{"id":127124,"date":"2025-03-11T21:45:47","date_gmt":"2025-03-11T21:45:47","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/legal\/verizon-and-its-cloud-vendor-must-face-lawsuit-for-reporting-csam-that-wasnt-lawshe-v-verizon-guest-blog-post\/"},"modified":"2025-03-11T21:45:47","modified_gmt":"2025-03-11T21:45:47","slug":"verizon-and-its-cloud-vendor-must-face-lawsuit-for-reporting-csam-that-wasnt-lawshe-v-verizon-guest-blog-post","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=127124","title":{"rendered":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t &#8211; Lawshe v. Verizon (Guest Blog Post)"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span style=\"font-weight: 400;\">by guest blogger <\/span><a href=\"https:\/\/hai.stanford.edu\/people\/riana-pfefferkorn\"><span style=\"font-weight: 400;\">Riana Pfefferkorn<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">Child sex abuse material, or CSAM, is a longstanding scourge on the Internet. Like the baseball diamond in \u201cField of Dreams,\u201d if you build a service that allows file transmission or storage, someone will come use it for CSAM. Less distressing but equally true (if only marginally less dated a cultural reference) is that <\/span><a href=\"https:\/\/avenueq.fandom.com\/wiki\/The_Internet_Is_For_Porn\"><span style=\"font-weight: 400;\">the Internet is for porn<\/span><\/a><span style=\"font-weight: 400;\">. While online services inevitably get used for both types of content, service providers tend to treat them very differently, given that adult pornography is generally legal in the U.S. whereas CSAM is illegal everywhere.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What if a provider messes up and treats legal porn like it\u2019s illegal CSAM? That\u2019s the basis for a recent opinion from a Florida federal district court that could have major implications for online services\u2019 CSAM detection and reporting practices.<\/span><\/p>\n<p><b>Relevant Federal Law: Balancing User Privacy with Child Protection<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In the 1980s, Congress passed a law called the <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/part-I\/chapter-121\"><span style=\"font-weight: 400;\">Stored Communications Act<\/span><\/a><span style=\"font-weight: 400;\"> (SCA) that created a statutory right of privacy for Americans\u2019 digital files and communications. The SCA generally <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2702\"><span style=\"font-weight: 400;\">prohibits<\/span><\/a><span style=\"font-weight: 400;\"> the providers of online services from voluntarily disclosing the contents of communications, except in a few specified circumstances. Out-of-bounds disclosures expose the provider to <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2707\"><span style=\"font-weight: 400;\">civil suit<\/span><\/a><span style=\"font-weight: 400;\"> by the subscriber or other aggrieved person, though good-faith reliance on a statutory authorization is a complete defense.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One of the SCA\u2019s exceptions lets providers \u201cdivulge the contents of a communication \u2026 to the National Center for Missing and Exploited Children [NCMEC], in connection with a report submitted thereto under section 2258A\u201d of Title 18. <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2258A\"><span style=\"font-weight: 400;\">Section 2258A<\/span><\/a><span style=\"font-weight: 400;\">, in turn, requires providers, upon \u201cobtaining actual knowledge\u201d of \u201cany facts or circumstances from which there is an apparent violation of\u201d federal CSAM laws, to report that information to NCMEC\u2019s <\/span><a href=\"https:\/\/report.cybertip.org\/\"><span style=\"font-weight: 400;\">CyberTipline<\/span><\/a><span style=\"font-weight: 400;\">. Flouting this obligation risks massive fines.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Section 2258A is a reporting requirement, not a monitoring requirement: the statute clearly states that providers do not have to search their services for CSAM. Nevertheless, many choose to do so voluntarily, yielding nearly 36 million reports to the CyberTipline <\/span><a href=\"https:\/\/www.missingkids.org\/content\/dam\/missingkids\/pdfs\/2023-reports-by-esp.pdf\"><span style=\"font-weight: 400;\">in 2023 alone<\/span><\/a><span style=\"font-weight: 400;\">. NCMEC routes received reports to the appropriate law enforcement agency.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A related statute, <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2258B\"><span style=\"font-weight: 400;\">18 U.S.C. \u00a7 2258B<\/span><\/a><span style=\"font-weight: 400;\">, limits providers\u2019 liability for making reports to NCMEC. It says a provider may not be held liable for claims \u201carising from the performance of [its] reporting \u2026 responsibilities\u201d under section 2258A, unless there was \u201cintentional, reckless, or other misconduct\u201d by the provider, including acting \u201cwith actual malice.