A dad took photos of his toddler for a doctor – Google flagged him as a criminal
nytimes.com
nytimes.com
Compared to a beach in Europe, where nearly half of children under 2 run naked, there seems to be no grey area or minimum acceptability in the US.
It makes me wonder if our hypersexualized treatment of child nudity /actively contributes/ to the sexualization of children in our culture.
I find it disturbing attributing particularly sexuality to children (actually I find a lot of adult looking clothes more disturbing than a nude child).
I know that there is people with sexual disorders (I would strongly argue that pedophilic arousal is one), that commit serious crimes. I also do not advocate publishing any nonconsensual pictures on the internet.
However disallowing something just because it can be abused is rediculous. Banning this guy protects nobody from nothing. Yes they could have blocked the upload of the image to the cloud (I would be happy to locally install any nude detection AI that does not communicate with the cloud. Even something that ask me if I have consent feom all identifiable persons in an image is fine for me. I think the father would actually have been happy about this. No need for manual inspection.)
You can't really fight nature. If a child is born to horrible parents who abuse them, there is only so much anyone can do... The child's life will be ruined from the beginning, the government cannot undo the damage which has been done.
But there's something weird about it. Just like when you look at previous periods in time and now they look weird, often just reactions to previous epochs or other cultures (like the neoclacissim came as an opposition to rococo and baroque).
This feels like it. It doesn't feel natural. It feels like it is purely out of a contrarian way of thinking, about how forward thinking they are, "look how superior we are that we are completely void of instinct to cover ourselves". and perhaps somewhat of a sexual counter balance to the strictness of the rest of their culture. I'm not sure i'm explaining this in the best way. I think there is a natural middle ground, the one that we have seen throughout hunter gathere human history, and Nordic countries are just being culturally weird by going to one extreme.
This is why police fired into a stolen minivan that had a unrelated child and a shoplifting/carjacking suspect in it, killing both. Protecting the child took a back seat to punishing the prep.
Therefore CP laws very quickly stopped being about protecting the children and more about punishing the pedophiles.
Vindictiveness and spite are the unspoken role models of the US justice system.
Nudity in kids is seen as obscene purely because a pedophile could find it arousing. We are preemptively sexualing children in order to prevent their sexualiztion.
A child was once forced to masturbate in front of a camera by COURT ORDER. Police held them down. All because the child was a victim of child pornography and the court wanted a "comparison image" in a similar arousal state to prove it was a image of that child.
Once again, a child was victimized by the justice system, in order to punish a perp.
Never make the mistake of thinking anybody in the justice system gives a rats ass about protecting anyone.
That summary is misleading and, I feel, wrong. It's not accurate to state that he was "a victim of child pornography," the complaint in this case was against him by the parent of another minor that he was "sexting" with.
That doesn't excuse the police behavior here, but you're attempting to paint a picture where the victims in these cases are outright ignored in a misguided search for justice. You're twisting this case[1] to fit your narrative, I think.
Further, he sued the government and won. The courts made it perfectly clear, the lower courts and police were absolutely in violation of this teens rights when it granted and executed this search warrant. So egregiously that "qualified immunity" doesn't even apply to the officers estate.
I wasn't going to address this, but..
> Therefore CP laws very quickly stopped being about protecting the children and more about punishing the pedophiles.
Pedophiles create a market through demand. Often it is also pedophiles that are on the supply side of this market, but not always. Merely participating in the demand side implicates you in these crimes against children as you are suborning their abuse. One could say that our system merely recognizes this fact.
[1]: https://arstechnica.com/tech-policy/2017/12/forcing-kid-to-m...
So if someone participates in say P2P sharing of a CP video with some background copyrighted music, she can be simultaneously guilty of:
1. Suborning the creation of the CP by participating in the demand side.
2. Undermining the creation of music by distributing it for free.
Something inside me says there is something wrong here.
It's sad you are downvoted for this, because it sums up the American mentality perfectly. Some people really can't handle the truth.
I was in a park in Manhattan last week, which had a bunch of big sprinklers for kids to run through. No one was naked in the sprinkler, but some parents helped their children change in/out of their bathing suits out in the open.
(Then again, I only remember this because I was a tad surprised by it.)
in america, you could destroy someone's life over that. (possibly even multiple lives)
But what does this have to do with nudity or destroying lives? Seems totally off base.
Not hard for me to imagine a 7 year old American getting expelled and potentially prosecuted for trying to play a "Kancho" prank on a friend.
So what.
"During a 2001 game with the North Queensland Cowboys, Hopoate inserted fingers in three players' backsides and anuses. The first incident occurred during the seventh minute of play. The matter was referred to the rugby league judiciary on 28 March. Hopoate was suspended for 12 weeks for what one commissioner described as "disgusting, violent, offensive behaviour""
edit: there's honestly never an excuse not to do an existence proof. All you have to do is cite one thing.
>And many normal cultural things in the US would be regarded as an egregious offense in Japan
Many taboos are specific to culture. That's the point
no, the similarity (and why it was posted) is that both games consist of kids attempting to stick their fingers up somebody else's butt.
The OP of this thread's life was wrecked in such a way that suggests our cultural norms are unhealthy.
It is therefore noteworthy to study extreme cultural practices which are HEAVILY legislated in the US (28% of 14-17 year olds report having been sexually victimized), almost always treated in a manner which results in trauma for both victim and actor, yet in a similarly advanced culture (with only 296 total child sex abuses reported last year), is literally a game you play and laugh about.
You have the logic backwards, it's sexual images that have an age, not nude images.
[1] https://netzpolitik.org/2022/dude-wheres-my-privacy-how-a-ho...
> “The more eggs you have in one basket, the more likely the basket is to break,” he said.
I only have a google account to have access to Play store. Everything else, mail, calendar, photos and storage, has been moved off Google
Self-hosting mail, calendar and media is too complex task for 99% of population. This is not a solution.
Currently more or less adequate solution in terms of integration is self-hosted Microsoft Exchange. I wonder how much does it cost (including Windows Server license).
I don’t trust it to be more reliable than a paid service. The thing about self hosted solutions is you’re completely on your own if something goes wrong. You need to make sure you’re backing things up, that you can restore your Nextcloud configuration if your sql database takes a dump or you fat finger and delete some config files (I’ve done both). Or if you have a power outage or lose internet connection and can’t access vital files, or even something simple like a bad software update causing issues.
While a great option, one can’t simply spin up next cloud and then move everything over like you would a Saas solution as a typical layman.
If something goes wrong with your at home nextcloud, you still have the data/hw, and you can either get help troubleshooting from someone who understands what they're doing, or you can try yourself (which will take more time). You're not on your own. And even if you are, you can just shelve it, and defer the recovery for later. But unless it figuratively crashed and literally burned, you're not fundamentally prevented from recovering your data.
Monthly or annual downloads though, can be scheduled manually simply by putting a note on your calendar.
If an account goes down, the thing you'll miss most may not be the recent things, but rather the many years of archives you might have in a Google account.
As for hosting... I just rent colo space and cut out all the cloud stuff.
Neo Backup - Currently maintained, and available on fdroid.
Titanium backup and restore - I don't think it is still maintained, but it still works.
Seedvault which does not require root can't backup a lot of things.
Depending on your phone, you may be able to backup everything with twrp, but it doesn't work with some new-ish phones.
It feels like they built it to say that you can, but your data is still just as locked as before…
If you have "too many" Google photos and that archive fails, create albums for every year, and only download a year/album at a time. It's a huge PITA, but at least you'll get your stuff back. (Kinda: depending on how you uploaded your photos, the metadata may come back truncated or altered).
