- Joined
- Nov 11, 2024
1. Reduce impact to regular users.
2. Increase response time
3. Decrease reliance on me.
4. Reversal of assymetrical nature of time spent (my time = valuable, his time = worthless).
5. Escalate law enforcement involvement until he is a non-factor.
It sounds like you've already sorted your next steps by now, but I'll reiterate the timestamp thing for probation.
ie. new accounts are text only. To gain the ability to post images, they are prompted to hand-write a timestamp (and timezone) on a piece of paper, take a picture of it, and sneed that picture to a mod - who correlates the timestamp with the submission's date and time within an arbitrary window, let's say ten minutes.
To spoof this, the attacker would have to pay an image gen service to generate passable handwriting for every minute of every hour of every day going forward, while trying for no telltale signs of AI Gen. If he continually uses his own handwriting, he is reduced to a manual process, and mods can learn to catch it on sight. He'd also have to get the correct time to line up with the location of his bot's proxy.
Since it's just one instance of numerals, the user is sacrificing little identifiable information. They can do it left-handed if they really want.
If exif data is preserved, it gives more data to organize a blockade around. (Timestamp must be within 10 minutes of exif timestamp. Batch AI generated images would fail this unless every image exif is modified and matched with the relevant timestamp. The same model of phone would come up each time, etc.)
(Additional complexity for suspicious accounts is also very simple. Mod can request a photo of the same paper be resubmitted as crumpled and wrinkled, torn into three pieces, list the DOW JONES price at that moment, etc. Very hard for an image gen to pull off without giving up the game.)
1. Reduce impact to regular users:
Regular people gladly photoshop a throwaway meme for a laugh. A timestamp is low effort and no cost for the user in exchange for a big prize - the right to post images. (I assume KF automatically scrubs exif on upload, however you would choose to deal with that.) I can't imagine anyone ragequitting over, say, a 24 hour waiting period for a mod to review the stamp - especially when they can still text-post.
2. Increase response time and 3. Decrease reliance on null:
The capacity to release CSAM from new accounts is immediately halted, while the approval process can happen at the moderator level with trivial effort on their part - a simple visual check. Maybe a 'is this picture real' AI check.
4. Reversing the asymmetric warfare:
The single attacker is reduced to a manual process, and is outnumbered by the moderation team.
The effort to produce a spoof is disproportionate to the effort to verify the image.
5. Escalation to law enforcement:
Consistent handwriting, (and/or exif data) paired with manual entry, increases the odds of mistakes on the attackers part and the gathering of actionable information that can be presented to the relevant agency.

