Child sexual abuse is exploding online. Tech’s best defenses are no match.

A new report argues there's more tech companies can do to stop child sexual abuse material from spreading online without sacrificing privacy.

silhouette of hands

In many cases, company safeguards are failing to keep pace with the evolving threat of child sexual abuse material.

Photo: Catherine Falls Commercial/Getty Images

Online child sex abuse material has grown exponentially during the pandemic, and tech's best defenses are no match against it, according to a new report on the threat facing countries around the world.

The report, published last month, was developed by the WeProtect Global Alliance, an NGO that represents nearly 100 governments as well as dozens of companies including giants like Apple, Google, Facebook and Microsoft in their efforts to stop the spread of child sexual exploitation. The report, which also includes a survey of 32 member-companies, found that not only is the sheer volume of child sexual abuse material, or CSAM, increasing, but it's growing more complex and capitalizing on tech's blind spots.

"The scale and rate of change is unprecedented," the report reads.

During the pandemic, global reports of suspected sexual child exploitation to the National Center for Missing and Exploited Children increased 106%, according to the report. That's while troubling trends like online grooming and livestreaming child sexual abuse for pay have grown. At the same time, companies and law enforcement officials are grappling with a rapid increase in "self-generated" content from kids, who may be sending images of themselves consensually to peers only to have those images circulated without their consent later on.

The report finds that while tech companies have come a long way toward addressing this problem over the last decade, in many cases their safeguards are failing to keep pace with the evolving threat.

"The scale of child sexual exploitation and abuse online is increasing. This sustained growth is outstripping our global capacity to respond," the report reads.

A 'perfect storm'

The COVID-19 crisis created a "perfect storm" for CSAM to proliferate online, the report argues. Children spent more time online than ever and offenders had reduced opportunities to commit offline abuses, which increased online demand for imagery.

Increases in reporting don't necessarily equate to an increase in volume, the report's authors caution, but they point to other recent trends that have also exacerbated the problem.

WeProtect's report included research that analyzed conversations in offender forums on the dark web and found that offenders use these forums to exchange best practices. More than two-thirds of the discussions were about technical tools for messaging, exchanging funds or storing content in the cloud. "They're talking about which social media platforms to use, they're talking about communication tools, they're talking about storage facilities," said Iain Drennan, executive director of the WeProtect Global Alliance. "There's that kind of community — in inverted commas — but that kind of exchange of information," he said.

The report also emphasizes the challenges in policing this content on a global scale. The internet makes it easy for offenders to exploit vulnerabilities in whichever country has the weakest technical and regulatory defenses, because it's just as easy to access a site hosted in the US as it is in Europe, Asia or anywhere else in the world.

In developing countries, the dramatic uptick in online adoption has outpaced those countries' ability to protect against these kinds of abuses, Drennan said. "The focus has previously been to get people online, and there's been amazing progress in that," he said. "But you're getting a situation where you don't necessarily have those specialized capabilities."

This is further complicated by the inherently global nature of CSAM. "This is a crime fundamentally where the victim could be in the Philippines, the offender could be in the United States, and they're using a platform that's headquartered in Finland. It's that kind of international dimension," said Drennan. To truly collect evidence or prosecute offenders that are overseas requires careful coordination with international entities like Interpol and Europol, or bilateral collaboration with other countries.

The report also points to an increase in "self-generated" sexual material over the last year. That includes imagery and videos that young people capture themselves, either because they were coerced, or because they voluntarily shared it with someone their own age, who then shared it more broadly without their consent. According to the Internet Watch Foundation, a UK-based non-profit that also works to stop child abuse online, there was a 77% increase between 2019 and 2020 in reports of self-generated material, a category of content that can be particularly difficult to police. "You can have a perfectly healthy consenting relationship between two teens, the relationship breaks up, one of them starts sharing it, then that gets into the internet," said Drennan. "And you've gone from something that was not harmful and that we don't want to criminalize in any way into something that's more problematic. And that's a real challenge for policymakers to try [to] address."