Many years ago Microsoft has banned my outlook account for no reason. I tried contacting the support to resolve the issue - nothing. Only after writing a letter, I received the answer from Microsoft Germany:
We banned your account because I was distributing porn through onedrive (which I was not doing). The investigation showed that Microsoft could not find any wrongdoing. The account was gone nevertheless.
This is why I say:
- skip Gmail/Outlook and all this crap, use something proper like mailbox.org with your own domain - dont trust cloud. Backup once a month, use two clouds at the same time, have a cold storage with your backups - biggest risk is your apple icloud account. dont be dependant on them: dont use their credit card - dont use google/ms 2fa apps - have multiple accounts in parallel: one for google drive, one for search, one for mail (if you need it), one for youtube, etc
This. Use Yahoo for your email, Verizon for your phone number, Dropbox for your backups, Facebook for your socials… It doesn’t matter which you choose, but fragment your digital life. When one part goes bad, it won’t infect the others.
Synology Diskstations are rather easy to setup and not very expensive.
Edit: yeah it is [1]
> Phone companies are required by law to port your number out when you start service with a new carrier. According to the FCC, a company can't refuse to port your number even if you have an outstanding balance or unpaid termination fees.
[1] https://telzio.com/blog/what-to-do-when-a-carrier-refuses-to...
It looks like with Google you are supposed use the Google Fi app or website to obtain a “port out number” and PIN [1] to give the new carrier when they ask for account number and PIN.
If you accounts have been banned I wonder if you can still get that information?
As it looks from LinkedIn comments, they still do.
During Google+, Google controversially instituted a "real name" policy. This was controversial and completely driven by Vic Gundotra who would get up at company meetings when asked about this (back when he still answered questions because believe me that ended) and said "we don't want people named 'dog fart'".
Legitimate concerns that people might have for their safety were completely brushed aside.
Anyway, the enforcement for this of course was automatic and resulted in I'm sure many false positives. But what happened when your account was flagged/ You lose access to everything.
This too was criticized at the time and people asked "well if it's a policy violation for Google+, why do people lose their Gmail?". These questions too were completely brushed off.
At this time I decided I simply couldn't and wouldn't use any other Google service because my Gmail is too important to risk by an automatic ban from a false positive on a completely unrelated product.
And here we are, a decade later, with the exact same nonsense happening.
Now of course the CSAM ban itself is ridiculous. Refusing to reverse it is ridiculous. All of that is true. But don't tie your email or your phone to a company's other services when they do blanket bans like this.
Disclaimer: Xoogler.
Give us de +Word back... dont "improve" the stupid quotes.
It's such a shame because having these services be healthy and popular benefits everyone.
hah, we're a hetzner costumer for .. years now, but I had no idea they have this :D
https://www.hetzner.com/storage/storage-box
so you can connect the NextCloud to the storage account? which protocol do you use for this?
It has gotten significantly better in the last year or so, but it's still pretty bad and pretty slow.
We “banned” alcohol for 13 years.
America’s greatest battle is with our dark religious past. We claim to be secular but really it’s an aspiration.
How do you know those nudes are taken consensually? And what's your liability for developing ("reproducing") them?
> You can't even take a photo of your own kid.
You missed the part where we're discussing a sub-topic off that story, someone's experience working in a photo store, and the policies in place there.
> Why would you assume a crime by default?
I assume you mean "you" as in a photo store that finds such negatives in a job order, and not me directly?
Because as I said, your liability or even reputation if this isn't from something legal, is not worth the profit made.
What say you
1)Government makes companies liable for hosted third party content
2)Companies set up workflows to detect said content
3)???
4)Blame capitalism
We are talking an adults private photos, not a billboard on the freeway.
there are absolutely no reason to ban it, because that only causes more harm.
somehow many people on Earth have a remarkable resistance to nuance.
Source: human history.
It’s time to move on.
>Source: human history.
The alcohol consumption statistics of certain ME states strongly disprove your thesis.
But it's very hard to find any data (let alone official data) on any of this, because nobody wants to suffer 72 lashes with 0-gague electrical cable at the hands of Iranian police for having admitted to have had a glass of wine or whatever one night.
Alcohol is an aspect of human civilization since per-historic times (as old as farming if not older) and always will be, regardless of what puritan Christians or foaming-at-the-mouth Mullahs might think of it.
Across the board (addiction, alcohol, abuse) any type of "zero-tolerance" "bring the hammer down" policy e.g. a blanket ban on alcohol has always been at best orthogonal and usually antithetical to harm reduction. As someone mentioned in the above comments, nuance is everything in providing support to the vulnerable --- ask any social worker. Religious guilt enjoys no such effectiveness.
(Sorry, two of the citations are in Persian, I couldn't find English sources. Google translate could be a workaround.)
Edit: spelling.
[1] https://www.bbc.com/persian/iran-features-49967036
I’ve lost track of how many people in this thread have blamed Christians. Why? Christian’s do not have a ban on alcohol. Where is this idea coming from, or are we just spreading hate?
Also, in many of the comments in this thread, the word “puritan” is not used.
My comment remains, this comment existed to spread hate, nothing else.
Also what other vices? The word vice generally means bad things so you’re upset that this “group” is giving life guidance? Are you equally as intolerant of a doctor telling people not to drink?
Apparently you’ve never been to Baltimore. There is no dark religious past haunting that city, just corrupt politicians.
Baltimore has 10,000,000 people. The United States is larger by a factor of thirty three.
Baltimore has a population of 600k not 10m, you're off by a factor of 13
That's as batshit crazy as recent assertions that nothing the courts rule can be sexist; after all, women would just run for seats on the supreme court if they cared; they're a majority of the population, after all.
Since the nonsense in the last paragraph actually came from a recent supreme court majority opinion, I'm wondering if you can point to a supreme court ruling backing up your statement.
According to the First Amendment, you have a conceptually unlimited right to write petitions (complaints). Practically, it is limited by the absence of violence during assembly.
There's surprisingly few rulings on the right to petition.
I expect most only complain about corruption because the basics aren’t being delivered, not out of a sense of civic responsibility.
This has so many holes in it you’re making Swiss cheese look rational.
> I expect most only complain about corruption because the basics aren’t being delivered, not out of a sense of civic responsibility.
I expect you have absolutely no idea what you’re talking about.
In fact, the policy was why they examined the photo carefully.
https://en.wikipedia.org/wiki/The_Package_(Seinfeld)
> Sheila, a clerk at the photo store, flirts with George when he picks up his photos, commenting on a mustard stain that appears in one. He photographs everything, even Jerry taking a screwdriver to his stereo, as an excuse to see her again. A lingerie model's picture is accidentally mixed in with George's photos; he assumes it is a photo of Sheila she inserted as a come-on. Kramer convinces George to return the compliment with seductive pictures of himself.
https://knowyourmeme.com/memes/seinfeld-effect
>The Seinfeld Effect is a phenomenon closely related to the Family Guy Effect (the idea that when a meme is referenced on a popular television show, it dies out). The Seinfeld Effect occurs when a TV show references an in-joke belonging to a subculture (in most modern cases, the Internet) and makes it mainstream, causing the show's viewership to mistakenly believe the meme originated with that show.
>The effect is named after the 1989-1998 sitcom Seinfeld's habit of referencing little-known ideas, jokes, and phrases, such as "Festivus," "yada yada yada," or "not that there's anything wrong with that," and making them extremely well-known through the show's populararity to the point that many have the misconception Seinfeld invented these phrases (for the purposes of this article, 1992 is listed as the meme origin date, as that was when the episode "The Contest" popularized the idea of masturbatory celebacy contests). [...]
