Facebook asks users for nude photos in project to combat revenge porn
theguardian.com
theguardian.com
Zuck: Just ask.
Zuck: I have over 4,000 emails, pictures, addresses, SNS
[Redacted Friend's Name]: What? How'd you manage that one?
Zuck: People just submitted it.
Zuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb fucks.
I sure as hell said some edgy stuff like this when I was 19.
Edit: Ugh. The witchhunt above was unrelated to those IM messages. Apologies for the mis-step.
Not sure which is better.
As a trivial example: In 2005, when Facebook was a non-trivial company, Zuckerberg [0] guest lectured at a Harvard CS50 class. When asked if Facebook would contribute to open-source, he said that he didn't foresee it being worth the trouble (can't find the exact timestamp, so this is all IIRC with a grain of salt). Now of course, open-source is a substantial part of Facebook. Is it because Zuckerberg in the following years had a Road to Damascus experience with Richard Stallman? Maybe, but it's more likely that Facebook evolved into the type of organization where OSS became a benefit to the bottom line, and it was a decision made by people lower than Zuckerberg at that point.
Even if Zuckerberg is still as much a creep as he was in private IM messages as a 19-year-old, he's no longer the sole captain of his tiny boat. Him breaking the law means that many people end up getting in legal trouble, i.e. it doesn't really much matter what he alone thinks is moral when he has dozens of people/potential whistleblowers looking over his shoulder with greater moral concerns.
Edit: What's above isn't quite right. There was a witchhunt, but unrelated to the leak of those old IM messages. Apologies. My point below, though, stands.
A mea culpa about the messages, and how you've changed personally in the meantime would have been a change.
And looking for (and finding) a specific person who has violated a specific, well-understood rule and sanctioning them is not exactly what a witch hunt is.
The value of mea culpas is under-appreciated. We all make mistakes, and you can't change that in life. But you can change course after recognizing a mistake has been made.
I personally find that the worst people I have interacted with in life are also those who cannot assert a mea culpa.
Isn't the point of Facebook to keep such kind of comments forever in each individual profile? I don't see why Zuck should be immune to something he benefited from in the first place.
We as rational humans though, can apply context to such situations and realize that teenagers often say insanely stupid things that they later wish they hadn't (and usually didn't mean).
It is pretty clear they are not interested and letting us really manage what we posted on its walledgardn. There's no way for me to mass delete/edit posts on facebook. Yes, facebook did not force me to post things 10 years ago but it seems like they are forcing me to hold my own post against me for eternity unless I spend years of my time to go through one post at a time.
Delete facebook profile? well it doesn't really delete it: https://www.quora.com/When-you-permanently-delete-your-Faceb...
Zuckerburg continues to only do what's in his best interest, even at an older age. i.e. not combating racism, harassment, or abuse on their website because it'd hurt their bottom line. This a business and everybody is willingly giving him products that exploit his user base.
If you want to say "Zuckerberg is selfish because he refuses to affect Facebook's bottom line to stop harassment" that's fine with me, and I won't disagree with you.
If you're saying "Zuckerberg stole someone's lunch money when he was 12 therefore he's a sociopath" I dunno, that's less convincing to me.
> A community operations analyst will access the image and hash it to prevent future instances from being uploaded or shared.
How long before the first community operations analyst begins selling the images they access? How long before the first one uses it to blackmail an already terrified victim? And when -- not if, when -- one of these things happen, what price will Facebook pay (I mean, with corporate accountability being what it is, we all know what price Facebook will pay, but it would be useful to at least have a fine print...)?
Considering that we haven't seen any stories of employees abusing backend access to the Facebook servers, it feel reasonably safe to assume that they have countermeasures like these in place.
Though I, personally, prefer counter-measure two: terminate everyone who approved/supported/championed this project
There are companies that (supposedly) implement various such countermeasures, and have a very strong incentive to do so, as they handle private, and potentially damning data of important people with millions of dollars to lose in case of a data breach. Just look at Panama Papers, Paradise Papers and the like. If that sort of data can be treated carelessly, I find it somewhat unrealistic to expect better treatment (even from Facebook) of private data belonging to terrified teenagers who effectively have no recourse against misuse of their pictures.
Second, it took considerable time for the fact that former NSA employees used the agency's surveillance tools to spy on their ex-lovers, too. The fact that we haven't yet seen any stories of employees abusing backend access to the Facebook servers does not tell us much. In fact, given how much information is publicly shared (sometimes unwittingly) via a Facebook account, it may be hard to tell when such an event occurs.
Why not use facial recognition + nudity detector to on-demand find potentially compromising videos online? Maybe even send my Facebook notification that says, "Hey we found what appears to be a compromising video with you in it shared to a wide group of people, are you cool with it?"
Am I mis-understanding the concept being proposed?
But what really bothers me is
> ... a community operations analyst will access the image and hash it to prevent future instances from being uploaded or shared.
Of course, this community operations analyst will not stash those photos in a flash drive somewhere, right? Because the humans FB hires are 100% trustworthy. /s
Then there's the issue of how your proposed system requires FB to show users the porn that other users are privately viewing.
https://www.facebook.com/help/122175507864081
You other points are true though, and I guess a lot of these type of photos don't always contain faces.
