Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

11–20 of 276 posts

Re: Tainting the CSAM client-side scanning database

#11
post #4
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

Also do not miss the recent good article about the US software development companies who are behind the lobbying of client-side scanning, how is this madness is being funded and by whom. https://balkaninsight.com/2023/09/25/who-benefits-inside-the...

Thanks - interesting. Phrases like this are eternally surprising:

> The same month, UK officials privately admitted to tech companies that there is no existing technology able to scan end-to-end encrypted messages without undermining users’ privacy

It's as though this is a secret that UK officials knew. Everyone technically minded knows this; it's a battle between those who regulate (the difficulty of whose job generally stops at "write down the rule and fine people if they don't do it") and those who know about current fundamental limitations.

Re: Tainting the CSAM client-side scanning database

#12

The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…

The general public submitting CSAM directly would indeed be highly unlikely, but the scenario we need to consider involves those in positions of authority who can manipulate systems behind the scenes.

Imagine that an unflattering or satirical image of Viktor Orban is circulating in France, and let's say it becomes viral, inciting discussions that the Hungarian government finds detrimental to its international image. The authorities might want to suppress this image, not just within Hungary but also in the whole of European Union.

The Hungarian government - who presumably has access to the EU CSAM database (or can coerce those who do), might attempt to add a fingerprint of a manipulated CSAM image that collides with the fingerprint of the satirical image. The principle here is not for public individuals to submit CSAM directly but for government actors to manipulate systems clandestinely.

Re: Tainting the CSAM client-side scanning database

#13
post #9

The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…

I guess it comes down to this black box list of hashes that no one would want to audit for pretty obvious reasons. The authority is only as good as the person paid to automate the hashing process feels that day. It’s not inconceivable that someone at the authority could put in an image known to be stored by someone else into the hash list just to cause an extremely scary and confusing month for that person. To be fai…

> I guess it comes down to this black box list of hashes that no one would want to audit for pretty obvious reasons. The authority is only as good as the person paid to automate the hashing process feels that day.

Isn't that exactly how it is run today, however? There are actual people at the National Center for Missing & Exploited Children who maintain the database and do in fact get incidentally exposed to the imagery. It's the one organization in the entire nation allowed to legally possess the actual images.

Re: Tainting the CSAM client-side scanning database

#14
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

And by next you mean in parallel. Spinning E2E encryption as a tool used only by bad actors is very common and pushing browsers to implement governments managed blacklists seems quite in progress. Banning VPNs from social networks (and more) was even suggested in France but quickly removed due to backlash.

Re: Tainting the CSAM client-side scanning database

#15

The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…

> You then submit the manipulated version of the found or generated image to the authority.

If this is easy (for some definition of easy), is it not easy to then alter the CSAM images every they trade it to another pervert, such that hashes never match? How much image alteration would that take?, would it be human perceptible? If perceptible, would it be ignorable?

I think the exploit here suggests that the whole system may end up obsolete sooner rather than later.

Re: Tainting the CSAM client-side scanning database

#16

The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…

[deleted]

Re: Tainting the CSAM client-side scanning database

#18
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

Governments will mandate by law that the OS do client side scanning by peeping inside the app directories. Apple, Google, Microsoft will comply and realistically, which phones and computers are we going to use if we don't buy from them? Desktop Linux might become illegal.

Re: Tainting the CSAM client-side scanning database

#19
post #6

Earlier quoted context omitted.

My understanding was that you generate a csam with a colliding fingerprint and put it online and trick somebody with an iPhone or whatever into clicking on it. Now they're on a watchlist and will get harassed by the police.

So you have to plant the manipulated csam somewhere that it'll be found by law enforcement and added to the database and just hope you did a good enough job to not be tracked?

Look if I want to host some white noise I can't be held responsible for what happens if people xor it together with some other file hosted elsewhere.

Re: Tainting the CSAM client-side scanning database

#20
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

Signal advises its users to install the app from the Play Store. While you can still get the .apk from Signal’s website, the developers warn against that. The EU can definitely exert pressure against what is hosted on the Play Store.

Telegram famously lacks end-to-end encryption (unless you intentionally use its private-chat feature, which few people do) and shouldn’t be mentioned in the same context as Signal.

Post reply on HN