Seinfeld Is Unfunny Trope:
https://tvtropes.org/pmwiki/pmwiki.php/Main/SeinfeldIsUnfunn...
>There are certain shows that you can safely assume most people have seen. These shows were considered fantastic when they first aired. Now, however, these shows have a Hype Backlash curse on them. Whenever we watch them, we'll cry, "That is so old" or "That is so overdone".
>The sad irony? It wasn't old or overdone when they did it, because they were the first ones to do it. But the things it created were so brilliant and popular, they became woven into the fabric of that show's genre. They ended up being taken for granted, copied and endlessly repeated. Although they often began by saying something new, they in turn became the new status quo. It's basically the inverse of a Grandfather Clause taken to a trope level: rather than being able to get away with something that is seen as overdone or out of style simply because it was the one that started it, people will unfairly disregard it because it got lost amidst its sea of imitations even though it paved the way for all those imitators. That is, a work retroactively becomes a Cliché Storm. [...]
Imagine having all your memories in the form of images and videos taken away because of sloppy review work at a tech company.
Does it though?
Also: I wear a helmet or a belt every single time I drive even for 1km. Should I not? I never needed them. 0% use rate so far for me, might as well not have done it.
The issue is that when it happens, you're done.
Considering that you probably don't need to keep all your eggs in one basket, why not at least try?
On this note, I wish providers were forced to provide a third-party backup mechanism for important data so that if I were to lose:
- the email: it could forward my email to at least receive them
- my photos: a copy could be kept on multiple hostings
etc
How is a laymen supposed to tell the difference between Backblaze - running their own servers, and a Dropbox-like - which is really just uploading your files to amazon's servers?
That's the point I was trying to make.
OneDrive IS Microsoft and iCloud IS Apple so they ARE BigTech, the same as Google? I don't see how that argues against the point?
Box is the only one in that seems to qualify? Kinda proves my point that it's not at all easy for a laymen.
You would even avoid DropBox because they also chose to use proven reliable technology until their own technology was good enough?
But the point I was making was that it was hard for a laymen to decide to avoid using any of the bigtech companies, since so many of the small upstarts are just build on-top of the existing bigtech and aren't forthcoming on if they own the datacentre or if its Azure/Aws etc, so for those who they really did have privacy as their key driver it probably would be easier to self-host, or you have to trust somebody.
The adage that there's no such thing as cloud computing, just somebody else's computer makes sense. If you're that concerned with privacy it's far easier to run your own.
And no, they're not going to spin up a VM. They should buy their own NAS and back everything up to that if they care enough about privacy to avoid cloud storage.
[0] https://pocketnow.com/no-such-thing-as-the-cloud [1] https://www.reddit.com/r/programming/comments/argram/the_clo... [2] https://www.redbubble.com/shop/there+is+no+cloud+stickers
I've also just seen, which you didn't disclose, that you work at AWS[0]. Not disclosing a vested interest doesn't exactly lend confidence to your impartiality. Either way, I'm still not sure how your argument is a rebuttal to my proposal. SO far it seems to amount to "other cloud providers exist" and "Your mistype wasn't accurate"?
Use email, phone and app 2FA plus printable 2FA codes, and you'll always have a way.
Frankly if all of these can be made inaccessible in one go then the setup was mighty flawed to begin with.
- iCloud 2FA is another Apple device.
- I don’t care enough about my Google account to have 2FA. Besides the occasional SMS.
- Microsoft 2FA is Microsoft Authenticator.
Apple iCloud - 2TB as part of a bundle.
Google Drive - I haven’t had to start paying for it yet.
Amazon Drive - part of Amazon Prime
Email is by far the biggest albatross around my neck. To migrate email requires me to setup two different failure points: purchase a domain and a Fastmail-like service. Now that is two different places that are subject to me forgetting to pay a bill, being social engineered into giving away my account, etc. To say nothing of the long tail of acquaintances who only know be my current address.
Yet still, this existential terror exists that I will Do Something Wrong (no you will never know what it was), and lose everything.
As far as the social engineering goes, personally I gladly take that risk in order to bring my email firmly into my control. If I'm going to lose access to my email, I want it to be because I did something stupid, not because an algorithm flagged my account and Google has no humans I can appeal to.
The long tail of acquaintances isn't bad either: just forward emails from Gmail to your new address. If you lose access to the Gmail account at some point, you'd have lost everything anyway, so this arrangement would be strictly better.
1) AI bot
2) Beg HN/twitter for insider help
3) Lawyers
That's absolutely insane for a product set that has become central to one's life
I have cloud backups of family photos, but they're all through restic or rclone with the crypt filter applied. Privacy is about the right to put yourself in context.
Wow. This is a brilliant. Did you come up with this?
Six Words on Privacy
Very well said.
People can't run their own encrypted messengers so we have Signal. People should be provided with interfaces, and advocated too, use cloud services for their data in a safe way.
Assuming, of course, that you don't use your personal account for your domains - that'd be crazy!
Google knows I am the same person, even though they are different accounts, so are the two other accounts safe when one of the three gets flagged?
> “I decided it was probably not worth $7,000,” he said.
I believe it is one of the roots of the problem. How is it even possible that getting justice in court in such a trivial case costs about three months of median income?
If not, you obviously aren't as committed as Google about ending CSAM.
The instant a company has evidence of a possible crime being committed they should be required to hand the evidence over to the police and then take no other action other than preventing distributing it or the like.
This is not just Google's AI goofing up on what constitutes CSAM (and it sounds like given the witch hunt about such things that Google was being reasonable in informing the police), but colleges expelling "rapists" without evidence etc. The accused never gets anything resembling a fair trial but since it's not the government doing it that doesn't matter, there's no repercussions from messing up lives based on completely incompetent investigations.
But clearly if they’re referring out to law enforcement, they need to close the loop on that and take responsibility when they get it wrong.
In the olden days, if the AT&T monopoly just cut off phone service to a (convicted in court) pedo, they would get in severe trouble. We the people imposed limits on powerful companies. Even today, with the monopoly split up, this would not be legal. Let alone just deciding on their own initiative to do it.
In this case, a utility provider is cutting off service based on a digital rumor. They are judge, jury, and executioner.
The laws governing telcos were made over a period of 150 years, but most particularly in the 1920s and 1930s.
Google does not fit these laws because they do not charge for them (perhaps this should be made illegal?) and monetize them differently. Also, obviously the services are far beyond simple voice or fax. And yet, they are definitely utilities.
Utility companies must not be politically partisan or active. Mixing those two things is toxic and bad for society. It also is too much of a temptation for politicians to use the implied power of utilities over the people to silence or supress opposition.
If Google wants to be an activist company, then it will need to shed its utilities. If Google wants to provide utilities, then it needs to shut down its activism.
I've been an Android user for a long time, but I think this might finally push me to switch to Apple. I'm just disgusted by this.
All of Big Tech is ultimately not so different.
Also, the bone-headed Apple plan had safeguards that would have prevented the victim in the article from losing their account.
The two policies aren't remotely comparable.
While there's problems with that too, it is a better design than what Google does.
1. Use on device ML to scan for child porn before iCloud Photos upload.
2. If not found, issue a cryptographic ticket for iCloud upload and include in upload request.
…the whole point of Apple’s scheme as far as I know was to keep as much of the processing on device as possible while also keeping illegal content off of their cloud servers.
