"Did They F***ing Consent to That?": Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual Abuse
Lucy Qin, Vaughn Hamilton, Sharon Wang, Yigit Aydinalp, Marin Scarlett, Elissa M. Redmiles
33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24
Overview
This compelling talk, "Did They Fing Consent to That?: Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual Abuse," presented by Lucy Qin and her co-authors, addresses the pervasive and devastating issue of non-consensual distribution of intimate imagery (NDII), often referred to as image-based sexual abuse (IBSA). The research delves into the practices, strategies, and challenges faced by individuals who share intimate content digitally, highlighting the urgent need for more robust and user-centric technological protections. The speakers argue that current societal norms, coupled with a significant lack of effective technological mitigations, place individuals at undue risk, shifting the burden of prevention onto victims.

Key moments
- 0:00 Introduction: Prevalence and impact of Non-Consensual Intimate Imagery
- 1:08 Research focus: proactive mitigation strategies against NDI
- 2:00 Intimate content shared across diverse settings and 40+ platforms
- 3:30 Participant fears: re-sharing, data breaches, platform misuse
- 4:30 Technological and interpersonal strategies against re-sharing
- 5:50 Key proactive strategy: avoiding identifying information in content
- 6:40 Assessment of platform features and patchy coverage for safety
"Did They F***ing Consent to That?": Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual Abuse
Speakers: Lucy Qin, Graduate Student Researcher, UC Berkeley; Vaughn Hamilton, Graduate Student Researcher, UC Berkeley; Sharon Wang, Graduate Student Researcher, UC Berkeley; Yigit Aydinalp, Graduate Student Researcher, UC Berkeley; Marin Scarlett, Undergraduate Student Researcher, UC Berkeley; Elissa M. Redmiles, Assistant Professor, Princeton University
Conference: USENIX Security '24
YouTube: https://www.youtube.com/watch?v=7gbnG_OYOHg
Overview
This compelling talk, "Did They F*ing Consent to That?: Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual Abuse," presented by Lucy Qin and her co-authors, addresses the pervasive and devastating issue of non-consensual distribution of intimate imagery (NDII)**, often referred to as image-based sexual abuse (IBSA). The research delves into the practices, strategies, and challenges faced by individuals who share intimate content digitally, highlighting the urgent need for more robust and user-centric technological protections. The speakers argue that current societal norms, coupled with a significant lack of effective technological mitigations, place individuals at undue risk, shifting the burden of prevention onto victims.
The core of the presentation lies in its investigation of how people proactively attempt to protect themselves against NDII, examining their use cases, the technologies they employ, their perceived threat models, and their defensive strategies. Through a comprehensive qualitative study, the researchers uncover critical gaps in existing platform functionalities and propose a series of design recommendations aimed at reallocating responsibility from individuals to technology platforms. This talk matters because it not only sheds light on a widespread form of sexual abuse but also offers actionable insights for technologists and platforms to foster safer digital spaces for intimate expression, fundamentally challenging the victim-blaming culture often associated with NDII.
Background
▶ Watch: Introduction: Prevalence and impact of Non-Consensual Intimate Imagery (0:00)
Sharing intimate content, defined as images or videos depicting a nude or semi-nude subject, containing intimate body parts, or intending to arouse, is a remarkably common practice. Psychology research estimates suggest that as many as 8 in 10 adults in the U.S. engage in this activity. Despite its prevalence, the non-consensual distribution of this content is a severe form of sexual abuse with profound impacts. A 2022 White House study revealed that one in six adults have experienced their intimate content being distributed without their consent. The consequences extend beyond immediate privacy violations, encompassing significant mental health repercussions akin to other forms of sexual abuse, and an increased risk of doxing and other forms of online hate and harassment.
The research presented in this talk focused on understanding and improving proactive mitigation strategies against NDII. The team interviewed 52 adults across European countries who share intimate content; notably, 28 shared for recreational purposes, 24 for commercial purposes, and 22 participants were victim-survivors of NDII. This diverse participant pool provided a rich understanding of the varied contexts and motivations behind sharing. Participants shared intimate content across a multitude of settings, including with strangers (e.g., in body positivity groups on social media), within new and established romantic relationships, and on commercial platforms. The structures of sharing were equally diverse, ranging from one-to-one exchanges to sharing the same image with multiple individuals or groups. This breadth underscores a critical finding: any platform capable of creating, sharing, or storing visual content is likely being used for intimate content. Participants reported using over 40 different platforms, including popular messaging apps like Telegram, Signal, WhatsApp, and Kick, as well as file-sharing services like Dropbox for larger files.
