3 ms·
If I've understood correctly, the test used was something along the lines of: two non-chinese accounts send back-and-forth messages including benign content (ma
by srl 6y ago
If I've understood correctly, the test used was something along the lines of: two non-chinese accounts send back-and-forth messages including benign content (maybe a picture of a pie) and less-benign content (maybe "I like Falun Gong almost as much as I like the CDC"). Then, chinese accounts would observe that the picture of the pie might be censored. I don't actually see an unambiguous description of what messages were sent, or how strong the effect is. Those questions don't really matter for addressing "are non-chinese accounts monitored?" (unless CL is outright lying, obviously yes), but they do matter for the fun question:
Can this be used to construct an attack on WeChat? Providing targeted misinformation for training, to suggest correlations where there really are none, thus triggering WeChat to have a higher false-positive rate when censoring messages?
I'm reminded of RMS's famous practice (and a script in emacs, IIRC): automatically append various keywords to the bottom of emails to screw with any US surveillance that might be getting too nosy.
EDIT: I'm a dope, and should have read the full report (here: https://citizenlab.ca/2020/05/we-chat-they-watch/#part-2---technical-assessment https://citizenlab.ca/2020/05/we-chat-they-watch/#part-2---t...) before commenting.
As far as I can tell, an attack isn't possible. WeChat would ideally like to analyze each document or video sent for sensitive content, but it takes some time (on the order of 20 seconds, maybe), and so that analysis can't be performed before messages are supposed to be delivered. However, if WeChat has already seen the video, then it can make the judgement quickly, and perform real-time censorship. Thus, sending a sensitive video the first time won't be blocked, but all subsequent sends will be. CL's result seems to be that if the first video send is between non-chinese accounts, that's still enough to get it analyzed and blocked the second time.
- hkai 6y agoWhen we are discussing whether the accounts are monitored, we need to remember the no-password mongo db databases containing these messages were available on the internet. https://www.theverge.com/2019/3/4/18250474/chinese-messages-millions-wechat-qq-yy-data-breach-police https://www.theverge.com/2019/3/4/18250474/chinese-messages-...
- gnur 6y agoThat it actually takes 20 seconds implies to me that actual people are viewing the content. I don't see any automated system taking that long as I do believe they would just throw more resources at the problem.
- srl 6y agoI dunno, to process a video (maybe 20-80 seconds) and scan for suspicious text/speech? I was impressed that it was under a minute. I wonder though... do we know enough now to know at what rate actual people view the content, vs just automated processing?
- eru 6y agoHumans in the loop just makes the machine more complicated. You can still give them spurious correlations?