>Who's to say protest-plans.ppt won't be the next thing on the list? Or justin-bieber.mp3? Or cia-torture-prisons.txt?
Because possession of those files doesn't break federal law, but possession of child pornography does?
And even if those things were added, obviously Google does some sort of rough verification process of the nature of the content being sent if it matches a hash.
Service providers have been sharing image hashes of CP for 6+ years now. It's definitely not just Google.
Your slippery slope makes no sense. This is probably the absolute least invasive thing that Google does. You are aware they show ads based on the actual text content of your emails, right?
I have zero confidence in the LEO/domestic intelligence services caring whether protest-plans.ppt break federal law. And I don't want Google to have to implement some completely opaque "rough verification process" to determine whether the government requested trigger is valid in one case but not in another.
I always do a sort of mental double-take when I see comments like this. If you have zero confidence in law enforcement caring about the law, then what does any of this matter? What's to discuss? The government is going to do whatever it wants, and there are no policy implications to Google's detection of child pornography. There's nowhere to go from that rhetorical position, so why even bother picking specific things in opposing comments to respond to?
It's perfectly consistent to think that law enforcement is willing to cheat when they can get away with it, but that other domestic forces are capable of holding them accountable for that.
Further, it strawmans the position: they do think that law enforcement cares about the law, just not so much as catching lawbreakers who aren't part of the political or policing class, and is willing to cheat the law in order to "fulfill the deeper mission", or some ascribed view like that.
A natural reply to thinking that law enforcement will cheat if it can is to think that other large, entrenched players must force law-enforcement to disclose its actions for review before lending their power to law enforcement goals - which is exactly the stance in insisting that Google not respond to hashed lists, and instead demand to see the files that they're supposed to be blocking.
It increases the number of players necessary to cheat successfully, and hence removes some of the incentive of law enforcement to cheat.
Your comment would be stronger without the first sentence, but glass houses, stones, &c. Since the rest of it was a good-faith response to my question:
I'm not sure I understand how it's consistent to believe that law enforcement (to be precise: "LEOs and domestic intelligence") are inclined to ignore the law entirely, and believe that there's accountability. If there was accountability, they could not easily incline towards ignoring the law, because doing that would have consequences. Belief in the former condition seems to equate to disbelief of the latter.
I don't think I responded to a straw man argument. I think you rehabilitated a broken argument and then supposed that I was responding to that better argument instead of the one that was actually posed.
I have pretty good confidence in law enforcement caring about the law in general.
I have quite low confidence in intelligence agencies using a law for its intended purpose. I expect them to stretch and distort what they are allowed to do, and to abuse mass filtering mechanisms. So they should for the most part not be allowed to have mass filtering mechanisms.
To put it more simply: I do not expect the details of these laws to be followed, and 'type of content blocked' is a detail. But at a macro scale the law will be followed.
Sure. I think I agree with this. However: what's being described here is not a system that can be directly abused by the CIA or NSA to trawl for documents. It is coupled in at least two specific ways with the search for child pornography: (1) it only works for images (from a known corpus), and (2) the corpus is managed not by the USG writ large but by a cooperative effort specific to child pornography.
I see the slope, but the traction on it is pretty solid.
I have a bit of faith in companies like Google and Microsoft though. If suddenly their feed of illicit image hashes began to contain content related to politics or protecting government secrets, I think they'd raise hell. I also don't think the FBI would be dumb enough to start pushing that sort of stuff and harming the relationship they have with tech companies.
Now, I can very much see NSA doing that kind of content inspection without the companies knowing about it. And that's not just because we already know it's been happening for years.
But law enforcement != intelligence, or at least it shouldn't. The FBI does still have a corps of good old fashioned cops, even if they're now getting more and more into the intelligence side of things.
Ah, that makes even more sense. And it makes it even more annoying that the original article didn't include any of this information (what Google is actually doing to find these, how hashing works, who manages the hashes) just to make a more sensationalist piece.
