Microsoft Teams: A vector for child sexual abuse material with a two-day processing time for complaints
- Reference: 1671172330
- News link: https://www.theregister.co.uk/2022/12/16/esafety_comissioner_csea_report/
- Source link:
The commissioner oversees Australia's [1]Basic Online Safety Expectations that spell out how Australia expects online platforms to behave. The core of the Expectations is that platforms will do their best to stamp out unlawful or harmful material, allow users to report it, and respond to requests for information from the commissioner.
In August 2022, the commissioner sent Transparency Requests requiring seven service providers – Apple, Meta, WhatsApp, Microsoft, Snap, Skype, and anonymous chat service Omegle – to explain the tools, policies and processes they use to address child sexual exploitation and abuse (CSEA) material and actions. The commissioner asked how they address proliferation of such vile material, the online grooming of children, and the use of video calling and conferencing services to provide live feeds of child abuse.
[2]
Among the [3]findings assessing the orgs' responses, the commissioner found Microsoft isn't using the PhotoDNA image-detection technology it helped to develop and [4]promotes as a tool "to stop the spread of online child sexual abuse photos."
[5]
[6]
The commissioner also singled out Apple and Microsoft for criticism on grounds that neither "attempt to proactively detect child abuse material stored in their widely used iCloud and OneDrive services, despite the wide availability of PhotoDNA detection technology."
"Apple and Microsoft also reported that they do not use any technology to detect live-streaming of child sexual abuse in video chats on Skype, Microsoft Teams or FaceTime, despite the extensive use of Skype, in particular, for this long-standing and proliferating crime."
[7]
Microsoft offered the following explanation for not monitoring for CSEA on Teams videos:
As there are significant jurisdictional and other conflicts associated with operating a global service for use by individuals in one country to communicate with individuals in other countries, Microsoft does not deploy classifiers or other automated content detection tools on video conferences held through Microsoft Teams.
Microsoft reported that the average response time for reports of CSEA on Teams was two days – the same as for OneDrive and a day longer than for its Xbox Live services. The report notes that Microsoft first indicated that some review queues for Teams saw matters left under consideration for 19 days.
Other platforms did better: Meta reported that Instagram can detect and remove CSEA in two hours and forty seconds after it is detected on a device, and handles reports from Instagram users in around 40 minutes.
[8]Egad, did Apple do something right? End-to-end encryption for (most) iCloud services
[9]WhatsApp boss says no to AI filters policing encrypted chat
[10]Tech world may face huge fines if it doesn't scrub CSAM from encrypted chats
[11]Apple quietly deletes details of derided CSAM scanning tech from its Child Safety page without explanation
But the report is also full of evasions, deflections, and excuses for why more comprehensive measures to detect and eradicate CSEA are not in place.
WhatsApp, for example, does not share information about banned users with Instagram or Facebook. If a user is banned for CSEA on Facebook, they may not be banned on Instagram.
Snap and Microsoft don't even try to detect previously unobserved CSEA material.
Only Omegle tries to detect CSEA in livestreams, video calls or video conferences. Snap and Apple don't attempt to identify grooming of minors. Apple doesn't offer any reporting tools in its online services.
[12]
We could go on, but you get the idea. Across the report's 63 pages readers will find many examples of inaction that, if corrected, would offer stronger protections to children.
eSafety commissioner Julie Inman Grant pointed out that the report is not comprehensive – it only details responses to questions her agency posed to seven specific service providers. But some of the answers provided describe respondents' global capabilities, meaning this report is at least a window into how some of tech's most powerful address – or fail to address – the horrors of CSEA. ®
Get our [13]Tech Resources
[1] https://www.esafety.gov.au/industry/basic-online-safety-expectations#summary-of-the-expectations
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5xP0NYqNz7htmevNBCMogAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.esafety.gov.au/newsroom/media-releases/world-first-report-shows-leading-tech-companies-are-not-doing-enough-tackle-online-child-abuse
[4] https://news.microsoft.com/features/microsofts-photodna-protecting-children-and-businesses-in-the-cloud/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5xP0NYqNz7htmevNBCMogAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5xP0NYqNz7htmevNBCMogAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5xP0NYqNz7htmevNBCMogAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/12/08/apple_encryption_icloud/
[9] https://www.theregister.com/2022/08/02/encryption_whatsapp_uk/
[10] https://www.theregister.com/2022/07/07/uk_online_safety_bill_chat_scanning/
[11] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5xP0NYqNz7htmevNBCMogAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
"will depend on whether those that make policy decisions are aware of what computers can do"
We're doomed.
Well fair play to Australia’s e-safety commissioner for being the first to find an area of collaboration that Teams is actually good at facilitating.
Now everybody in MacD is staring at me
*mops laptop keyboard* ... at least Stinkpads are drip-resistant.
Re: Now everybody in MacD is staring at me
> *mops laptop keyboard*
Probably not the best thing to say when talking about child porn ...
Apple's recently announced end to end encryption for iCloud
Is why they were proposing their CSAM detection scheme last year that was to check the unencrypted copy of the photos on the phone as they were uploaded. Because once that full encryption was available, any sort of cloud side scanning would no longer be possible for anyone who has enabled the full data encryption (Apple hadn't been doing any cloud side scanning which is what Australia is complaining about, reportedly Google and Amazon do perform such scanning)
The backlash Apple received for proposing automated checking of everyone's phone (as opposed to just those subject to a court order) caused them to back off, and is undoubtedly the reason they mentioned in the same announcement that those plans had been permanently shelved. They're letting people know "we gave you what you asked for, so don't complain to us later because some bad people are misusing it".
Australia is complaining now, wait until they find subpoenas for iCloud contents being returned with "no data available" because the suspect has enabled full data protection! Guess the cops will have to content themselves with dealing with scum like Cellebrite to get the evidence off a suspect's phone (and if necessary use that phone to get it off iCloud)
Since no one has figured out how to secure software projects of any size, let alone something on the scale of a smartphone OS, I guess no matter how much whack a mole Apple plays with them fixing the exploits they're using there will always be another way in.
Control
What do you expect from the country where the laws of mathematics must bow to the laws of the land... Of course, you think of the children as a scapegoat to implement full control over all communication and decree that 2+2=5.
need two icons to describe the idiocracy
Wow, Teams can actually do something?
I am stunned to hear that there is a single person anywhere on this planet who is accusing Teams of actually being good for something.
Hey MS, maybe you should pivot and go with that, because Teams is shite for office work.
Asking the Unattainable?
Are we here in agreement that, alone, software solutions for preventing/mitigating CSEA are not sufficient? In other words, human action is required. Well, who does expect to do this? Or do they believe this is solvable with technology alone?
I tried to find sources that indicate (eg) PhotoDNA can not be bypassed by modifying an image (cropping/inverting/changing-colours etc) to mismatch against the stored hashes (of known offending material). I didn't find any. Is the source available? Doubt that very much.
It's further obvious that false claims can be made against innocents, both in good faith and maliciously (to make their life hell).
I'm repeating this quote from the other day, it's too pertinent:
Looking forward 20 years, I'm quite certain that the coming of the computer will have a significant effect on all businesses and most private lives. Whether these effects will be fully favorable, as they could be, or in-part harmful, will depend on whether those that make policy decisions are aware of what computers can do and what they cannot do.
- John G Kemeny