Live data from Hacker News

One Bad Apple

hackerfactor.com

401–410 of 557 posts

Re: One Bad Apple

#401

Earlier quoted context omitted.

One example I quote from EFF's post Apple's Plan to "Think Different" About Encryption Opens a Backdoor to Your Private Life [1] on the topic: We’ve already seen this mission creep in action. One of the technologies originally built to scan and hash child sexual abuse imagery has been repurposed to create a database of “terrorist” content [2] that companies can contribute to and access for the purpose of banning such…

Thanks, I think I see what you mean. Essentially another organisation has used file hashes to scan for extremist material, by their definition of extreme. I agree that has potential for abuse but it doesn't seem to explain what the actual link is to NCMEC. It just says "One of the technologies originally built to scan and hash child sexual abuse imagery has been repurposed..." but doesn't name this "technology". Is i…

Here in France, law enforcement & probably some intelligence agencies used to monitor P2P networks for child pornography & content terrorists like to share with one another.

Now we have the expensive and pretty much useless "HADOPI" paying a private company to do the same for copyright infringement.

Ironically enough, it seems the interior and defence ministries cried out when our lawmakers decided to expand it to copyright infringement on the request of copyright holders. They were afraid some geeks, either out of principle or simply to keep torrenting movies, would democratise already existing means to hide one's self online, and create new ones.

Today, everyone knows to look for a VPN or a seedbox. Some even accept payments in crypto or gift cards.

¯\_(ツ)_/¯

Re: One Bad Apple

#402
post #400

Earlier quoted context omitted.

By laws I mean the laws governing police work. And bringing police up to speed. Obviously CP and other things are already very much illegal, these laws are just hardly enforced online. That has to change.

The internet isn't the wild west, laws are very much enforced.

Stalking and harrasment isn't, at least over here. Victims are constantly left out in the cold. Same goes for fraud, most cases are not prosecuted. Especially if these cases cross state, and in the EU, nation borders. Because it becomes inconvenient, so police isn't really bothering. And if they do, the fraud is done. The stalking went on for years. And nothing really improved.

Hell, do I miss the old internet. The one without social media.

Re: One Bad Apple

#403

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

Thanks for the write-up and putting all the work into this important issue. > "There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18." One thing I wondered and have not seen brought up in the discussion so far is this: As far as I understand the perceptu…

> doesn't that increase the pressure on the abusers to produce new content and in consequence hurt even more children?

Not really. Two points:

1) Many / all CP boards these days ask applicants to provide CSAM (as police in almost all jurisdictions except for IIRC US and Australia are banned from bringing CSAM into circulation). And to keep police where allowed from simply re-uploading stuff, they (as well as the "client base") demand new, yet-unseen stuff, and so no matter what the police is doing there will always be pressure for new content.

2) The CSAM detection on popular sites only hits people dumb enough to upload CSAM to Instagram, Facebook and the likes. Granted, the consumer masses are dumb and incompetent at basic data security, but ... uhh, for lack of a better word, experienced CSAM consumers know after decades of busts that they need to keep their stashes secure - aka encrypted disks.

> If so, an AI solution that also flags previously unknown abuse material and a lot of human review are probably our only chance. What is your take on this?

There are other chances to prevent CSA that don't risk damaging privacy, and all of them aim at the early stages - preventing abuse from happening:

1) teach children already in early school years about their body and about consent. This one is crucial - children who haven't learned that it is not normal that Uncle Billy touches their willy won't report it! - but unfortunately, conservatives and religious fundamentalists tend to blast any such efforts as "early sexualization", "gay propaganda" and whatnot.

2) provide resources for (potential) committers of abuse. In Germany, we have the "Kein Täter werden" network that provides help, but many other countries don't have anything even remotely similar.

3) Screening of staff and volunteers in trust / authority positions dealing with children (priests and other clergy, school and pre-school/kindergarten teachers, sports club trainers) against CSA convictions. Unfortunately, this is ... not followed thoroughly very often and in some cases (cough Catholic Church) the institutions actively attempt to cover up CSA cases, protect perps and simply shuffle staff around the country or in some cases across the world.

Re: One Bad Apple

#404
post #98

Earlier quoted context omitted.

Something else I haven’t heard anyone bring up: when child abusers are caught, sentences are often a joke. They often spend less time in prison than low to mid level drug offenders. CP is rape porn. People who produce or knowingly distribute actual rape porn (of children or adults) should be going to jail for 25+ years. I would not rule out life for extreme cases that also involve other forms of abuse. Yet as far as…

I think you’re mistaken. Lots of rape porn is produced by women, for women. Typically novels, and sometimes graphic novels. It’s legal, and definitely not something that takes with it a 25+ year sentence. You can literally find rape porn on Amazon bookshelves. Literally.

Clearly they were talking about non-fictitious rape.

Re: One Bad Apple

#405
post #231

Earlier quoted context omitted.

yep. what if i take a burst of 12 photos that all incorrectly fall as a false positive to NeuralHash (which is a ML black box), and an Apple reviewer is now invading my privacy by looking at my photo library?

The the technical paper Apple put out that is linked to in the post talks about the risk, but isn’t very helpful “Several solutions to this were considered, but ultimately, this issue is addressed by a mechanism outside of the cryptographic protocol.”