The Eu starting to fine the living daylights out of Google for not allowing people get their data from their account per the new digital gatekeepers act that the big tech has 6 months to comply.
They did it to Microsoft when Microsoft refused to comply with the browser ballot box initiative, saying that it was "technically near impossible". They started fining them 500,000 Eur/day or something. Then Microsoft magically made the ballot box happen within 2 weeks.
That sounds like a permanent stain on his records.
What's recommended for a domain registrar to move my domains over to?
I figure I can probably self-host photo/file backups, move 2FA to Bitwarden, and migrate mail over to a paid Protonmail plan, but who can I trust for domain names? Mostly just for email aliases, but a couple for some hobby websites. GoDaddy can take a hike, and I've used namecheap before but what other options are good/trusted?
You are always only one algorithmic fuck-up away from losing access and having to spend days and weeks dealing with the consequences.
I think the only way to deal with this is through regulation. Make it as inconvenient for Google to ignore customers as it is inconvenient for customers to be ignored by their service provider when something goes wrong.
Systemic mistreatment of customers ought to have consequences of existential proportions to a company. There is no societal benefit to companies like Google getting away with behaving this poorly.
Opinions on what should be done have more credibility when based in observable reality rather than blind ideology.
Isn’t that also a description of breastfeeding?
also, while we might find it unwise to make a video, but also we were not there.
the meaning of both words being defined by their provacy policy and ToS
Whether you would consider that private and secure enough, is a different story
This is a big part of the problem, technically you have a recourse, but the cost for individuals is a barrier to justice. Organisations have a lot of freedom to act behind the cost to litigate.
At least the two I recommend won't destroy your whole digital life if they don't like you.
The other commenter is trying to optimize for "doctor does not go to jail".
The two goals are mutually exclusive in this case.
https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-...
It would seem like there would be HIPAA concerns with using a channel that does not guarantee privacy, and allows Big Corp to snoop on the content.
Less cynically:
I think signal is likely a superior choice from a privacy and usability perspective.
However, I imagine the hospital probably wants the chat logs to be an immutable part of my medical record. That's probably helpful in the case of bogus malpractice suits, for example.
In fairness, state-of-the-art practices store all this data in an enterprise storage array at the hospital (with a remote backup in a colo or something), not on hardware owned by Big Corp.
It’d be more interesting to meet the patients where they are and find some way to securely get those images into a medical file.
And even if you are not located in the US, I would recommend that your wife looks up local regulation and considers alternative methods to communicate with patients.
While historical approaches to finding this content have relied exclusively on matching against hashes of known CSAM, the classifier keeps up with offenders by also targeting content that has not been previously confirmed as CSAM.[1]
[1] https://www.blog.google/around-the-globe/google-europe/using...
Works for (almost) all devices.
Besides, there is less likely of a chance that a medical app targeted toward virtual care for babies would be flagging parents for sending pictures of their children to a doctor.
They required me to send them photos to the receptionist over plain email - I complied because they weren't particularly sensitive parts of my body however it did make me mad that this was their system for dealing with sensitive health data
No, you shouldn't have to use some special software to take a picture. Taking a photo with your phone's camera app should never trigger an account suspension.
The health sector isn't known for having a secure anything, furthermore getting health companies to agree on one thing together is almost impossible.
I'm sort of surprised you haven't encountered it yet (and that the people writing responses to your comment haven't either).
Here's a PR piece about their secure video chat feature. (They also support emailing around photos, and the app has a built in camera, but that's old news, and not in their PR blog reel)
https://www.epic.com/epic/post/expanding-telehealth-during-t...
They are doing some interesting stuff with outpatient monitoring and treatment-specific workflows, apparently:
You can get customer service from Google's hardware just like Apple.
It's the software/services that have awful/non-existent customer service.
I can depend on Google to support a Google branded phone I bought in 2013 with security updates 8 years later like an iPhone 5s user could or with operating system updates for a phone I bought in 2015?
The original poster couldn’t get anyone on the line about a Google account. You can call an Apple CSR about an iCloud issue.
Perma-deleting his account on an automated accusation is bad. That should hinge on, at minimum, law enforcement's decision to charge a crime. [Edit: unless the criminality of the images is obvious - again, a human needs to be in the loop.]
citation needed.
do these CSAM scanning things actually help reduce kid exploitation?
and if they do, is this the best use of our resources?
Even an account lock is probably a bad idea; it alerts the pedophile that they're under investigation, allowing them to destroy evidence, cut ties with coconspirators, etc.
Best to let law enforcement deal with it. In this case, assuming it somehow went to trial, the jury would almost certainly acquit, and the account would be restored.
There is the matter of the accused losing access to the account while the case was active though. That's potentially a big deal.
No, there really should not. I would not want a facebook employee to look at my pictures. I don't use their services, but the thought is pretty off-putting. The idea that these companies have to police content is what is wrong.
There are other ways to get to offenders here. An environment that takes good care of kids will spot it. Not some poor fella that needs to look at private images.
* Criminalizing possession and creation of child pornography equivalently
* Conscripting the tech sector into detecting it via SESTA/FOSTA.
Look forward to reading stories like this ad nauseum.
Child pornography is only one of many areas where false positives in legally mandated sescanners end up ruining people.
Credit card payments come to mind, though I think those are mostly self-regulation.
lol. Missing 4 zeros there.
Part of the reason for the brazen actions of companies like Google is that their substantial financial means and legal department sizes grant them a substantial degree of immunity to judicial review.
Also some execs behind bars won't be a bad idea. Granted that mistakes do happen, but when they don't resolve it in a timely manner, punishment is fair.
Addendum : I don't know if companies have a govt imposed rule to report porn, in that case I'd say the root cause is the govt, not the company. Of course if the root cause is govt, and even more root cause is people themselves. People collectively generally get the govt they deserve...
In the US there isn't and generally cannot be a government requirement to search the customer's data. If there were, the provider would effectively acting as an agent of the government and the customer would enjoy 4th amendment protection of their privacy (absent a warrant or other, similarly targeted and justified reason).
Unfortunately, there is a bit of a wink-nod situation going on where the government quietly pressures companies to engage in these activities "voluntarily" -- in exchange for varrious forms of preferential treatment and refraining from enforcing other regulations -- and in court when a target attempts to present 4th amendment defenses everyone pretends (and testifies) that the provider was searching the customers private files of their own volition and not on the government's behalf.
In this game neither the provider nor the governments hands are clean because they are both conspiring to undermine the constitutional rights of the public.
Why?
Because they are not in contact with our authorities and, frankly, the chances my private files will be of any interest for Chinese authorities are close to zero.
Not that I have nothing in particular to hide, but as this example proves once again, if life damaging mistakes can happen, they will happen.
china extradited from us
Produces many independent cases of China successfully extraditing suspects from the US and vice versa.
I haven't been to the US since they made it legal for custom officers to search travelers' personal electronics without a warrant and deny entry if you refuse, because, thanks but no thanks.
My guess is that the "trigger" for "any other country" is much higher.
Criticize the US President all you like on every social network: not a problem.
Save a screenshot of Winnie the Pooh: you're playing with fire.
given that this [1] already happened in my country, and also this [2] also happened (just to name a couple) and nobody paid, that there are 13,000 American soldiers on my Country's soil and that this [3] man has been POTUS and is probably running again for election, I wouldn't say "not a problem".
US could reach me at my house if they wanted to, OTOH PRC can't do much.