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This limitation of liability, coupled with the SCA\u2019s NCMEC-reporting exception and good-faith-reliance defense, addresses a dilemma providers would otherwise face upon discovering a user\u2019s CSAM: either report it as required by statute and risk getting sued by the user for violating the SCA, or ignore the reporting obligation and risk six- or seven-figure fines.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As discussed in <\/span><a href=\"https:\/\/cyber.fsi.stanford.edu\/news\/cybertipline-report\"><span style=\"font-weight: 400;\">a paper I co-authored last spring<\/span><\/a><span style=\"font-weight: 400;\">, this set-up created an incentive to \u201cover-report\u201d material that might not qualify as CSAM. Trusting they couldn\u2019t be held liable to the user, providers have long been able to err on the side of caution by reporting (leaving NCMEC and law enforcement to sort things out) rather than risk making the wrong call and paying the price. Now, however, a district court decision suggests that providers can no longer take it for granted that they won\u2019t face liability for reporting non-CSAM.<\/span><\/p>\n<p><b>The District Court\u2019s Opinion<\/b><\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/blog.ericgoldman.org\/wp-content\/uploads\/2025\/03\/ncmec.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-27489\" src=\"https:\/\/blog.ericgoldman.org\/wp-content\/uploads\/2025\/03\/ncmec-300x181.jpg\" alt=\"\" width=\"300\" height=\"181\" srcset=\"https:\/\/blog.ericgoldman.org\/wp-content\/uploads\/2025\/03\/ncmec-300x181.jpg 300w, https:\/\/blog.ericgoldman.org\/wp-content\/uploads\/2025\/03\/ncmec.jpg 675w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\"\/><\/a>Verizon\u2019s cloud storage service is provided by a vendor called Synchronoss. Verizon and Synchronoss monitor the cloud for CSAM using hash lists <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2258C\"><span style=\"font-weight: 400;\">supplied<\/span><\/a><span style=\"font-weight: 400;\"> by NCMEC (among other sources). Some list items include tags (also provided by NCMEC) describing the image category. Verizon and Synchronoss instantly report hash matches to NCMEC in CyberTips without human review or gathering any additional information about the images.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Plaintiff Lawshe was a Verizon customer who stored legal adult pornography in the cloud. Two images he stored got flagged as hash matches. One flagged image was tagged as \u201capparent\u201d CSAM, the other as \u201cunconfirmed\u201d CSAM. Synchronoss reported each image in a separate CyberTip to NCMEC.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The second CyberTip stated that Synchronoss \u201chad viewed the entire contents\u201d of the second image, which \u201ccontained the lascivious exhibition of a \u2018pre-pubescent\u2019 minor.\u201d In fact, Lawshe alleges, those statements were false, and the individuals in both images \u201cwere easily identifiable as adults by the barest of review.\u201d Nevertheless, Lawshe was investigated and arrested on the basis of the second CyberTip. (It\u2019s not mentioned here, but he later <\/span><a href=\"https:\/\/scholar.google.com\/scholar_case?case=2753575473138973927\"><span style=\"font-weight: 400;\">got the charges dropped<\/span><\/a><span style=\"font-weight: 400;\"> and filed a civil-rights lawsuit against multiple government officials.)\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Lawshe sued Verizon and Synchronoss for defaming him and violating his privacy rights under the SCA. The defendants moved to dismiss, asserting that they were obligated to report both images to NCMEC under section 2258A, that section 2258B immunized them for both reports, that the disclosures to NCMEC fell within the SCA\u2019s exception for NCMEC reporting, and that their good-faith reliance on these statutory authorities is a defense against SCA liability.