Live data from Hacker News

Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

wired.com

321–330 of 407 posts

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#321

Earlier quoted context omitted.

It's more like oblivious high-paid product managers and devs who can't fathom why people wouldn't trust Facebook or that Facebook might not be a purely beneficial organization.

I think you've completely missed the point here. Teenagers who have naked photos in the possession of their peers need a solution for preventing dissemination. And so if you're in this situation trusting Facebook is by far the lesser of two evils.

How is Facebook legally able to solicit child pornography? Because it sounds like that's what they're doing.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#322
post #174

Earlier quoted context omitted.

That's so ridiculous it could have been written by The Onion. Facebook has absolutely no businesses to store nude pictures of their users.

They don't. They store a perceptual hash, which can't be converted back into the original photo.

"They trust me, the dumb fucks." - Mark Zuckerberg

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#323

Earlier quoted context omitted.

This is the KYC (Know Your Customer) laws. Online-only banks like Ally and Simple require the same thing. In fact, every bank requires this. If you opened a bank account in-person some years ago you may not remember but they asked you for your government-issued ID card. It's the same thing.

KYC doesn't require a photo, does it?

I think it does. Couple of online banks I tried out all needed a short video of my face saying my name, not just photo of ID, that’s not enough anymore.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#324
post #224

Earlier quoted context omitted.

The main obstacle that I can think of is: where does that hashing get done? Is it a feature that can efficiently be part of the phone app? Keeping in mind that this is a feature that would only be used by a very, very small part of the general userbase. Let's assume that it is possible, the other issue that might come up is that the system is still suspect to a sort of denial of service attack, in which a group (for…

The attack against the uploaded hash approach fails with default-deny, which seems like a good thing for users. The current implementation can be attacked by uploading thousands of legitimate images delaying takedown requests - therefore any images that should be taken down will stay up longer. I'll agree that whatever approach FB is doing to hash the photos may not work on a phone for technical reasons, but given FB…

> The current implementation can be attacked by uploading thousands of legitimate images delaying takedown requests

How would that work, exactly? A user uploads hundreds of fraudulent images to FB's revenge-porn-abuse queue. At some point, the human who verifies whether the image is legit is going to realize that the user account is fraudulent and then disable the account.

If images are hashed, FB has no way to know if a user who is uploading hundreds of hashes is a malicious user or is actually an incredibly unfortunate revenge-porn victim. And the price for being wrong is extremely high. Maybe it's possible for FB's auto-detection system to be robust if the hashes it has to scan for is now several orders of magnitude than ever expected, making this all a moot point. But I can't imagine that the system scales with no penalty.

> But consider this - if you truly, deeply cared about user safety and privacy, would you implement this feature the same way?

The wording of your question implies a false dilemma, and I think reveals how different the premises you and I have about it. What exactly about Facebook's implementation of this feature makes it any less safe for users and their privacy than not having the feature at all? When a user sees and reports an abusive image of themselves -- that photo and that user, and that user's connection to the photo are already in Facebook's system".

Every fear there is about this data being exposed to malicious human workers, or that FB is trying to harvest sensitive images for nefarious means -- that risk has always existed. How do you think abuse-takedown requests are currently handled?

So if my argument is accurate, that an evil-pervy Facebook wants to do a mass collection of sensitive/comprising images of its user, all the infrastructure and dataflow is already in place, then this revenge-porn initiative does nothing to make that process more efficient. Even worse for pervy-Facebook, the initiative's very existence, nevermind announcing it, reminds the entire world again that holy-shit-think-of-all-the data-Facebook-has-on-us-including-our-sexy-times -- which is generally the kind of PR you want to avoid when you're conspiring to mass-harvest illicit imagery and data.

And let's be real here: Facebook doesn't have to do anything special for revenge porn victims, in the way that the Postal Service isn't obligated to open everyone's mail to make absolutely sure there's no child porn being sent -- the act of prevention ends up causing far more harm to all users than it benefits the comparatively small number of potential victims.