[1] https://en.wikipedia.org/wiki/1998_Cavalese_cable_car_crash
[2] https://en.wikipedia.org/wiki/Abu_Omar_case
[3] https://www.politico.com/news/2020/10/07/trump-demands-barr-...
> Save a screenshot of Winnie the Pooh: you're playing with fire.
I imagine this is sarcasm.
Winnie the Pooh has never actually put anyone in real troubles.
https://www.washingtonexaminer.com/news/university-of-minnes...
I don't support China methods, but mocking the president of your country in public, from abroad, when you know what your Country is is capable of is not a smart move, ever.
It happens everywhere, different solutions, same goal: censorship and setting an example.
https://time.com/4644297/saturday-night-live-katie-rich-susp...
In a recent comment thread I noted that my father’s generation went from fighting a bitter war with Vietnam to Apple building MacBooks there. My grandfather landed on D-Day and drove Volkswagen Beetles for most of his life.
None of us know what will happen in the future. China could become a close ally. They’re already an existential economic partner.
The only path to real privacy is personal sovereignty. If you don’t control the data it is public. Period.
I am your of the same generation of your father...
My grandfather was already 40 years old when D-Day landed.
> None of us know what will happen in the future
It's safe to assume that it doesn't matter.
You could die tomorrow, so why are you worrying?
> If you don’t control the data it is public
Unless the network is firewalled by Chinese government...
Safety is not about paranoia, but about layers.
car alarms aren't there to make it impossible to steal your car, but only to make it inconvenient for the thief and convince them to steal someone else's car.
Funny, censorship (which this case somewhat is) is about making things not public. Though I somewhat agree.
based on what?
At least is an entire Country that will blackmail me, must think I am really important, not some rando that hacked iCloud to find celebrities boobs and post them online...
> Just encrypt your data rclone would do that.
yeah, but rclone is an offline backup, basically.
cloud storage is for when you need immediate access and search capabilities.
And there are a million more people who don't have security clearances and work at companies such as Alphabet, Meta, a datacenter, Boeing, etc.
it's private files, not secret state information.
things like my address book, SMS (mostly inbound alerts, nobody sends them anymore), WhatsApp backups (which are encrypted) or pictures I took with the phone's camera, nothing compromising.
Exactly, which for some people contains content that you could blackmail them with.
> pictures I took with the phone's camera
I'm glad you don't take nude selfies, or cheat on your spouse through SMS, etc; but others do, and that potentially makes them susceptible to blackmail.
What if, instead of money, the blackmailers asked Jeff Bezos for access to some AWS servers. He most likely is not the only CEO that took nude selfies and can grant access to sensitive areas. What if, it was pictures/information from before someone knew any better, had access, or were famous.
https://www.reuters.com/article/us-yahoo-nsa-exclusive-idUSK...
The problems that befell the fellow in this story were not due to Google being in contact with the authorities. The authorities unobtrusively investigated, determined that the reports were false positives, and closed the case.
If all Google had done was contact authorities he would have never even known that he was investigated, and there would have been no impact at all on his life.
China has bans in most of the same categories that the US and other western countries do, but typically broader (e.g., they broadly ban pornography). If ISPs there are on the lookout for things China bans you are probably more likely to have a false positive there than with a western ISP.
The question then is a Chinese ISP more likely to overreact on a false positive than a western ISP? I believe China is more likely to hold a business responsible for the bad acts of that businesses customers, which I expect would lead to Chinese businesses being more likely to overreact.
They are not in contact with our authorities, until they decide they want to. It's not like you are a Chinese factory owner making counterfeit wranglers, I doubt they would deny any kind of request from a western government about a westerner.
Your access to the service is also under risk, at any time there could be a breakdown of relations leaving you unable to pay for the service, that would have happened already, if you had chosen Russia instead of China.
Your behavior also looks suspicious to the western intelligence apparatus. Sending potentially terabytes to Chinese servers as a private individual may very well put you on their radar.
As others have noted you are setting yourself up as a prime candidate for an intelligence asset, they could at any point blackmail you to perform any action they want.
With what would they blackmail you? The terrabytes of CSAM they could at any point plant in your account. Do you think they would be above doing that, if they had anything to gain and were aware that you exist? Or do you think your Chinese provider would require a court order to give you up? Your entire bet is that they don't know that you exist.
My main point as advice to others mostly is you shouldn't put your self in the hands of your adversary.
I don't even know how you trust their software to run on your system.
PS: If you think all these are farfetched and paranoid, I will remind you that China routinely takes hostages to achieve diplomatic concessions https://en.wikipedia.org/wiki/Hostage_diplomacy#China
My future proof solution will be hosting my data on bare metal in Iceland.
They are quite serious about data privacy.
It never occurred to me that this might get my account banned.
To sort of add a lively "Here's what's trending!" kinda thing
They pulled that feature really fast when it made users acutely aware that their searches were not at all private.
So... Likely this reason.
(For the first time ever, I wish I had a DALL-E 2 account)
Wow. Just wow. This is worse than the usual Google's automated screw-ups. In this case, Google was notified of the issue by the NYT. Yet they actively chose to continue to screw over their victims just because they can.
> In a statement, Google said, “Child sexual abuse material is abhorrent and we’re committed to preventing the spread of it on our platforms.”
Just how tone deaf can Google be, continuing to treat these innocent folks as criminals in this passive aggressive statement even after being proven wrong? Do these people have no empathy at all?
A private company is the de-facto judge, jury and executioner because it owns half the infrastructure you live your life on.
Always makes me laugh when I see employees of Google, Amazon etc. claiming to be “anti-fascist” and “standing in solidarity with the common man” etc etc…
Not having an internet connection is NOT an option. There is a legal process to get a special permit to avoid having to use these state mandated electronic systems but it is almost only theoretically in that you will need to have a doctor's note saying that you are unable to use such systems. E.g., by suffering by severe dementia or similar.
They serve the fiction of confirmed mail delivery. If you don't pick it up from this mailbox, it is considered delivered anyway and your problem, if you miss something here.
Governments have accessibility obligations and so their key services should absolutely be usable with something like Chromium/Linux. And it definitely shouldn't be more onerous than using a smartphone.
It is the portal for Slovak republic. You are supposed to have your national ID card, which is a smart card. To use it, you need a smartcard reader and an application, which basically listens on localhost and is kind of a intermediate between your browser, the pages than need authentication and the department of state, which handles IAM.
That application runs on Windows, Mac and Debian (9,10)/Ubuntu (18.04,20.04)/Mint (19.20) (it is not open source). Other distributions are not supported, forget ChromeOS.
It is quite onerous. You have to enter your PIN for smartcard about four times, before you see the content of the inbox.
I learned it like this, its since recently that applying by email more commonly an option.
People on Hacker News like to propose "just use low-tech!" or "just self host!" often and I don't get how that's a solution. I _could_ spend hours of my day printing out and mailing my resume to companies (if they allowed me to) and waiting days-weeks for my response _after_ they made their decision (during which time I still have to pay bills and have no job) or I could apply with one button on Linkedin and get my response back instantly. It just saves so much time.
Others will say that that's a small price to pay to retain my freedom, which might be true. But what's not true is the other qualities of life that internet and big data affords me. If I don't have instagram or snapchat I literally lose all spontaneous contact with my friends and family. Sure, I _could_ mail them a letter, but with the delay in communication a lot of the intimacy is lost, and we would truthfully just talk a lot less. This, along with a lot of other problems (how do I contact my professor for help after class? go to their house?). Combined with the fact that I would have to be _extremely_ thorough and make sure that my data is scrubbed from all of Facebook/Google/Twitter/Whatever and it's subcompanies, it's just not a real solution. It's actually really annoying that so many are content with infeasible individual solutions instead of advocating for things like pushing against the EARN IT act or the like. I shouldn't have to have a computer science or cyber security degree to be private online - it should be done for me by the government. I don't know what the fuck is in that vaccine (or any medicine I take for that matter) but I can trust that it does me good because of regulations.