A bit late for a reply, but for the record: That's a double straw man. I always do a mental double-take when that happens because now suddenly I feel like I have to defend a position that's twice removed from my own.
I did not say "LEO doesn't care about the law", I said I have no confidence that LEO and domestic intelligence agencies will care whether the documents they scan for are against the law.
It doesn't take much imagination that they can easily justify watching for protest-plans.ppt because of terrrism, both towards themselves and against outside supervision, if there is any. Of course they're not going to charge you for protest-plans.ppt, but it sure is a useful document to have and might even come in handy as character evidence.
Furthermore, even if I had said they don't care about the law preventing them from monitoring communication in this way[0] it's unreasonable to assume that I also think they don't care about any law at all and hence "the government is going to do whatever it wants".
[0] in fact, if LEO is monitoring all mail in this manner, I would hope that they are breaking the law (domestic intelligence can probably do whatever the hell they want); but again, that was not what I had in mind
His slippery slope does make sense. Your argument seems to suggest you would think it's okay for the police to show up at your door everyday and go though your files looking for child porn as long as they promise not to care about anything else like that weed you've got or those taxes you didn't file perfectly.
I'm assuming you wouldn't be happy with that .
Google shouldn't be looking in my email in the first place period for anything . The end. I'll give them permission to automate scanning to place ads but that's it. Anything past that is out full stop
You do realize that automation of scanning to place ads is FAR more invasive to your privacy than what's being described in this article?
Scanning if any of the images you sent, when hashed, meet a certain hash is about as blind and automated as you can possibly get. They have no clue of what images you send or what they look like, they just know if you sent an image that is an exact match to an image of child pornography. No one is actually reading through emails and "looking" at the pictures; a program is hashing them all.
> Google shouldn't be looking in my email in the fiery place period for anything . The end. I'll give them permission to automate scanning to place ads but that's it. Anything past that is out full stop
All services have clauses saying what you're not allowed to do on those services; and that they monitor to ensure that you're not doing that. I'd be amazed if the user agreement you signed when you started using Google (assuming you use Google) didn't have that.
> I'll give them permission to automate scanning to place ads but that's it. Anything past that is out full stop
If you look at the relevant section of Google's Privacy Policy - https://www.google.com/intl/en/policies/privacy/#nosharing - you have already given them permission to access your email to "meet any applicable law, regulation, legal process or enforceable governmental request".
One reason is that it's extraordinarily expensive to enlist Google and Microsoft in the pursuit of government secrets compared to the alternatives.
The USG (like most F-500 companies) invests a lot of money in patrolling the borders of its networks for breaches of sensitive information. For commercial entities, there's a whole class of product ("data loss prevention" systems) that do this out of the box.
Since (a) the information the USG is watching for is generated from within their network borders, and (b) USG isn't comfortable sharing that information or artifacts of that information with third parties, it doesn't make a lot of sense for them to invest a huge amount of effort (both technically and legally) to come up with some cockamamie scheme to have Google look for those secrets without knowing what the secret is.
Instead of engaging with the intractable problem of having Google dragnet GMail for documents Google is not allowed to read, the USG is much more likely to just subpoena the accounts of people it suspects to be trafficking in those documents.
Not that I have much faith in the idea that something being extraordinarily expensive prevents the government from pursuing a particular course, but what you say would cover most cases.
But let's say instead of classified documents, we're talking about al-qaeda-training-manual.pdf. One can easily imagine such a document violating federal laws.
Say there are various documents the government catches during a raid, on say Bin Laden's compound for example. Say the government would like Google to look around and see who has trafficked in these documents. They don't have to tell Google what the documents are, exactly, just provide hashes/file sizes/ etc.
Because possession of those files doesn't break federal law, but possession of child pornography does?
And even if those things were added, obviously Google does some sort of rough verification process of the nature of the content being sent if it matches a hash.
Service providers have been sharing image hashes of CP for 6+ years now. It's definitely not just Google.
Your slippery slope makes no sense. This is probably the absolute least invasive thing that Google does. You are aware they show ads based on the actual text content of your emails, right?