Live data from Hacker News

Microsoft PhotoDNA scanning problem

elevenforum.com

41–49 of 49 posts

Re: Microsoft PhotoDNA scanning problem

#41
post #5

> Microsoft's PhotoDNA scanning is not just in OneDrive, through the Microsoft's eco-system. Basically, if you are using your Microsoft account to sign in to Windows 11, PhotoDNA scans your entire computer. This information came directly from Microsoft Support. This sounds like a horrible privacy violation. Is it true? What do they do if they find a match?

The general consensus from I saw from discussions years ago was that scanning of your local files was not something that happened (which would be detectable and eventually discovered and called out by someone). Doing so would also require the dll which contains how photodna works, which Microsoft does/did not want out in the wild and requires an NDA to use. Secretly exfiltrating your files for scanning would get Microsoft in legal trouble.

Incidentally, how it works is clever and interesting imo, though defeatable if you know how it works: https://www.hackerfactor.com/blog/index.php?%2Farchives%2F93...

The obvious alternative of course, is openly and aggressively getting users to agree to uploading their files to Microsoft’s computers (OneDrive), which are scanned.

However in the age of machine learning, copilot and the like, I would not be surprised if local scans start becoming a thing, since offering classification of objects in photos is a perfectly reasonable thing to offer from Microsoft’s point of view, and of course CSAM detection can come along with that.

Re: Microsoft PhotoDNA scanning problem

#42
post #5

> Microsoft's PhotoDNA scanning is not just in OneDrive, through the Microsoft's eco-system. Basically, if you are using your Microsoft account to sign in to Windows 11, PhotoDNA scans your entire computer. This information came directly from Microsoft Support. This sounds like a horrible privacy violation. Is it true? What do they do if they find a match?

The general consensus from I saw from discussions years ago was that scanning of your local files was not something that happened (which would be detectable and eventually discovered and called out by someone). Doing so would also require the dll which contains how photodna works, which Microsoft does/did not want out in the wild and requires an NDA to use. Secretly exfiltrating your files for scanning would get Micr…

I’m surprised that such scanning isn’t built into windows defender, the enabled-by-default tool already designed to scan all your files.

But yeah, they also just super aggressively try to trick you into sending all your files to onedrive.

Re: Microsoft PhotoDNA scanning problem

#43

>I had at least 12 Microsoft accounts immediately closed What?

What what? I take it you're not one of the many people who've had a dozen different services over the years get bought up by Microsoft, then forcefully migrated to multiple Microsoft Accounts, and then lose access to all of them?

Maybe try it with a different image the 12th time?

Re: Microsoft PhotoDNA scanning problem

#44
post #35

Earlier quoted context omitted.

That sounds like straight up scammer behavior. "Yes, this is Microsoft calling. We need to confirm your info with the local authorities."

> That sounds like straight up scammer behavior. " Microsoft reached out to the police department, then the person went to the local police department to verify who they were. I don't see how this could be a scam.

Then again: how does the local police department verify they are indeed talking to Microsoft?

It’s been done before: https://krebsonsecurity.com/2022/03/hackers-gaining-power-of...

Re: Microsoft PhotoDNA scanning problem

#45
post #5

> Microsoft's PhotoDNA scanning is not just in OneDrive, through the Microsoft's eco-system. Basically, if you are using your Microsoft account to sign in to Windows 11, PhotoDNA scans your entire computer. This information came directly from Microsoft Support. This sounds like a horrible privacy violation. Is it true? What do they do if they find a match?

The general consensus from I saw from discussions years ago was that scanning of your local files was not something that happened (which would be detectable and eventually discovered and called out by someone). Doing so would also require the dll which contains how photodna works, which Microsoft does/did not want out in the wild and requires an NDA to use. Secretly exfiltrating your files for scanning would get Micr…

An alleged implementation of PhotoDNA was posted to GitHub a few weeks ago:

https://github.com/ArcaneNibble/open-alleged-photodna/

Re: Microsoft PhotoDNA scanning problem

#46

the police part makes me really question what is going on here and the validity of this report. if you get multiple child sexual abuse material (CSAM) matches, the police will be knocking on (down) your door. microsoft isnt going to nicely ask you to go down the the police station. they dont even contact local police, they forward the information to the appropriate national entity (e.g. NCMEC) who coordinates the law…

> and if it isnt CSAM related, microsoft is not going to be contacting your local police, period.

Why would they not? I once had a problem with material uploaded on a file sharing system hosted on Hetzner. I received an email about it from Hetzner, but I was on holiday and I didn't check my email so after 48 hours or so the local police (French gendarmerie) came to my address and politely asked for my server logs.

Luckily I had forgotten to update my billing address on my Hetzner account, so it was my parents address and I was on holidays at my parents.

Re: Microsoft PhotoDNA scanning problem

#47
Blocking the account because the image was used by another account that had been suspended etc. sounds more like the specific image had been flagged as offensive while in use by that account, rather than it having anything to do with them establishing a relationship between the actual accounts

(If they established connections between accounts by using images, surely they would block vast swathes of people using generic harmless images you can find online)

Re: Microsoft PhotoDNA scanning problem

#48
post #35

Earlier quoted context omitted.

That sounds like straight up scammer behavior. "Yes, this is Microsoft calling. We need to confirm your info with the local authorities."

> That sounds like straight up scammer behavior. " Microsoft reached out to the police department, then the person went to the local police department to verify who they were. I don't see how this could be a scam.

I think there are a few scammer red flags in this - it stood out to me that they said "support watched me setup 3 different accounts" - not saying MS support couldn't do this, but remoting into the machine and watching a victim enter form details is a very scammer-y thing for sure

Re: Microsoft PhotoDNA scanning problem

#49

>I had at least 12 Microsoft accounts immediately closed What?

What what? I take it you're not one of the many people who've had a dozen different services over the years get bought up by Microsoft, then forcefully migrated to multiple Microsoft Accounts, and then lose access to all of them?

How did they find out that all 12 accounts were suspended instantly? Were they signed into 12 Microsoft accounts on the same device?
Post reply on HN