2/ So, @ncmec are basically goaled and compensated for their headline "number of reports" metric. The bigger the number, the more govbucks and funding, for instance in their *previous* counterblast to end-to-end encryption: missingkids.org/blog/2019/post…
3/ Hardly anyone ever asks about the cost-benefit of doing this, because children. Simply: it would be rude.
So you should totally go read this thread and then come back here:
4/ Okay: into this walks @Apple, who have majorly screwed up the launch of their "developed in a vacuum" CSAM solution, and who are attempting to work around major criticisms which others [LIKE ME] are raising, re: their misconceived and ill-planned idea.
Aaaaand…
5/ "Let's use databases from several countries, to minimise risk that one Government could insert hashes to discover leaks of (say) NSA documents."
But NCMEC is goaled to drive the number of reports *upwards*.
Can you see where this is going, yet?
6/ NCMEC are not goaled towards minimising the number of hashes, nor towards deduplication, nor performance, and from what I understand they are not goaled upon quality assurance.
They are goaled on *growth* - which means: EVER MORE HASHES, AND SHARING.
7/7 So: Apple are presenting as a "solution" to governmental collusion, their unstated faith in NCMEC @MissingKids and @IWFhotline and … we don't know how many more… as-if they're all independent, above reproach, and not sharing data in/amongst themselves entirely "on trust".
8/7 ps: if you need evidence of an "institutional mindset" at @MissingKids, look no further than their "Screeching Minority" comment:
Hot on the heels of #ChatControl and in the name of “identity” and “consumer choice” the EU seeks the ability to undetectably spy on HTTPS communication; 300+ experts say “no” to #Article45 of #eIDAS #QWAC alecmuffett.com/article/108139
If you would like to see more discussion regarding:
Regulation: EU Digital Identity Framework — including #eIDAS and #QWAC
When Signal and WhatsApp have fled the surveillance of the #OnlineSafetyBill, what app will still be around for politicans, journalists, and actual normal people to use, securely.
@JohnNaulty @matrixdotorg Let's be clear: we are talking about the evacuation of the entire Signal and WhatsApp userbase / niche, from the United Kingdom.
That's a lot of people.
WOW:
- No Signal
- No WhatsApp
- No iMessage
- No Facetime
@jamesrbuk called it #internexit; the UK will be extraordinarily isolated from the rest of the internet.
A big part of the the reason for the existence of that API was because the European Union wanted to enable people to access their data; so they created the problem, complained when the inevitable leaks happened, and are now reinventing it
Could be the attached, but my suspicion is that this is going to be another CYBER! DARKWEB! CYB3R! SYBER! CAMBRIDGE ANALYTICA‼️BRAIN CONTORL! YOU SAW AN ADVERT AND SO A RUSSIAN ARTIFISHIAL INTELLIGENCE APP MADE YOU VOTE FOR UKIP! … thing.
Plucky spooks in Cheltenham but dressed for speed-dating in 2015-era Shoreditch, battle "Russian influence operations" that Nadine Dorries will soon cite as rationale for the #OnlineSafetyBill.
Token American subplots help sell the series to the US.
Back in 1991 I published an open-source password cracking tool which defined the state of the art for the next 5+ years, so much so that echoes of it can be found in all major password crackers of today.
Some folk criticised me for doing this, choosing words like these to do so:
I know that in general it's bad form to take a single quote out of context and use it to critique an entire essay (concerned.tech) — but I do feel that this time it's deserved.
The concerned-dot-tech essay has had extensive technical debunking, e.g.: