WhatsApp has an encrypted child porn problem
techcrunch.com
techcrunch.com
Wait what? Moderators for end-to-end encrypted communication?
Something doesn't add up!
WhatsApp doesn't provide search but groups can be joined via links. Third-party apps and sites use the links to index groups. Some groups share illegal content. WhatsApp should hire people to crawl those apps/sites, find the illegal groups, join, verify and ban.
Not entirely unreasonable. Won't fix anything* but if the company is big and well funded they should at least make some effort.
* so you ban the users? $10 gets you a new pre-paid sim card
Could it be that "tech companies" are reluctant to pursue cat and mouse solutions (which also cost money) while "non-tech public" seems content enough if attempts are made to push the issue deeper under the surface?
And then when they recycle the unused number, and you get it and discover you are "lifetime banned", and I'm quite sure there's no appeal process.
For instance, steams anti-cheating service will lifetime ban you and your phone number if you ever get chaught cheating in any game that uses steam anti cheating services. And apparently you will also get banned if you update your account to a previously banned number. That sucks for normal users who get a new phone number but doesn’t do much against determined cheaters who just purchase a new SIM card if they get caught (and they won’t use their real steam account as well).
Steam is not the only service that heavily relies on phone numbers not changing and I find it very troubling how little is reported about that (which might become a real concern later).
I believe the only reason WhatsApp doesn’t do that is because 90% of all people aged 16 to 69 use it at least a few times a week in many of their markets and a recycled phone number will very likely be given to a new, innocent user (unlike smaller sites such as steam where giving a cheaters number to another person who also uses steam is quite slim).
This is a problem that needs a good solution, but you're literally suggesting that an arm of the one of the world's largest data collectors and propaganda engines, which offers free encrypted public communication to the masses, should fund and operate an internal spy agency whose job is to blend in and infiltrate groups and conversations in order to find illegal content. At what point is Facebook still not a mass-surveillance network?
I'm also not sure to what extent the onus should be on WhatsApp to try and remove this stuff, in the same way that I'm not sure to what extent the onus is on Google to trawl through Gmail inboxes it finds through crawling child porn sharing sites - the latter idea seems ridiculous to me, but maybe it's just because of the scale of the platform or the issue, but with a lack of hard data made available as to the extent of WhatsApp being used for CP, I think it's better to remain skeptical.
But I will add this: if (and it's a very big "if") it is determined that it is right (in whatever sense we can use the word) to stop people using the platform in this way, I would never consider "but it costs money to do that" to be a reason against doing it in most cases. Justice doesn't stop because it's expensive.
I can't imagine these people are writing something like "child porn in this chat --> <whatsapplink>".
I haven't the faintest idea how people who're interested in that sort of thing're finding these links.
Definitely a problem which seems potentially intractable to me, although perhaps more familiarity with the platform and the offending chat groups would help (or... more likely... leave me rather disturbed).
Obviously it wouldn't work with the way WhatsApp groups work now, but it is in a strange place half way between private and public.
I don't think WhatsApp in particular has a problem.
Are houses a problem because they hide crimes with their walls?
This seems more like blaming a hotel for letting one of their conference rooms be used for an illegal porn swap meet.
Just like houses. Except you can share more than images on those.
If not, why is that different?
People always say in retrospect about new technology 'they shouldn't have done this because I don't like the outcome' but how could they have known ahead of time and what would not doing it get them? There are very few cases when they really should have known better - leaded gasoline for instance.
That's a very bad trade-off, which would no doubt also result in other types of crimes being committed. It would also be completely pointless since these people could just switch to the next app, or setup their own app, or encrypt the files before sharing them on any random file sharing service.
It's hard to read some of these stories without ignoring the current surge of schadenfreude that writers are capitalizing on.
In a few years blockchain based messaging apps will be launching and they will not be controlled by Facebook or anyone else. You won't be able to ban anyone. This is something we are going to have to accept and deal with. There will be things you don't like on the internet.
Out of genuine curiosity, where do blockchains enter into the messaging space? Auditable chat histories and identities? As opposed to other cryptography/security techniques, blockchain doesn't seem like an especially good match for the problem space.
A messenger using the blockchain as its medium requires no staff to operate it and has nobody responsible for it. There is nobody to blame for whatever it's used for and nobody to dictate what it can and can't be used for. The group chats will simply exist and require no maintenance which is very desirable from an app point of view. Also a big positive is that you don't have to worry about the company running your messenger going out of business and then you lose the ability to use your app.
The part I'm having a hard time with is that blockchain's specific strength relative to other distributed approaches is the ledger. That's not really the crux of the decentralized messaging problem.
Unless you need the immutable ledger, other approaches solve identity, privacy, and persistence aspects of messaging just as well or better without the overhead that blockchain approaches introduce.
I can see the value in the distributed part certainly but if the storage requirements are very large due to a large volume of messages (I'd imagine any solution which caught on could quickly outpace the number of transactions on something like the ethereum or btc network), wouldn't it necessarily just end up centralized?
It's an interesting idea though.
