Live data from Hacker News

Tainting the CSAM client-side scanning database

blog.xot.nl

241–250 of 276 posts

Re: Tainting the CSAM client-side scanning database

#241

Earlier quoted context omitted.

> Are they guilty of a crime? Unless there is a very specific "attempt to acquire CSAM" law then no they're not fucking guilty of any crime. If you live in a state where marijuana is illegal and you smoke some oregano because you thought it was marijuana you're not guilty of actually possessing marijuana. A criminal law is composed of a number of individual statutes. When a state is trying to prosecute someone for a…

> If a cop sells you oregano and you think it's marijuana you might have the intent to buy marijuana but there's no actual criminal act because oregano isn't illegal. If you make a law that only requires intent then congratulations, you've created thought crimes. You're a lawyer, I take it? I'm not a lawyer, and I admit your analysis of this scenario confuses me. Is there no legal difference between merely having int…

I'm definitely not a lawyer.

> Is there no legal difference between merely having intent to commit a crime at some point in the future, and actually attempting to commit a crime?

That was my point. To be charged with and prosecuted for a crime you need to both intend to commit it and then actually/attempt to commit it. Attempted murder is a crime, I both intend to kill someone and try to do so even if I fail. It's not punished as severely as actual murder but it's still a crime. But attempted murder is actual a specific crime in the criminal code. There's elements of it that need to be proven in court.

Unless a jurisdiction has a crime of "attempted possession of marijuana", intending to buy marijuana but ending up with oregano isn't a crime someone can be charged with. If we start writing laws outlawing attempted possession it's a slippery slope that gets into outlawing thoughts. It also opens the door to stupid pre-crime ideas like someone would only use cryptography to get ahold of illegal content therefore anyone using cryptography is instantly guilty of attempting to get illegal material.

You can be sure this is what will happen because it's the very arguments the anti-cryptography groups use.

Re: Tainting the CSAM client-side scanning database

#242

Earlier quoted context omitted.

> Get back to me when you've read some legal cases or know anyone who's been abused to produce such material Hello, I'd be the anyone in this scenario. I don't believe that the pros outweigh the cons, violating the privacy of every single person to protect us from the absolute minority (abusers) of a minority (those attracted to children) is not worth the exchange. CSAM detection would not have protected me from abus…

OK, but if you read my posts above I am not arguing for mass privacy violations. I'm saying the tech community isn't going to get any traction for its advocacy unless it makes some effect to propose privacy respecting solutions to the CSAM proliferation problem. I'm sorry that happened to you, but I presume you would also prefer that imagery including you did not continue to circulate?

what? we already know the legislation will not pass. the "tech community" doesn't have to do anything. why are you trying to make it sound like there is a dilemma here. cringe

Re: Tainting the CSAM client-side scanning database

#243

Earlier quoted context omitted.

> Get back to me when you've read some legal cases or know anyone who's been abused to produce such material Hello, I'd be the anyone in this scenario. I don't believe that the pros outweigh the cons, violating the privacy of every single person to protect us from the absolute minority (abusers) of a minority (those attracted to children) is not worth the exchange. CSAM detection would not have protected me from abus…

OK, but if you read my posts above I am not arguing for mass privacy violations. I'm saying the tech community isn't going to get any traction for its advocacy unless it makes some effect to propose privacy respecting solutions to the CSAM proliferation problem. I'm sorry that happened to you, but I presume you would also prefer that imagery including you did not continue to circulate?

How about putting more of the onus on services who might be used to traffic it?

> I'm sorry that happened to you, but I presume you would also prefer that imagery including you did not continue to circulate?

I've reported CSAM posts on tumblr and twitter and seen them survive for weeks before they finally disappear. It seems like that's a much riper target than propping up this kind of worst case solution.

Re: Tainting the CSAM client-side scanning database

#244
post #149

Earlier quoted context omitted.

>Even the words "intellectual property" sound ridiculous together when you think about it. For this reason, many would suggest not using it. It's a vague way of combining the separate issues of copyright, patents, and trademarks. It also illegitimately tries to equate those things to property, which changes how many feel about it. https://www.gnu.org/philosophy/words-to-avoid.html#Intellect...

Thank you for that information. In the future I'll direct my criticism more precisely. To clarify, it is mainly copyright laws I have a bone to pick with. Trademarks make sense. Patent laws sort of make sense in some circumstances, less in others.

As we get closer to Star Trek replicators, patent law begins to look similarly inapplicable.

Re: Tainting the CSAM client-side scanning database

#245

Earlier quoted context omitted.

You'd be publishing child porn, which I think is not the wisest thing to be doing.

Nah; you'll probably go about it by publishing very realistic AI generated copies so your actions are still legal.

> Nah; you'll probably go about it by publishing very realistic AI generated copies so your actions are still legal.

In many jurisdictions worldwide, producing/distributing/possessing "very realistic AI generated" child pornography is a crime.

