Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

191–200 of 276 posts

Re: Tainting the CSAM client-side scanning database

#191

Earlier quoted context omitted.

okay, ill bite: yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities. however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating. CSAM is a propaganda word: 1. right wing uses it to push their agenda of punishing people for havi…

people are not naturally sexually attracted to children (13 and under) in more than say 0.0001%. In the US alone, that would be ~30,000 people. Get back to me when you've read some legal cases or know anyone who's been abused to produce such material. Perhaps you'll learn some critical thinking and better manners along the way.

> Get back to me when you've read some legal cases or know anyone who's been abused to produce such material

Hello, I'd be the anyone in this scenario. I don't believe that the pros outweigh the cons, violating the privacy of every single person to protect us from the absolute minority (abusers) of a minority (those attracted to children) is not worth the exchange.

CSAM detection would not have protected me from abuse. At best it would have prevented continued sexual abuse.

And yet had my abuser been caught early I would have been returned to a different, brutally abusive man. One whose abuse no one particularly seems to care about, because there's less to get righteous about when there's no sex involved in the abuse.

Re: Tainting the CSAM client-side scanning database

#192

Earlier quoted context omitted.

what is happening in Youtube world?

This one happened just a month ago so it might be what the parent comment is referring to. Basically, somebody made a fake company to make bogus copyright claims against someone to hurt their channel. Youtube refuses to deliver counterclaims unless the YTer puts their government name on it (he originally tried to deliver it via an attorney). Additionally, the other party is actively trying to compromise the YTer's ot…

What I don’t get is this: why does youtube still have such a monopoly after all this time? It’s had a shitty reputation since I can remember, why don’t creators just band together and take their viewership somewhere less hostile?

Re: Tainting the CSAM client-side scanning database

#193

Earlier quoted context omitted.

Broadening the definitions of crime to make it easier to punish the ethically guilty on scant evidence while incidentally sweeping up the ethically innocent is a hack around a legal tradition that is designed exactly on the principal that it is better that the guilty go unpunished than the innocent are punished, by making the genuinely innocent administratively guilty, and we ought to reject that kind of justificatio…

Broadening the definition of a crime isn't exactly unheard of. To choose a less emotional subject, mattress tags. The ethical reason for mattress tags is because historically people would sell mattresses stuffed full of all sorts of unsavory garbage. What we actually criminalized, or at least were trying to prevent, was some sort of fraud or public endangerment. But we also along the way made it illegal for sellers t…

You are going into forced labelling disclosure, which can have a lot of benefits beyond fraud prevention because it increases informed consent and all sorts of other net goods. It's the logic and ethics of nutrition labels, and IMO is probably one of the more good vs bad things that govts can mandate.

Re: Tainting the CSAM client-side scanning database

#194

Earlier quoted context omitted.

That’s not what a hash collision is. Uploading popular (public domain) music and claiming you own it is just fraud

I agree that it's not hash collision, but the fingerprinting strategy makes precise language on this topic a bit difficult/tedious. The CSAM detection isn't proper hash collision either, in so far as I understand it. There's some fuzzy matching formula that generates the fingerprint, it's not simply a byte for byte hash taken of the image, and therein lies the comparison. The fraud in question is reliant on content I…

It's a hash, but it's not a cryptographic hash.

Re: Tainting the CSAM client-side scanning database

#195
post #179

Earlier quoted context omitted.

okay, ill bite: yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities. however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating. CSAM is a propaganda word: 1. right wing uses it to push their agenda of punishing people for havi…

Your claims of things that do happen are likely true. It is a propaganda word. People do use it as a bludgeon to push their agenda through. Police do use it for bullshit arrests. Teenagers' lives are ruined for basically no reason. Your claims of things that don't happen are, unfortunately, false. Law enforcement agents whose jobs involve ever looking at CSAM basically cannot stand the mental toll of the job for any…

> Your claims of things that don't happen are, unfortunately, false. Law enforcement agents whose jobs involve ever looking at CSAM basically cannot stand the mental toll of the job for any significant amount of time. Unthinkably horrible things happen to children to create these images.

literally just propaganda and i have no doubt that this is a massive exaggeration.

>The idea that we would legalize it is not on the table, and suggesting such a thing is a great way to immediately lose support from everyone in the world.

cool, and i was going to open my first post with "CP being contraband is out of the question and never should have became a thing".

