6 ms·
> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offenc
by CSAECop 5y ago
> "Can’t the police do good old fashioned police work to catch people doing these things?"
I'm a detective that works exclusively on online child sexual offences.
The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology.
Perhaps you could expand more on what "good old fashioned police work" means, in this context?
- ssss11 5y agoThanks for your reply - I meant that police caught criminals before the internet (I do not know the effectiveness and am unknowledgeable on this subject generally), however they did that, getting out there speaking to suspects and victims, and investigating with evidence I would guess
- CSAECop 5y agoWell, police still investigate with evidence, but the potential scope of "evidence" is pretty much the whole physical universe. File hashes and TCP packet captures are evidence, DNA fragments are evidence, weather patterns are evidence, in the same way that people's memories are evidence. Through the decades, the respect shown to eyewitness testimony has generally declined, and crimes with no eyewitness evidence are still expected to be solved. For offences with a huge online aspect there is no prospect of "getting out there" until you work out where "there" is, because it could be anywhere in the world.
- lovemenot 5y agoDo you have any qualms? For you does the CP protection end justify any means? Where would you personally draw the line on mass surveillance by LE for the sake of your specific LE goals? CP aside, are there other crimes that you feel should be folded-in to a dragnet like this?
- CSAECop 5y agoYou probably don't realise it, because you're coming from a perspective that has been heavily influenced in a particular way, but some of these questions are kind of insulting and don't really assume good faith (or even basic decency) on my part. > "does the CP protection end justify any means?" Like, is this legitimately a question you think I might answer "yes" to? This is the equivalent of "do you support the rape of children?". I'll gladly comment on more specific points if you are genuinely struggling to understand how Apple could honestly implement this system in good faith.
- lovemenot 5y agoI apologise if you you genuinely felt my questions were assuming bad faith. It was not my intention. > "does the CP protection end justify any means?" It's a style of argumentation. Not personal. When trying to find where to draw a line in the sand, one way is to draw a line that almost certainly encompasses us both. We are obliged to consider: if not this line (obviously) then what line? My intent was to find your limit. Do you have any qualms with what you may do under the law? For you personally, how much erosion of innocents' liberties would be acceptable? Based on your earlier comment, I was not asking Apple, I was asking a LEO who acts with some but limited justification. Legal and moral. And I would like to ask in good faith about how you see those limits. >> This is the equivalent of "do you support the rape of children? No need to make it black and white. Almost nobody supports this. I am sure you don't. Please assume good faith on my part too. There are always trade-offs. How far would you go?
- CSAECop 5y agoHow are you expecting me to describe this limit? I think it's legitimate for companies to implement automated systems, such as CSAM and spam filtering, to limit the amount of unwanted material on their networks. I don't have any problem with Apple, Google, and Microsoft, checking the hashes of files I upload (or attempt to upload, in Apple's case) to their servers against ICSE. I would have an issue if employees of those companies had unfettered, unaudited access to users files. Outside of giving my opinion of a specific proposal I don't know what you expect me to say. Perhaps you could describe your own "limit" to how much avoidable suffering is acceptable to you before you would support automated scanning of uploads. I don't personally believe it's possible to precisely explain an overarching "limit" in situations that balance competing moral and philosophical concerns. --- I'm being rate limited now due to downvotes, might not be able to respond further
- feanaro 5y agoNot the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from there. If there's reasonable suspicion, you'd get the suspect's address and go talk to them in person. Before we started trying to push government-sanctioned and unwanted spyware engines on private devices, I imagine the process looked something like that. Is this incorrect?
- CSAECop 5y agoThe system is basically what you describe except the explicit report is precisely what Apple send to NCMEC. By the time it gets to the police, there will be an identified crime. This has been the case for many years. I don't have the numbers to hand but I believe NCMEC receives around the order of 100 million referrals a year. EDIT: it's 20 million according to https://www.missingkids.org/ourwork/ncmecdata https://www.missingkids.org/ourwork/ncmecdata https://www.missingkids.org/footer/media/keyfacts https://www.missingkids.org/footer/media/keyfacts - around 99% are from tech company referrals, 1% from members of the public
- feanaro 5y agoBut we've already established there is no public oversight over the contents of the NCMEC database and that there cannot ever be, by design. Furthermore, it's known to contain hashes of non-CSAE images simply because they were found in a CSAE-related context. So how can this system guarantee civil freedom? How can it be guaranteed that it won't be exploited by the small number of people in power to actually inspect it and manipulate it?
- CSAECop 5y agoHave we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they? Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already? Proponents of these systems can point to thousands upon thousands of actual "wins" (such as identifying teachers, police officers, sports coaches, judges, child minders etc who are pedophiles) and detractors cannot provide actual evidence of their theoretical disadvantages. No system is perfect, no system "guarantees civil freedom", this is not a fair test. The actual evidence suggests automated scanning for CSAM is a net win for society.
- stjohnswarts 5y agoFirst very brave of you to post here and thanks for that. Second thanks for all your hard work in keeping this world sane. However, I would point out that this is a complete invasion of privacy and essentially working around the 4th amendment in both spirit and the law via using Apple as a proxy to spy on us. I realize police just want to do their job and have to push on the limits, but with all due respect I think this is going too far. That's why we push back when something as ridiculous as this happens. I don't want to be policed on my own devices, and the only way police should have a way into that is with a warrant, then you can drop a world of security on me. The pedos will just work around this and this is the first step into allowing police into all our personal devices while the criminals work around it. Anyway, again I mean this in a respectful tone, I just think it goes way too far. Cloud drives are already being scanned and that's with corporate permission on their own devices, so that's tolerable if undesirable but what Apple is doing here is going too far.