Live data from Hacker News

Google Drive may restrict files identified as violating ToS

workspaceupdates.googleblog.com

241–250 of 269 posts

Re: Google Drive may restrict files identified as violating ToS

#241
post #237

Earlier quoted context omitted.

Fucking hell, voluntarily running scans on your computers for CSAM? Are you going to voluntarily get a brain wave scan for whether you have anti-patriotic thoughts?

The choice isn't between scans and no scan. It's between voluntary scans (which can be white box and controlled) and involuntary scans (which are black box and totally uncontrolled).

That's silly; voluntary scans aren't voluntary if they're to work, and no scans is always an option. Human decisions to do things one way or another have never been set in stone.

Re: Google Drive may restrict files identified as violating ToS

#243
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

> ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine".

How does someone who doesn't know me determine that it's my kids in the bathtub? (The answer can't be "you have to submit other pictures of your kids" because if I can get pictures of random kids in a bathtub, I can probably get other pictures of said kids.)

Re: Google Drive may restrict files identified as violating ToS

#244

Earlier quoted context omitted.

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

This ended up being a longer post than I intended, but overall I think your entire idea is fundamentally flawed, requires taking control of a computer away from the owner, and wouldn't even solve the issue. > to voluntarily run a CSAM scan on our systems The results of such a scan are meaningless to anybody who doesn't control the computer that performed the scan. If these results are to be trusted by authorities, th…

>There aren't. There really, really aren't. You can only trust computers that you control, or that are controlled by people that you trust. Trying to implement these leads to obscenities such as the Clipper Chip, Sony's rootkit, ring-0 DRM, and so on. Every single one takes control of the computer away from the owner and gives it to somebody else.

And even then it won't work. Video games are a great example: a lot of annoyance is caused by cheaters. Games have been ruined by cheaters. And yet there exists no solution that gets rid of them. Even LAN tournaments in CSGO have had an aim botter at a high level. The hardware they use is provided on location, but the players bring their own mouse and keyboard. In the case of CSGO the mouse had an aim bot on it.

Re: Google Drive may restrict files identified as violating ToS

#245
post #237

Earlier quoted context omitted.

Fucking hell, voluntarily running scans on your computers for CSAM? Are you going to voluntarily get a brain wave scan for whether you have anti-patriotic thoughts?

The choice isn't between scans and no scan. It's between voluntary scans (which can be white box and controlled) and involuntary scans (which are black box and totally uncontrolled).

No, the choice is indeed between scans and no scans.

Re: Google Drive may restrict files identified as violating ToS

#246

Earlier quoted context omitted.

Similarly: Google Forms being used for phishing, Google Calendar invite spam... I've even heard of Google Photos being used for spam (by "sharing" photos, or by posting photos with text as the target of a spam campaign). Spammers ruin everything.

They truly do. And it doesn't even have to be many spammers, it only really takes one person to ruin a free service. I've had plenty of personal projects I had to shut down due to some random person who just decided to hammer my servers for no reasons. I block the IP or IP block and they get more. I put Captcha (HN always complains about it but this is why it's often needed...), and users (who pay nothing) complain t…

Same experience here, one spammer DOSing my site, always with similar patterns. I'm already behind Cloudflare and use https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blo... but I still have to identify and block them manually, which is annoying and a waste of time. Some IP-range blocks affected users so it's not fine grained enough. I wish I could identify, expose and sue them into oblivion, but the internet is too international and anonymous for this to be feasible. I also had to limit some site functionality because of this.

Re: Google Drive may restrict files identified as violating ToS

#247
post #85

We need a distributed volunteer backed free replacement. Is IPFS or gnunet ready for that yet?

"We need a distributed volunteer backed free replacement. Is IPFS or gnunet ready for that yet?" Or you could just choose a provider who respected your privacy and had a very long history of standing for freedom of speech and the rights of users. If only such a provider existed. If only ...

Nextcloud

Re: Google Drive may restrict files identified as violating ToS

#248
post #226

The join over {IPR theft, AI, censorship and "think of the children"} is a strong reinforcing superset of all of the motivations here. CSAM opened the door to a conversation but we're a long way down the road to cloud backed storage being a gatekeeper not just a storage space. In my cloud or on my device, it's being looked at. What's missing is arbitration via neutral mediator. The contracts are written to favour the…

There is hope, and there will be fumbles on the way I think. The real solution is for us all to voluntarily run a CSAM scan on our systems that can trigger a notification to a nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine". We would subscribe to updates to a CSAM…

What a massively invasive system just to find pre-registered images and not prevent abuse at all...

Re: Google Drive may restrict files identified as violating ToS

#249

We need “dumb” infrastructure again, that you can simply pay for with few strings attached, where the provider cannot fiddle with things at all, leaving enforcement to other authorities. We build roads; yes, those roads might be used to transport stolen goods but the road builder doesn’t get to sit there and inspect every vehicle (and accuse the wrong people sometimes and ban them from driving). It’s just so damned c…

I've again started using a usb-c thumb drive in place of google drive. It's extremely convenient and safe from big brother eyes.

Re: Google Drive may restrict files identified as violating ToS

#250

Earlier quoted context omitted.

No don't do that, this is exactly why IT/opsec is hated in organizations. False positives.

I have so far seen a single instance where a legitimate organization sent someone a storage.googleapis.com URL. I have seen literally hundreds of phishing emails do it. Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them. And probably Google should be doing a better job policing content on their content domains if they don't want them to be blocked by defau…

Why don't you use a vendor that provides the concrete URLs as IOCs to block?
Post reply on HN