Man charged after media storage site Dropbox finds child porn in his account
publicopiniononline.com
publicopiniononline.com
This isn't "Dropbox employees digging through everybody's files hunting for CP". It's all automated, likely triggered by uploads of certain types of files (images/videos). They almost certainly have a human verify the validity before reporting (which is probably a 100% manual process). They're required by law to report it once they have reasonable suspicion.
An interesting abuse edge case here I've pondered for a while: someone hacks into your account and intentionally posts bad stuff to get you in trouble. It could be pretty difficult to prove that someone did this if the company's logs were inadequate. A similar flavor of this: someone sent Brian Krebs heroin in the mail, and then "tipped off" the police. Fortunately, it didn't work https://krebsonsecurity.com/2015/10/hacker-who-sent-me-heroi...
If a script can access users' data what's the difference?
That said, the point probably still stands that encryption is probably not feasibly with Dropbox feature set (or while maintaining a certain performance).
Dropbox deduplicates everybody's data, so that they'll be able to take advantage when you and someone else both store the same file. (Of course, this trivially means they can recognize when someone stores a file which the FBI has previously provided to them.)
Oh, and thanks for a product that does what I need it to do. I'd maybe have liked a bit more documentation (for example, how to speed up retrieving a backup), but other than that I'm very happy with it!
Probably some others but that's the main US one. IIRC, they may be given special legal status here to this effect.
I don't envy anyone that has to deal with child abuse at any level but I guess someone has to do it.
Passwords are everywhere, and most people don't use MFA. If dozens of celebrities had their iCloud accounts hacked, there's no doubt that thousands of normal people could have their dropbox accounts hacked - for the purpose of adding nefarious files, not downloading sensitive ones.
I mean, I just went to their "about us" page and here is what it says:
We create products that are easy to use and are built on trust. When people put their files in Dropbox, they can trust they’re secure and their data is their own. Our users’ privacy has always been our first priority, and it always will be.
Wholesale scanning of user data with heuristics and automatic police reports out of no legal necessity whatsoever certainly doesn't spell "privacy always our first priority" to me.
Dropbox scans user accounts. It alerts the police that objectionable material appears on an account.
The police attempt to associate the account with a person. Social media profiles and IP adresses turn up a name and general geographic location.
Police find a person's name associated with said profiles, email, and IP.
They show up at his address, and ask him, hey, are these accounts yours?
"Maybe, why?"
The police then execute a warrant, confiscate his phone.
The phone contains an app, which is logged into an account with objectionable material on it.
You are now charged with possession of child porn.
Child porn is a terrible and heinous crime. Put that aside for a moment.
What happens if someone illegally accessed your account and placed those images there?
Is it unreasonable for my account to have been hacked and used to hold illegal material?
There are accounts of mine that I don't even remember existing.
Multiple use multiple devices of mine from time to time.
Should my dad be hauled to prison when I use his computer, and I catch a virus that stores child porn in his dropbox account from 5 years ago?
I wouldn't necessarily say unreasonable. Incredibly unlikely, though.
The question is whether there could be reasonable doubt that, given there is CP on an account, it was put there by the account owner.
What we don't know is what proportion of Dropbox accounts that contain CP had that CP planted by a hacker. If a significant enough proportion of CP on Dropbox was not put there by the account owner, it's reasonable to at least consider the possibility.
It doesn't have to be an attempt to frame the account owner: somebody who wants to exchange CP with other people might well use a hacked Dropbox account to do that, in an attempt to cloak their identities.
If it's the case that someone illegally accessed your account and stored child porn on it, there would presumably be evidence to show that illegal access, such as IP addresses that you don't use that were used to upload that porn.
What if it was (somehow) accidentally uploaded byy little brother who torrents?
Technical evidence, is difficult to associate with meatspace users.
I'm not trying to give criminals potential defenses---
I am trying to prevent people from going to jail for malleable evidence.
There's still the possibility that some malware on the user's laptop uploaded the files and then deleted itself, but if that were a reasonable excuse, you could use that to get out of basically any computer-related crime.
Depends who planted them...
You'll go to jail, and have to figure out how to post a $100,000 bail right then or stay there for quite some time, sometimes indefinitely (see current Riker's Island cases in NYC), you'll have to figure out how to find a good lawyer who maintains a reputation AND won't take the state's charge and media smearing at face value, and also pay their retainer.
