4 ms·
> What's the situation like if you have two chunks of data (perhaps at two separate locations on the blockchain) and only if you XOR them you get the illegal im
by gst 8y ago
> What's the situation like if you have two chunks of data (perhaps at two separate locations on the blockchain) and only if you XOR them you get the illegal image?
That's an interesting legal question and there's also already a content publishing system (Publius) that afaik uses a similar approach: https://en.wikipedia.org/wiki/Publius_(publishing_system) https://en.wikipedia.org/wiki/Publius_(publishing_system)
Let's assume person A publishes 1 MiB of random data on their web server. Afterwards person B XORs illegal content against that data and publishes the result on their own web server (which to an outsider looks like random data). A's file XORed to B's file re-creates that illegal content.
Let's assume that at a later point it's not possible anymore to determine who published their file first. Who is liable for the illegal content? And who needs to remove that data from their server? Neither of them? Both of them? The first variant definitely sounds wrong, but the second variant implies that you can get in trouble for publishing perfectly random data.
- bilbo0s 8y agoI think it may cloud how the Feds pursue a production or a distribution charge. The issue in the US is that simple possession, in and of itself, is illegal. Whether the images are encrypted, xor or base64 encoded, steganographically hidden, whatever, if they are in your possession, and you don't report them, you're guilty of possession. And here's the thing in the US, not only the producers of the content are guilty of the possession, but everyone who has a storage device with that content stored on it is guilty of possession. You can try to trickety-trick the Feds, but with that particular charge, you're not gonna get out of it. Don't try to outsmart the law on something like this. The best thing to do is to find a way technologically to remove this content from blockchains, and to report whoever had it or created it.
- johnwyles 8y agoThis comment is why I came to comment myself. You cannot remove these types of things once they are baked in they are there for good unless there is some very complex math involved in somehow safely removing or flagging this section of the blockchain but then that would defeat the purpose of the whole cryptographically secure nature of it. Second is you can stomp down on websites that search the blockchain for text, images, videos, illegal documents, etc. However that is not solving the issue directly. However that is hurting a lot of positive potentially interesting uses on account of the very small percentage of abuses. What you essentially have is a GIANT public whiteboard but you've given everyone a permanent marker. If you can control the content that goes in very directly (doing some AI analysis on photos for example) then there will always be a subversive tactic like the XOR one mentioned above, etc. I suppose the real reason I comment here is that I cannot forsee anyway that these things will not happen and will not continue to happen. Like with ThePirateBay I suppose you have to go after the sites that make it convenient to find this information rather than trying to solve the problem in the blockchain itself _somehow_, which I think we can pretty much agree from a security standpoint and tech-forward approach would render the whole concept of blockchain dubious.
- Canada 8y agoActus reus and mens rea are both necessary in order for there to be a crime. In order to commit a crime, you need to do the criminal act and have the intention or knowledge of the criminal act. And you have to do it willfully, which means you can't be forced to do so under duress. If someone throws a bag full of contraband into your house you're not guilty of possession. It can sit there for an arbitrary period of time without making you guilty of anything as long as you don't know what it is. If, against your will, someone handcuffs a locked briefcase that you know contains contraband to your wrist, you cannot be guilty of possession of it even though you're in a real sense in possession of it. It can remain there for an unlimited amount of time, and you are not guilty of anything merely because you are unable to remove it. Immutable data structures pose an interesting problem. Normally we can say that someone knew, or ought of have known something was there. If someone handcuffed a briefcase to you, it's expected that you would freak out and do whatever you could to detach and dispossess it. We haven't had to deal with situations like someone being forcibly tattooed with what they know to be child pornography. If that happened, would the person so marked be guilty of possession if they didn't burn or cut it off? New technology definitely makes those assumptions highly questionable. Is Google guilty of possession and redistribution of illegal material because it indexed and cached it? It is not. Distributed situations make the issue even more acute. Your computer might need to download, process, and redistribute to others some representation of child pornography, or copyrighted material you have no license to distribute, stolen credit card numbers, classified material, or some other prohibited material. You might even be aware that it is there. But if it is necessary that your software take those actions with that data, that you have no choice, in order to send to confirm receipt of funds, then is it justified or lawful to make it a crime for you to do so?
- johnwyles 8y ago> is it justified or lawful to make it a crime for you to do so? Certainly not. My point above yours although you were not replying to it is asking a question I'd like to also ask you. We clearly have a very clear definition on what intent is and how that is the resounding factor considered in such a case. However, do we simply do nothing because it's the nature of the project itself to be distributed and immutable history through time. We clearly cannot change the overwhelming applications that technology has so my guess is the only way this is dealt with is a few easy low-hanging fruit items can be done to safeguard against it and if anyone is caught operating outside of that with the sole intent of some illegal activity then we deal with it like we would any other case of illegal materials being found in someone's possession. The nice thing here is that everything is traceable given enough time and calculating power and that this person can theoretically be caught, even if at one point they were to have paid cash for coins with someone off the street. Good old detective work can kick in from there. I guess I am more curious if these instances can be used to shoehorn law enforcement or the federal agencies into areas that hinder the full capability of the various blockchain applications. I remember back to the San Bernardino shooters cell phone needing to be unlocked and how nail-biting it was that Apple might give away that they had a secret backdoor they were willing to give out to all of our horror. Likewise I hope this doesn't go that same route, and it seems really unlikely, that something such as this would slow the progress of these technologies - not building a backdoor but slowly down transactions to check for illegal content essentially.
- dzek69 8y agoGoing deeper into XOR topic: Virtually any data can be decrypted into illegal content. It's a matter of algorithm. So if one would like to put you in jail, you could be accused of possesing illegal thing, your disk drive could be taken and then cyber crime guys will discover child abuse images in your perfectly valid zip file of a Word document. Sounds like out of mind but it's technically valid. And scary.