News: 1654169349

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Dear Europe, once again here are the reasons why scanning devices for unlawful files is not going to fly

(2022/06/02)


While Apple has, temporarily at least, backed away from last year's plan to run client-side scanning (CSS) software on customers' iPhones to detect and report child sexual abuse material (CSAM) to authorities, European officials in May proposed rules to protect children that involve the same highly criticized approach.

The European Commission [1]has suggested several ways to deal with child abuse imagery, including scanning online private communication and breaking encryption. It has done so undeterred by [2]a paper penned last October by 14 prominent computer scientists and security experts dismissing CSS as a source of serious security and privacy risks.

In response, a trio of academics aims to convey just how ineffective and rights-violating CSS would be to those who missed the memo the first time around. And the [3]last time , and [4]the time before that.

[5]

In [6]an ArXiv paper titled "YASM (Yet Another Surveillance Mechanism)," Kaspar Rosager Ludvigsen and Shishir Nagaraja, of the University of Strathclyde, and Angela Daly, of the Leverhulme Research Center for Forensic Science and Dundee Law School, in Scotland, revisit CSS as a way to ferret out CSAM and conclude the technology is both ineffective and unjustified.

[7]

[8]

Client-side scanning in this context involves running software on people's devices to identify unlawful images – generally those related to the exploitation of children but EU lawmakers have also discussed using CSS to flag content related to terrorism and organized crime.

Apple's approach involved using its NeuralHash machine-learning model to compute an identifier for images set to be synced to iCloud against a list of known CSAM identifiers. And it didn't fare all that well when security researchers found they could [9]create hash collisions with non-CSAM images. European officials haven't settled on a specific technical approach, but as far as the paper's authors are concerned, CSS isn't fit for the task.

[10]

Ludvigsen, Nagaraja, and Daly argue that CSS can no more prevent the distribution of CSAM than antivirus scanning can prevent the distribution of malware.

Even if you assume, they argue, that a CSS system caught all CSAM it encountered – an unrealistic assumption – there's no clear definition of CSAM. There's a legal definition, they say, but this cannot be translated into rules for a CSS system.

So adversaries will respond to CSAM scanning by finding ways to craft images that evade detection.

[11]Europe proposes tackling child abuse by killing privacy, strong encryption

[12]Client-side content scanning as an unworkable, insecure disaster for democracy

[13]Apple quietly deletes details of derided CSAM scanning tech from its Child Safety page without explanation

[14]Australia gave police power to compel sysadmins into assisting account takeovers – so they plan to use it

"CSS contains in its very notion constant surveillance upon the system, and unlike pure logging, attempts to oversee all events within a given framework," the boffins explain. "This makes it very similar to software like antivirus, which we cannot be 'perfect' as the definition of malicious software can never define all the types in existence."

What's more, the researchers claim the cost of trying to solve CSAM far outweighs the benefits, and that's likely to be the case regardless of how the technology evolves. Presumably there would be some benefit to finding CSAM images loaded onto phones by child exploiters unaware that their devices now surveil for the state, but these would be overshadowed by violating other people's privacy rights all the time and denying everyone the benefits of encryption.

[15]

"Surveillance systems are well known to violate rights, but CSS present systems which will do this routinely or constantly, which is why we find them to be dangerous and cannot justify [them] by the goals they aim to serve," the computer scientists argue.

They are, however, convinced that EU legislators will attempt to move forward with some sort of CSAM scanning scheme, so they've also attempted to explain the legal problems they expect will follow.

"We find that CSS systems will violate several rights within the European Convention of Human Rights, but our analysis is not exhaustive," the researchers state in their paper. "They will likely violate the Right to a Fair Trial, in particular the Right to Remain Silent and Not Incriminate Oneself, Right to Privacy, and if implemented further than current examples, Freedom of Assembly and Association as well."

For example, a trial cannot be fair, the researchers argue, if defendants cannot easily challenge evidence produced by an undisclosed algorithm. There's always the possibility that the imagery may have been planted by authorities or fabricated or downloaded as a result of entrapment.

The authors go on to chide the European Commission for the techno-solutionist belief that CSS is the only possible way to combat CSAM. The Commission, they say, "disregards and does not analyze the potential consequences either CSS or server-side scanning would have on cybersecurity and privacy, while they justify the victim’s potential positive outcomes outweighing the negative of everyone else."