Your lawyer will have hoped you actually didn't say "Maybe, why?"
Why do you ask, were you expecting some enlightening thought exercise on changing the process? This happens everyday in this country.
I suspect that you should feel some of these things should change.
Perhaps a lower bail? Perhaps house arrest instead of jail? Perhaps a less costly legal process that vehemently screens for reasons to not go to trial in non-violent crimes? (child porn possession is debatably non-violent).
How do we increase the possibility of bringing about these changes?
If you can't do any of the things I mentioned above, you will take the plea deal and there will be no trial, you will go to prison for at least several years, possibly decades, but either way you'll be a felon and unemployable for the rest of your life, also a sex offender for the rest of your life, and not for one of those debatable reasons either. But thanks for keeping the process quick, that was very considerate.
But change? Good question. Something broad that isn't about the topic and laws at hand, perhaps leaning on another country's system while being sensitive of our punishment culture. Yeah, I've got nothing, rehab perhaps? I do have to commend you for trying here, and I do hope less people are ignorant to the user experience problems in our justice system.
Once again proves that "don't go to the US" is a viable legal strategy.
My company uses Dropbox extensively for storing documents with sensitive information.
Although there is a database of hashes and whatnot for child porn that service providers can access, so they don't necessarily need unencrypted access to the files, since they can hash locally and send that to their servers.
If Dropbox did that, you wouldn't be able to reset your password (since they do not store your password, just a salted hash, I hope).
Dropbox does plenty of interesting things with its users' files to optimize storage. I know they dedupe files, probably using a file hash. Perhaps they optimize even further.
Right, or course. I'm thick today.
Dropbox has been in the news for scanning user files for years (eg, [1][2][3]). Note that the third link dates back to 2011; not a new issue.
If you do want to keep your data secure from the cloud provider, encrypt it yourself, or use a service that encrypts it before uploading using a key you provide (and with a client you trust not to be compromised). Spideroak makes a big play for this market[4], but I can't vouch for them.
[1]: http://www.pcworld.com/article/2048680/dropbox-takes-a-peek-...
[2]: https://www.extremetech.com/computing/179495-how-dropbox-kno...
[3]: https://readwrite.com/2011/04/20/how-to-keep-dropbox-employe...
I don't mean to nitpick and it's been a while, but Dropbox used to claim that "even our employees can't access your files". People called them out on the misleading language and they changed it.
https://www.cbsnews.com/news/at-dropbox-even-we-cant-see-you...
Specifically I recall a story that pirates were using their api to just upload the hash and basically use it as a file transfer service. They had to start requesting random chunks of files to make sure you actually had the file you were trying to sync.
Edit - I found a link: http://www.wired.co.uk/article/dropbox-dmca-position
The file uploaded in an instant, lending a lot of credibility to the theory that the software hashes a file and looks for the same hash in a central database, and if there's a match doesn't bother to upload the file but simply adds a pointer to it.
Not really surprising
I have no knowledge of Dropbox' internals, but I've been involved with several cloud backups solutions that "fully encrypt your data". Only to have a hard time convincing people that "Full Disk Encryption on a server" will do little to prevent an employee of that company accessing data.
That's how I store all of my illegal content on dropbox.
If the reason for your report is that the content involves child abuse, then the company is generally accountable for checking it out. This means different things depending on the type of content, the country, and lots of other moving parts, but it is the "safety of the children" argument at work. In practice, often an American content host will let NCMEC know, since they compile and forward on reports to law enforcement. Sometimes content will simply be removed. Again, it depends on the details.
This is indeed one of those cases where your privacy, and the rights you have over your property, are impinged upon as a regular person. The courts where I live (Australia) take this quite seriously and are aware that a balance must be struck. I get nervous and uncomfortable when the "think of the children" argument is misused during discussions involving encryption, intellectual property violations, and general freedoms - but I'm aware that on some occasions it is important.
A lot of work goes into identifying and where possible rescuing the children involved in this stuff, and preventing more. That is always the focus, in my experience.
A final note - the child protection industry is keen to remove the word pornography from the lexicon, and to refer to this type of material as "child abuse" or "child exploitation" material. I think it would be good to reflect that in the headline, because while most everyone knows what child porn means, calling it such mentally associates it with the pornography aspect (the end user) rather than the victim (the child).