work. By the time I finished my comment I realize I wrote enough for the comment to be a fleshed-out enough argument; anyone wanting to see those past threads could look them up if necessary. I guess I could have saved you some angst by jumping up to the top of my comment and removing the sentence about me being lazy.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#227
post #78

Earlier quoted context omitted.

There was a thread about this on HN -- too lazy to look it up now or repeat some of the longer comments about it. But going into this assuming that FB has no ill-intentions, FB's proposal seems by far the best solution in a world of ugly and terrible solutions. For starters, it's intended for victims of revenge porn, which is a fairly extreme category and one in which the harassment is distinctively aggressive and vi…

Open source a desktop and mobile tool that generates the image hash w/o the image leaving the device and have the code publicly reviewed seems like one potential approach.

Still vulnerable to duping users via App Store fakery: https://motherboard.vice.com/en_us/article/evbakk/fake-whats...

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#228
post #214

Earlier quoted context omitted.

A hash would only match an identical file, right? It sounds like image recognition is used here to catch derivatives of the original file, which a hash wouldn't catch.

I think it would be easy to create multiple hashes (reverse, flipped, etc...) and upload them all and look for matches. Provide the users with image recognition signature creating software (which is exactly what they are going to do) and let the users do it, vs uploading extremely personal and potentially embarrassing images to strangers on the internet.

How about recompressed, resized, photoshopped, format-converted... a filter against trivial transformations like transposition is worthless.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#230
post #183

Earlier quoted context omitted.

It applies to Europeans, even if they're not in Europe, and even if they don't identify themselves as being in Europe.

To correct your correction I'd like to add that far from every European country is a member of the EU.

He is saying that that law applies to EU citizens even when they are not located in the EU. Much more difficult then determining which country the user is connecting from.

Not sure if this is the law though

Post reply on HN