The researchers conclude that CSS is just too disruptive.

"If you want to dig for gold, you predict accurately where it is," they say. "What you usually do not do, is to dig up the entire crust of the surface of the earth. CSS systems and mass surveillance represent the latter." ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2022/05/12/eu_encryption_csam/

[2] https://www.theregister.com/2021/10/15/clientside_side_scanning/

[3] https://www.theregister.com/2019/07/23/us_encryption_backdoor/

[4] https://www.theregister.com/2015/04/28/us_politicians_complain_that_silicon_valley_cant_create_encryption_unicorn/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpjeowF0dkTf1BixXnUkgAAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://arxiv.org/abs/2205.14601

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpjeowF0dkTf1BixXnUkgAAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpjeowF0dkTf1BixXnUkgAAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/08/18/apples_csam_hashing/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpjeowF0dkTf1BixXnUkgAAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2022/05/12/eu_encryption_csam/

[12] https://www.theregister.com/2021/10/15/clientside_side_scanning/

[13] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/

[14] https://www.theregister.com/2021/09/14/identify_and_disrupt_bill_australia/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpjeowF0dkTf1BixXnUkgAAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



The sound of Perseverance

El Bard

Interesting how perseverance is almost universally considered a positive trait, when it can as well (possibly even more often) be a sign of the utmost stupidity.

Re: The sound of Perseverance

Sixtiesplastictrektableware

There always seems to be a tendency toward narrative over knowledge. People can't shake it until they hit something hard enough to break it.

Re: The sound of Perseverance

MiguelC

Perseverance ≠ stubbornness

Re: The sound of Perseverance

yetanotheraoc

It's a "single issue" voter. I once heard such a voter being interviewed, they said "Yes, I am a single issue voter. All I care about is this one issue. Any other issue I don't care about. This one issue is the most important thing in the country/world/universe and overrides any other possible consideration."

So my single issue is I think smurfs should be outlawed. Politician says they will do away with smurfs. They get my vote. Interviewer: "That politician has been convicted of corruption." Me: "I don't care, they are tough on smurfs." Interviewer: "There is nothing that would change your mind?" Me: "Only if they go back on their promise to get rid of the smurfs." Politician: "No more smurfs!"

Never mind the politician is shagging a smurf as soon as the interview is over.

Re: The sound of Perseverance

Anonymous Coward

I've been fighting with my boss for a month trying to convince him (yet again) that spamming is bad. He hired some new sales clown who has him convinced he "just send small batches" and get a "great response rate". They just won't take no for an answer. Not sure why they care so much about getting me to agree with them.

They just can't accept "no" for an answer.

Re: The sound of Perseverance

John Brown (no body)

"Not sure why they care so much about getting me to agree with them."

Are you in charge of the outgoing spam filters? :-))

heyrick

No need to autoscan billions of random images. Just subpoena the stepfather's phone/computer. That'll likely catch more than this nonsense ever would.

Yet Another Anonymous coward

Or the second son of a monarch, or CEO of any large USA company, or TV/movie executive

There is a need.

yetanotheraoc

"No need to autoscan billions of random images."

What happens if there is insufficient criminal images on the stepfather's phone? A cache of suitable images could come in quite handy at times.

Cav

Before everyone jumps all over me, I agree with the problems this poses but.. I dislike illogical arguments.

"Ludvigsen, Nagaraja, and Daly argue that CSS can no more prevent the distribution of CSAM than antivirus scanning can prevent the distribution of malware."

So we shouldn't have antivirus scanning or laws against murder etc, because they won't stop all instances? That's ridiculous.

Yet Another Anonymous coward

Hashes attempt to detect known images.

If you are doing this on people's phones you are presumably trying to identity new images from the phones camera

How is the algorithm going to decide if a picture of a baby in the bath is child porn? Or distinguish a legal image of your 16year old wife from an illegal photo of a 17 year old ?

Pascal Monett

If your wife is 16 years old I think you have a different problem.

Yet Another Anonymous coward

In Britain, and most of Europe, you can get married at the age which Americans are only allowed to buy a machine gun.

LDS

No, actually in US many States have no minimum age for marriage. And any attempt to establish one failed.

