Is there a reason the legal entity which deployed the software can't be named? Seems like the next logical step, anyway.
Is there a reason the legal entity which deployed the software can't be named? Seems like the next logical step, anyway.
These are all things that, in a functioning system, the police officer receiving the report would take into account. If it's a first report, diaregard. If it's a second, check the file name that was also presumably in the report, see it's a Whatsapp folder and disregard it. If it's a third report or there are multiple pieces, get a warrant to run a CSAM scan on the person's device, go to their apartment, run it, see there's nothing else, close the case. If it's a clear "prank", start investigating the person who sent it.
But since the police are, in general, trigger happy lunatics, you get a full raid instead. And since computer forensics is hard and doesn't pay well, the investigation took many months instead of an afternoon. The fuckup was squarely on the law enforcement side, as well as in the law itself.
That's the slippery slope nature of these laws. For sure a CSAM is "out there" and easily acquired. And now it some sort of toxic, radioactive content that destroys systems, corporations, and most importantly, invididuals if weaponized.
I suppose these people with good intentions, seeking to wipe CSAM off the face of the earth with religious fervor ... I suppose they never realized that such thing as a troll exists on the internet who will gladly point their fervor as the troll pleases like a firehose of seething