-
PseudoDNA: Identifying Critical Vulnerabilities in Microsoft’s PhotoDNA
Researchers from the COSIC group at KU Leuven have uncovered major security weaknesses in PhotoDNA, a technology widely used to detect Child Sexual Abuse Material (CSAM) online. The system is currently used by major platforms including Google, Instagram, TikTok, Facebook, and Microsoft, and is deployed at a global scale. https://www.pseudodna.eu/
Fediverse reactions
-
“Natural collisions in Apple’s NeuralHash & Microsoft’s PhotoDNA show worrying false positives/negatives in widely deployed perceptual hashing”
At Facebook 2013-16 it was a discreet secret within parts of the Trust & Safety team that PhotoDNA “had problems with collisions but we are not allowed to talk about them” – discussion prevented by Microsoft license terms but also because criticising any “child safety” technology was an industry taboo. I’m glad this is coming out
Fediverse reactions
-
Investigation: UK spends millions on VPNs as government weighs ban for children | TechRadar
“Since the publication of this investigation, the Department for Science, Innovation and Technology (DSIT) published a contract that shows it is spending nearly £50,000 on a survey to understand how children are using VPNs. Details have been added below.” https://www.techradar.com/vpn/vpn-privacy-security/investigation-uk-spends-millions-on-vpns-as-government-weighs-ban-for-children
Fediverse reactions
-
UK House of Lords seeks ban on Swiss Army Knives that “…could be used to cut people”
“We are not against pen knives in principle”, says peer, “…but we want manufacturers to take steps to prevent them being used to cause harm.” https://www.thebureauinvestigates.com/stories/2026-03-17/baroness-kidron-interview Quote: To “create” a chatbot or model that can “encourage” crime would be an offense punishable by 5 years imprisonment under amendments voted through (203 to 148) by the
Fediverse reactions
-

This is absolute perfection: UBUNTU SECURE BOOT AGE VERIFICATION | Hacker.House
Perfect commentary on nerds following authoritarianism because it is an interesting intellectual challenge:
Fediverse reactions
-
Lawyer mocks Ofcom’s big fine with bigger hamster | RollOnFriday
Apparently RollOnFriday is kind of “Slashdot meets HackerNews” for the UK legal community, and they are covering that Ofcom is being hamstered by 4chan. Public ridicule amongst the legal community may actually be quite impactful, plus the article has some genuinely interesting background information which does not get much airtime. https://www.rollonfriday.com/news-content/lawyer-mocks-ofcoms-big-fine-bigger-hamster
Fediverse reactions
-
Let Me Explain How a State Actor Could Perform a Denial-of-Service Attack on the Entire UK Government in the Wake of Ofcom “Online Safety Act” Client-Side Scanning
1/ obtain a hash of abuse material that’s both known & banned; if pervasive as claimed this shouldn’t be hard 2/ use algorithms from this paper to create a cat meme with the same hash 3/ send the cat meme to all MPs & Civil Servants via SMS, E-Mail, WhatsApp (bonus if it goes viral) 4/
Fediverse reactions
-
Ofcom persist in pretending that 4chan are trading in the UK, rather than accepting that Britons are visiting a foreign website
Regulate the Britons, not the foreign websites: “4Chan responds to £520,000 Ofcom fine with AI picture of hamster” “Companies – wherever they’re based – are not allowed to sell unsafe toys to children in the UK. And society has long protected youngsters from things like alcohol, smoking and gambling. The digital world should be no
-
I suspect that Ofcom only ever accept that it is “highly effective age assurance” if somebody gets paid, ideally repeatedly | Apple permit “account age” as a means of age verification
This will be fun to watch, because the age verification lobby community are equal parts not rational and commercially minded; also the mere passing of the arrow of time does nothing to fund the UK Government, and a potential tax fruit the size of the Apple user base will be too tempting to leave be:
Fediverse reactions
-
Moxie Marlinspike, of Signal fame, announces partnership with Meta to bring end-to-end encryption to Meta AI Chat
This is going to cause a safety regulatory meltdown: Quote: Confer is built so that nobody has access to your conversations but you (not even me!) … Ten years ago, I worked with Meta to integrate the Signal Protocol into WhatsApp for end-to-end encrypted communication. That enabled end-to-end encryption by default for billions of people.
Fediverse reactions
