Protocol | Policy

Child sexual abuse is exploding online. Tech’s best defenses are no match.

A new report argues there's more tech companies can do to stop child sexual abuse material from spreading online without sacrificing privacy.

silhouette of hands

In many cases, company safeguards are failing to keep pace with the evolving threat of child sexual abuse material.

Photo: Catherine Falls Commercial/Getty Images

Online child sex abuse material has grown exponentially during the pandemic, and tech's best defenses are no match against it, according to a new report on the threat facing countries around the world.

The report, published last month, was developed by the WeProtect Global Alliance, an NGO that represents nearly 100 governments as well as dozens of companies including giants like Apple, Google, Facebook and Microsoft in their efforts to stop the spread of child sexual exploitation. The report, which also includes a survey of 32 member-companies, found that not only is the sheer volume of child sexual abuse material, or CSAM, increasing, but it's growing more complex and capitalizing on tech's blind spots.

"The scale and rate of change is unprecedented," the report reads.

During the pandemic, global reports of suspected sexual child exploitation to the National Center for Missing and Exploited Children increased 106%, according to the report. That's while troubling trends like online grooming and livestreaming child sexual abuse for pay have grown. At the same time, companies and law enforcement officials are grappling with a rapid increase in "self-generated" content from kids, who may be sending images of themselves consensually to peers only to have those images circulated without their consent later on.

The report finds that while tech companies have come a long way toward addressing this problem over the last decade, in many cases their safeguards are failing to keep pace with the evolving threat.

"The scale of child sexual exploitation and abuse online is increasing. This sustained growth is outstripping our global capacity to respond," the report reads.

A 'perfect storm'

The COVID-19 crisis created a "perfect storm" for CSAM to proliferate online, the report argues. Children spent more time online than ever and offenders had reduced opportunities to commit offline abuses, which increased online demand for imagery.

Increases in reporting don't necessarily equate to an increase in volume, the report's authors caution, but they point to other recent trends that have also exacerbated the problem.

WeProtect's report included research that analyzed conversations in offender forums on the dark web and found that offenders use these forums to exchange best practices. More than two-thirds of the discussions were about technical tools for messaging, exchanging funds or storing content in the cloud. "They're talking about which social media platforms to use, they're talking about communication tools, they're talking about storage facilities," said Iain Drennan, executive director of the WeProtect Global Alliance. "There's that kind of community — in inverted commas — but that kind of exchange of information," he said.

The report also emphasizes the challenges in policing this content on a global scale. The internet makes it easy for offenders to exploit vulnerabilities in whichever country has the weakest technical and regulatory defenses, because it's just as easy to access a site hosted in the US as it is in Europe, Asia or anywhere else in the world.

In developing countries, the dramatic uptick in online adoption has outpaced those countries' ability to protect against these kinds of abuses, Drennan said. "The focus has previously been to get people online, and there's been amazing progress in that," he said. "But you're getting a situation where you don't necessarily have those specialized capabilities."

This is further complicated by the inherently global nature of CSAM. "This is a crime fundamentally where the victim could be in the Philippines, the offender could be in the United States, and they're using a platform that's headquartered in Finland. It's that kind of international dimension," said Drennan. To truly collect evidence or prosecute offenders that are overseas requires careful coordination with international entities like Interpol and Europol, or bilateral collaboration with other countries.

The report also points to an increase in "self-generated" sexual material over the last year. That includes imagery and videos that young people capture themselves, either because they were coerced, or because they voluntarily shared it with someone their own age, who then shared it more broadly without their consent. According to the Internet Watch Foundation, a UK-based non-profit that also works to stop child abuse online, there was a 77% increase between 2019 and 2020 in reports of self-generated material, a category of content that can be particularly difficult to police. "You can have a perfectly healthy consenting relationship between two teens, the relationship breaks up, one of them starts sharing it, then that gets into the internet," said Drennan. "And you've gone from something that was not harmful and that we don't want to criminalize in any way into something that's more problematic. And that's a real challenge for policymakers to try [to] address."

