Catbox.moe got screwed 😿 (blog.catbox.moe)
from Toes@ani.social to technology@beehaw.org on 02 Jun 2025 23:20
https://ani.social/post/14569311

#technology

threaded - newest

db0@lemmy.dbzer0.com on 02 Jun 2025 23:34 next collapse

I wonder what kind of of csam detection they have. If they’re only relying on hash matching, they’ve gonna get fucked from novel genai csam. This is why stuff like the fedi-safety exists which they could use as well

Aatube@kbin.melroy.org on 03 Jun 2025 01:58 collapse

It seems to be unspecified "automated and manual" systems plus reports from the NCMEC https://lemm.ee/post/65739566/20890503 , which they process quite fast https://lemm.ee/post/65739566/20890630 .

db0@lemmy.dbzer0.com on 03 Jun 2025 07:53 collapse

Sorry your links don’t work it seems. Maybe those posts were deleted.

In any case, if their “automated” is just hash matching, it’s just not going to cut it.

user224@lemmy.sdf.org on 03 Jun 2025 10:23 collapse

Just guessing what the links may have been…

Possibly my post on lemmy.world, removed due to breaking rule 2, “Only tech related news or articles”

I’ll copy paste my comment from there:

In the reply to Patreon they mentioned having some automated and manual ways of removing CSAM, plus “closely working with NCMEC”, but I have no idea what that means.
And these statistics of resolved reports: missingkids.org/…/2024-notifications-by-ncmec-res…

Total number of reports of 128 resolved on average in 1.91 days. Less than half the time spent by Amazon, Google and Microsoft (for Bing).

The other link might have been to this comment:

<img alt="" src="https://i.imgur.com/jrC5OT1.png">

db0@lemmy.dbzer0.com on 03 Jun 2025 13:46 collapse

“Having manual ways to remove csam” means almost nothing. All of lemmy has a “manual way to remove csam”. “closely working with NCMEC” can mean they just use the cloudflare mechanism which is just hash matching. Point is, it’s very easy for a malicious actor to upload csam and then report them to patreon for it, without ever reporting it to them.

Redjard@lemmy.dbzer0.com on 03 Jun 2025 16:27 collapse

Can’t you always attempt uploads until they bypass arbitrary filters and then report-snipe on that?
How would a content-based filter prevent this if the malicious actor simply needs to upload correspondingly more images?

I think the sad reality is that the only escape here is scale. Once you have been hit by this attack and been cleared by the 3rd parties, you’d have precedent for when this happens again and should hopefully be placed in a special bin for better treatment.
Scale means you will be fire-tested, and are more likely to receive sane treatment instead of the ai-support special.

db0@lemmy.dbzer0.com on 03 Jun 2025 17:32 collapse

There can be warning about someone getting caught with multiple failed attempts

fluffykittycat@slrpnk.net on 03 Jun 2025 00:50 next collapse

Screwing with payments is a go to scummy tactic these days. It’s enough to make you go full commie

Chozo@fedia.io on 03 Jun 2025 00:57 next collapse

This sucks. I use Catbox quite heavily. I'll probably buy a sub to help support them, but I hope they're able to recoup enough to stay afloat. It's been really great having access to a non-enshittified, login-free host for video files and I'd hate to lose it.

[deleted] on 03 Jun 2025 22:18 collapse

.