A significant background concern for participants, even those who trusted their direct recipients, was the passive and background fear that their content would be re-shared without consent. This concern is amplified by the pervasive stigma and victim-blaming associated with sharing intimate content. Beyond direct recipients, participants also worried about accidental sharing, data breaches, or images being compromised through other means, including the unsettling concern that platform employees might purposefully access their intimate content stored on company servers. These multifaceted threat models highlight the complex security landscape individuals navigate when engaging in digital intimacy.
Key Findings
▶ Watch: Intimate content shared across diverse settings and 40+ platforms (2:00)
The study revealed a complex interplay of technological and interpersonal strategies employed by individuals to protect their intimate content. Participants frequently combined in-app safety features with explicit communication and personal vetting to manage risks.
When defending against recipient re-sharing, participants adopted strategies across different stages of the sharing process:
- Before sharing: Many established explicit rules with recipients, such as "please don't screenshot anything I share with you." For less established relationships, they engaged in vetting mechanisms to build trust.
- While sharing: Participants leveraged in-app features like expiring messages, which disappear after a preset time, or screenshot notifications, which alert the sender if the recipient captures the screen.
- After sharing: Strategies included asking recipients to delete content or utilizing message unsend features to remove content from message histories.
A major concern was defending against identification if content were to be non-consensually shared. Over 50% of participants proactively avoided capturing identifying information in the first place. This involved intensive efforts such as covering tattoos, ensuring their face was not visible, or meticulously choosing neutral backgrounds. One participant noted being "very cognizant of the items in their background and the language that was on for example a shampoo bottle" as such details could reveal their country in a European context. Participants also used metadata removal tools to strip additional identifying information from images.
The researchers conducted a landscape analysis of popular platforms to assess the availability of these protective features. The findings revealed a patchy coverage of features, with many either unavailable, requiring payment, or necessitating repurposing existing features for unintended functionality. Even when features existed (e.g., Instagram's Vanish Mode), they often lacked customization options and were limited to specific modes, rather than being universally applicable or granularly controllable.
Crucially, the study highlighted the immense difficulty and time commitment involved in implementing these protective strategies. As one participant (P33) lamented, "I spend more time scrubbing personal info off my pictures putting them in private folders than actually taking set pictures." The learning curve for effective self-protection is steep, and participants were acutely aware of the limitations of existing technical defenses, knowing that, for example, screenshot notifications could be bypassed by simply taking a photo with a secondary device. Consequently, participants viewed these strategies not as a means of complete prevention, but as a form of harm reduction, with the ultimate goal being to "create friction" to slow the spread of NDII. The underlying philosophy was that while complete prevention might be impossible, a minimum level of safety could deter most malicious actors.
Technical Deep Dive
▶ Watch: Participant fears: re-sharing, data breaches, platform misuse (3:30)
The technical implications of this research primarily revolve around the design and implementation of platform features to better support proactive protection against NDII. The current technological landscape, as revealed by the study, is inadequate, forcing users into laborious and often ineffective self-defense.
Participants overwhelmingly expressed a desire for a full suite of safety features within their default messaging applications, which are their primary channels for sharing intimate content. The landscape analysis showed that while some features exist (e.g., expiring messages, screenshot notifications), their availability is inconsistent across platforms, often hidden, or requires specific modes (like Instagram's Vanish Mode) that are not universally applied or easily discoverable. This indicates a fundamental design flaw: intimate content is not treated as a first-class use case requiring dedicated, robust protection mechanisms.
The researchers' recommendations for platforms include:
- Increased Availability and Visibility: Safety features should be widely available across all relevant platforms and prominently displayed, rather than being obscure or requiring users to "dig" for them.