Safety by design

In addition to outlining the scope of the problem, the report also takes stock of what the tech industry has done so far to address it. In February and March of this year, WeProtect and the Technology Coalition, a group of tech companies working to fight child sex abuse on their platforms, conducted a survey of 32 companies and found that 87% of them are already using image-specific hash-based detection tools to automatically block known child sexual abuse material from their platforms.

And yet, far fewer companies actually contribute new material to existing hash databases. Only 26% of tech companies make their content classifiers available to other companies, the survey found, indicating a major lack of collaboration.

Sean Litton, the executive director of the Technology Coalition, said tech companies have a responsibility to share "hard lessons learned, to share technology, to share best practices, to share insights." Even if one platform is impenetrable to abuse — and none are — "that leaves all the other platforms for bad actors to exploit," he said.

While companies may be making progress on removing static images, the survey found that only 30% of companies surveyed are using classifiers to detect CSAM in videos. Just 22% of them are detecting this behavior in livestreaming, even as that medium has become a popular new frontier for CSAM.

That needs to change, the report argues. The report also suggests tech companies use techniques such as deterrence messaging, age-estimation tools and digital literacy training. These interventions can include showing users a message when they attempt to make searches for CSAM or using AI to scan a user's face and check their age.

Some regions, including Australia, are also pursuing an approach known as "safety by design," creating toolkits that tech companies can use to ensure their platforms are considering safety from their inception. "It's creating the technology in such a way that it's child-friendly, and children can't be harmed using it," said Litton. "And it's designing it specifically for children."

Safety or surveillance

The authors of the report advocate for more regulation to protect against online harms to children, as well as new approaches to encryption that would protect users' privacy without making CSAM virtually invisible. But many of the techniques for detecting CSAM come with serious privacy concerns and have raised objections from some of WeProtect's own member-companies.

Privacy experts, like the ACLU's Daniel Kahn Gillmor, worry that features like Apple's proposed child safety features — which WeProtect publicly supports, but which the company has put on hold — can open gateways to infringements on privacy and security. Apple proposed scanning users' iCloud accounts for known CSAM and submitting a report to NCMEC if the volume of material passes a certain threshold. "You want your information being read by the folks that's intended to be read by," Gillmor said. "You don't want whoever is hanging on to your backup to be able to dig into that and find information that you don't like."

Another proposed feature would scan iMessages on devices of children under 13 and alert their parents if they send or receive sexually explicit imagery. But privacy advocates say that could put vulnerable kids, including most prominently LGBTQ+ youth, at unnecessary risk.

Another concern is miscategorization. In a world where tech platforms use metadata to detect adults who may be grooming young people, what would that mean for, say, a teacher who's regularly in contact with students, Gillmor asked.

There's also the risk of mass surveillance in the name of protection, he argued. "If what we say to kids is, 'Here's your safety tool, and it's safe because someone is surveilling you,' we shouldn't be surprised if those kids become adults who equate surveillance with safety," Gillmor said.

Gillmor is careful to frame the conversation as surveillance versus security rather than privacy versus child safety, because he doesn't see the latter as mutually exclusive. "I view working for people to have effective privacy as also being a child-safety concern," he said.

Tech companies have a long way to go in making sure prevention and detection methods are up to speed and that their platforms provide protections without sacrificing security. But there's no neat and easy solution to such a complicated, multidimensional threat.

Drennan likens it to counterterrorism: "You put the big concrete blocks in front of the stadium — you make it hard," he said. While some perpetrators may slip through, "you immediately lose all of those lower-threat actors, and you can focus law enforcement resources on the really dangerous and high-priority threats."

Protocol | Fintech

Crypto wallet maker Ledger gears up for battle with Dorsey’s Block

CEO Pascal Gauthier wishes Block’s CEO were still distracted with Twitter, but he’s still gunning for the big opportunity in securely stashing customers’ coins.

Ledger CEO Pascal Gauthier talked about Ledger’s strategy in an interview with Protocol.

Photo: Ledger

Ledger CEO Pascal Gauthier reacted with an odd mix of excitement and fear to news that Jack Dorsey was leaving Twitter to focus full-time on Square.

