Earlier quoted context omitted.
> I assume the answer to that will be that there is no need to differentiate between them. And honestly, I agree with that I disagree. The point is to reduce actual child abuse. The images are in a way only tangential. If an image is made with an AI with no actual child being abused, then it shouldn't be a crime. In a way, it's better , because it will distract the crowd of people into this sort of stuff from activit…
> because it will distract the crowd of people into this sort of stuff from activities that harm real people. This is actually the main point in dispute, and almost everyone arguing one side or the other on this topic seems to assume one side or the other on this point and argue from there, rather than seeking to support their position on the fundamental disputed fact question. Which results in the most of the debate…
Tainting the CSAM client-side scanning database
161–170 of 276 posts
Re: Tainting the CSAM client-side scanning database
#162Earlier quoted context omitted.
Wow what a mess. At what point do we move on from copyright laws? Or more broadly intellectual property, in general. Even the words "intellectual property" sound ridiculous together when you think about it.
If you think deeper about it, the general concept of property is similarly ridiculous too. An arbitrary piece of land being ‘owned’ is similarly arbitrary human social concept, enforced by law and a registry
Re: Tainting the CSAM client-side scanning database
#163Earlier quoted context omitted.
Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…
That’s not what a hash collision is. Uploading popular (public domain) music and claiming you own it is just fraud
The CSAM detection isn't proper hash collision either, in so far as I understand it. There's some fuzzy matching formula that generates the fingerprint, it's not simply a byte for byte hash taken of the image, and therein lies the comparison.
The fraud in question is reliant on content ID attempting to fuzzy match audio content, in this specific instance.
Re: Tainting the CSAM client-side scanning database
#164I however have precisely zero concerns about impersonating hashes:
1. It's trivial to deal with tainting the database: both secondary hashing and more invasive hashes deal with that problem.
2. It's trivial to deal with impersonated hashes, all positives can be scanned on device in a second round with a different hash method. Those which are still positive can have be checked off device in an automated, yet privacy preserving, way such as by sending a low resolution crop with faces blurred to a system that does a likeness check against the matched CSA image: only the real image will bear likeness.
3. These systems have undisclosed minimums. A person sharing CSAM will be generating positive results at a significant rate. Receiving a few images with faked hashes won't set off alarms, and if a victim is suddenly receiving hundreds of images, that would already be obvious.
4. These articles over sensationalise what occurs when a positive match is found. They vaguely gesture to serious consequences from a single match. In reality even without secondary automated checks, the false positive will be noticed by a human and then discarded. If a person is receiving a lot of false positives that may lead to the individual being informed that they are begin targeted.
Overall the idea of scanning chat content seems ineffective, for much of the same reasons why it's ineffective to ban end-to-end encrypted chat: those with criminal intent will just use something else or roll their own.
Re: Tainting the CSAM client-side scanning database
#165Earlier quoted context omitted.
I get people's opinions of law enforcement are low, but do you really think that no one would question why a huge number of people have a single CSAM image on their device especially when the hash for that image was just added to the database? Do you think that no one would question that maybe there is something wrong with that hash? Do you think that no one would look at the flagged image on any of those devices? I…
It's really about preventing images from circulating. Yes, the database maintainers would notice, but it could take them a while to get around to it. And they're not going to be eager to remove a collision, because that would effectively "legalize" the child porn member of the image pair. There are lots of images that could be useful to suppress temporarily . And if you actually succeed in suppressing the false-posit…
They may not know it immediately, but the actual CSAM image wouldn't actually be shared in any real numbers which removes much of the concern with "legalizing" the image. You can argue this makes this system ineffectual, but that also means this isn't repeatable since weakening the impact of this system would quickly result in Hungary losing the power to add hashes to the database.
>And if you actually succeed in suppressing the false-positive image, it may not get passed around very fast, and it won't get vastly more hits than real target images, so it will take longer for anybody to notice or care.
Who is sharing the real target image? Is Hungary now an active creator and distributor of actual CSAM in addition to manipulating the database?
>There's also a possible end game where the child porn traders start perturbing their images to collide with really common images like flags, corporate logos, iconic movie stills, and whatever else. So now you either have to ban the US flag, or let this or that actual child porn image go.
Once again, this behavior would get Hungary booted pretty quickly. Also it is important to remember these are hashes. Not all images of the US flag would trigger the system only that specific image that has a hash collision.
>I don't actually think that the false hits would ruin very many lives in most places. But it's worth noticing that the original article was talking about authoritarian regimes repurposing the system without the consent of the database maintainers. In the Orbán example, it's possible that the system might flag you for child porn, but you might actually get arrested for sedition. And that continues to happen to people until the database maintainers pull the hash.
But this isn't a closed system within that authoritarian regime. It leaves bread crumbs of this behavior out for everyone to see. If Hungary is going to arrest people on made up charges, they can do that anyway.