Safety by design

In addition to outlining the scope of the problem, the report also takes stock of what the tech industry has done so far to address it. In February and March of this year, WeProtect and the Technology Coalition, a group of tech companies working to fight child sex abuse on their platforms, conducted a survey of 32 companies and found that 87% of them are already using image-specific hash-based detection tools to automatically block known child sexual abuse material from their platforms.

And yet, far fewer companies actually contribute new material to existing hash databases. Only 26% of tech companies make their content classifiers available to other companies, the survey found, indicating a major lack of collaboration.

Sean Litton, the executive director of the Technology Coalition, said tech companies have a responsibility to share "hard lessons learned, to share technology, to share best practices, to share insights." Even if one platform is impenetrable to abuse — and none are — "that leaves all the other platforms for bad actors to exploit," he said.

While companies may be making progress on removing static images, the survey found that only 30% of companies surveyed are using classifiers to detect CSAM in videos. Just 22% of them are detecting this behavior in livestreaming, even as that medium has become a popular new frontier for CSAM.

That needs to change, the report argues. The report also suggests tech companies use techniques such as deterrence messaging, age-estimation tools and digital literacy training. These interventions can include showing users a message when they attempt to make searches for CSAM or using AI to scan a user's face and check their age.

Some regions, including Australia, are also pursuing an approach known as "safety by design," creating toolkits that tech companies can use to ensure their platforms are considering safety from their inception. "It's creating the technology in such a way that it's child-friendly, and children can't be harmed using it," said Litton. "And it's designing it specifically for children."

Safety or surveillance

The authors of the report advocate for more regulation to protect against online harms to children, as well as new approaches to encryption that would protect users' privacy without making CSAM virtually invisible. But many of the techniques for detecting CSAM come with serious privacy concerns and have raised objections from some of WeProtect's own member-companies.

Privacy experts, like the ACLU's Daniel Kahn Gillmor, worry that features like Apple's proposed child safety features — which WeProtect publicly supports, but which the company has put on hold — can open gateways to infringements on privacy and security. Apple proposed scanning users' iCloud accounts for known CSAM and submitting a report to NCMEC if the volume of material passes a certain threshold. "You want your information being read by the folks that's intended to be read by," Gillmor said. "You don't want whoever is hanging on to your backup to be able to dig into that and find information that you don't like."

Another proposed feature would scan iMessages on devices of children under 13 and alert their parents if they send or receive sexually explicit imagery. But privacy advocates say that could put vulnerable kids, including most prominently LGBTQ+ youth, at unnecessary risk.

Another concern is miscategorization. In a world where tech platforms use metadata to detect adults who may be grooming young people, what would that mean for, say, a teacher who's regularly in contact with students, Gillmor asked.

There's also the risk of mass surveillance in the name of protection, he argued. "If what we say to kids is, 'Here's your safety tool, and it's safe because someone is surveilling you,' we shouldn't be surprised if those kids become adults who equate surveillance with safety," Gillmor said.

Gillmor is careful to frame the conversation as surveillance versus security rather than privacy versus child safety, because he doesn't see the latter as mutually exclusive. "I view working for people to have effective privacy as also being a child-safety concern," he said.

Tech companies have a long way to go in making sure prevention and detection methods are up to speed and that their platforms provide protections without sacrificing security. But there's no neat and easy solution to such a complicated, multidimensional threat.

Drennan likens it to counterterrorism: "You put the big concrete blocks in front of the stadium — you make it hard," he said. While some perpetrators may slip through, "you immediately lose all of those lower-threat actors, and you can focus law enforcement resources on the really dangerous and high-priority threats."


Niantic is building an AR map of the world

The company’s Visual Positioning System will help developers build location-based AR games and experiences; a new social app aims to help with AR content discovery.

VPS will allow developers to build location-based AR experiences for tens of thousands of public spaces.

Image: Niantic

Pokémon Go maker Niantic has quietly been building a 3D AR map of the world. Now, the company is getting ready to share the fruits of its labor with third-party developers: Niantic announced the launch of its Lightship Visual Positioning System at its developer summit in San Francisco on Tuesday. VPS will allow developers to build location-based AR experiences for tens of thousands of public spaces, Niantic said.