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The court sides with the defendants as to the first CyberTip but not the second. In short, the court holds that the \u201capparent CSAM\u201d tag for the first image\u2019s hash match was enough to trigger the defendants\u2019 reporting obligations and shield them from liability, but the \u201cunconfirmed CSAM\u201d tag for the second image was not. Plus, the good-faith-reliance defense doesn\u2019t appear on the face of the complaint so it isn\u2019t available at this early stage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The opinion dwells heavily on the various statutory provisions I quoted above. The court is irked that Congress used the term \u201capparent violation\u201d without defining \u201capparent,\u201d but concludes that \u201ca hash match to \u2018apparent CSAM\u2019\u201d constituted \u201cfacts or circumstances from which there is an apparent violation\u201d of federal CSAM law, thus obligating the defendants to report the first image to NCMEC, as allowed by the relevant SCA exception and immunized by section 2258B.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But as to the second image, the court says NCMEC\u2019s \u201cunconfirmed CSAM\u201d tag revealed only that someone at NCMEC at some point had somehow decided that image \u201ccould not be determined to be CSAM (presumably because the person reviewing the image could not tell if the individual depicted was a minor).\u201d That\u2019s not enough to persuade the court that \u201cknowledge of an \u2018unconfirmed\u2019 CSAM tag match is \u2018knowledge of the facts or circumstances from which there is an apparent violation\u2019 of CSAM laws\u201d sufficient to trigger the reporting obligation.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Since the second CyberTip wasn\u2019t obligatory, it was voluntary \u2013 which severs its link to section 2258A. That means the disclosure to NCMEC wasn\u2019t made \u201cin connection with a report submitted [to NCMEC] under section 2258A\u201d as required to fall within the relevant exception to the SCA\u2019s general rule forbidding voluntary disclosures of users\u2019 private files. It also means the defendants can\u2019t claim section 2258B\u2019s immunity against claims \u201carising from the performance of [their] reporting responsibilities\u201d under section 2258A, because there was no such responsibility as to that image given how little they knew about it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In response to the defendants\u2019 argument \u201cthat requiring additional investigation into images tagged as \u2018unconfirmed\u2019 CSAM would chill providers\u2019 content moderation and undermine Congressional intent,\u201d the court responds only that \u201ca review of \u00a7 2258A caselaw reveals that image-by-image human review is not uncommon,\u201d though it acknowledges that some providers automate reports and that \u201cminimizing the number of people who view CSAM is a paramount concern.\u201d Nevertheless, with age-difficult images, \u201csome level of further investigation is appropriate before a provider is shielded from liability for reporting its customer\u2019s private information to the government.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The court denies that its decision will destroy the immunity Congress gave providers. Congress, it says, intended to immunize only mistaken or incorrect reports, not <\/span><i><span style=\"font-weight: 400;\">unfounded <\/span><\/i><span style=\"font-weight: 400;\">reports \u2013 like the second CyberTip, where Synchronoss (which allegedly automates all of its tips) supposedly didn\u2019t review the reported image despite representing that it had. That, says the court, is enough to plausibly allege actual malice, which makes the second report ineligible for 2258B immunity even if it arguably was obligatory.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The defamation and SCA claims for the second CyberTip go forward as to each defendant. The next stage of the litigation will likely involve (expensive, time-consuming) fact discovery into the circumstances surrounding the second CyberTipline report.<\/span><\/p>\n<p><b>Implications<\/b><\/p>\n<p><span style=\"font-weight: 400;\">To sum up: Mistaken or incorrect reports to NCMEC get immunity, but unfounded reports do not. Consequently, human review of flagged files is preferable from a risk management standpoint, whereas automated reporting is risky. For the many providers who use NCMEC\u2019s hash lists and tags as part of their voluntary CSAM detection efforts, automated reports are OK if based on some tags but not others. It\u2019s safe to rely on NCMEC\u2019s \u201capparent CSAM\u201d tag (and probably also \u201cknown\u201d CSAM), but the \u201cunconfirmed CSAM\u201d tag should trigger further investigation.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What other tags does NCMEC use, and which bucket does each one fall into: safe or unsafe? If using NCMEC\u2019s tags turns immunity from liability into Russian roulette, what good are they, and what good is <\/span><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2258C\"><span style=\"font-weight: 400;\">the law<\/span><\/a><span style=\"font-weight: 400;\"> letting NCMEC share them with providers?