I just think this in a complicated and ineffectual bullet that can only be fired once because it has a fingerprint of the person who fired it. That adds up to make this type of abuse less of a worry.
Re: Tainting the CSAM client-side scanning database
#166Earlier quoted context omitted.
Wow what a mess. At what point do we move on from copyright laws? Or more broadly intellectual property, in general. Even the words "intellectual property" sound ridiculous together when you think about it.
>Even the words "intellectual property" sound ridiculous together when you think about it. For this reason, many would suggest not using it. It's a vague way of combining the separate issues of copyright, patents, and trademarks. It also illegitimately tries to equate those things to property, which changes how many feel about it. https://www.gnu.org/philosophy/words-to-avoid.html#Intellect...
Re: Tainting the CSAM client-side scanning database
#167IFL these threads always give vibes like, "oh, thank god that anti CSAM measure wouldn't actually work".
I think that some people are terrified that their (possibly AI generated) "loli pictures" would be caught by a scanner.
Because the database can't be audited by anyone but a select group we have to trust that it only contains actual bad images. I do not trust that such databases don't also contain images that are embarrassing to powerful/connected people. I also do not trust such databases don't contain false positives.
The sort of people that are super zealous about a topic aren't simultaneously super rational and objective about that topic. There's a non-zero probability that those databases contain lewd yet entirely legal images that the submitters just didn't like.
Because of the false positive rate a photo of my dog might trigger an alarm and then my phone sends an automated message to the police. I'm then told by proponents there will be some manual review. I have to then hope that the local DA doesn't have an election coming up and wants to push a "tough on crime" message so charges me with a crime despite a review.
In short these scanning systems require far too much unearned trust. They also present a slippery slope thanks to the incendiary nature of the topic. Today it's CSAM but what undesirable content will the systems be used for tomorrow? Such systems require trust in the stewards of today and tomorrow. Do you want people of the opposite ideology to you in charge of such systems? Do you trust they'll never be abused? Do you trust well meaning people never make mistakes?
I do not trust in any of those things. I'm not worried about myself doing actual bad things, I'm worried that demonstrable false positive rates will ruin my life with the mere accusation of doing something bad.
Re: Tainting the CSAM client-side scanning database
#168[...] One could conclude that the abuse centre could thus easily spot the malicious entry in its database after a few of these reports all concerned with the same image, and delete the corresponding fingerprint from the database. If that were the case, this avenue of attack would not be a problem in practice. This assumes, however, that the abuse centre keeps track of such false positives over time to detect such mal…
yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities.
however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating.
CSAM is a propaganda word:
1. right wing uses it to push their agenda of punishing people for having sex
2. left wing uses it to push their agenda of punishing males or kulaks or whatever
3. police use it to make it look like they're solving a crime so they can get paid for nothing: they can arrest someone for looking at a nude picture of a 17 year old (which the suspect is often unaware of), then in the media and police statements: "he was arrested for the possession of child sexual abuse material". and this is the majority of convictions: people (and even teens) being into teens.
people are not naturally sexually attracted to children (13 and under) in more than say 0.0001%.
so now that we actually looked at the subject beyond the taboo veil, it seems the discussion is just to stop 14-17 year olds from having sex, which is insane and does not justify one single thing that police do about it. CP being illegal is just completely out of the question. we should be debating re legalizing CP, or changing it to 13 and under at the very least (i don't see any harm in the existence of porn of any age since it does not encourage abuse since most people will not become sexually attracted to children no matter how much you expose them to it).
so again, your rhetoric is pure cancer. i don't need a "privacy respecting solution to CSAM". what the hell do you think that would be? do we also need a freedom respecting solution to the murder problem? would you have my legs cut off and say i should just order door dash?
Re: Tainting the CSAM client-side scanning database
#169Earlier quoted context omitted.
Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…
I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.
But there are penalties for false claims. There is a fine for claiming copyright you don't own, and if you go further and ask for takedowns, you are also liable for damage.
The problem is that these are rarely enforced. Even a $100 fine for a false claim on YouTube would be enough to weed out bots and click farms. And for the most serious cases, have the infringer pay damage and a bigger fine. No need to change the law for that, it just has to be enforced.
Re: Tainting the CSAM client-side scanning database
#170Because client-side scanning is not going to work, and no one wants to government issued black box binary to send their conversations and photos to unnamed police person randomly, the non-compliance is the only way. People just start to use chat programs in the EU that do not comply. This would be Signal, Telegram, others. The EU can fine and fight with Meta/WhatsApp, Apple, others, but that’s about it. The EU bureau…
Also do not miss the recent good article about the US software development companies who are behind the lobbying of client-side scanning, how is this madness is being funded and by whom. https://balkaninsight.com/2023/09/25/who-benefits-inside-the...