“Oh, shit,” was his immediate thought, he told Protocol. “I would have preferred him to stay with more companies and not focus on anything.”

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at bpimentel@protocol.com or via Signal at (510)731-8429.

In a tight labor market, businesses are competing for top talent, even as employees leave in droves. A record 4.4 million Americans resigned in September 2021 — the highest on record for nearly 20 years — ushering in what some call the Great Resignation. That same month, 65% of U.S. workers said they were looking for a new job.

Business leaders have to respond to mitigate the negative impacts of this disruptive churn, with 36% of CFOs saying they're very concerned about turnover remaining high indefinitely and weighing on revenue growth. The answers to this challenge should be informed by the root causes of employee dissatisfaction as well as retention drivers.

Keep Reading Show less
Suneet Dua, PwC
As PwC’s US Products & Technology Chief Revenue and Growth Officer, Suneet Dua is responsible for driving more than $1 billion in product revenue and executing PwC’s product revenue strategy. He’s focused on driving innovation, delivering world-class, forward-thinking products and digitally upskilling the workforce and society at large. With 20+ years of technology, media and entertainment industry experience, he’s positioned as a catalyst for organizational transformation and delivers on the firm’s promise to solve the world’s most important problems. Additionally, he launched Salesforce and client-focused centers of excellence, such as our Cybersecurity centers in Israel, Singapore and India––all to improve the way PwC serves its clients. During his tenure as US Chief Product Leader, Suneet, and his team, played a critical role in designing and implementing digital tools that upskilled more than 55,000 of its US employees, which led to the development of PwC’s digital learning platform, ProEdge, that addresses the digital skills gap crisis facing today’s workforce. He also serves as a board member of PwC’s Trifecta Consulting (US, China, Japan and Mexico). Previously, Suneet served on PwC’s US leadership team and was Global Client Market Leader for PwC’s Global Network.
Protocol | Fintech

A legal brawl failed to uncover bitcoin’s fabled creator

Is Craig Wright Satoshi Nakamoto? A trial didn’t lead to an answer.

Craig Wright has claimed to be the creator of bitcoin.

Photo: Eugene Gologursky/Getty Images for CoinGeek

A legal battle was supposed to answer the biggest question in crypto: Who is Satoshi Nakamoto?

Well, that didn’t exactly happen. The identity of bitcoin’s fabled creator remains a mystery, despite high hopes that an unusual civil suit would lead to Nakamoto’s unmasking.

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at bpimentel@protocol.com or via Signal at (510)731-8429.

Snap CTO Bobby Murphy on embracing Apple’s AR glasses

Snap is building its own AR Spectacles, but the company also wants to embrace third-party devices.

Bobby Murphy wants Snap’s AR lenses to run everywhere — even on hardware made by competitors.

Photo: Getty Images for Snap Inc

Snap is all in on AR: The Snapchat maker has been building its own AR glasses, and is currently testing an early version with a small group of creators. Snap has also signed up 250,000 creators to build mobile-centric AR experiences through its Lens Studio platform, whose lenses have collectively been viewed over 3.5 trillion times.

Snap celebrated those milestones at its Lens Fest Tuesday, which the company also used to release a number of updates for both mobile and headworn AR. Snap CTO Bobby Murphy recently put that work in context in an interview with Protocol, in which he talked about the company’s progress in building AR Spectacles, why it isn’t focused on non-AR wearables anymore and why it ultimately also wants to build apps and experiences for AR devices made by its competitors.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Discord launches paid channel memberships

The company’s new subscription tiers effectively broaden the creator economy to include people managing communities.

Select Discord server creators can start charging membership fees as part of a new pilot program.

Image: Discord

Creating and managing successful communities can be a lot of work. Now, Discord wants to make sure that the people doing this on its platform can also reap some rewards: The company launched a pilot program for premium memberships Tuesday that allows community creators to put parts or all of their servers behind a paywall.

“We want to make sure that running communities on Discord is more sustainable,” said Discord Engineering Director Sumeet Vaidya in an interview with Protocol.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Latest Stories
Bulletins