Didn’t the UK just blink when chat apps said hell no we will leave instead? Does the EU expect to get better results? Apple has very publicly come out and said that their proposal like this was a bad idea and I’d expect Signal to also not comply, the only remaining question is whether WhatsApp would threaten to leave again.
Tainting the CSAM client-side scanning database
151–160 of 276 posts
Re: Tainting the CSAM client-side scanning database
#152It says: > This shows that the database can be tainted with non-CSAM material by an entity that can submit entries to it. Actually, it can easily be tainted by anybody . Take your massaged hash-colliding image, which remember is still visually child porn , and post it on some pedos-R-us forum. The people who maintain the database actively troll those forums. They'll see the image and add the hash to the database for…
[flagged]
It sure sounds like a bad idea for you or I to do, but would be it be a bad idea for $HOSTILE_NATION's intelligence agency? What about domestic intelligence agencies?
Re: Tainting the CSAM client-side scanning database
#153Earlier quoted context omitted.
The point is a real CSAM image can be manipulated such that when hashed it matches the hash of the Orban image. So your phone calls the police saying you have CSAM when you get the Orban image. Your life is ruined and you're financially impacted trying to defend yourself. Even if you're cleared of charges you're fucked. This now has a chilling effect on sharing of the Orban image. Orban's people won't face any pushba…
I get people's opinions of law enforcement are low, but do you really think that no one would question why a huge number of people have a single CSAM image on their device especially when the hash for that image was just added to the database? Do you think that no one would question that maybe there is something wrong with that hash? Do you think that no one would look at the flagged image on any of those devices? I…
Yes, the database maintainers would notice, but it could take them a while to get around to it. And they're not going to be eager to remove a collision, because that would effectively "legalize" the child porn member of the image pair. There are lots of images that could be useful to suppress temporarily.
And if you actually succeed in suppressing the false-positive image, it may not get passed around very fast, and it won't get vastly more hits than real target images, so it will take longer for anybody to notice or care.
There's also a possible end game where the child porn traders start perturbing their images to collide with really common images like flags, corporate logos, iconic movie stills, and whatever else. So now you either have to ban the US flag, or let this or that actual child porn image go.
I don't actually think that the false hits would ruin very many lives in most places. But it's worth noticing that the original article was talking about authoritarian regimes repurposing the system without the consent of the database maintainers. In the Orbán example, it's possible that the system might flag you for child porn, but you might actually get arrested for sedition. And that continues to happen to people until the database maintainers pull the hash.
Re: Tainting the CSAM client-side scanning database
#154The logical conclusion is that someone is going to get a knock on their door and a warrant for search because of an unknown signature match on a file some where at some point?
And people seriously think this will stop at being “for the children”?
Re: Tainting the CSAM client-side scanning database
#155Re: Tainting the CSAM client-side scanning database
#156Earlier quoted context omitted.
> Possession of CSAM should be illegal regardless of whether it's "real" or not. From a purely ethical standpoint: why? What is the purpose of punishing someone who has harmed no one? No victim means no crime.
Plenty of actions are crimes without real victims. Not having insurance while driving is an example. Possession of explosives is another one.
To put it another way, consider a thought experiment where a police officer generates CSAM with AI and then sells it to someone who thinks it's a real picture of a real victim. We should arrest the buyer, right? They thought they were committing a crime.
Re: Tainting the CSAM client-side scanning database
#157I think it's pretty clear this is not about "CSAM", we have to stop using the term. It's just censorship, plain and simple. Client side means you'll pay from your own pocket for this wrongthing detector to work. It can even be automated so as soon as the detector gets triggered by anything, you'll get locked out of your bank accounts, until further notice I guess. If this thing gets a serious discussion in a parliame…
But parliament wants to seed your camera with mugshots of the FBI's top-ten most wanted list so the instant a false positive appears (directly on the camera, potentially even prior to writing the image to disk, potentially even prior to pressing the snapshot button)... they beacon an alert (or exfiltrate piggybacking via Bluetooth/AirTag/Covid exposure tracking mrchanisms), and bob's you're uncle.
Re: Tainting the CSAM client-side scanning database
#158The article considers "an entity that is allowed to propose new entries to the CSAM database". You don't even need this! You could target a whole "social cluster" of people without having any special privileges within this system. As an example, lets say you want to attack environmental protesters. For image A, you create a meme about climate change. For image B, you procure something that looks, to humans, like CSAM…
Re: Tainting the CSAM client-side scanning database
#159Earlier quoted context omitted.
AI cannot generate CSAM, because AI cannot abuse children. AI makes fictional images, which definitionally cannot be images of child sexual abuse. There is literally no victim of any kind, even conceptually, in the case of computer generated imagery. It should be protected artistic expression.
What if a police officer generates some AI CSAM and then sells it to someone who thinks it's real? There's still "no victim," but the buyer thinks that there was. Are they guilty of a crime? Your logic would seem to imply that there's no crime with possession of real CSAM either, and that the only crime lies with the original abuser who took the pictures.
Unless there is a very specific "attempt to acquire CSAM" law then no they're not fucking guilty of any crime. If you live in a state where marijuana is illegal and you smoke some oregano because you thought it was marijuana you're not guilty of actually possessing marijuana.
A criminal law is composed of a number of individual statutes. When a state is trying to prosecute someone for a crime they need to prove three elements for each statute: the criminal act (actus reus), intent (mens rea), and the concurrence of both of those.
If a cop sells you oregano and you think it's marijuana you might have the intent to buy marijuana but there's no actual criminal act because oregano isn't illegal. If you make a law that only requires intent then congratulations, you've created thought crimes.
If you want to make entirely fake CSAM possession illegal, that's essentially the same as an intent-only law and creates thought crimes. It's a slippery slope.
Re: Tainting the CSAM client-side scanning database
#160Earlier quoted context omitted.
>The Hungarian government - who presumably has access to the EU CSAM database (or can coerce those who do), might attempt to add a fingerprint of a manipulated CSAM image that collides with the fingerprint of the satirical image. Then what? What does that achieve? There would be a huge spike in images identified as CSAM which would obviously throw up red flags. It seems like this would mostly just be headache for the…
One idea would be for the government of Hungary to create a list of its citizens that share this inciting, dangerous or whatever you you wanna call it material. If they keep on finding the same persons distributing multiple times, they may pay them a visit, get them fired from their government job, block their bank accounts, put them on the no-fly list or whatever. And that’s just one idea, probably there’s others.