Live data from Hacker News

Google Drive may restrict files identified as violating ToS

workspaceupdates.googleblog.com

231–240 of 269 posts

Re: Google Drive may restrict files identified as violating ToS

#231
post #194

Earlier quoted context omitted.

The storage owner can have a terms of service - i.e. you can't store flammable material/liquids. They also probably reserve the right to enter your unit to perform repairs.

Right, and to keep this analogy consistent, do storage owners routinely open all storage units, then open up all your boxes and search through them to check for flammables?

They don't give out free storage. If you aren't paying with money you're paying with something else and you have no expectation of privacy when you agree to terms that say as such.

Re: Google Drive may restrict files identified as violating ToS

#232

Earlier quoted context omitted.

No don't do that, this is exactly why IT/opsec is hated in organizations. False positives.

I have so far seen a single instance where a legitimate organization sent someone a storage.googleapis.com URL. I have seen literally hundreds of phishing emails do it. Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them. And probably Google should be doing a better job policing content on their content domains if they don't want them to be blocked by defau…

> Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them.

Blocking this domain definitely isn't common, at least not in large organizations. Several of my company's B2B apps use Google Cloud Storage (it's just Google Cloud's version of S3) and have always used storage.googleapis.com/bucketname rather than bucketname.storage.googleapis.com. (AFAIK it was the default URL format shown in their documentation when I last looked at it years ago.)

We've had to deal with overzealous corporate web filters now and then - comes with the territory of B2B apps - but I've never heard of storage.googleapis.com being blocked. It'd be pretty straightforward for us to change it if a customer had trouble, but we'd probably gently push back and ask them to whitelist the domain before doing so.

Re: Google Drive may restrict files identified as violating ToS

#233
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine".

We would subscribe to updates to a CSAM scanning corpus which would parameterize the scan. The whole thing requires "trusting the client" but I bet there are ways to make it work. If it would defuse this movement toward total black box checking of content, then I think it's worth it to voluntarily do this kind of scan. The effectiveness presumes that the intersection of child porn consumers and users sophisticated enough to disable a scan like the one I'm imagining is very small.

Re: Google Drive may restrict files identified as violating ToS

#234
post #2

Google says you can request a review if you believe something should not have been flagged as a ToS violation but no mention is given to any rights you have. To me this reads as "You can request whatever you want but it might not mean anything in reality.": https://support.google.com/docs/answer/2463328 Conversely, the information for how to report what you perceive as a ToS violation is far more complete: https://su…

[deleted]

Re: Google Drive may restrict files identified as violating ToS

#235
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

You're modelling the compliance for good people. Threat and risk analysis has to model for bad actors. Your solution won't work because bad actors exist and will exploit it.

Re: Google Drive may restrict files identified as violating ToS

#236
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

Why should we run a scan on ourselves? Why should we be treated as a criminal for doing nothing wrong? The solution is to vote out anyone who thinks this is a good idea. To not support any company who tries to implement this kind of technology. It is absurd to think people will give up their rights to privacy in their homes to accommodate this kind of idea. Encryption is math and won’t be stopped. People will find a way to hide what they need any any of these systems only effects the non criminal user. Also I have hundreds of pictures of my kids in the bath. I always try and not get their private parts in the picture but with my hundreds and millions of people potentially with the same numbers it really is not possible for a human to lay eyes on that many pictures. Also that would itself open up avenues for abuse say it was just an innocent picture of my kids butt their are perverts out there that will get off on this. They are private photos of my family enjoying their youthfulness in a bathtub and never will I consent to someone browsing my private photos. This just seems whack.

Re: Google Drive may restrict files identified as violating ToS

#237
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

Fucking hell, voluntarily running scans on your computers for CSAM? Are you going to voluntarily get a brain wave scan for whether you have anti-patriotic thoughts?

Re: Google Drive may restrict files identified as violating ToS

#238
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

How about no? I don't view CSAM, and I don't need to voluntarily run a scan to prove I don't.

Re: Google Drive may restrict files identified as violating ToS

#239
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

This ended up being a longer post than I intended, but overall I think your entire idea is fundamentally flawed, requires taking control of a computer away from the owner, and wouldn't even solve the issue.

> to voluntarily run a CSAM scan on our systems

The results of such a scan are meaningless to anybody who doesn't control the computer that performed the scan. If these results are to be trusted by authorities, that implies that we no longer control the computers that you are describing as "our systems".

> nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine".

Wait, wait, wait. So the response to finding suspected CSAM would be to make a copy of it, then to deliver that copy TO OTHER PEOPLE OVER THE INTERNET!? Every single study about Facebook's CSAM reviewers shows it to be an emotionally damaging job, because you're constantly shown psychologically damaging material. With that in mind, who do you think would volunteer to be on such a review board?

> We would subscribe to updates to a CSAM scanning corpus

This introduces an unnecessary failure mode to devices whose core functionality does not require internet access. If I have a digital camera, a tv, or a picture frame, those fundamentally do not require internet access. Given the prevalence of targeted advertising and surveillance of customers, any device requesting internet access should be viewed with immediate suspicion.

> The whole thing requires "trusting the client" but I bet there are ways to make it work

There aren't. There really, really aren't. You can only trust computers that you control, or that are controlled by people that you trust. Trying to implement these leads to obscenities such as the Clipper Chip, Sony's rootkit, ring-0 DRM, and so on. Every single one takes control of the computer away from the owner and gives it to somebody else.

> defuse this movement toward total black box checking of content

Your suggestions would require implementing a black box checking of content, running on my computer, and not under my control. Calling it "voluntary" in the sales pitch makes it useless, because the person who controls the computer can disable any reports from it.

> presumes that the intersection of child porn consumers and users sophisticated enough to disable a scan like the one I'm imagining is very small

The size of the intersection doesn't matter, because only a single person needs to write a script that disables the scan. In addition, if a scan requires sophistication to disable, that implies that it is an opt-in scan, and that goes against your sales pitch as "voluntary".

Re: Google Drive may restrict files identified as violating ToS

#240
post #237

Earlier quoted context omitted.

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

Fucking hell, voluntarily running scans on your computers for CSAM? Are you going to voluntarily get a brain wave scan for whether you have anti-patriotic thoughts?

The choice isn't between scans and no scan. It's between voluntary scans (which can be white box and controlled) and involuntary scans (which are black box and totally uncontrolled).
Post reply on HN