7 ms·
It is only supposed to detect CSAM already known to NCMEC, not identify new images.
by phnofive 5y ago
It is only supposed to detect CSAM already known to NCMEC, not identify new images.
- simondotau 5y agoThat's my point. If the original photographer doesn't delete them by the time they're known to NCMEC and the hash database is updated, they would match. As I said, I recognise this is beyond implausible.
- 0xy 5y agoNCMEC's database does not only contain CSAM. It has never been audited. It's full of false positives. They are immune from FOIA requests. They are accountable to nobody. They work so closely with the FBI that there are FBI agents working on the database directly. NCMEC is essentially an unaccountable, unauditable department of the FBI that also happens to be incompetent (the amount of non-CSAM in the database is large).
- simondotau 5y agoYou don't know what's in it, but you do know it's full of false positives? I wonder, do you know how many of those false positives are flagged as A1?
- 0xy 5y agoI know for a fact that it is full of false positives, there's also public sources making the same claim. [1] [1] https://www.hackerfactor.com/blog/index.php?/archives/929-One-Bad-Apple.html https://www.hackerfactor.com/blog/index.php?/archives/929-On...
- simondotau 5y agoI clicked on your link hoping for serious analysis. I would have settled for interesting analysis. I was disappointed. It's just a guy who found one MD5 hash collision. The paragraph was written in a way that makes it unclear whether source of this specific hash was in fact NCMEC or if it was "other law enforcement sources". So which was it? Did this person follow up with the source to confirm whether his hash match was a false positive or a hash collision? So in short, the source for your claims has evidence of between zero and one false positives. Unimpressive would be an understatement.
- 0xy 5y agoIt was not a hash collision. It was a false positive. The way the hashing solution works doesn't really allow for a false positive except in extraordinarily rare circumstances. It matched a man holding a monkey full clothed as a CSAM image, direct from NCMEC's database. He encountered a 20% false positive rate while running a moderately popular image service, with an admittedly low sample size. It's still evidence, and given NCMEC is immune from oversight, FOIA and accountability, it's concerning. Also, the fact I know there are false positives does not stem from that post. I know it independently, but since you asked for a source stronger than "just trust a random internet guy", I gave you one. He's not the only person making the claim though, others throughout these threads with industry knowledge have confirmed what I already knew. If you're asking me to reveal how I know, I'm afraid you'll be disappointed. I'd rather be accused of lying than elaborate.
- simondotau 5y ago> It was not a hash collision. It was a false positive. Again, this was an MD5. It's literally impossible to assert that it was a false positive with absolute certainty. A hash collision is not outside the realm of possibility, especially with MD5. Apparently no attempt was made to chase this up. And we still don't know whether it was the NCMEC database or "other law enforcement sources". You continue to claim that it was "direct from NCMEC's database" but again, that isn't asserted by your source. > He encountered a 20% false positive rate He encountered one potential false positive. Converting one data point into a percentage is exactly why earlier I described this nonsense as being disingenuous. The fact that you would cite this source and then defend their statistical clown show is, in my opinion, strong positive evidence that your other citation-free assertions are all entirely made up.
- 0xy 5y agoWhat you're missing is the statistical probability of two MD5 hashes colliding, which is astronomically unlikely. Your argument is essentially that a collision is more likely than a false positive, which would imply a false positive rate of 0.00% in NCMEC's database based on its size. It's clear that nothing will convince you if you believe that humans managing a database will never, ever make a mistake after over 300,000,000 entries. Because if they make one single mistake, then it supports my argument -- a false positive becomes substantially more likely statistically than a hash collision. You're also providing a pretty large red herring with your suggestion that he could've simply asked NCMEC if it was a false positive or a hash collision. NCMEC would never provide that information, because the database is highly secret. Given those statistics, I think that source is more than valid. >in my opinion, strong positive evidence that your other citation-free assertions are all entirely made up I am happy to let you believe that I'm lying. One industry insider whose employer works with NCMEC cited a false positive rate of 1 in 1,000. [1] The product he works in is used in conjunction with NCMEC's database. Elsewhere, in press releases, the company cites a failure rate of 1% (presumably both false positives and false negatives) [2] [1] https://news.ycombinator.com/item?id=21446562 https://news.ycombinator.com/item?id=21446562 [2] https://www.prnewswire.com/news-releases/thorns-automated-tool-to-remove-child-abuse-content-at-scale-expands-to-more-platforms-through-aws-marketplace-301297111.html https://www.prnewswire.com/news-releases/thorns-automated-to...