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This case illustrates Eric\u2019s <\/span><a href=\"https:\/\/blog.ericgoldman.org\/archives\/2024\/07\/google-can-terminate-account-based-on-csam-allegations-baker-v-google.htm\"><span style=\"font-weight: 400;\">observation<\/span><\/a><span style=\"font-weight: 400;\"> that \u201cdetermining if a content item is CSAM isn\u2019t always a zero or one. The border cases leave [a provider] caught between its legal obligations to remove and report what might be CSAM and a user\u2019s view that the CSAM characterization was overly cautious,\u201d where \u201ceach choice creates legal peril\u201d for the provider.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That said, it\u2019s been surprisingly rare for users to sue service providers for reporting them for CSAM. A Google Scholar search for \u201c2258B\u201d turns up just two prior lawsuits (both fruitless) against <\/span><a href=\"https:\/\/scholar.google.com\/scholar_case?case=8638991907433021854\"><span style=\"font-weight: 400;\">AT&amp;T<\/span><\/a><span style=\"font-weight: 400;\"> in 2013 and <\/span><a href=\"https:\/\/scholar.google.com\/scholar_case?case=11646638613218098779\"><span style=\"font-weight: 400;\">Meta and Yahoo<\/span><\/a><span style=\"font-weight: 400;\"> in 2020. And Eric has blogged a <\/span><a href=\"https:\/\/blog.ericgoldman.org\/archives\/2024\/07\/google-can-terminate-account-based-on-csam-allegations-baker-v-google.htm\"><span style=\"font-weight: 400;\">couple<\/span><\/a> <a href=\"https:\/\/blog.ericgoldman.org\/archives\/2023\/04\/service-can-terminate-user-for-allegedly-possessing-csam-but-what-if-the-service-made-a-mistake-deutsch-v-microsoft.htm\"><span style=\"font-weight: 400;\">other<\/span><\/a><span style=\"font-weight: 400;\"> failed cases where the gravamen of the complaint was account termination and content removal, not reporting.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This paucity of litigation is remarkable considering the high volume of CyberTips. Maybe Lawshe has opened the door to more \u2013 but probably only for reporting content that ultimately wasn\u2019t deemed CSAM. Lawshe\u2019s reported images depicted adults, unlike the users whose unsuccessful <\/span><a href=\"https:\/\/scholar.google.com\/scholar_case?case=11936832846139090207\"><span style=\"font-weight: 400;\">AT&amp;T<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/scholar.google.com\/scholar_case?case=4785745253990069247\"><span style=\"font-weight: 400;\">Meta\/Yahoo<\/span><\/a><span style=\"font-weight: 400;\"> suits feel a bit like sour grapes over their criminal convictions.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If providers can no longer count on ironclad immunity for filing underbaked CyberTips, that has both pros and cons.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On the plus side, many parties and interests will benefit if providers send less chaff to the CyberTipline. As <\/span><a href=\"https:\/\/cyber.fsi.stanford.edu\/news\/cybertipline-report\"><span style=\"font-weight: 400;\">my prior research<\/span><\/a><span style=\"font-weight: 400;\"> notes, a \u201ckick the can down the road\u201d approach diverts NCMEC and law enforcement time and resources from real kids in real danger. Meanwhile, being baselessly reported for CSAM can <\/span><a href=\"https:\/\/www.nytimes.com\/2023\/11\/27\/technology\/google-youtube-abuse-mistake.html\"><span style=\"font-weight: 400;\">ruin<\/span><\/a><span style=\"font-weight: 400;\"> people\u2019s <\/span><a href=\"https:\/\/www.nytimes.com\/2022\/08\/21\/technology\/google-surveillance-toddler-photo.html\"><span style=\"font-weight: 400;\">lives<\/span><\/a><span style=\"font-weight: 400;\">. As Lawshe experienced firsthand (and as those linked stories detail in depth), these \u201cfalse positives\u201d cost the provider nothing but cost the user dearly, jeopardizing their families and jobs and subjecting them to intrusive police investigations. The default rule of the SCA is to protect people\u2019s digital privacy, and this court is sympathetic to the idea that its exceptions should not be allowed to stretch so far that they swallow the rule. Providers currently externalize the costs of over-reporting without consequence, and the court is saying maybe that situation is due for a correction. (It\u2019s a little reminiscent of the quest to make <\/span><a href=\"https:\/\/blog.ericgoldman.org\/archives\/2024\/05\/plaintiffs-make-some-progress-in-512f-cases.htm\"><span style=\"font-weight: 400;\">DMCA \u00a7 512(f)<\/span><\/a><span style=\"font-weight: 400;\"> mean something. But the desire to shrink the SCA is evocative of a California <\/span><a href=\"https:\/\/www.lawfaremedia.org\/article\/privacy-protections-of-the-stored-communications-act-gutted-by-california-court\"><span style=\"font-weight: 400;\">appellate court decision<\/span><\/a><span style=\"font-weight: 400;\"> that would destroy digital privacy if upheld, as Eric and I recently <\/span><a href=\"https:\/\/cyberlaw.stanford.edu\/blog\/2025\/02\/privacy-law-amicus-brief-to-california-supreme-court\/\"><span style=\"font-weight: 400;\">told the California Supreme Court<\/span><\/a><span style=\"font-weight: 400;\">.)