Still distributing images of a minor is unlawful...

simkin

Sure but what if it's an image of your own kid that you messengered to your wife?

Yet Another Anonymous coward

>Still distributing images of a minor is unlawful...

The point was that the UK (and much of europe) have a bizarre feature where the age of consent/marriage is 16 but child porn laws are imported from America and use 18

So taking a picture of your wife breastfeeding would be child porn.

John Brown (no body)

"The point was that the UK (and much of europe) have a bizarre feature where the age of consent/marriage is 16 but child porn laws are imported from America and use 18"

It's 18 in the UK now. Until recently, it was 16 but only with parental consent.

gnasher729

What apple proposed didn’t need to decide. Before uploading a picture onto iCloud (Apples servers, so they have a right not to want some images on there), your phone would scan an image and say it looks dodgy. It tells you and shows you the image, then you decide whether to upload (because it’s harmless), or whether to upload (because you don’t care it’s illegal), or not to upload (because it’s illegal and you don’t want it outside your phone), or to delete it (because it’s dodgy, you have no idea how it got on your phone, and you don’t want it).

That's now how Apple's system works

yetanotheraoc

"It tells you and shows you the image"

No, it rejects the image upload, applies secret "points" against your license to upload, and if you go over the allowed number of points then it locks your phone and reports you to the authorities.

Alumoi

Oh, easy! Is the target a political opponent or journalist? Then it's child porn.

simkin

Unless it's on Hunter Biden's laptop. Then it's Russian propaganda.

Charlie Clark

You're making false equivalences. People choose to install anti-virus software, it isn't perfect and it doesn't automatically report them to the police.

Detecting undefined pornographic images is much, much harder. Videos are orders of magnitude more difficult and it's all easier to fuzz.

Version 1.0

Malware delivery workers all install AV software to make sure their deliveries can pass through, so the child porn folks would probably install the software to get their images through it. We're all running around saying "this is good" and "this is bad" but nothing's going to change in the world until we admit that humans have the ability to be stupid.

Which politicians are involved in this?

Anonymous Coward

The only name I've heard connected to this is Ursula von der Leyen, who argued against getting involved over Crimea. Who else is trying to degrade Europe's cyber security at a time when Russian cyber threats are exceptionally high?

It will happen . . .

m4r35n357

Try explaining to Boris/Priti exactly how this is a bad idea, and see how far it gets you!

Re: It will happen . . .

John Riddoch

That's fairly easy. "This is an EU initiative, but Brexit allows us to avoid this onerous red tape".

Re: It will happen . . .

m4r35n357

Good effort! However . . .

I think they are more likely to just not mention the EU aspect. This is something they _want_.

Re: It will happen . . .

Yet Another Anonymous coward

Except they are going to play down the child bit, it will be scanning images on your phone to spot immigrants

Wrong question answered

b0llchit

It is not about the kiddie porn or terrorists. It is all about getting access to the client side of the devices. Having the foot in there means the ability to bypass any and all encryption. Any agency will queue when access to the device is available. That is the point.

Re: Wrong question answered

gnasher729

All the data on an iPhone is accessible. Once the user entered the passcode. I can attach a photo from my photo library to an email. And send it. How is that working if my phone can’t read the photo? So this argument of “getting a foot in” is pointless. Data that my phone can’t read is useless.

Re: Wrong question answered

Yet Another Anonymous coward

The 'foot in' is having a button in ACPO's secret lair that let's them also access everything on your phone - in case you are the sort of potential criminal that doesn't love the Police enough

Re: Wrong question answered

Paul Crawford

And the feature-creep. Remember when ISP-level network blocking was only for CSAM sites? Then it was re-used for copyright enforcement? Then for anti-terror?

What next we wonder...disputed elections? Corrupt politicians martial being exposed?

Re: Wrong question answered

Yet Another Anonymous coward

Or local authorities using anti-terrorist laws to track dog crap and fly tipping

Re: Wrong question answered

John Brown (no body)

and declaring Icelandic banks as terrorist groups.

From Sir Humphrey's Playbook

Charlie Clark

Given the slew of consistent judgements from all over Europe against preventive action, I think those involved know that this policy has no chance of being enacted. It's all about making the right kind of noises and then finding someone else to blame, increasingly the courts.

