Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

91–100 of 276 posts

Re: Tainting the CSAM client-side scanning database

#91

Earlier quoted context omitted.

Notifications generally go through Google Firebase so by not running private messages through firebase they avoid potential leaks. At least that's my guess

A common way around this is to simply send a notification through Firebase/other push notification mechanism that tells the app there is a new message. The app can then retrieve the message and decrypt it. Most of them will then update the notification shown to the user with the full message content.

Maybe the concern is that Firebase still learns that user A and user B receive notifications back and forth at around the same time, interspersed with periods of no notifications for both

If A and B talk regularly, there might not be many other C who by coincidence exchange notifications at the same time

So you might be vulnerable to a sort of traffic analysis

Re: Tainting the CSAM client-side scanning database

#92
post #53

Earlier quoted context omitted.

I assume the answer to that will be that there is no need to differentiate between them. And honestly, I agree with that argument. Possession of CSAM should be illegal regardless of whether it's "real" or not. But the proposed scanning system is the wrong solution, regardless of any "real or AI" ambiguity, because it's possible to generate false positives with nonsense images that aren't even close to the expected CS…

> Possession of CSAM should be illegal regardless of whether it's "real" or not. From a purely ethical standpoint: why? What is the purpose of punishing someone who has harmed no one? No victim means no crime.

There are plenty of "victimless" crimes that society deems unsavory and punishes. e.g. smoking pot in your home, alone is a crime in a lot of jurisdictions, even though clearly no-one is harmed.

In a lot of jurisdictions the decision has been made, whether it is right or wrong, to criminalize AI CSAM. The people have spoken and the lawmakers have made the laws. If you or I think that is wrong then the options are to lobby for a change.

Re: Tainting the CSAM client-side scanning database

#93

Earlier quoted context omitted.

I agree with you. I think our disagreement here is over the level of innocence of someone possessing AI generated CSAM. If you believe, as I do, that such a person is guilty of a crime, then we're not risking the false guiltiness of an innocent person. At best, we're risking their level of sentencing. And I'm open to the idea of reduced sentences for AI CSAM, but it shouldn't be a factor in determination of guilt (i.…

> I think our disagreement here is over the level of innocence of someone possessing AI generated CSAM. > If you believe, as I do, that such a person is guilty of a crime, You just explicitly said upthread that ethically they are not, but argued that it is useful for them to be treated as criminals because it denies an excuse to those who are ethically guilty because they are possessors of genuine CSAM. You seem to b…

My ethical premise is that there is no direct victim of AI generated CSAM, but that it's worth criminalizing because otherwise it further victimizes victims of existing law. In other words, there is a societal victim of it. To me it's the same ethical premise but interpreted within two different frameworks: one that's purely idealistic, and one that's based in practical reality.

Re: Tainting the CSAM client-side scanning database

#94
post #69

Earlier quoted context omitted.

And I absolutely want both parties to have to prove crime/innocence and have an opportunity to argue. The current situation, where anything involving CSAM is so toxic that lives are ruined without trial is not healthy and isn't good for anybody

Point of order: victims are not "parties" in criminal cases, not in remotely modern legal systems. The parties are the accused and the state. For the same reason, victims don't get to pardon crimes committed against them. ... which is the way it should be, because criminal punishment should not be seen as a form of revenge, but as a deterrent.

Right. Most crimes are essentially ones that "the people" found unsavory.

For instance, there is no "victim" if I got caught enjoying cannabis in my own home in a jurisdiction where such a thing is illegal, but "the people" have made a decision that they don't like it and I should be punished for committing an anti-social act.

That is one of the fundamental aspects of democracy at work.

Re: Tainting the CSAM client-side scanning database

#95
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

> The EU bureaucrats do not have power to magically insert spyware in our devices as long as we can install our own software.

EU bureaucrats have power to force ISPs to block connections to the messengers that would not comply, Chinese-style. They already do block websites they don't like - e. g. in Cyprus local provider CYTA shown me "access blocked due to EU comission regulation #whatever" for most of the Russian media sites.

Re: Tainting the CSAM client-side scanning database

#96
post #53

Earlier quoted context omitted.

> Possession of CSAM should be illegal regardless of whether it's "real" or not. From a purely ethical standpoint: why? What is the purpose of punishing someone who has harmed no one? No victim means no crime.

There are plenty of "victimless" crimes that society deems unsavory and punishes. e.g. smoking pot in your home, alone is a crime in a lot of jurisdictions, even though clearly no-one is harmed. In a lot of jurisdictions the decision has been made, whether it is right or wrong, to criminalize AI CSAM. The people have spoken and the lawmakers have made the laws. If you or I think that is wrong then the options are to…

> There are plenty of "victimless" crimes that society deems unsavory and punishes.

That is not an argument against the concept that that should not be the case.

Re: Tainting the CSAM client-side scanning database

#97
post #27

Earlier quoted context omitted.

Signal advises its users to install the app from the Play Store. While you can still get the .apk from Signal’s website, the developers warn against that. The EU can definitely exert pressure against what is hosted on the Play Store. Telegram famously lacks end-to-end encryption (unless you intentionally use its private-chat feature, which few people do) and shouldn’t be mentioned in the same context as Signal.

If you enable private chat, you don't get notifications for new messages, that way the feature is self defeating, it seems to me at least. (Something could also have gone wrong?)

I don't have problems with notifications for secret chats ?

Re: Tainting the CSAM client-side scanning database

#98

Earlier quoted context omitted.

From a purely ethical standpoint, sure, I agree. But we live in reality, and there are plenty of activities that seem ethically victimless, but are practically necessary to criminalize, in order to uphold societal frameworks and expectations of morality. In this case, by giving every CSAM criminal a potential excuse that they "thought it was AI generated," the real victims are further victimized by being deprived of…

Broadening the definitions of crime to make it easier to punish the ethically guilty on scant evidence while incidentally sweeping up the ethically innocent is a hack around a legal tradition that is designed exactly on the principal that it is better that the guilty go unpunished than the innocent are punished, by making the genuinely innocent administratively guilty, and we ought to reject that kind of justificatio…

Broadening the definition of a crime isn't exactly unheard of.

To choose a less emotional subject, mattress tags.

The ethical reason for mattress tags is because historically people would sell mattresses stuffed full of all sorts of unsavory garbage. What we actually criminalized, or at least were trying to prevent, was some sort of fraud or public endangerment.

But we also along the way made it illegal for sellers to remove the tags from mattresses.

Removing the tag isn't inherently harmful; if you don't deceive the purchaser on the contents of the mattress, it's not even fraud.

But we broadened the definition of the crime to make it easier to enforce.

Re: Tainting the CSAM client-side scanning database

#100
post #2

Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…

The EU is trying to make it mandatory to allow sideloading. This is bad, but also the opposite of what you are saying.
Post reply on HN