\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That said, I\u2019m not sure the court understands what \u201cadditional investigation\u201d to reduce the incidence of \u201cunfounded\u201d reports would entail in practice. The court\u2019s blas\u00e9 statement that \u201cimage-by-image human review is not uncommon\u201d ignores the sheer scale of content uploaded to the Internet every single day. Even small providers depend on automation to fight CSAM: hash matches; ML tools for detection, triage, and victim identification; automated reporting flows like that allegedly employed by Synchronoss. The court says hash matches for \u201cknown\u201d or \u201capparent\u201d CSAM are reliable \u2013 but does that mean any and all other tags demand more scrutiny? The court doesn\u2019t say.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Plus, the court ignores a <\/span><a href=\"https:\/\/harvardlawreview.org\/print\/vol-135\/united-states-v-wilson\/\"><span style=\"font-weight: 400;\">circuit split<\/span><\/a><span style=\"font-weight: 400;\"> that arose from precisely the question of hashing systems\u2019 reliability. In courts on the other side of that split, this court\u2019s rationale would mean providers couldn\u2019t automatically report even matches to \u201cknown\u201d and \u201capparent\u201d CSAM. <\/span><i><span style=\"font-weight: 400;\">Every <\/span><\/i><span style=\"font-weight: 400;\">flagged image would require human review in order to preserve immunity against allegations of \u201cunfounded\u201d reporting. Even Meta, which submitted 85% of all 2023 reports, would struggle (as it would require an army of additional moderators), while smaller platforms (without budget for more people) might quickly be swamped.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Not only would that introduce huge delays to a system that\u2019s already <\/span><a href=\"https:\/\/cyber.fsi.stanford.edu\/news\/cybertipline-report\"><span style=\"font-weight: 400;\">under strain<\/span><\/a><span style=\"font-weight: 400;\">, it would come with a major human cost. Human review of suspected CSAM has a mental-health impact on the reviewer for true positives. (Fix \u201cunfounded\u201d reports with this one weird trick: traumatizing low-paid contractors in the Global South!) That\u2019s another \u201cdamned if you do, damned if you don\u2019t\u201d: providers are <\/span><a href=\"https:\/\/www.impactfund.org\/social-justice-blog\/scola-v-facebook\"><span style=\"font-weight: 400;\">getting<\/span><\/a> <a href=\"https:\/\/www.codastory.com\/authoritarian-tech\/reddit-content-moderation-lawsuit\/\"><span style=\"font-weight: 400;\">sued<\/span><\/a><span style=\"font-weight: 400;\"> by content reviewers for the trauma they suffer from doing this work, meaning there\u2019s potential legal liability with or without human review. Even with false positives, there\u2019s some privacy intrusion to the user whose private files get reviewed by moderators, albeit less than that of disclosure to the government. Automation may have falsely ensnared Lawshe, but it plays a crucial role in keeping CSAM off the Internet.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What\u2019s more, human review isn\u2019t a cure-all. As <\/span><a href=\"https:\/\/www.techdirt.com\/2019\/11\/20\/masnicks-impossibility-theorem-content-moderation-scale-is-impossible-to-do-well\/\"><span style=\"font-weight: 400;\">Masnick\u2019s Impossibility Theorem<\/span><\/a><span style=\"font-weight: 400;\"> goes, \u201ccontent moderation at scale is impossible to do well.\u201d At high volume, \u201cedge\u201d cases come up all the time. With age-difficult content, someone has to make that judgment call, perhaps multiple times a day, without a lot of information. Tools for age detection still require human oversight, and they <\/span><a href=\"https:\/\/home.crin.org\/readlistenwatch\/stories\/explainer-detection-technologies-child-sexual-abuse-online\"><span style=\"font-weight: 400;\">struggle<\/span><\/a><span style=\"font-weight: 400;\"> with age determinations around the cutoff. As the court observes, not even NCMEC can reliably tell if an image depicts an adult or a minor. Mistakes happen, and no matter what call gets made, someone will be unhappy with it. For example, Meta went through a negative press cycle in 2022 for reportedly training moderators to <\/span><a