- Granular Control and Customization: Users need the ability to customize features to reflect the dynamic nature of trust and relationships. This includes applying protections like expiration or password protection to single messages, rather than just entire conversations or modes. The current lack of granularity means users often have to apply blanket protections that don't fit specific contexts, or forgo protection entirely.
- Preset Modes: To mitigate the burden of constantly adjusting settings, platforms should offer preset modes that users can select and modify, tailoring configurations for different trust levels or sharing scenarios.
- Technological Support for Manual Strategies: Participants spend considerable time manually removing identifying features. Platforms should integrate built-in editing tools—such as automated blurring of faces or tattoos, or one-click metadata removal—to streamline these time-consuming processes. This shifts a significant manual burden onto automated systems.
Beyond current feature deficiencies, the research also identified crucial directions for future research and technical development, particularly concerning the limitations and potential negative externalities of existing and proposed protections:
- Bypass Likelihood and Incentive Structures: While screenshot notifications are a technical defense, they are easily bypassed by a secondary device. More concerning is the hypothesis that some safety features, like expiring messages, might paradoxically incentivize harmful behavior. By creating an aura of "secrecy," these features might provoke recipients to attempt to "hold on to it" through unauthorized means. Further research is needed to quantify this likelihood and understand its contextual triggers.
- Identifying Non-Consensual Sharing: Participants expressed a strong desire for technologies to detect NDII once it has occurred. While hash-based solutions (comparing image hashes to identify duplicates) exist, they presented a mixed bag of interest and skepticism. Concerns included the storage of hashes (and potential for reconstruction attacks if not properly implemented), and the high potential for false positives. A false positive notification of NDII can be highly distressing, highlighting the need for extremely high accuracy and careful user experience design for such sensitive alerts.
- Balancing Content Control and Harm Documentation: A significant technical and ethical tension arises with disappearing messages. While features like expiring messages and unsending offer critical content control and proactive protection, they directly conflict with the need for harm documentation in the event of NDII. For legal action, records of the sender, recipient, and message content are often necessary. New design ideas are urgently needed to resolve this tension, perhaps through encrypted, time-limited, verifiable logs accessible only under specific, legally sanctioned circumstances, or by offering users the choice to retain records for legal purposes.
The overarching technical message is that platforms must move beyond reactive measures and integrate proactive, user-centric, and context-aware security features from the ground up, acknowledging the unique sensitivities and risks associated with intimate digital content.
Demo / Proof of Concept
▶ Watch: Key proactive strategy: avoiding identifying information in content (5:50)
While the talk did not feature a live technical demonstration of a new tool or exploit, the researchers presented wireframes and discussed personas as conceptual proof-of-concept design ideas based on their research findings. These wireframes illustrate how the proposed features could be integrated into existing messaging applications. For instance, they might depict user interfaces offering granular controls to apply expiration timers or password protection to individual messages, or a "preset mode" selector for different sharing contexts. The personas, reflecting the diverse user needs identified, serve to ground these design concepts in real-world scenarios, demonstrating how different individuals with varying trust levels and sharing habits would benefit from the proposed functionalities. This approach highlights the study's focus on user-centered design principles and practical recommendations for platform developers.
Defensive Implications
▶ Watch: Assessment of platform features and patchy coverage for safety (6:40)
The research presented has profound defensive implications, both for individuals sharing intimate content and for the platforms that host such interactions.
For Individuals:
- Acknowledge Limitations: Individuals must understand that current technological safeguards are often incomplete and can be bypassed. For instance, screenshot notifications can be circumvented by using a secondary device to photograph the screen. This knowledge fosters a more realistic threat model.
- Prioritize Proactive Identification Defense: Given the challenges of preventing re-sharing, individuals should continue to prioritize strategies that hinder identification. This includes meticulously avoiding capturing identifying features (faces, tattoos, unique backgrounds) and consistently using metadata removal tools before sharing.
- Explicit Communication: Interpersonal strategies remain crucial. Clearly setting explicit rules with recipients regarding content usage (e.g., "do not screenshot, do not re-share") can act as a deterrent and establish boundaries.
- Harm Reduction Mindset: Individuals should view their protective actions as a form of harm reduction rather than absolute prevention. The goal is to create "friction" to slow the spread of NDII, recognizing that complete prevention may not always be achievable with current tools.
