People appear to be writing Tumblr blog posts and backdating them to use as evidence for Google DCMA takedowns.
Yes exactly as you said, scammers doing visa scams and such are copying articles that criticise them, backdate them on tumblr, then use DCMA to take them down, then delete the tumblr post.
2: Why does Google not have a mitigation/validation strategy in place? They surely know Tumblr timestamps cannot be trusted.
This is the type of obvious gaping vulnerability I expect to see in a personal side project, not on two of largest tech platforms.
btw on the social media side of Tumblr (dashboard feed of followed blogs), the user-editable post date is ignored, so it cannot be used for manipulating the dashboard sort order.
Maybe the article is more intelligible to whomever knows how to skim whatever style it is. Or maybe it's LLM-generated and accessible to no one.
1) A blogger publishes an article warning about scammer/fraudster/terrorist known as person Person X. They publish on January 1 2024.
2) Person X wants to get this info out of the Google results.
3) Person X goes to one one of these reputation management companies. They copy verbatim the article and post it to Tumblr. Tumblr has a feature to back-date posts so they back-date their post to December 1 2023. This makes it appear like the content appeared before the blogger published their article.
4) The reputation management company then sends a DCMA takedown notice to Google with the Tumblr post as evidence that the blogger is infringing on their content. Google does their DCMA thing and de-indexes the blog post.
The blog poster's remedy is to appeal the takedown at which point Google would then re-list their post...at which point this process starts over again?
Stuff like this is incredibly frustrating. It's so simple yet effective because of how the DCMA compliance process is implemented.
I guess it is a risk for longstanding hosted services.
This might sound wacky, but the more pervasive AI becomes the more important it will become to link any significant requests to real humans. That might be legal requests, but it will also include financial services, etc.
Remember during the resolution of the mortgage fraud / title insurance issue in the US people were coming forward and being videoed in depositions saying 'I was hired at this bank, my job was to sign forms, I had no idea what or why I was signing, I was just told these forms required a human signature, I signed thousands per week.'
Unfortunately it seems the legal system has already baked in a 'yes, a person signed, but they were too stupid to recognise what they were doing wasn't legal because they worked at a big company and assumed it must have been okay.'
I don't really know how you work around that sort of institutional acceptance of what must be some type of fraud.
The 'system' doesn't really when people seem to have decided 'well, if we break enough laws on a large enough scale there's nothing they can really do.'
I can see it being useful for for re-hosted content like usenet posts, but as far as I could tell it's more commonly used as some sort of SEO meta.
Might be a nice bit of side income for people who are in an already pretty shady industry, take a payment to insert a percent or two in their otherwise legitimate reports.