href=\"https:\/\/www.nytimes.com\/2022\/03\/31\/business\/meta-child-sexual-abuse.html\"><span style=\"font-weight: 400;\">\u201cerr on the side of an adult\u201d<\/span><\/a><span style=\"font-weight: 400;\"> with age-difficult content \u2013 just what Lawshe wanted here. (It\u2019s not clear to me how Synchronoss reviewing his images would have helped: if it was so obvious that they depicted adults like he claims, how come he got arrested?) But failure to report false negatives (i.e., true CSAM) can mean <\/span><a href=\"https:\/\/blog.ericgoldman.org\/archives\/2023\/12\/twitter-defeats-fosta-case-over-csam-doe-v-twitter.htm\"><span style=\"font-weight: 400;\">messy, expensive FOSTA lawsuits<\/span><\/a><span style=\"font-weight: 400;\">. Yet again, you\u2019re damned if you do, damned if you don\u2019t. Protecting the exercise of discretion, in recognition that batting 1.000 is impossible, is precisely why immunity is so important.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The big question this opinion leaves hanging in the air is, where\u2019s the line between \u201cmistaken\u201d or \u201cincorrect\u201d CyberTipline reports (which it says get immunity) and \u201cunfounded\u201d ones made without actual knowledge of an apparent violation (which don\u2019t)? If the rule is \u201cimmunity for mistaken reports but not unfounded reports,\u201d that just tells plaintiffs how to phrase their complaints when they file lawsuits almost nobody bothered to file before now. In a world with tens of millions of CyberTipline reports per year (of which some unknown number aren\u2019t actually CSAM), it\u2019s not feasible to open the courthouse doors to case-by-case litigation over the sufficiency of any given provider\u2019s actions in submitting a specific report. The court criticizes the domain of CSAM detection as \u201clargely unregulated,\u201d but immunity <\/span><i><span style=\"font-weight: 400;\">is <\/span><\/i><span style=\"font-weight: 400;\">a form of regulation. And immunity doesn\u2019t mean much if it\u2019s not robust.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">At the extreme, the court\u2019s decision could wind up facilitating more CSAM distribution: if courts start routinely letting users second-guess providers\u2019 CSAM reporting practices, why should providers keep looking for CSAM at all? They don\u2019t have to, as the court notes. (<\/span><a href=\"https:\/\/www.judiciary.senate.gov\/committee-activity\/hearings\/ending-the-scourge-the-need-for-the-stop-csam-act\"><span style=\"font-weight: 400;\">Later today<\/span><\/a><span style=\"font-weight: 400;\">, though, we can expect Congress to discuss <\/span><a href=\"https:\/\/www.lawfaremedia.org\/article\/online-service-providers-and-fight-against-child-exploitation-fourth-amendment-agency-dilemma\"><span style=\"font-weight: 400;\">unconstitutionally<\/span><\/a><span style=\"font-weight: 400;\"> making them look.) Not looking means finding less to report, which means fewer lawsuit opportunities. Of course, that would throw the baby (accurate CSAM detection and reporting) out with the bathwater (inaccurate reports like Lawshe\u2019s). But <\/span><a href=\"https:\/\/www.404media.co\/behind-the-blog-stunt-blogging-and-the-fuck-it-paradigm\/\"><span style=\"font-weight: 400;\">with content moderation in its \u201cfuck it\u201d era<\/span><\/a><span style=\"font-weight: 400;\">, it\u2019s not unthinkable. These days nothing is.\u00a0\u00a0<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Case citation: <\/span><\/i><a href=\"https:\/\/cases.justia.com\/federal\/district-courts\/florida\/flmdce\/3:2024cv00137\/423839\/45\/0.pdf?ts=1740826484\"><span style=\"font-weight: 400;\">Lawshe v. Verizon Commc\u2019ns, Inc., et al.<\/span><\/a><span style=\"font-weight: 400;\">, 2025 WL 660778 (M.D. Fla. Feb. 28, 2025). (The <\/span><a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.flmd.423839\/gov.uscourts.flmd.423839.39.0.pdf\"><span style=\"font-weight: 400;\">operative complaint<\/span><\/a><span style=\"font-weight: 400;\">.)<\/span><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>by guest blogger Riana Pfefferkorn Child sex abuse material, or CSAM, is a longstanding scourge on the Internet. Like the baseball diamond in \u201cField of Dreams,\u201d if you build a service that allows file transmission or storage, someone will come use it for CSAM. Less distressing but equally true (if only marginally less dated a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":127125,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97],"tags":[3767,12564,43722,844,4251,55552,13236,2649,13609,16444,11716,16962],"dealstore":[],"offerexpiration":[],"class_list":["post-127124","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-legal","tag-blog","tag-cloud","tag-csam","tag-face","tag-guest","tag-lawshe","tag-lawsuit","tag-post","tag-reporting","tag-vendor","tag-verizon","tag-wasnt"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=127124\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"by