6 ms·
That's a nice, subtle way of fucking with someone: spoofing messages that trip these pedo-sensors won't result in an obvious mistaken raid, because the police w
by bcoates 12y ago
That's a nice, subtle way of fucking with someone: spoofing messages that trip these pedo-sensors won't result in an obvious mistaken raid, because the police will want something more solid to go on (like the case in the OP) -- the victim will just show up as 'pedophile, we just can't prove it yet' in a bunch of police databases/background checks/opposition research, and won't know why the random searches randomly choose them every time.
- tptacek 12y agoThere's no such thing as a "pedo-sensor". This is a hash-based search against a corpus of known images, where the hash function was designed explicitly (a) to survive image transformations and (b) to prevent unauthorized parties from predicting the hash of a given image. Either of those two goals could fail and it would still be implausible that an attacker could trigger a false positive without using an image derived from actual known child pornography.
- true_religion 12y agoI think he means spoofing the message was sent by a particular person, but not actually spoofing the content. The content has to be real to trip the hash-search.
- deleted 12y ago[deleted]
- dredmorbius 12y agoI'm actually aware of systems which were built to identify porn through neural-network training. I don't know if these were sensitive to distinguish child porn from other, but as a method of finding images likely to contain more skin than desired, they worked fairly reliably. That said, the Google/Microsoft tool does seem to work based on a known image corpus.
- joeframbach 12y agoPerhaps this may change if a certain list of 535 people in DC are added to this list.
- Ueland 12y agoI suspect that the "hash" actually is the following info per file: sha1-hash, md5-hash, crc32-hash and file size. If a file matches the file size, hash1 is checked, then hash2 and so on. I will be pretty impressed if you can fake that somehow. Edit: this is a normal algorithm for files in general, but it appears to be a image-specific algorithm used in this case. (A la imageDNA)
- lifeisstillgood 12y agoIf you are the sort of person able and willing to screw with someone's life like that, you will have no qualms using your stolen credit cards to buy child porn images to use in this way. I remember a episode of some legal drama where our hero the judge had his laptop "hacked" and child poem images installed on it. (Luckily it was make believe so he was able to "delete" them before the other judges arrived with the tipoff but that's not the point) I think we shall soon enter a legal landscape where mere possession of digital products does not imply legal possession. It's going to be an interesting world.
- pooper 12y agoThis scares me. What can we do though? Can we decriminalize/legalize possession of anything? Perhaps just make it illegal to produce illicit materials? How would it work? Would that mean bad guys would be able to legally own weapons-grade plutonium if they didn't produce it?
- lifeisstillgood 12y agoIt only applies to digital products. If you are found with next doors stolen TV it's not much of a defence to say "I did not put it there", but since any script kiddie from Russia or China can dump bitcoins, porn or military files on your bot netted PC we shall have to see a higher level of proof from prosecuters beyond "well it's on his PC so he must be a MtGox exec / paedophile / spy"
- pooper 12y ago