Well https://tox.chat and https://ring.cx (now Jami) can do just that as well as https://briarproject.org.
So these do exist. Such a thing was also being proposed for Ricochet https://github.com/ricochet-im/ricochet/issues/54
The problem is that "content that stands to gain most from using [encryption]" also includes activists protesting authoritarian governments, or even government officials themselves who don't want to be spied on by their rivals, or victims of stalkers and domestic violence.
I have no doubts that the big companies which this seems mostly for will be doing everything to decentralize and remove themselves from the problem citing "systemic weakness" and then doing nothing for the government.
ASIO has to provide statistics on how many notices they issued in their yearly reports. In addition, recipients of reports are allowed to provide statistics about his many reports they've received. See s317ZF.
> I have no doubts that the big companies which this seems mostly for will be doing everything to decentralize and remove themselves from the problem citing "systemic weakness" and then doing nothing for the government.
Except that Apple (and other such companies) have explicitly designed their e2e systems in a way that they could be backdoored (users don't need to sign new identities with a key, so Apple can add a new one -- which is how the device adding feature works).
In addition, many such companies have the ability to provide a single backdoored binary to a single user. This, according to the legislation, would not be a systemic weakness. There is work you could do to make yourself resilient to company-wide sabotage but no company I'm aware of is doing it.
EDIT: Okay, that came out more snarky than I wanted it to. On the one hand, you are right, of course: Provide a secure, encrypted, easy-to-use means of communication, and people with something to hide will use it. If I wanted to download or spread child pornography, I would not do it via an unencrypted channel, either.
On the other hand, your comment might be read by some to mean that you think encryption is the problem. And I think, by the time somebody posts a video of a child getting raped to a WhatsApp group, the problem has been around for while and is not going to magically disappear if WhatsApp were to remove end-to-end encryption from their service.
And child pornography, understandably, provokes strong emotions, which is why politicians and law enforcement officials eager to push more surveillance or censorship like to use it as a reason to push their agenda.
Huh? Who are these NGOs looking out for? Why wouldn't you tell FB in the first instance?
If you can track down a bunch of these groups through public / advertised urls you can probably figure out a whole bunch of them based on the participants in each group. I bet it forms a beautiful graph.
There might be some other user patterns you can identify which point to suspicious groups / patterns as well
How else could you solve this? Create hashes of known illegal images and check them locally?
What if that someone doesn’t show up in the list of group members because WhatsApp has this built in
What if you don’t control the source code so you can’t verify this
What if RMS was right
What then
The medium used to communicate is irrelevant to the discussion here. If they can't control the unencrypted platforms, why are they pulling focus to encrypted platforms if not to influence public opinions regarding encrypted mediums?
Also, this (Frankly dumb) article perhaps unknowingly just marketed the existence of these groups to new fans (I note that the link to the cited Android app for whatsapp-group-discovery now 404's) and THAT will surely be harmful.
I'd comment on the article itself but Techcrunch's website is a dogpile of shit with a terrible onboarding workflow and site design.
[0]:https://arstechnica.com/tech-policy/2018/06/ex-cia-engineer-...
Like what? Does no one who looked at this article (before publishing) have any idea how the internet works? Do they have this wonderful illusion that just because something is made slightly easier to access that it suddenly boosts how many pedophiles in the world? Little Johnny doesn't just browse a WhatsApp directory listing and say, "You know what? I've never really wanted to see children abused but now that there's a nice 'Adult' section containing this sort of content... I think I'm a pedophile now!" Anyone viewing that crap voluntarily was a pedophile to begin with, and like every single one of them, public castration should be an acceptable form of punishment (legalize it).
CP (a known abbreviation) has been circulated on the world wide web since the first big wave wherein more than a few thousand people were using it (back before it was referred to as the 'internet'). Hell i remember accidentally running across several images in my early teen years (when I was moderating for a forum), surprise surprise, it didn't "growth-hack" that vile garbage into my life, you know what it did? It ruined my day that's what it dig, and I absolutely hated the fact that I even saw that, it made me want to never see it again! Flagged for deletion, offender's account was terminated, and a report was filed (with the authorities).
It was also around this time that me and some of my friends decided to have some fun on IRC, I was bored enough that I would often troll IRC for hours, found several questionable channels, where RP (a known abbreviation) was huge and a few of the members were looking for someone to RP as... well children. Yikes! So... we didn't RP, what we did was act like real 12 yr. olds just to mess with them, and after a while of conversing, we'd sometimes get these creeps to get on a greyhound and make a trip (several times across the country) to send them to non-existent meetings, often humorously sending them to a place right across from a police station or whatever we thought was funniest.
Innocent fun I'd say, but anyway, more to the point of the article. No this does not "growth-hack" pedophilia, it just makes it all the more apparent that people are not inherently good and it's stupid to think you can stop the rot. Though I do support the push to limit this as much as possible, though I'd like to see arrests, I'd like to see these bastards rot in prison till they drop dead, and any solution that just covers up the issue without actual consequences for the offenders does not get my consideration. Children are our future, they must be protected.
Goodness, who knew?