Most of the jobs I've worked for have come via old school phone calls.
Having helped my 92 years old grandmother sorting out her tax returns on the government’s website, I can confirm that this is exactly what it means. And it’s the only practical way of communicating with the administration. Most local branches have been closed to the public, and the phone lines are congested all day (and cut you off after one hour waiting, which is always fun).
Having had the pleasure of sharing the elevator with said individuals in shared office buildings the "common man" part almost made me lose my coffee.
I really wish it wasn’t so, but when your company serves the advertiser you aren’t serving humanity. The balance is off and which each passing year it isn’t getting better.
Big Tech monopolies need to be resisted
I can't fault them too badly for that. I consider myself personally against the horrors that go into gathering the constituent materials for, and the assembly of, computers. This position co-exists with the fact that I, like most others here, derive the majority of my livelihood from Doing Things With Computers, which wouldn't be possible without the computers themselves, which wouldn't be possible without the horrors.
Worse still, I live a provably better life than those of my peers whose youth did not, for whatever reason, revolve around Doing Things With Computers, let alone the far-flung people whose labour provides me with the computers on which I do those profitable things.
It's difficult to morally reason about.
So you are forced to use an iPhone or Pixel phone, forced to search with Google, forced to use AWS.
Even though open alternatives exist for all these who would love your support.
I would better let Google have all my photos and track my location than my father ...
In my personal view the internet became one big country with overlapping laws and government policies and collusion by corporations. Ever so often I use google to see what search results they can muster but otherwise I don't use cloud storage and do not find myself depending on google. For email I try to teach my friends how to use Thunderbird so they can click a button and their email is mostly GPG encrypted.
If I wanted to share files with someone that will not fit in that GPG encrypted email then I plonk them down on a mini-PC or a VM and share them over HTTPS with cache-control headers to reduce risk of file caches or SFTP with authentication. This is just my own preference and I am a stodgy cranky old bastard but if someone decides that basic auth is too much friction then it was not important for them to receive the files. I implement my own data retention and destruction policies. How my doctor or lawyer decides to store the files is up to them. I can only hope they are wise enough to not store things on their fondle-slab. An intelligent doctor should be able to handle basic authentication and/or be able to follow simple instructions for creating and sharing a GPG public key with me.
Or I could just snail-mail them an encrypted USB drive, however a GPG encrypted email should suffice for sending a few little images to a doctor. Some will bring up rubber hoses and wrenches but there are mitigations for such things. Some might even want legislation to to bandage these dark patterns but experience has taught me to not trust that corporations would be held to account at the same level and standards as citizens.
Edit: I recently read this book called "The Every" which explores a similar scenario https://www.goodreads.com/en/book/show/57792078-the-every
(a) compute cost for uploaded brains is probably more than the cost for the pig slop and water/sewer bills of current model. Recall that prisons right now almost never have AC. If you're going away from corpses, you'll have to pay for that.
(b) Cost of caring for the physical body has pretty much been solved by the markets. The customer has a social network that sends money in and pays transfer fees. This network also pays per call and email. Then the customer purchases food and clothing at monopoly prices, since... it's a captive market! Just imagine the ARR hit when people stop eating.
Reminds me of another "Social Media Corp Gone Bizarrely Crazy" plot that I read recently, The This, by Adam Roberts. You won't anticipate how Crazy the social corp in question goes till you're halfway.
Our best bet is to shame those using products of unethical companies.
We know what effect affective privacy policies have - the ten line policy change on Apple App Store has caused all of the ad supported platforms to announce falling revenue. The GDPR has only caused cookie pop ups.
Plot twist: (maybe) Xyz is (not) an (un)ethical company, so we should establish some sort of authority on ethics with a malleable but firm framework to guide the consistent -- and proportional to the unethics in question -- application of shame to the people using the products.
Unfortunately the state has dropped the ball about anti-trust, thanks to stupid economic theories from the Chicago School of Dumbfuckery. Those are the main culprits for the shit we're in.
So perhaps fascism doesn't fit perfectly, but it's pretty damn close in my opinion (especially if you use definition 3 by Wordnik "Oppressive, dictatorial control").
Few to none of the loudest users of “fascist” describe Cuba, Venezuela, or China with the term according this definition. Can only conclude the definition is given in bad faith, and used by people with a silent exception for “states and organizations I find ideologically appealing.”
In fascism 1.0, singular authority vested with the head of government who then subjugated every other institution under the government. In fascism 2.0, power consolidates from the bottom up as corporations weave themselves into our individual lives, merge and collude with each other, and expand their scope in a way that subsumes existing institutions including the existing government.
It's not the same, but it rhymes. Each version seems to be heading towards a similar end state, but coming at it from a different direction. The distinction seems to be the same distinction as between totalitarianism and inverted totalitarianism. Maybe we should call it inverted fascism?
In some cases, it conforms more to classical fascism than many realize.
That said, in this particular case, I’m still not sure it applies.
When it comes to stopping the distribution of child abuse material, there’s no reason to believe that anyone’s acting in bad faith. We can certainly see where they have everything needed to do so (access to people’s personal data, ability to mobilize law enforcement, and a relationship with government that is amenable to suppressing criticism as “dangerous”).
But in this specific case and others like it, we actually see that law enforcement did their job - they did not overreact, they investigated as appropriate, and nobody was charged.
Google continuing to be a dick about it and holding someone’s account hostage isn’t exactly fascism yet, but it is a great demonstration to people how easily big tech can become weapons of fascism, and why it’s important to opt out of centralized big tech (while they still have the chance), to discourage public/private collusion, and reason to support efforts to keep their powers in check, the same as they would any government.
This is a highly loaded paradigm, carrying an extremely misleading framing. From my perspective, US corporations and US government are indeed colluding, against an outside attack trying to tear them down to replace with a different power structure. I've had no love for the US power structure and have myself often wished to wholesale replace it, but the vision that attack is offering is so regressive that I've become extremely conservative for the time being.
> no reason to believe that anyone’s acting in bad faith
Of course nobody is acting in bad faith. Bad faith actions are decently punished by our society, so the structures that have built up operate on good faith, and produce constructive bad outcomes in spite of it.
> but it is a great demonstration to people how easily big tech can become weapons of fascism
This feels like it's missing the ultimate dynamic, by falsely asserting that fascism can only flow from the bona fide government. Whereas actually, Google's actions within Google's currently-limited sphere of influence are fascist in nature, and that sphere is growing. As I said, "similar end state, but coming at it from a different direction".
> it’s important to opt out of centralized big tech
I wholeheartedly agree, which is why I think it's important to describe the fundamental dynamics of these centralized surveillance companies before they have grown to be truly all-encompassing. Even presently, using Google is a mandatory requirement to interact with many government services (Recaptcha), and the more you make yourself known the Google the fewer roadblocks they hit you with. It's not a stretch to think as non-Google browsers ramp up their surveillance protection, that logging into a Google account will become default mandatory to pass such checks, giving Google account status the bona fide force of law.
