4 ms·
> But you're telling me privacy preserving solutions to combat illicit content are impossible? Yes. You cannot have a system that positively associates illici
by least 11mo ago
> But you're telling me privacy preserving solutions to combat illicit content are impossible?
Yes. You cannot have a system that positively associates illicit content with an owner while preserving privacy.
- notepad0x90 11mo agoThanks for the reply, but you are exactly the audience my post is for. Because you say that, we will lose what little figments of privacy and freedoms we have left. Apple tried and made good progress. They had bugs which could be resolved but your insistence that it couldn't be done caused too much of an uproar. You can have a system that flags illicit content with some confidence level and have a human review that content. You can make any model or heuristic used is publicly logged and audited. You can anonymously flag that content to reviewers, and when deemed as actually illicit by a human, the hash or some other signature of the content can be published globally to reveal the devices and owners of those devices. You can presume innocence (such as a parent taking a pic of their kids bathing) and question suspects discretely without an arrest. You can require cops to build multiple sufficient points of independently corroborated evidence before arresting people. These are just some of the things that are possible that I came up with in the last minute of typing this post. Better and more well thought out solutions can be developed if taken seriously and funded well. However, your response of "Yes." is materially false, law makers will catch on to that and discredit anything the privacy community has been advocating. Even simple heuristics that isn't using ML models can have a higher "true positive" rate of identifying criminal activity than eye witness testimony, which is used to convict people of serious crimes. And I suspect, you meant security, not privacy. Because as I mentioned, for privacy, humans can review before a decision is made to search for the confirmed content across devices.
- admash 11mo agoExcept that it is not materially false. Only in a perfect society will your “system that flags illicit content” not become a system that flags whatever some authoritarian regime considers threatening, and subverting public logging/auditing is similarly trivial to a motivated authoritarian. All your hypothetical solutions rely on humans, who are notoriously susceptible to being influenced by either money or being beaten with pipes, and on corporations, who are notoriously susceptible to being influenced by things that influence their stock price. The Pleyel’s corollary to Murphy’s law is that all compromises to individuals’ rights made for the sake of security will eventually be used to further deprive them of those rights. (I especially liked the line “You can require cops to build multiple sufficient points of independently corroborated evidence before arresting people.”)
- notepad0x90 11mo agoThis is already the case with other means of communication. the internet isn't that special. If you don't trust your government, do something else about it. We rely on eye witness testimony and human juries all the time. The innocence project has a long list of people that spent decades in prison because of this. The solution to authoritarian regimes is to not have one, not tolerate cp on the internet.
- dngray 11mo ago> The solution to authoritarian regimes is to not have one, not tolerate cp on the internet. Perhaps the problem doesn't have a binary solution.
- notepad0x90 11mo agoI think it does, but not having such a regime has lots of implementation complexities? either you have one or you don't, so binary.
- dngray 11mo ago> The solution to authoritarian regimes is to not have one The solution to not being poor is being rich. You could apply that logic to a lot of things. Have this thing instead of that thing. Using your example above of "differential privacy scanning" Differential privacy is a property of a dataset meaning you can’t tell an individual was part of a dataset. If it’s traceable back to the individual device it’s not differentially private. I think at this point you're just trying to say "don't have this thing have that thing instead" as a response to anything.
- notepad0x90 11mo ago> You could apply that logic to a lot of things. Certainly you can. The solution to being poor is not being poor. how? that is a different story, but ultimately, the solution to being poor must be not being poor, otherwise it isn't a solution right? And of course it is a reductive take, but it is nevertheless correct. Solutions that don't result in poor people no longer being poor are not solutions. Solutions that don't involve in not having an authoritarian regime are not solutions to that problem either. Your solution to authoritarian regimes is not fighting CSAM, you made the CSAM problem worse, and it does not prevent authoritarian regimes. An authoritarian regime does not need your permission to scan your phone. And most human governments in history qualify as authoritarian, and they didn't need phones let along scanning of phones. > I think at this point you're just trying to say "don't have this thing have that thing instead" as a response to anything. I'm saying: "If you don't like apples, don't eat apples. Don't talk about how we need to kill all the bees and worms that help apple trees reproduce". > Differential privacy is a property of a dataset meaning you can’t tell an individual was part of a dataset. Yeah, that's correct. And that's a violation of individual's privacy..how? What would it take for you to consider scanning of phones a valid solution. Would mass murder, global nuclear war, pandemic containment? Is it a question of not understanding the harm being done? My frustration is that, ok, let's not scan phones. what's your solution? You have none. Your solution is to do nothing and accept things should be the way they are. If I said let's verify everyone's ID before they can access the internet, is that acceptable? Let's ban Tor and VPNs instead, is that acceptable? What is your solution? Can you at least agree what we should aggresively be working on a solution? We have people training LLMs to generat CSAM and you hear not a peep out of all these companies and devs working on the tech. Just slap knees and declare "welp, that's unfortunate". I don't care what governments do. If it takes an authoritarian regime to stop this insanity, I'm all for it. I'll be royally screwed, it will be a nightmware. But if that is the cost, so be it. This is how authoritarians gain power by the way. You have the apathetic educated and ruling classes, and the masses crying for change, and they will actually solve the problem but destroy everything else along the way. I'm tell you that if I, someone who is relatively aware and informed of the risks of privacy loss, of tech underlying the systems we use, if I am saying this, imagine what the majority of people would say. it took one 9/11 attack to get us the patriot act, if someone used Tor on their rooted android phone to do something worse, phone scanning will be the least of your concerns. And the public would support it. You need a solution because the public demands it, at the cost of privacy if required. But it is for technologists to device a mechanism that solves the problem without costing us privacy.