The status quo seems to be to do nothing until reports come in, which is OK for most situations but inadequate for the kind of attack vector that revenge-porn victims suffer. Facebook could have accepted that, as everyone else does, but invested time/resources into coming up with a technical solution that only benefits a very small but high-suffering part of its userbase while not increasing invasiveness (FB already autoscans the content of user messages, including with the use of PhotoDNA [0]).

Call me Pollyannish, but I don't see this instance as yet another time of Facebook being heartless and devious.

[0] http://www.businessinsider.com/facebook-google-and-microsoft...

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#325

Last paragraph of the article: "The new authentication scheme is the second in recent weeks that relies on photos. Earlier this month, Facebook asked users to upload nude photos to Facebook Messenger, as part of an effort to prevent revenge porn. Facebook said it would use the nude photos to create a digital fingerprint against which to compare future posts." Wait what? I had to check whether today was April 1st.

In context of Zuckerberg’s “They trust me, dumb fucks” comments, the invitation to upload nude photos seems especially alarming.

after he gets enough photos he can start a website where people rate and compare two bodies!

http://www.thecrimson.com/article/2003/11/19/facemash-creato...

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#326

Last paragraph of the article: "The new authentication scheme is the second in recent weeks that relies on photos. Earlier this month, Facebook asked users to upload nude photos to Facebook Messenger, as part of an effort to prevent revenge porn. Facebook said it would use the nude photos to create a digital fingerprint against which to compare future posts." Wait what? I had to check whether today was April 1st.

basically it's "don't worry, people will review the image, but they're 'specially trained' "

when will people stop using facebook?

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#327

Instagram did this same bullshit to me when I signed up for an account to to follow some photographers. 'Please provide a clear photo of yourself holding your government issued ID, and a piece of paper with the following code handwritten on it'. No, fuck that for a joke. There's this growing trend of everyone wanting your photo and some ID, and then you have no way to verify that information is being kept securely or…

This is the KYC (Know Your Customer) laws. Online-only banks like Ally and Simple require the same thing. In fact, every bank requires this. If you opened a bank account in-person some years ago you may not remember but they asked you for your government-issued ID card. It's the same thing.

I have opened several bank accounts online and never have been asked for photo id. SSN and some knowledge-based auth sure, but no photos.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#328

Earlier quoted context omitted.

No, Facebook's side needs to verify that the image is you, and that you're not just hashing a photo of the McDonald's logo.

they can verify that after they have found a match. if there is no match you gave them no data of interest. if there is a match then they already have that image anyway and you didn't make your privacy situation worse, except maybe telling them that you claim that is you, now allowing them to associate more images was you, but that's probably an acceptable tradeoff if there is actual revenge porn of you out there.

If they already have the image, then you don't need this system.

If they don't have it, but are doing verify-after, then the image won't actually be blocked right away. The proposed system would be of pretty marginal value. Some value, yes, but low enough that facebook decided it wasn't worth building that system.

You can't avoid having a tradeoff somewhere.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#329
post #221

Earlier quoted context omitted.

That's exactly the topic we're discussing now. Sorry, with "userbase" I meant " general userbase". This initiative they're proposing -- in coordination with a safety group in Australia -- is aimed at revenge porn victims. The general userbase of Facebook aren't in that group.

I don't think there's any appropriate time for FB to request nude photos of their userbase. I don't understand why you think I should explain this.

They aren't "requesting" it. The service exists for a specific reason, and is exceptionally optional.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#330
post #103

>"Please upload a photo of yourself that clearly shows your face. We’ll check it and then permanently delete it from our servers." >"To determine if the account is authentic, Facebook looks at whether the photo is unique." The two statements are a bit contradictory. They might delete the photo but they won't delete its signature/fingerprint, because they need the later to check for uniqueness of other accounts.

Count your blessings. They could have additionally asked for a picture that "clearly shows your genitals". Anywho, once the 'revenge porn' crowd starts hacking around this by chopping the said head from the said images, the central servers of FB are sure to ask for pics of genitals.

> Count your blessings.

No.

Facebook is not the Almighty God.

Post reply on HN