"The word Fascism has now no meaning except in so far as it signifies ‘something not desirable’. The words democracy, socialism, freedom, patriotic, realistic, justice, have each of them several different meanings which cannot be reconciled with one another. In the case of a word like democracy, not only is there no agreed definition, but the attempt to make one is resisted from all sides. It is almost universally felt that when we call a country democratic we are praising it: consequently the defenders of every kind of régime claim that it is a democracy, and fear that they might have to stop using the word if it were tied down to any one meaning. Words of this kind are often used in a consciously dishonest way. That is, the person who uses them has his own private definition, but allows his hearer to think he means something quite different"
https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim...
Wait for the next EU lawsuit against Google, you will drown under all the comments claiming it is an attack on American companies.
What you're describing here is more like a cyberpunk corporatocracy, where corporations hold so much power independent of the state, that they are able to exercise their own arbitrary decisions extrajudicially, while still maintaining so much power over people so as to completely control their lives.
In fact, here you can see that the person was exonerated by the state but punished by the corporation. In fascism, nothing supercedes the state.
It sounds to me as if a class action lawsuit is the most appropriate remedy for the unfortunates who are caught in this predicament. Their only problem is finding each other.
For the rest of us, it is unwise to use cloud storage for photos, for several reasons.
I imagine unblocking someone due to them being exonerated by a government entity is legally risky - perhaps doing so would be considered enough proof/evidence to deem the entire CSAM scanning practice as a search/seizure at the request of the government.
0: https://www.hackerfactor.com/blog/index.php?/archives/929-On... • “ According to NCMEC, I submitted 608 reports to NCMEC in 2019, and 523 reports in 2020. In those same years, Apple submitted 205 and 265 reports (respectively). It isn't that Apple doesn't receive more picture than my service, or that they don't have more CP than I receive. Rather, it's that they don't seem to notice and therefore, don't report.”
Why would it matter where it's held?
EARN IT threatens to expand this to CSAM. Meanwhile, anti-CSAM legislation continues to develop in other jurisdictions, and being global entities big tech companies are exposed to that risk. Hence why Apple published explicit plans to actively scan (albeit locally on-device and with creative use of cryptography to soften the blow) for CSAM on their devices, and integrate with NCMEC. They’ve shelved this for now, but made it clear that they’re not done with this concept.
Big tech dreads the loss of their liability shield, and these measures are an attempt to stay ahead of the policymakers. It’s not as free a choice as it may appear, and the federal government does not appear restrained by the constitution here.
Google actively inspects and analyzes data, and does so with their cloud services. Microsoft does as well. They have a reasonable means to know that a user has problematic content. Other services that sync but don’t process data do not.
In many US states, you are legally compelled to report child abuse and are subject to criminal sanction. In New Jersey it’s a misdemeanor for anyone who fails to report child abuse. In New York, mandated reporters are compelled to report and have criminal and unlimited civil liability if they do not (and immunity from liability if they do).
For a company like Google or Microsoft, the risk assessment is very complex and the smart, and arguably the morally righteous move is to report.
No Android has not been a financial success. It came out in the Oracle trial that Android had only made Google $27 Billion in profit from its inception through the trial start date.
For comparison, Google pays Apple a reported $14 Billion a year to be the default search engine on iOS devices. Apple makes more in mobile from Google than Google makes from Android.
And I usually find myself on your side of these discussion, trying to avoid hyperbole. I don’t think ‘evil’ is hyperbolic in this case.
Standard disclaimer; I work for AWS.
Android's value may not be easy to measure, but it's worth in building and maintaining Google's moat positively boggles the mind.
It doesn’t matter that Android is running on a bunch of $100 phones where they are getting a low ARPU. The Oracle trial showed how little profit came from Android.
Who do you think business would rather target iPhone users or Android users?
> How else do you explain how they are willing to pay a competitor $14 billion+ a year?
Obvious that they have more than >14B+ value extracted out of their competitor's ecosystem per year? I am not sure if you are aware of this or not but when Apple screwed FB with all the anti-tracking changes, there was one notable exception - the browser. Guess who benefited the most? All the ad dollars, which used to be spent on FB and other user-targeting based ad products, are now being diverted to search ads. Just read Google's earnings report - YT revenue declined while Search Ads revenue shot up.
> Who do you think business would rather target iPhone users or Android users?
Think 2-3 steps ahead. How do businesses target users? Via ads in a significant way. If they cannot target iPhone users anymore based on user data, what do you think they will use instead? The next best thing they know - Search Ads. Btw this is why you will Apple and Amazon's ad revenue surging as well.
On top of that, Google doesn’t even compete in the worlds largest cellphone market - China. Sure most phones run “Android”. But without any Google services.
Then you don't understand the strategy behind Android. This is a fantastic article to help you explain: https://techcrunch.com/2011/03/25/search-googles-castle-moat...
TL;DR: Android was one of the best moats Google could build for its data-and-ads business.
Note that it was the telehealth provider who provided the images to Google in the first place, not the SF techie dad.
If Google wrongly gives an account back, you get a different article: "Google helped child pornographer even after discovering CP in their account". Now that gets attention. That's a scandal that leads to political action, criminal charges, etc.
To be clear, I'm not advocating for how Google behaves. They're a lot more like a utility and probably should be treated like one (alongside the protections and requirements that come of a utility, you don't hear "eletric company stopped serving house since man suspect of CP lives there").
For the responses saying "Well the police cleared them", again I don't disagree. But if you're an executive making this decision you're thinking:
1. We never give back an account in this case and avoid the massive downside risk
2. We go through a lot of work to design a process that will impact a marginal portion of customers and really really hope nobody manages to social engineer themselves past, and pray that no enterprising news outlet/politician tries to make the "Google helped CP person recover their CP story" - they already have a target on their back.
— Dwight K. Schrute
At least, that’s what I’d hope.
Google here looks even worse than I thought possible, and I’m a de-Googled, anti-fan, so I already had a very dim view of them.
They didn't do anything. Investigation/State scrutiny shouldn't be considered an act of guilt that requires a vouchsafing.
These are interesting cases but it seems like they happen to be ones where the police bothered do anything.
Google's surveillance system and automated ban hammers are already bad enough. But the actions they took following the ban in this case is egregious and 100% indefensible. At the very least, Google could've reinstated their victim's account and issued a full sincere apology upon being contacted by the NYT. If Google has any care for their users, they'd do that for every people they wrongly reported who had their names cleared. Instead, Google doubled down, continued to treat their victims as criminals in their statement, and even leaked details about intimate photos in a blatant attempt to discredit the users they wronged.
No parent should ever have to go through what Google has put them through when trying to cure their child. Most of all, they should never have to risk losing custody of their child because their child went sick. They should never lose access to their whole digital identity because they didn't know any better than to rely on Google. Yet this is what Google did to these parents, full stop.
Google's users are advertisers. Ordinary people are data sources and ad viewers. Android phones and Chrome are for collecting data about people and showing them ads.
Google doesn't care about losing two data sources and ad viewers.
1. This is a rare edge case with asymmetric risk and an easy way to avoid said
2. A single failure could be catastrophic
3. No process is perfect especially in the face of someone actively trying to thwart it
You could try really hard to make sure it's not attackable and pray, for little benefit to Google. Or just tell people "too bad, you're on your own".
Even if this processes was assuredly bulletproof,
> In what world would Google receive criticism for giving back accounts to people who has been proven innocent?
The sort of drivel/clickbait that gets published to 'make a good story' is astounding. Or politicians, not known for honesty, could totally play this up if their base has an axe to grind against Google.