guest blogger Riana Pfefferkorn Child sex abuse material, or CSAM, is a longstanding scourge on the Internet. Like the baseball diamond in \u201cField of Dreams,\u201d if you build a service that allows file transmission or storage, someone will come use it for CSAM. Less distressing but equally true (if only marginally less dated a [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=127124\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-11T21:45:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"675\" \/>\n\t<meta property=\"og:image:height\" content=\"408\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=127124#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t &#8211; Lawshe v. Verizon (Guest Blog Post)\",\"datePublished\":\"2025-03-11T21:45:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124\"},\"wordCount\":2751,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg\",\"keywords\":[\"Blog\",\"Cloud\",\"CSAM\",\"Face\",\"Guest\",\"Lawshe\",\"Lawsuit\",\"Post\",\"Reporting\",\"Vendor\",\"Verizon\",\"wasnt\"],\"articleSection\":[\"Legal\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=127124#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=127124\",\"url\":\"https:\/\/fivemor.com\/?p=127124\",\"name\":\"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg\",\"datePublished\":\"2025-03-11T21:45:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=127124#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=127124\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=127124#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg\",\"width\":675,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=127124#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t &#8211; Lawshe v. Verizon (Guest Blog Post)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=127124","og_locale":"en_US","og_type":"article","og_title":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network","og_description":"by guest blogger Riana Pfefferkorn Child sex abuse material, or CSAM, is a longstanding scourge on the Internet. Like the baseball diamond in \u201cField of Dreams,\u201d if you build a service that allows file transmission or storage, someone will come use it for CSAM. Less distressing but equally true (if only marginally less dated a [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=127124","og_site_name":"Som2ny Network","article_published_time":"2025-03-11T21:45:47+00:00","og_image":[{"width":675,"height":408,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=127124#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=127124"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t &#8211; Lawshe v. Verizon (Guest Blog Post)","datePublished":"2025-03-11T21:45:47+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=127124"},"wordCount":2751,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=127124#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg","keywords":["Blog","Cloud","CSAM","Face","Guest","Lawshe","Lawsuit","Post","Reporting","Vendor","Verizon","wasnt"],"articleSection":["Legal"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=127124#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=127124","url":"https:\/\/fivemor.com\/?p=127124","name":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t - Lawshe v. Verizon (Guest Blog Post) - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=127124#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=127124#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg","datePublished":"2025-03-11T21:45:47+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=127124#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=127124"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=127124#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/ncmec.jpg","width":675,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=127124#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting \u201cCSAM\u201d That Wasn\u2019t &#8211; Lawshe v. Verizon (Guest Blog Post)"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/127124","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=127124"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/127124\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/127125"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=127124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=127124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=127124"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=127124"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=127124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}