> I don't think that analogy is hitting the way you're intending. Yes, we'd all love a "freedom-respecting solution to the murder problem". In fact convicted murderers still have some rights and freedoms, and balancing those against preventing murder and rehabilitating murderers is another difficult problem. Cutting off legs hasn't been seen as a reasonable punishment for a crime since the Bronze Age, so I'm not sure what that's supposed to mean.

i don't know what i didn't make clear. i said that i don't want a law to cut off everyone's legs at birth with a casus beli like "terrible people are going around murdering people with their bare hands now that we all live in a cage and if you don't want to get rid of legs you are part of the problem". the analogy is in fact absolutely perfect even better than i intended, since you know whoever argued this is hugely exaggerating.

and then we have the other guy i'm replying to who can't even write a coherent response (for instance calculating 30K instead of 300, and then ignoring the fact that most of those people will not actually do anything) because he's too angry from his inner sheep being offended because someone dared question is terrible law which is basically just racket where they can use fabricated and overblown cases instead of having to perpetrate the crimes themselves (although the FBI is also known for serving CP themselves, which contradicts a huge amount of the "CP should be illegal" arguments, such as "seeing it makes more pedos")

Re: Tainting the CSAM client-side scanning database

#196

The article considers "an entity that is allowed to propose new entries to the CSAM database". You don't even need this! You could target a whole "social cluster" of people without having any special privileges within this system. As an example, lets say you want to attack environmental protesters. For image A, you create a meme about climate change. For image B, you procure something that looks, to humans, like CSAM…

> Apple's proposed device scanning system had a threshold before your device would be flagged

Which always struck me as odd as it would extremely easy to spin this as “Apple detected CSAM on this device but their policy is only to alert authorities once a set quantity of CSAM is found…”

Re: Tainting the CSAM client-side scanning database

#197
post #169

Earlier quoted context omitted.

I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.

That would be ridiculous. But there are penalties for false claims. There is a fine for claiming copyright you don't own, and if you go further and ask for takedowns, you are also liable for damage. The problem is that these are rarely enforced. Even a $100 fine for a false claim on YouTube would be enough to weed out bots and click farms. And for the most serious cases, have the infringer pay damage and a bigger fin…

Consider the penalties given for a crime, and compare those to the penalties given when police or prosecutorial or judicial misconduct falsely, incompetently, or corruptly imprisons someone for that crime.

The latter are overwhelmingly more rare, but overwhelmingly larger. Society in general thinks false penalties for crimes are worse than the crime itself.

"It is better that 10 guilty men go free, than that one innocent man should suffer." I think that if the penalty for copyright infringement is $250,000, the penalty for a false claim should be $2,500,000.

You're right that a $100 low-effort, frequently-enforced counterclaim process would weed out ContentID bot farms (just like a $0.01/email transaction cost would weed out spam). But remember that the whole ecosystem is already ridiculous; if the pro-copyright MPAA/RIAA are pushing for $250k/infringement you have to be equally ridiculous to balance counterclaims.

Re: Tainting the CSAM client-side scanning database

#198
post #83

The issue described here, to my understanding, is that you find or create csam and then manipulate it so that its fingerprint collides with another image that you want to be flagged as csam. You then submit the manipulated version of the found or generated image to the authority. First, at what point does the authority go "uh... Where did you get this from?" Practically speaking, the people doing this would have to b…

>Like if an ordinary citizen showed up with csam the excuse "oh I found this JPEG in a trunk in my late grandpa's attic" isn't gonna fly Just post it to 4chan, it’s actively monitored by intelligence services

Also by unintelligent services

Re: Tainting the CSAM client-side scanning database

#199

The article considers "an entity that is allowed to propose new entries to the CSAM database". You don't even need this! You could target a whole "social cluster" of people without having any special privileges within this system. As an example, lets say you want to attack environmental protesters. For image A, you create a meme about climate change. For image B, you procure something that looks, to humans, like CSAM…

> and if the platform fulfills its obligations, that report will bubble up to the relevant authorities, who will review it and add its fingerprint to the database.

I don't think NCMEC adds random images they find to the A1 list without knowing their origin.

> until the average meme-savvy environmental protester's device gets flagged for further scrutiny.

Who is this an attack on? A moderation contractor maybe, but not the protester. "Further scrutiny" doesn't mean "you go to jail", it means someone looks at the pictures.

Re: Tainting the CSAM client-side scanning database

#200
post #164

I am against the idea of scanning for the reason that the author pointed out: It's trivial to repurpose the technology to use it in dystopian ways. I however have precisely zero concerns about impersonating hashes: 1. It's trivial to deal with tainting the database: both secondary hashing and more invasive hashes deal with that problem. 2. It's trivial to deal with impersonated hashes, all positives can be scanned on…

If you can make one algorithm collide, you can make two collide.

You can't because you don't have access to one of the algorithms.
Post reply on HN