Tainting the CSAM client-side scanning database
1–10 of 276 posts
Re: Tainting the CSAM client-side scanning database
#2People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureaucrats do not have power to magically insert spyware in our devices as long as we can install our own software.
… which of course means we know what’s going to come next.
Re: Tainting the CSAM client-side scanning database
#3When the allegation is as serious as CSAM, I would rather be very very certain before accusing someone, rather than taking a shotgun approach and just randomly searching phones. But what do I know.
Re: Tainting the CSAM client-side scanning database
#4Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…
https://balkaninsight.com/2023/09/25/who-benefits-inside-the...
Re: Tainting the CSAM client-side scanning database
#5First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to be authorized law enforcement, no? Like if an ordinary citizen showed up with csam the excuse "oh I found this JPEG in a trunk in my late grandpa's attic" isn't gonna fly.
My assumption is that the central authority that compiles the database isn't just taking fingerprints, they want the actual source images. And I'm assuming they actually look at them to ensure they are, in fact, csam. Otherwise anyone could put anything into the database.
Now let me be very clear: I hate the idea of my device scanning for csam on principle. But what's the attack here? That someone looks at my device and determines that I do not, in fact, have csam? And that false positive might even be investigated and reveal that the bad actor sought out or generated CSAM for the purposes of perpetrating this! Which is even worse!
If the police want to look at your device, they can do that already through any number of other sketchy means that don't involve what's likely weeks of effort. The US searches phones at the border when they're feeling like it. I don't want to defend this stuff, but the potential for abuse in this specific case seems vanishingly small.
Re: Tainting the CSAM client-side scanning database
#6The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…
Re: Tainting the CSAM client-side scanning database
#7Re: Tainting the CSAM client-side scanning database
#8The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…
My understanding was that you generate a csam with a colliding fingerprint and put it online and trick somebody with an iPhone or whatever into clicking on it. Now they're on a watchlist and will get harassed by the police.
Re: Tainting the CSAM client-side scanning database
#9The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…
It’s not inconceivable that someone at the authority could put in an image known to be stored by someone else into the hash list just to cause an extremely scary and confusing month for that person.
To be fair, that’s also the same problem of say, someone at your ISP dislikes you. There’s always a chance your supplier has a “bad apple”. Maybe it’s not an issue but I get the idea.
Re: Tainting the CSAM client-side scanning database
#10Earlier quoted context omitted.
My understanding was that you generate a csam with a colliding fingerprint and put it online and trick somebody with an iPhone or whatever into clicking on it. Now they're on a watchlist and will get harassed by the police.
So you have to plant the manipulated csam somewhere that it'll be found by law enforcement and added to the database and just hope you did a good enough job to not be tracked?