For Platforms and Technologists:
- Reallocate Responsibility: The most critical defensive implication is the call to reallocate responsibility for preventing NDII from individuals to platforms. This means designing for intimate content as a core use case from the outset, rather than an afterthought.
- Comprehensive Feature Suites: Platforms must develop and integrate a full suite of safety features that are highly visible, easily accessible, and customizable. These should include robust expiring messages, reliable screenshot notifications (with mitigation for bypasses), and sophisticated unsend capabilities.
- Granular Control: Implement features that allow users granular control over their content, such as applying specific protections (e.g., expiration, password protection) to individual messages or media within a conversation.
- Integrated Editing Tools: Incorporate built-in editing tools that facilitate proactive identification defense, such as automated blurring of faces or tattoos, and one-click metadata removal directly within the sharing workflow.
- Address Negative Incentives: Conduct further research and design iterations to understand and mitigate potential negative incentives created by safety features (e.g., expiring messages encouraging screenshots). This requires careful user experience design and clear communication of feature functionalities and limitations.
- Advance NDII Detection: Invest in research and development for more accurate and less distressing NDII detection technologies, overcoming current challenges with hash-based solutions (storage, reconstruction attacks, false positives).
- Balance Control and Documentation: Innovate design solutions that balance users' desire for content control (e.g., disappearing messages) with the critical need for harm documentation for legal recourse in NDII cases. This might involve secure, verifiable, and legally accessible logging mechanisms.
- Educate and Empower: Beyond features, platforms have a role in educating users about the risks and effective use of available protections, without shifting the full burden of prevention onto them.
Ultimately, the defensive posture against NDII requires a collaborative effort, with platforms taking a leading role in creating a safer technological environment that supports digital intimacy without compromising user safety.
Key Takeaways
- Non-consensual distribution of intimate imagery (NDII) is a widespread and severely impactful form of sexual abuse, affecting at least one in six adults who share intimate content.
- Individuals employ a wide array of personal and technological strategies for proactive protection, but these are often time-consuming, difficult to implement, and viewed as harm reduction rather than complete prevention.
- Existing platform safety features are inadequate, characterized by patchy availability, limited customization, and often hidden or difficult-to-discover functionalities, failing to treat intimate content as a primary use case.
- Platforms bear a critical responsibility to reallocate the burden of protection from individuals by designing and implementing comprehensive, visible, customizable, and granular safety features directly into their core services.
- New design challenges include understanding how safety features might inadvertently incentivize harmful bypasses, developing more reliable and less distressing NDII detection technologies, and balancing content control with the essential need for harm documentation in legal contexts.
- The ultimate goal of proactive protection is to "create friction" to slow the spread of NDII, acknowledging that while absolute prevention may be elusive, a higher baseline of technological safety can significantly reduce harm.
About the Speaker(s)
The research presented in this talk was a collaborative effort by a team of graduate and undergraduate student researchers from UC Berkeley and an assistant professor from Princeton University.
Lucy Qin is a Graduate Student Researcher at UC Berkeley.
Vaughn Hamilton is a Graduate Student Researcher at UC Berkeley.
Sharon Wang is a Graduate Student Researcher at UC Berkeley.
Yigit Aydinalp is a Graduate Student Researcher at UC Berkeley.
Marin Scarlett is an Undergraduate Student Researcher at UC Berkeley.
Elissa M. Redmiles is an Assistant Professor at Princeton University.
Their collective expertise contributed to this in-depth study, combining insights from human-computer interaction, security, and social sciences to address the complex challenges of digital intimacy and image-based sexual abuse.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk tackles the critical issue of non-consensual distribution of intimate imagery with a comprehensive qualitative study, exposing severe gaps in existing platform protections. It provides actionable, user-centric design recommendations, effectively reallocating the burden of safety from individuals to technology platforms. This is real research that directly impacts user safety and product design.
Heather Calloway (CISO) — STRONG ACCEPT
This research forcefully articulates the urgent need for platforms to assume proactive responsibility in preventing image-based sexual abuse. It diagnoses significant gaps in current safety features and offers clear, actionable design recommendations that shift the burden from individuals to technology providers, fundamentally altering the governance of digital intimacy.