- least 11mo ago> Because you say that, we will lose what little figments of privacy and freedoms we have left. I understand that you seem to think that adding systems like this will placate governments around the world but that is not the case. We have already conceded far more than we ever should have to government surveillance for a false sense of security. > You can have a system that flags illicit content with some confidence level and have a human review that content. You can make any model or heuristic used is publicly logged and audited. You can anonymously flag that content to reviewers, and when deemed as actually illicit by a human, the hash or some other signature of the content can be published globally to reveal the devices and owners of those devices. You can presume innocence (such as a parent taking a pic of their kids bathing) and question suspects discretely without an arrest. You can require cops to build multiple sufficient points of independently corroborated evidence before arresting people. What about this is privacy preserving? > However, your response of "Yes." is materially false, law makers will catch on to that and discredit anything the privacy community has been advocating. Even simple heuristics that isn't using ML models can have a higher "true positive" rate of identifying criminal activity than eye witness testimony, which is used to convict people of serious crimes. And I suspect, you meant security, not privacy. Because as I mentioned, for privacy, humans can review before a decision is made to search for the confirmed content across devices. It's not "materially false." Bringing a human into the picture doesn't do anything to preserve privacy. If, like in your example, a parent's family photos with their children flag the system, you have already violated the person's privacy without just cause, regardless of whether the people reviewing it can identify the person or not. You cannot have a system that is scanning everyone's stuff indiscriminately and have it not be a violation of privacy. There is a reason why there is a process where law enforcement must get permission from the courts to search and/or surveil suspects - it is supposed to be a protection against abuse.
- notepad0x90 11mo ago> I understand that you seem to think that adding systems like this will placate governments around the world but that is not the case. We have already conceded far more than we ever should have to government surveillance for a false sense of security. You have an ideological approach instead of a practical one. It isn't governments that are demanding it. I am demanding it of our government, I and the majority. I don't want freedoms paid for by such intolerable and abhorrent levels of ongoing injustice. It isn't a false sense of security, for the victims it is very real. Most criminals are not sophisticated. Crime prevention is always about making it difficult to do crime, not waving a magic wand and making crime go away. I'm not saying let's give up freedoms, but if your stance is there is no other way, then freedoms have to go away. But my stance is that the technology is there, it's just slippery slope fallacy thinking that's preventing from getting it implemented. > What about this is privacy preserving? Persons aren't identified before a human reviews and confirms that the material is illicit. You have to identify yourself to the government to drive and place a license plate connected to you at all times on your car. You have to id yourself in most countries to get a mobile phone sim card, or open a bank account. Dragnet surveillance is what I agree is unacceptable except as a last resort, it isn't dragnet if algorithms flag it first, and it isn't privacy invading if false hits are never associated with individuals. > you have already violated the person's privacy without just cause, regardless of whether the people reviewing it can identify the person or not. There is just cause, the material was flagged as illicit. In legal terms, it is called probable cause. If a cop hears what sounds like a gunshot in your home, he doesn't need a warrant, he can break in immediately and investigate because it counts as extenuating circumstance. The algorithms flagging content are the gunshots in this case. You could be naked in your house and it will be a violation of privacy, but acceptable by law. If you said after review, they should get a warrant from a judge I'm all for it. It is materially false, because that the scanning can be done without sending a single byte of the device. The privacy intrusion happens not at the time of scanning, but at the time of verification. To continue my example, the cop could have heard you playing with firecrackers, you didn't do anything wrong but your door is now broken and you were probably naked too, which means privacy violated. This is acceptable by society already. The false positive rates for cops seeing/hearing things, and for eyewitness testimony is very high in case you're not aware. by comparison, apples csam scanner was very low. > There is a reason why there is a process where law enforcement must get permission from the courts to search and/or surveil suspects As stated above, so long as the scanning is happening strictly on-device, you're not being surveilled. When there is a hit, humans can review the probable cause, a judge can issue a warrant for your arrest or a search warrant to access your device. Another solution might be to scan only at transmission time of the content, not capture and storage (still not good enough, but this is the sort of conversation we need, not plugging in of ears). Let's take a step back. Another solution might be to restrict every content publishing on the internet to people positively identifying themselves.