Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

131–140 of 276 posts

Re: Tainting the CSAM client-side scanning database

#131

Earlier quoted context omitted.

The general public submitting CSAM directly would indeed be highly unlikely, but the scenario we need to consider involves those in positions of authority who can manipulate systems behind the scenes. Imagine that an unflattering or satirical image of Viktor Orban is circulating in France, and let's say it becomes viral, inciting discussions that the Hungarian government finds detrimental to its international image.…

Won't that easily be found out when the hash matches the image of Viktor Orban rather than an image of CSAM. I'm not sure the legal system is as stupid as you think it is. Then Hungary would just have their hashes reviewed. Sure a conspiracy of all the relevant authorities across the whole EU would work, ... but that seems a stretch to enable what, political elites to _cooperatively_ censor images the public hold. Th…

The point is a real CSAM image can be manipulated such that when hashed it matches the hash of the Orban image. So your phone calls the police saying you have CSAM when you get the Orban image. Your life is ruined and you're financially impacted trying to defend yourself. Even if you're cleared of charges you're fucked. This now has a chilling effect on sharing of the Orban image.

Orban's people won't face any pushback because they submitted an actual CSAM image. It's on you to prove somehow they intentionally poisoned the CSAM image such that its hash matches the Orban image.

Re: Tainting the CSAM client-side scanning database

#132

Earlier quoted context omitted.

> I assume the answer to that will be that there is no need to differentiate between them. And honestly, I agree with that I disagree. The point is to reduce actual child abuse. The images are in a way only tangential. If an image is made with an AI with no actual child being abused, then it shouldn't be a crime. In a way, it's better , because it will distract the crowd of people into this sort of stuff from activit…

> because it will distract the crowd of people into this sort of stuff from activities that harm real people. This is actually the main point in dispute, and almost everyone arguing one side or the other on this topic seems to assume one side or the other on this point and argue from there, rather than seeking to support their position on the fundamental disputed fact question. Which results in the most of the debate…

This feels a bit like "cold reading", I think you're absolutely right, but for all I know you could have been intending to post that comment on half the other threads on the front page.

Re: Tainting the CSAM client-side scanning database

#133
post #63

Earlier quoted context omitted.

> I assume the answer to that will be that there is no need to differentiate between them. And honestly, I agree with that I disagree. The point is to reduce actual child abuse. The images are in a way only tangential. If an image is made with an AI with no actual child being abused, then it shouldn't be a crime. In a way, it's better , because it will distract the crowd of people into this sort of stuff from activit…

You may think that intuitively, but actual studies actually indicate the opposite. Usage of CSAM material leads to increased risks of contacting and abusing children. This needs to be balanced against rights to privacy and expression, which I personally think take precedence, but pretending that it can serve as harm reduction is just not correct.

Studies such as?

Re: Tainting the CSAM client-side scanning database

#134

Earlier quoted context omitted.

what is happening in Youtube world?

Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…

Wow what a mess. At what point do we move on from copyright laws? Or more broadly intellectual property, in general. Even the words "intellectual property" sound ridiculous together when you think about it.

Re: Tainting the CSAM client-side scanning database

#135
post #132

Earlier quoted context omitted.

> because it will distract the crowd of people into this sort of stuff from activities that harm real people. This is actually the main point in dispute, and almost everyone arguing one side or the other on this topic seems to assume one side or the other on this point and argue from there, rather than seeking to support their position on the fundamental disputed fact question. Which results in the most of the debate…

This feels a bit like "cold reading", I think you're absolutely right, but for all I know you could have been intending to post that comment on half the other threads on the front page.

Its certainly a common-enough phenomenon, what makes it specific to the topic is the specific factual disagreement relevant to this issue that people just assume a side on.

Re: Tainting the CSAM client-side scanning database

#136
[...] One could conclude that the abuse centre could thus easily spot the malicious entry in its database after a few of these reports all concerned with the same image, and delete the corresponding fingerprint from the database. If that were the case, this avenue of attack would not be a problem in practice. This assumes, however, that the abuse centre keeps track of such false positives over time to detect such maliciously uploaded fingerprints. This may or may not be the case.

Why would it not be the case, unless the abuse center wanted to waste time and resources and have unreliable records? This essay is technically sophisticated and socially naive. Tech people keep spinning up the most unlikely and hard-to-explain reasons for why leveraging technology to interfere with the spread of CSAM is bad, instead of working toward any kind of privacy-respecting solution to target CSAM itself.

Constantly emphasizing the scope for government intrusion and privacy violation (legit but at the same time overblown to the point of paranoia) and constantly minimizing or dismissing the real harms of CSAM is a great way to alienate the normal non-technical people you need to have on side.

Re: Tainting the CSAM client-side scanning database

#137

Earlier quoted context omitted.

what is happening in Youtube world?

Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…

That’s not what a hash collision is.

Uploading popular (public domain) music and claiming you own it is just fraud

Re: Tainting the CSAM client-side scanning database

#138

Earlier quoted context omitted.

Won't that easily be found out when the hash matches the image of Viktor Orban rather than an image of CSAM. I'm not sure the legal system is as stupid as you think it is. Then Hungary would just have their hashes reviewed. Sure a conspiracy of all the relevant authorities across the whole EU would work, ... but that seems a stretch to enable what, political elites to _cooperatively_ censor images the public hold. Th…

The point is a real CSAM image can be manipulated such that when hashed it matches the hash of the Orban image. So your phone calls the police saying you have CSAM when you get the Orban image. Your life is ruined and you're financially impacted trying to defend yourself. Even if you're cleared of charges you're fucked. This now has a chilling effect on sharing of the Orban image. Orban's people won't face any pushba…

I get people's opinions of law enforcement are low, but do you really think that no one would question why a huge number of people have a single CSAM image on their device especially when the hash for that image was just added to the database? Do you think that no one would question that maybe there is something wrong with that hash? Do you think that no one would look at the flagged image on any of those devices?

I understand people's concerns with this tech, but this seems like a rather silly hypothetical to me.

Re: Tainting the CSAM client-side scanning database

#139

Earlier quoted context omitted.

what is happening in Youtube world?

Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…

I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.

Re: Tainting the CSAM client-side scanning database

#140

Earlier quoted context omitted.

Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…

Wow what a mess. At what point do we move on from copyright laws? Or more broadly intellectual property, in general. Even the words "intellectual property" sound ridiculous together when you think about it.

If you think deeper about it, the general concept of property is similarly ridiculous too. An arbitrary piece of land being ‘owned’ is similarly arbitrary human social concept, enforced by law and a registry
Post reply on HN