Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Setup Cloudflare CSAM Scanning Tool #93

Open
kj4ezj opened this issue Mar 26, 2024 · 2 comments
Open

Setup Cloudflare CSAM Scanning Tool #93

kj4ezj opened this issue Mar 26, 2024 · 2 comments
Assignees
Labels
automation Infrastructure Cloud or physical datacenter infrastructure

Comments

@kj4ezj
Copy link
Contributor

kj4ezj commented Mar 26, 2024

Warning

Trigger Warning
This ticket discusses child abuse.

Important

The contents of this ticket is not legal advice, does not reflect official policy of the EOS Network Foundation, and is not a formal statement by the EOS Network Foundation including but not limited to a statement of intention. This ticket is a proposal from the author to the larger organization provided according to the terms of the license in this repository. This disclaimer also applies to all comments and metadata surrounding this ticket, including but not limited to the GitHub Projects status.

From issue 88, this ticket is to setup the free Cloudflare CSAM Scanning Tool for the eosnetwork.com "website." Cloudflare's use of the term "website" includes eosnetwork.com and any *.eosnetwork.com domain or subdomain.

The Cloudflare CSAM Scanning Tool compares all of our web content proxied by Cloudflare to fingerprints of known child sexual abuse material (CSAM) provided by various child safety advocacy organizations.

If matching content is found, Cloudflare will automatically:

  1. Block the content, preventing it from being served to clients.
  2. File a report on our behalf to the National Center for Missing and Exploited Children (NCMEC), a private non-profit funded by the United States Congress, using their CyberTipline API.
  3. Email the report ID along with technical information necessary for incident response to the EOS Network Foundation using an email address created for this purpose.

The NCMEC will review Cloudflare's report, inform the US government, and initiate an investigation.

The EOS Network Foundation is then responsible for responding to the incident in compliance with United States and International law, informed by internal policy and any legal advice. Such a response might look like this.

  1. Escalate Cloudflare's report internally to relevant Engineers, Lawyers, and Executives.
  2. Determine whether the content identified by Cloudflare is CSAM, or a false-positive.
  3. Collect forensic information, potentially including but not limited to:
    • The offending content.
    • External access logs.
    • Internal access logs.
    • System logs.
    • Server images.
    • Specific software versions being used.
    • Current web architecture and relevant documentation.
    • Recent server backups.
  4. Encrypt the collected data using modern cipher suites, such as AES-256 and SHA-512, to protect the privacy and identity of victims.
  5. Store the encrypted copy of the collected data and the decryption key, separately, with a retention policy as required by law.
  6. Cooperate with the corresponding law enforcement investigation.

The EOS Network Foundation does not host adult content, nor do they currently host user-uploaded content as far as the author is aware. However, illegal content could still become present on our infrastructure in the event of a cybersecurity incident or similar.

@kj4ezj kj4ezj added Infrastructure Cloud or physical datacenter infrastructure automation labels Mar 26, 2024
@kj4ezj kj4ezj self-assigned this Mar 26, 2024
@kj4ezj kj4ezj moved this from Todo to In Progress in ENF Engineering Mar 26, 2024
@kj4ezj kj4ezj moved this from In Progress to Blocked in ENF Engineering Mar 26, 2024
@kj4ezj
Copy link
Contributor Author

kj4ezj commented Mar 26, 2024

I have requested CyberTipline API credentials from the National Center for Missing and Exploited Children via email.

@kj4ezj kj4ezj moved this from Blocked to In Progress in ENF Engineering Mar 27, 2024
@kj4ezj kj4ezj moved this from In Progress to Blocked in ENF Engineering Apr 10, 2024
@kj4ezj
Copy link
Contributor Author

kj4ezj commented Apr 10, 2024

This ticket is currently blocked, waiting on CyberTipline API credentials to be issued by the National Center for Missing and Exploited Children.

The NCMEC asked us to fill out a form about two weeks ago. I collected the necessary information from relevant stakeholders and submitted that form this afternoon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automation Infrastructure Cloud or physical datacenter infrastructure
Projects
Status: Blocked
Development

No branches or pull requests

1 participant