According to Wikipedia, [0] it is criminal in these jurisdictions: Australia, Canada, Ecuador, Estonia, France, Ireland, Mexico, New Zealand, Norway, Poland, Russia, South Africa, South Korea, Switzerland, United Kingdom.

Furthermore, Wikipedia says it is in somewhat of a legal grey area in Argentina, Austria, Italy, Spain, Sweden, and the United States.

Regarding the US in particular: the Supreme Court ruled in the 2002 case of Ashcroft v Free Speech Coalition [1] that the child pornography exception to the First Amendment does not include "virtual child pornography", so long as it does not involve images of real children (i.e. using AI to take a non-pornographic image of a real child and turning it into a pornographic image of that child). However, while this bars prosecuting AI-generated child pornography under child pornography laws, it does not bar prosecuting it under obscenity laws. In the US, obscenity laws are much narrower than child pornography laws, so it is more difficult to get convictions, but people have gone to prison for violating them (e.g. Ira Isaacs [2] in 2012/2013, Paul F Little aka Max Hardcore [3] in 2008/2009). It can be difficult to convince a jury to convict, but realistic AI-generated child pornography may be one of those cases in which many juries would. Furthermore, Ashcroft v Free Speech Coalition is not set in stone–given technological developments since then, and the changed composition of the Supreme Court, it is possible that some prosecutor might seek to overturn it, and you can't say for certain they would fail. Given all this, I think Wikipedia is right to say it is a "legal grey area" in the US.

[0] https://en.wikipedia.org/wiki/Legal_status_of_fictional_porn...

[1] https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit...

[2] https://en.wikipedia.org/wiki/Ira_Isaacs#Further_charges,_re...

[3] https://en.wikipedia.org/wiki/Max_Hardcore#2005_arrest_and_p...

Re: Tainting the CSAM client-side scanning database

#246

Earlier quoted context omitted.

> Apple's proposed device scanning system had a threshold before your device would be flagged Which always struck me as odd as it would extremely easy to spin this as “Apple detected CSAM on this device but their policy is only to alert authorities once a set quantity of CSAM is found…”

It means they recognize there can be false positives. And that you can be the innocent recipient of it.

I absolutely understand that's what they're thinking.

I also know it will only take one case of someone being arrested for a related crime, and material being found on their phone that's under the threshold for reporting, and the associated headlines that could be written.

Re: Tainting the CSAM client-side scanning database

#247

Earlier quoted context omitted.

But parliament wants to seed your camera with mugshots of the FBI's top-ten most wanted list so the instant a false positive appears (directly on the camera, potentially even prior to writing the image to disk, potentially even prior to pressing the snapshot button)... they beacon an alert (or exfiltrate piggybacking via Bluetooth/AirTag/Covid exposure tracking mrchanisms), and bob's you're uncle.

I’m starting to think that a government large enough to get all the things it could want might be a bad idea.

I'd generalize this to any hierarchy. That includes corporations, institutions, religions, governments, cults, basically any time there are more than two people in the same room.

Re: Tainting the CSAM client-side scanning database

#248

Earlier quoted context omitted.

I'm personally highly skeptical of the "offering them an outlet" argument. I'd be less suspicious of the idea if its proponents also suggested limiting it to controlled settings, e.g. during meetings with a professional psychiatrist. But I'm sorry, I just don't believe anyone holed up in their room with a bunch of fake CSAM is "just using it as an outlet" or "protecting real kids from harm." I mean, it almost sounds…

Pornography reduces rape. Violent movies that appeal to teens reduce vandalism and the like--they're in the theater rather than out causing trouble. (And it's not displaced, rates don't spike later, they just return to normal.)

Citation needed.

Re: Tainting the CSAM client-side scanning database

#249

Earlier quoted context omitted.

In fact, you might even argue that possessing real CSAM has no victim. After all, the person possessing the image isn't the one who committed the abuse and took a picture of it, right? But we've collectively decided that it's worth punishing that crime, because every viewer is an enabler of the abuser. The same logic should extend to AI-generated content. To put it another way, consider a thought experiment where a p…

You have literally proposed 'thought crimes'.

There's plenty of precedent where police officers pretend to be an underage person and some shmuck replies to them and agrees to meet at a hotel. Then they get arrested, and much of the time they also get prosecuted and convicted. You could argue it's entrapment but the fact is that most of society supports that sort of preemptive law enforcement.

If you looked at it through a purely ethical framework then you could never convict the person because there was never any "real victim." But is that the right way to look at it? It's certainly not the way most people look at it.

Re: Tainting the CSAM client-side scanning database

#250

Earlier quoted context omitted.

> Seems all need to here is obtain a finger print of a CSAM image then you can reverse engineer a non CSAM image to match that finger print. Distribute this image wide enough and you effectively render these algorithms useless. You can't do this without committing an illegal act (downloading CSAM) and it also wouldn't work (because there's a second server side hash), so no I don't think you should do this.

No, all he would need as the hash which his device would have access to (client side scanning)

You can design the system so the client doesn't have a list of hashes either, eg with a Bloom filter or other probabilistic system you can change.
Post reply on HN