That secondary data does not exist reliably in the context of revenge porn videos that go viral. Nevermind that the penalty of a false positive -- which would presumably involve exposing the user to a bit of random porn -- is substantially higher than it ever is with mistagging friend photos.
I think this can be addressed as "Show me all suspected compromising videos of me that is available to more than 10 users". The answer to that query can be produced with facial recognition and nudity detector, no?
Anyway, does this mean that I can take down other people's legitimate photos by submitting them to this service?
https://cloud.google.com/vision/docs/detecting-safe-search
EDIT: Just read the part that says a "community operations analyst" will hash and analyze the photo. That's terrible!
"responses": [
{
"safeSearchAnnotation": {
"adult": "VERY_UNLIKELY",
"spoof": "VERY_LIKELY",
"medical": "UNLIKELY",
"violence": "UNLIKELY"
}
}
]
How is that useful for efficient detection of what the OP describes?edit: "useful" as in, how would that be granular enough for what FB would need? I don't mean that FB literally uses Google's API/endpoint response, but that FB isn't trying to detect and prevent adult content, but malicious content that invariably happens to be adult content.
But my perception is that victims of revenge porn -- the ones who feel the need to make a complaint (and risk drawing publicity to themselves) have had (or perceive) their images disseminated so widely to such psychologically devastating effect [0] that the thought of a FB employee seeing them is among the least of their worries. Probably because FB employees have already seen them if the user has submitted an abuse complaint.
[0] https://www.theguardian.com/lifeandstyle/2015/feb/06/experie...
1. User submits hash.
2. Other user submits photo, which matches the hash, which is detected by the system.
3. Facebook employee is notified. Looks at photo.
4. Photo is removed.
This way, the employee only looks at the photo if it was actually submitted. If (2) never happened, then (3) never happens.
Otherwise I could hash and submit the Disney logo.
Persons found abusing the reporting system could have their own trust revoked -- their hashes would be considered noncredible absent independent verification. Similar standards apply, e.g., in witness testimony ("impeaching a witness").
https://www.theverge.com/2016/4/13/11387934/internet-moderat...
> When Dave Willner arrived at Facebook in 2008, the team there was working on its own "one-pager" of cursory, gut-check guidelines. "Child abuse, animal abuse, Hitler," Willner recalls. "We were told to take down anything that makes you feel bad, that makes you feel bad in your stomach." Willner had just moved to Silicon Valley to join his girlfriend, then Charlotte Carnevale, now Charlotte Willner, who had become head of Facebook’s International Support Team. Over the next six years, as Facebook grew from less than 100 million users to well over a billion, the two worked side by side, developing and implementing the company’s first formal moderation guidelines.
A normal file hash is probably not useful in this scenario.
[0] http://phash.org
Is there an app for that? /s
To be honest, this is a great idea. I think its something that should be built into OS's -- select a file, 'calculate WorldHashValue' / 'publish WorldHashValue' should just be a menu-item ..
Of course, every user can do that knowingling, just crop the image a very tiny bit or change one color of one pixel and the hash is going to be completely different.
[0] http://phash.org/ [1] https://github.com/westonplatter/phashion
I feel like many people won't be super comfortable with Facebook having their nudes on top of everything else.
> The technology was first developed in 2009 by Microsoft, working closely with Dartmouth and the National Center for Missing and Exploited Children to clamp down on the same images of sexually abused children being circulated over and over again on the internet. There was technology that could find exact matches of images, but abusers could get around this by slightly altering the files – either by changing their size or adding a small mark.
> PhotoDNA’s “hash” matching technology made it possible to identify known illegal images even if someone had altered them. Facebook, Twitter and Google all use the the same hash database to identify and remove illegal images.
with(image):
post = facebook.post(image)
if post.is_deleted():
image.is_blackmail = True
otherplatform.post(image)1. Don't make nude pictures of yourself or let someone else make one.
If you manage to screw up step #1, then:
2. Don't let other people have those nude pictures or upload them to the Internet.
That's it! Can you believe that this has actually worked for me for a good 20+ years so far? I know it seems too good to be true, but trust me it totally works. I should blog about it.
Every time I think I met the Peak Stupid, Internet proves me wrong.
Use standard ML Algorithms to validate if the image includes nudity and confirm the hash overlap.
Also need to be hesitant since people at FB will be able to see these images (as recently mentioned in another post on HN where some random folk ended up viewing a Google Doc shared via Messenger)
Or have a checkbox in the profile settings: Do you permit other people to upload nude photos of you? [ ] Yes [x] No
What would they do if they detect a possible match, though? Ask the person they think is in the photo "is this you, are you ok with John Doe sending this photo to Jane?". That could lead to trouble when the system gives false positives.
edit: Downvotes without suggestions or rebuttals? That's disappointing. I didn't say that this system is without flaws (or worse, unintended consequences). If you think the status quo (whatever that status quo is) for the anticipated victims, then let's hear it.
Don't let your partners take photos when you are intimate. End of story.
As such, the parent comment goes a long way towards protecting you.
Think of it like a padlock: it keeps honest people honest.
On the other hand, unauthorized photos taken of you in a place you'd expect privacy is a fairly well explored body of law; basically unless you're a celebrity figure, it's a no-no.
IANAL, of course.
Surely, not letting people take nude photographs of you is both (a) common sense and (b) likely to make a significant dent in the problem.