Not acceptable for a technology being deployed to hundreds of millions of people.

Re: One Bad Apple

#406
post #188

Earlier quoted context omitted.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

1. We judge these programs under the wrong assumption that it is run by the good guys. Any system that depends on the goodness of the people running it is dangerous, because it can be taken over by the bad guys. 2. I am a law abiding, innocent citizen. Why should I have to face the same compromised privacy as a criminal? It used to be that only people under suspicion are surveilled and that a judge had to grant this…

> We judge these programs under the wrong assumption that it is run by the good guys. Any system that depends on the goodness of the people running it is dangerous, because it can be taken over by the bad guys.

And sometimes, the "good guys" in their attempts to be as good as they can imagine being, turn into the sort of person who'll look a supreme court judge or Congresspeople or oversight committees in the eye and claim "It's not 'surveillance' until a human looks at it." after having built PRISM "to gather and store enormous quantities of users’ communications held by internet companies such as Google, Apple, Microsoft, and Facebook."

https://www.hrw.org/news/2017/09/14/q-us-warrantless-surveil...

Sure, we copied and stored your email archive and contact lists and instant messenger history. But we weren't "surveilling you" unless we _looked_ at it!

Who are these "good guys"? The intelligence community? The executive branch? The judicial branch? Because they're _all_ complicit in that piece of deceit about your privacy and rights.

Re: One Bad Apple

#407

Earlier quoted context omitted.

1. We judge these programs under the wrong assumption that it is run by the good guys. Any system that depends on the goodness of the people running it is dangerous, because it can be taken over by the bad guys. 2. I am a law abiding, innocent citizen. Why should I have to face the same compromised privacy as a criminal? It used to be that only people under suspicion are surveilled and that a judge had to grant this…

>We judge these programs under the wrong assumption that it is run by the good guys Speaking as someone who as a boy was tortured and trafficked by operatives of the Central Intelligence Agency of the United States of America, I am surprized how little appreciation there is for the standard role of misdirection in the espionage playbook. It is inevitable that all these obstensibly well-intended investigators will hav…

"Wont somebody think of the (white, wealthy, documented) chiiiiilren!"

:sigh:

Re: One Bad Apple

#408
post #188

Earlier quoted context omitted.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

Surveillance does have its place, but a large part of the problem with the new technology of surveillance is the people passing the laws on surveillance don't understand the technology that surrounds it. Take, for instance, the collection of metadata that is now so freely swept up by the American government without a warrant. This includes the people involved in communication, the method of communication, time and du…

> is the people passing the laws on surveillance don't understand the technology that surrounds it.

And that the people running the surveillance have a rich track record of lying to the people who are considering whether to pass the laws they're proposing.

"Oh no, we would _NEVER_ surveil American citizens using these capabilities!"

"Oh yeah, except for all the mistakes we make."

"No - that's not 'surveillance', it's only metadata, not data. All we did was bulk collect call records of every American, we didn't 'surveil" them."

"Yeah, PRISM collects well over 80% of all email sent by Americans, but we only _read_ it if it matches a search we do across it. It's not 'surveillance'."

But they've stopped doing all that, right? And they totally haven't just shared that same work out amongst their five eyes counterparts so that what each of them is doing is legal in their jurisdiction even though there are strong laws preventing each of them from doing it domestically.

And how would we even know? Without Snowden we wouldn't know most of what we know about what they've been doing. And look at the thanks get got for that...

Re: One Bad Apple

#409

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. The problem is people use this perfectly legitimate problem to justify anything. They think it's okay to surveil the entire world because children are suffering. There are no limits they won't exceed, no lines they won't cross in the name…

This quote sums it up perfectly :

“Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies.

The robber baron's cruelty may sometimes sleep ,his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience.

They may be more likely to go to Heaven yet at the same time likelier to make a Hell of earth. This very kindness stings with intolerable insult. To be "cured" against one's will and cured of states which we may not regard as disease is to be put on a level of those who have not yet reached the age of reason or those who never will; to be classed with infants, imbeciles, and domestic animals.” C.S. Lewis

There are so many problems with this feature :

- it can easily be used to identify also other types of dangerous material such as warnings against government activity or posters of organized protests

- some malicious actor can send you this kind of content in order to get you in trouble

- false positives

- moral busy bodying (your employer not agreeing with you going drinking sunday night)

Honestly, it feels like we're about to enter a new age of surveillance. Client-side surveillance.

Re: One Bad Apple

#410

Earlier quoted context omitted.

They don’t send unencrypted full-res files, they send low res “visual representation” and can only decode if they get > x “hits”. Assuming it works as described I do think it’s better than just having full keys as they do now. And why else would they go to all this trouble? They can scan images now on their servers if that’s what they want.

Low-res I suppose is better but...If it's enough for a human to tell whether it's CSAM or not, it's probably high-res enough to be a significant invasion of privacy in case of a mistake. Also the > x "hits" part is a good feature assuming that the database only looks for CSAM. Otherwise it's useless (not to mention totally unauditable). My guess is that they're doing it on device because they've had several years of…

Do you actually think they didn't have CSAM scanning implemented server-side before this?
Post reply on HN