Niantic also announced a new service called Campfire that adds a social discovery layer to AR, starting with Niantic’s own games. Both announcements show that Niantic wants to be much more than a game developer with just one or two hit apps (and a couple of flops). Instead, it aims to play a key role in the future of AR — and it’s relying on millions of Ingress and Pokémon Go players to help build that future.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Sponsored Content

Why the digital transformation of industries is creating a more sustainable future

Qualcomm’s chief sustainability officer Angela Baker on how companies can view going “digital” as a way not only toward growth, as laid out in a recent report, but also toward establishing and meeting environmental, social and governance goals.

Three letters dominate business practice at present: ESG, or environmental, social and governance goals. The number of mentions of the environment in financial earnings has doubled in the last five years, according to GlobalData: 600,000 companies mentioned the term in their annual or quarterly results last year.

But meeting those ESG goals can be a challenge — one that businesses can’t and shouldn’t take lightly. Ahead of an exclusive fireside chat at Davos, Angela Baker, chief sustainability officer at Qualcomm, sat down with Protocol to speak about how best to achieve those targets and how Qualcomm thinks about its own sustainability strategy, net zero commitment, other ESG targets and more.

Keep Reading Show less
Chris Stokel-Walker

Chris Stokel-Walker is a freelance technology and culture journalist and author of "YouTubers: How YouTube Shook Up TV and Created a New Generation of Stars." His work has been published in The New York Times, The Guardian and Wired.


Why it's time to give all your employees executive coaching

In an effort to boost retention and engagement, companies are rolling out access to executive coaching to all of their employees.

Coaching is among personalized and exclusive benefits employers chose to offer their workforce during the pandemic.

Image: Christopher T. Fong/Protocol

Executive coaching has long been a quiet force behind leaders in the tech industry, but that premium benefit, often only offered to the top executives, is changing. A new wave of executive coaching services are hitting the market aimed at workers who would have traditionally been excluded from access.

Tech companies know that in order to stay competitive in today’s still-hot job market, it pays to offer more personalized and exclusive benefits. Chief People Officer Annette Reavis says Envoy, a workplace tech company, offers all employees access to a broad range of opportunities. “We offer everyone an L&D credit that they can spend on outside learning, whether it's executive coaching or learning a new coding language. We do this so that people can have access to and learn skills specific to their job.”

Keep Reading Show less
Amber Burton

Amber Burton (@amberbburton) is a reporter at Protocol. Previously, she covered personal finance and diversity in business at The Wall Street Journal. She earned an M.S. in Strategic Communications from Columbia University and B.A. in English and Journalism from Wake Forest University. She lives in North Carolina.


Microsoft thinks Windows developers are ready for virtual workstations

The new Microsoft Dev Box service, coupled with Azure Deployment Environments, lets developers go from code to the cloud faster than ever.

Microsoft hopes a new cloud service will address one of developers' biggest challenges.

Photo: Grant Hindsley/Bloomberg via Getty Images

Microsoft hopes a new cloud service will address one of the biggest challenges that developers have raised with the technology giant over the last several years: managing developer workstations.

Microsoft Dev Box, now in private preview, creates virtual developer workstations running its Windows operating system in the cloud, allowing development teams to standardize how those fundamental tools are initialized, set up and managed.

Keep Reading Show less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.


Okta CEO: 'We should have done a better job' with the Lapsus$ breach

In an interview with Protocol, Okta CEO Todd McKinnon said the cybersecurity firm could’ve done a lot of things better after the Lapsus$ breach of a third-party support provider earlier this year.

From talking to hundreds of customers, “I've had a good sense of the sentiment and the frustrations,” McKinnon said.

Photo: David Paul Morris via Getty Images

Okta co-founder and CEO Todd McKinnon agrees with you: Disclosing a breach that impacts customer data should not take months.

“If that happens in January, customers can't be finding out about it in March,” McKinnon said in an interview with Protocol.

Keep Reading Show less
Kyle Alspach

Kyle Alspach ( @KyleAlspach) is a senior reporter at Protocol, focused on cybersecurity. He has covered the tech industry since 2010 for outlets including VentureBeat, CRN and the Boston Globe. He lives in Portland, Oregon, and can be reached at kalspach@procotol.com.

Latest Stories