Adding Client-Side Scanning Breaks End-to-End Encryption
eff.org
eff.org
There is a thing called "mandatory reporting" where teachers have to report suspected cases of even low levels of abuse. The organisations that do the investigations are so under funded and under staffed that the only issues they are able to investigate are those where the child's life is in immediate danger. Anything less just falls off the radar.
That's how much governments really, actually care about protecting children.
When they want to scan electronic communications, it ain't for reasons of protecting children from harm.
This is complete nonsense
-----
Ridiculous that this was downvoted. You understand OP is saying crimes likes rape and kidnap are not being investigated?
It doesn't become a crime until it happens though.
Maybe I've answered my own question / outrage? As a rule, I don't support "pre-crime" ideology. What are the definitions of 'abuse'? What household situations point towards the likelihood of future 'abuse' and is this just 'pre-crime'...?
Do you think the anti-encryption / communications surveillance would help to stop these things from happening?
Are most of the crimes perpetrated by relatives of the children?
If Child Services visited these people prior to an incident occurring, in what percentage of cases would there have been cause to intervene?
Do you have the resources to investigate all the cases you feel worthy of investigation?
What political decisions would help minimize these incidents from occurring?
I want my commentary to be hand-wavey and wrong. I'd be very happy to hear that it is.
Surveillance in the general sense definitely stops offending from happening because it allows on-going offenders to be identified. This article is about client-side prevention of distributing known IIOC, which is more a method of preventing a crime before it happens (the crime being Distribution of IIOC, not the sexual assault/rape the imagery depicts).
Loads of things "worthy of investigation" are closed off due to resourcing issues but what you said was that only cases where there is an _immediate threat to life_ are investigated which is completely false.
Without any of this, your comment comes across as low value and will attract downvotes.
There is room to argue against my point just based on the fact that if a kid is going to school, that implies a certain amount of 'care' by the parent / guardian already, so maybe my argument's subset is already flawed.
However, rape and kidnap are actual crimes whether against children or not, so these aren't really under the auspices of Child Services - that's precisely where police and detectives do come in.
It's not an easy area to work with, which is why politics probably tries to ignore it. Certain scales of abuse may actually be preferable, in the long term, to removing the child from the situation and putting them into the hands of the state. Removal from parents is psychologically damaging in itself. It's a very fine line, and one that pretty much all humans should be squeamish about.
"When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3.""
> Ridiculous that this was downvoted
"Please don't comment about the voting on comments. It never does any good, and it makes boring reading."
It's even worse than that imo. It basically says "That is idiotic", skipping over the "1 + 1 is 2, not 3" part. The amusing part is not that this was downvoted, but rather that it gains a positive number of votes every few hours.
14? They’ll gladly do it with even younger kids.
This war against end-to-end encryption is a complete nonsense and is meant as a control for general public as anyone who doesnt want to be spied on can and will take actions against.
It looks like even for the non techie GPG-literate person, encryption is available, simple, non stoppable.
That’s a big shift in who uses encryption and how easy it is to passively surveil them.
Any half-serious operation would likely just order a custom encryption app, anonymously, paid for by monero, or something.
What really is important is reliability. An open source app, checked by experts, buildable from scratch in a controlled environment, is much less likely to have a bug planted by a three-letter agency.
So yes, good and widespread end-to-end encryption is a large nuisance for said agencies, even if a successful ban on it does not prevent criminals from encrypted communication in principle.
This makes government backdoors not only an unwelcome intrusion, but also entirely pointless.
Instead it’s just a lock the reports who visits your house and can choose not to allow some people in.
Given that, it's reassuring when the evil don't get pwned. Because they're canaries. If they're safe, you're safe.
Testing can only prove the presence of bugs, not their absence. Reading about other people getting hacked can warn you that you're vulnerable to the same bug, but if they didn't get hacked it doesn't prove anything.
Still, if available software and systems don't let them be safe, those software and systems won't let you be safe either. And arguably, the assholes are better at staying safe than you are. Or at least, the ones who aren't will go down fast.
And when they do get pwned, it's often a public matter. Because criminal matters are public in sane countries, and they're newsworthy. So, for example, busts have alerted us to file snooping by anti-malware apps, retention and disclosure of VPN service logs, Firefox bugs, and leakage of Apache error messages around Tor. Also the risks of using unusual slang, although that's a human failure.
On the other hand, for criminals it's a little different since they rely entirely on technology. That's also an ideal for some people of a libertarian mindset who are not criminals, but it's not the only way to do things.
A combination of legal, political, and technical safeguards may work better than purely technical rules for most people? We don't have to live outside the law if we make the law work for us. Anyone who talks about legal rights is implicitly putting some faith in the legal system to put things right, as an ideal, anyway.
1.) Simple alteration (change a pixel in MS paint) or encryption of content bypasses the filter 2.) Patching out the filtering routine bypasses the filter 3.) Blocking the phone-home address (pihole, router firewall, etc) bypasses any reporting 4.) Any vulnerability in the future that allows an attacker to report arbitrary clients (disclosure of client IDs, weakness in app, weakness in server) renders evidence gathered by the system unreliable.
At best clientside filtering allows you to draw relationship maps of technically incompetent perverts who might possibly be sharing CP. What harm reduction are they trying to get out of that?? Why not just refocus efforts on catching the small minority of individuals who are actually producing this content??
But hey, if these garbage clientside filtering of image uploads is enough security theatre to keep governments satisfied, I say let them have it.
The thing to be wary of is that they may be intended to be useless. Their purpose is not to work, but to establish the precedent / principle that invasion of privacy is warranted / justified / accepted / needed. This then sets the stage for later saying "we now want to outlaw encryption completely because the previous methods that are already [accepted / justified / needed] are not working". So for the ultimate aims of their proponents, it's better if they don't work than if they do.
If you want to see it in action you can look to Australia where it is exactly this argument being employed: ie - police have always had surveillence capability for telephone calls, so new powers that inject interception capability into the OS layer of phones are just re-establishing something already accepted, not introducing something new.
That said, I'm not sure from a privacy perspective that I like communication apps playing the referee. Sure, its terrorism or child porno now. What about when it is political content regarding 'X' that is prohibited?
There is also similar problem with spam where spammers send email with images in order to fool the spam filter. If the algorithms in PhotoDNA would be effective then the problem of spam images would be a fairly solved problems, but what I keep hearing is that the only effective tool is machine learning.
The image could be scanned when it's received, and not when it's sent. That way you can't use hacked clients to send forbidden images.