Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

271–276 of 276 posts

Re: Tainting the CSAM client-side scanning database

#271

Earlier quoted context omitted.

Nah; you'll probably go about it by publishing very realistic AI generated copies so your actions are still legal.

> Nah; you'll probably go about it by publishing very realistic AI generated copies so your actions are still legal. In many jurisdictions worldwide, producing/distributing/possessing "very realistic AI generated" child pornography is a crime. According to Wikipedia, [0] it is criminal in these jurisdictions: Australia, Canada, Ecuador, Estonia, France, Ireland, Mexico, New Zealand, Norway, Poland, Russia, South Afri…

I mean I know a lot of the West are big on thought crimes. Hell people in the UK get arrested for being too mean in tweets now a-days. I don't think that's going to happen here though.

Re: Tainting the CSAM client-side scanning database

#272

The article considers "an entity that is allowed to propose new entries to the CSAM database". You don't even need this! You could target a whole "social cluster" of people without having any special privileges within this system. As an example, lets say you want to attack environmental protesters. For image A, you create a meme about climate change. For image B, you procure something that looks, to humans, like CSAM…

> and if the platform fulfills its obligations, that report will bubble up to the relevant authorities, who will review it and add its fingerprint to the database. I don't think NCMEC adds random images they find to the A1 list without knowing their origin. > until the average meme-savvy environmental protester's device gets flagged for further scrutiny. Who is this an attack on? A moderation contractor maybe, but no…

The proposed legislation and rules indicate that the “EU Centre,” Interpol, and local law enforcement and governments would all have access to alerts (reports, unfiltered) and the databases and systems used to generate them.

Re: Tainting the CSAM client-side scanning database

#273
post #169

Earlier quoted context omitted.

I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.

That would be ridiculous. But there are penalties for false claims. There is a fine for claiming copyright you don't own, and if you go further and ask for takedowns, you are also liable for damage. The problem is that these are rarely enforced. Even a $100 fine for a false claim on YouTube would be enough to weed out bots and click farms. And for the most serious cases, have the infringer pay damage and a bigger fin…

Why? I've long thought that, as a general principle, willfully false accusations of a crime should carry the same penalty as the crime itself.

Re: Tainting the CSAM client-side scanning database

#274

Earlier quoted context omitted.

You can't because you don't have access to one of the algorithms.

We don't actually have access to the first algorithm either, but it's been reverse engineered and a binary published. According to article.

I should have said "algorithm deployment" or something. The main point is that on the server side, you can change the hash (or its seed) anytime you want, if the false positive rate is getting too high.

It may be possible to do the same thing to the client actually.

Re: Tainting the CSAM client-side scanning database

#275

Earlier quoted context omitted.

Google was not required to implement that the way they did, which is basically a server-side scanning policy of having contractors look at your nudes if you put them on your cloud drive. NCMEC may approve of it, sure, but another aspect of their not being a government agency is that you don't have to listen to them.

Problem is, as they are not a goverment agency and don't really see you as customer (more like a product) you have almost no avenue to get your account reinstated... And as there are some people (and even companies) who rely on google services and their account there it can really shoot you in the knee

"Not being a government agency" was about NCMEC, not Google.

Re: Tainting the CSAM client-side scanning database

#276

Earlier quoted context omitted.

> If a cop sells you oregano and you think it's marijuana you might have the intent to buy marijuana but there's no actual criminal act because oregano isn't illegal. If you make a law that only requires intent then congratulations, you've created thought crimes. You're a lawyer, I take it? I'm not a lawyer, and I admit your analysis of this scenario confuses me. Is there no legal difference between merely having int…

I'm definitely not a lawyer. > Is there no legal difference between merely having intent to commit a crime at some point in the future, and actually attempting to commit a crime? That was my point. To be charged with and prosecuted for a crime you need to both intend to commit it and then actually/attempt to commit it. Attempted murder is a crime, I both intend to kill someone and try to do so even if I fail. It's no…

Attempted possession of an illegal item/substance is absolutely a crime.

Source: decade in the criminal justice system.

Post reply on HN