4 ms·
1) be a horrible human and want to troll 2) modify close up/ambiguous adult porn to be flagged as CP with free GitHub tool 3) batch a few thousand porn photos
by zionic 5y ago
1) be a horrible human and want to troll
2) modify close up/ambiguous adult porn to be flagged as CP with free GitHub tool
3) batch a few thousand porn photos like this to poison them
4) upload them everywhere, 4chan/Reddit/tumblr/discord/imagefap
5) some poor sap manages to save 20+ of your bait images
6) apple reviewer sees 100x100px blurry gray image of definitely porn that was flagged as CP. hits report.
7) a SWAT team bust down your door and takes all your devices while you go to jail and your mugshot is everywhere
Someone will do this, and the poisoned images will spread organically until they find a victim
- smabie 5y agoThis is actually a good idea. Maybe can convince apple this won't work.
- owlbite 5y agoHasn't this ship already sailed though? At least I'm given to understand that they already scanned all these photos uploaded to iCloud anyway (in the same way many other similar providers do). Whether it happens on the device or the server doesn't seem to make any difference to this attack. (That's not to say that (a) the scanning of stuff on a server was a good idea in the first place or (b) encouraging politicians to use your own device to spy on you is a good idea or (c) this isn't the thin end of a very painful wedge, just that we've not opened a new vulnerability)
- rapnie 5y agoPlus by doing this at scale you generate such workload for reviewers that they are way more likely to quickly press 'report' in step 6.