And when they catch them, what they do?

LDS

Get a slap on their wrist, especially when they are rich, famous, or both? I wonder how many of Apple or Google executives will have that software actually running. And I can imagine a lot of "exceptions" for "special persons".

This while influencers aim at teenagers and even younger people teaching them how to become idiots (so they can be better exploited), and social media pretend to control the age of their profiles.

Porn's effect on real life

Anonymous Coward

Maybe people will hate me for saying this, but this is based on impressions I get.

Doing stuff with 'porn' reduces ability to do 'x stuff' in real life.

So perhaps if you want people to do less 'x stuff' in real life with minors, give them 'porn' with minors.

Re: Porn's effect on real life

yetanotheraoc

Not hate, but exasperation. You haven't thought it through. "give them 'porn' with minors." -.> you are taking a picture of a crime.

Re: Porn's effect on real life

Anonymous Coward

The picture is proof of the crime. The crime is the crime. The picture can provide evidence to convict those that do this. That's where scanning new pictures can help, but afterwords, if the people in the picture don't mind... it shouldn't matter who has it.

Re: Porn's effect on real life

yetanotheraoc

"if the people in the picture don't mind"

Ugh. I think it's safe to say the victim does mind. Especially since the victimization and the picture-taking of it are the whole point of the crime. But keep posting, I can learn to hate you.

Re: Porn's effect on real life

Anonymous Coward

"I think it's safe to say the victim does mind"

I was about to say something like that, although there might some cases...

The 'victim' should probably have a/the say in what to do about it.

Re: Porn's effect on real life

Charlie Clark

Will you hate us for pointing out the problems of anecdotal evidence? While some people may, indeed consume stuff in porn that they would never do in real life. For example, some studies have suggested that female crime readers and writers indulge in violent fantasies that they would very much never want to be involved in.

However, this does not hold true for all and what might be a "pressure valve" for some, may just be encouragement for others. Furthermore, there is evidence suggesting that pornography "normalises" pornographic sex, setting up unrealistic expectations on bodies, sexual preferences, prowess and violence that can cause problems, particularly for adolescents. I don't think that gives the basis for mass surveillance or blanket-banning but, with all due respect for the freedom of the individual, I also don't think it means "anything goes"™.

Have I mentioned in the past....................

Anonymous Coward

........that PRIVATE ENCRYPTION BEFORE ANYTHING ENTERS A PUBLIC CHANNEL.........will defeat all and any attempt to snoop by third parties?

*

So......the alleged abusers only need to encrypt their images (say three passes) using a hard to crack algorithm (say AES or chacha20 with a 8192 bit key)....and all this debate about CSAM (or about any other potentially illegal communication)....all this debate is MOOT!

*

Suggestions:

1. Tool up with gcc, gdb and gmp

2. Read up on Diffie/Hellman (see "Applied Cryptography" by Bruce Schneier)

3. Make all this discussion COMPLETELY MOOT!

....there.....some privacy at last!!

Wrong approach

Boris the Cockroach

the right approach is to demand scanning of every device at the end of the day looking for anything that can be used against you.

If found the cameras/mics are switched on to record you doing anything, and then all that evidence is used to jail you.

Because after all.... the cameras/mics would not be switched on unless you were already being bad.....

And as the old saying goes "those with nothing to hide have nothing to fear"

Whats this 'satire' tag do?

Re: Wrong approach

Anonymous Coward

@Boris_the_Cockroach

.....as I mentioned before, if the messaging is privately encrypted......

.....how would anyone actually know that a snooped message "can be used against you"?

Re: Wrong approach

Yet Another Anonymous coward

>.....how would anyone actually know that a snooped message "can be used against you"?

If you have an encrypted message you are either a terrorist (if skin brown) or a child pornographer (if skin white )

Re: Wrong approach

Anonymous Coward

@Yet_Another_Anonymous_coward

Quote: "...If you have an encrypted message..."

......so banks are all run by terrorists? Credit card companies are run by terrorists? Proton Mail is only used by terrorists? WhatsApp is only used by terrorists?

......perhaps you might like to edit your comment?

You'd better beat it. You can leave in a taxi. If you can't get a taxi, you
can leave in a huff. If that's too soon, you can leave in a minute and a huff.
-- Groucho Marx