No giant corporation (especially publicly traded) is going to take such risks to revive a few wrongfully terminated email/photo accounts unless they have an obligation to (i.e. should Google be a utility). Their responsibilities aren't to be nice, or act in a good way, but to protect their profits. To the extent that I've seen corporations 'act nice' it's largely been to benefit their own employees or pursue some pet cause of an executive.
Proven innocent is not a thing, there is only "declined to prosecute [because there was no crime]."
(Your use of "full stop" suggests you're not American either - so I'll rephrase, "is proven innocent a thing in any English speaking country"? I actually don't know...)
Ethical, moral responsibility? Being a nice entity. And it takes zero effort to do so, especially once he is cleared by the cops?
You know, stuff like Don't be evil? Oh wait...
This is relevant to how outraged one should be by this story. I think it is probably > 1:100000. As such, probably not much outrage is warranted, although it’s obviously not great for this one guy.
Or at least the ratio is clearly not 1:100000, maybe more like closer to 1:10.
You would need statistics how many times google have reported police and how many times it have turned out to be a false alarm. Does google even keep record of false alarms? Most likely they don't to avoid responsibility.
It's fairly normal for parents to take pictures of their children naked in the bathtub/at the beach/ camping/etc.
Conversely, I'd expect actual pedophiles and CSAM producers to be really quite rare.
So even a relatively low base-rate of normal parents with normal nude photos would likely dwarf CSAM upon detection.
So, if we say 1/100 are pedophiles, and 30/100 are parents, and of the parents 10% have such photos, the ratio I'd expect without getting into detection rates is like 3:1 in favor of normal parents.
And what I understand is that each of these private photos of their children that parents take on an Android phone with Google cloud enabled gets specifically flagged to be shown to a stranger working for Google.
That sounds pretty insane to me.
*In fact that seems like it could be an effective form of extortion or swatting. Someone with access to your credentials could (threaten to) send CP over your account and ruin your life. Or destroy a small business.
There is a lot of child pornography in image sharing platforms. Facebook, which reports most reliably, had 20 million CSAM reports in 2021, and that’s photos posted to a social network or sent via messenger, not even in private albums. As I understand it CSAM is more focused on reporting re-uploads or transmission of known abuse material, rather than new material. So I still maintain that if we take the type of image referenced in the article as the denominator, vastly more of such photos would be child abuse material. Granted, 1:100000 is too high, I would revise that down to 1:1000.
One, We really need to know the base rates and false positive rates to reason well here.
Two, I think you'd also need to consider the number of people and number of photos. So like, a photo can be considered a trial, OR flagging a person can. I would imagine a given pedophile has a large number of CSAM photos, but there are few pedophiles. There are however lots of normal parents with fewer photos that might trigger a false positive, but because of that base-rate issue, even if the probability that a given photo is falsely identified as CSAM is quite low, the probability that a given person is falsely flagged/reported may NOT be low.
Bill Waterson somehow managed to sneak watercolor paintings of a naked little boy into every major newspaper under the guise of being a “comic strip”— the perv.
Dare I say that it is a peek into how Black people feel when they go out in public to do...anything.
Google has inserted itself into almost all spheres of digital life by hook or crook. It's practically difficult to avoid them in many services - especially email. And now they play judge, jury and executioner. I don't understand any of these are acceptable, much less justifiable. The old argument 'think of the kids' used to justify digital authoritarianism is such a cliché by now.
The guy in the article works in the tech industry and lives in a city where a lot of journalists live, so he could get his story into the media.
What about others?
I’d like to contribute to a crowdsource fund to prosecute cases like this.
When I was a kid the Comic Book Legal Defense Fund [0] was set up to pay for lawyers to defend comic book stores that were being targeted by over eager police departments and civil suits.
Maybe something like the Google is an Asshole Legal Defense Fund could collect donations. The article mentions $7000 as the cost to prosecute this persons case. Crowdsourcing can help with that.
[0] https://en.wikipedia.org/wiki/Comic_Book_Legal_Defense_Fund
Such costs are actually why so many police agencies are backing off of CP investigations. They still prosecute where evidence is clear, such as when someone emails such material openly, but they arent willing to invest the tens and hundreds of thousands of dollars necessary to handle the complex cases involving encrypted communication/storage. 7000$ would be a bare minimum for only the simplest of legal defenses in the simplest of cases.
If Google has to choose between sending an executive to small claims to defend the company without representation or try to resolve a dispute via settlement, they are likely to try to resolve it via settlement which is the type of relief this individual appears to be seeking.
The question everyone needs to ask themselves, if Google closed your account right now, for good - what would that do to your life...
They don't care a single bit about the effect their actions have on others. They only care about having to build a system, which can distinguish such cases from actually criminal ones. Because that wouldn't scale and would be bad for business $$$. So they try to turn and twist the image in the light of the public, that it is "right" what they did, so that the public does not cry out and demand change of their systems. Empathy doesn't even enter the equation for Google.
There are only two ways to actually do that:
1) Make Google's policies 100% subservient to the United States legal system, which would look a lot like the "corporate / national lock-step unity" one sees in actual fascism
2) Google build its own court system, independent from the United States court system but with equivalent power
Are either of those scenarios desirable?
Instead of going: "Nooo! We were still right! We don't care what others say or what facts were found out!"
So I am thinking you are painting the scenario a bit wrong here, saying, that there are only 2 options. An honest apology and actions to make up for ones mistakes can go a long way. Of course I would not expect Google to act that way.
Probably the button simply doesn’t exist to undo the termination 30/60/90 days later. Good luck getting them to admit it.
I've said it before and I'll say it again: Google now has enough power that it has effectively turned into a globalist government, a government you did not vote for.
I love the use of the disclaimer "sexual" here, to make it clear they don't care about other types of child abuse (like interfering with access to health care, which Google is clearly guilty of in this case...)
Well crafted weasel words, PR folks!
Is this not a huge breach of HIPAA?
Telehealth is sort of done for if randos at bug tech can find there way into your sexual health records.
It didn't. If it had, it wouldn't have been the fathers' accounts being hit.
It sounds like it was probably the texting (maybe via the Google Messages app?) that got the images flagged, rather than the telehealth system.
I assume it was triggered when the photos were backed up to Google Photos based on the above quote.
Because why on earth would you oppose protecting children? /s
I am extremely fortunate that the account that was deleted without recourse only contained data I had copies of on my hard drive, and to my knowledge law enforcement isn't involved.
The article fails to mention the stress and trauma of being accused of having CSAM. That remains to this day ... I'm posting from an alt because even the false accusation carries a potentially career and family destroying stigma.
Someone with enough clout would 100% be able to get accounts reinstated (likely without even needing a police report of no wrong-doing).
Google’s refusal to have appropriate moderation and support for edge-case situations is a completely different thing.
Well... here we are, normal people don't think it's possible to transfer an image over the internet without a megacorp being in the middle of it. Pretty strong sign something has gone wrong.
"Apple announced plans last year to scan the iCloud for known sexually abusive depictions of children, but the rollout was delayed indefinitely after resistance from privacy groups."
- Corona
- Specialist far away
- Quick Checkup
- Doctor is on vacation
You shouldn't have to travel to a doctor's office to get privacy. There is nothing wrong with a parent or a doctor taking pictures of a medical condition (rashes, etc).
Also, I am sorry this happened. It is very human to respond to a person in authority - but we need to be better and start asking questions. It is our privacy at stake.
Hopefully everyone learns from this; Also, Google was doing the right things.
And I really don't see how Google insisting that banning them was the right thing to do and being cleared by police doesn't warrant undoing the ban is "doing the right things".