Sign in

David Callies

@dcallies.bsky.social
69 followers 41 following 58 posts

Open Source Trust & Safety Software Engineer

PostsRepliesMedia
David Callies @dcallies.bsky.social · 02/09/2026
Hooray!
static.klipy.com
Oprah Winfrey Reacts to Bees
Alt: A manipulated memetic video depicting a segment of the Oprah Winfrey show, where Oprah reveals behind a curtain not a gift to the audience, but a swarm of bees. Oprah and the audience's original joyful reaction to the reveal is given new context with a fictional swarm of insects spewing, with flashing overlay text reading: BEES.
010
David Callies @dcallies.bsky.social · 25/07/2026
@orbitaldropkick.bsky.social - looks like the maintainers of the plug-in just cut a new version (1.17) mentioning deprecated versions in the release notes. At the very least that means it's still under active development and the author might be able to help you!
010
Reposted by David Callies
austin (eeek!/ackkk! 👻) @thebadcode.com · 24/07/2026
that’s just unsolvedslop. you only like it because its pressing outward against the boundaries of human knowledge
2618
David Callies @dcallies.bsky.social · 14/05/2026
Everyone knows what they say about he who fights with monsters, but I desperately need to know the fate of he who fights with robots. For a friend.
000
David Callies @dcallies.bsky.social · 04/05/2026
Thanks for contributing this! The start of great things!
020
Reposted by David Callies
Emelia @thisismissem.social · 04/05/2026
Okay so – with a big caveat that we still need to write a lot more documentation – between the @roost.tools team, @dcallies.bsky.social and myself we've managed to ship a new documentation site for ThreatExchange / HMA: facebook.github.io/ThreatExchan...
facebook.github.io
ThreatExchange
Trust & Safety tools for working together to fight digital harms.
24117
David Callies @dcallies.bsky.social · 28/02/2026
Say what you want about the IP or the Amazon show, but something I really like about the Fallout setting is that it shows that even after the "end", life goes on. And even after the end, some things never change about human nature. What it glosses over is how much you lose in the course of falling.
000
David Callies @dcallies.bsky.social · 22/02/2026
Parts unknown!
010
David Callies @dcallies.bsky.social · 28/01/2026
Stumbling onto Hubrid's "Cosmic Punk" album has been the first Spotify algorithm W for me in 2026.
000
David Callies @dcallies.bsky.social · 26/11/2025
It's overall a sensitive topic I think. I have my own theories and my reasons for believing them, but like many things in trust and safety I think it's a complex problem with some interlinked dependent challenges.
040
David Callies @dcallies.bsky.social · 26/11/2025
> This was also one of the reasons there was low adoption of integration for TVEC hash-sharing. I have some doubts on this front. After all, there are now several other TVEC hash exchanges, and you can always exchange via email. My experience is the bottleneck is elsewhere.
150
David Callies @dcallies.bsky.social · 26/11/2025
The protocol is straightforward, I've gotten close to open sourcing it many times, but nobody has ever told me they would pay for hosting!
130
David Callies @dcallies.bsky.social · 26/11/2025
MD5 is fairly well adopted thanks to being a common format in pretty much every content safety program I'm aware of. It's also so cheap to run, so the cost of double/triple hashing is less than for perceptual hashing.
030
David Callies @dcallies.bsky.social · 26/11/2025
We did tests with TMK for StopNCII, and the cost of running the algorithm on people's phones was prohibitive. TMK adoption in the wild is overall less than PDQ.
020
David Callies @dcallies.bsky.social · 26/11/2025
Open source PDQ -> you can now host PDQ sharing on ThreatExchange to combat harm. Folks having trouble with the infrastructure to match images with the algorithm? Open source a more complete package that does all the stages, including sharing (HMA).
011
David Callies @dcallies.bsky.social · 26/11/2025
Meta's approach to cross-industry T&S work is multidimensional. We have the ThreatExchange program which we provide for free for folks that want to host data sharing programs. However, access to the data shared is a separate matter. Open sourcing is a separate track, but have some synergy.
110
Reposted by David Callies
Bluesky Safety @safety.bsky.app · 25/11/2025
We're announcing a new partnership with StopNCII.org to prevent non-consensual intimate imagery (NCII) from spreading on Bluesky. While NCII hasn't been frequent on our platform, these incidents are devastating for victims and preventing them is a top safety priority. 1/4
stopncii.org
Stop Non-Consensual Intimate Image Abuse | StopNCII.org
StopNCII.org is operated by the Revenge Porn Helpline which is part of SWGfL, a charity that believes that all should benefit from technology, free from harm.
501101288
Reposted by David Callies
Juliet Shen @julietshen.online · 29/10/2025
🚨 IT'S FINALLY PUBLIC 🚨 I am very, very, very proud of this launch and am so excited to finally share it with everyone! @roost.tools has worked with OpenAI over the past few months to open source a reasoning model that is fine-tuned for Trust & Safety use cases.
3639
David Callies @dcallies.bsky.social · 17/10/2025
I've been pilled on negative offsets through python: last = val[-1]
040
David Callies @dcallies.bsky.social · 30/05/2025
How many social surveys did you complete this week??? We noticed you aren't sharing your personal hobbies in work slack, what's with that, you know your performance is tied to internal likes right? Vs 5 stars or death, working extremely late hours to clear the support queue, etc :P
120
David Callies @dcallies.bsky.social · 28/05/2025
I enjoyed the book, but many of its premisses are so disconnected from workability it was distracting, but maybe that's what I get for working in the industry. However, the onsite apartments were rad, and the real life equivalent of the CitizenM in Menlo Park near MetaHQ net value to the world imho
110
David Callies @dcallies.bsky.social · 11/04/2025
As a "graphql is the required API" fully Stockholm syndromed employee, what stinks about graphql? We have oodles of integrated tooling, so guessing /path/to/thing?param=yes is way easier than the DSL query/finding fetch__the_thing()?
000
David Callies @dcallies.bsky.social · 10/04/2025
The Q in PDQ stands for quality, and it's an attempt by the algorithm to identify images that it's not very good at discerning between before it discards all the information by turning it into a hash. Classic low quality images are highly padded images, regular patterns, or even blank squares.
130
David Callies @dcallies.bsky.social · 10/04/2025
Awesome work! I've been poking around the edges of fediverse land to see if PDQ would be valuable to use for providing image based features (especially harm detection). Let me know if you think the idea has legs, happy to chat with you about it!
010
Reposted by David Callies
hailey @hailey.at · 10/04/2025
turns out that with facebook's pdq hashing algorithm, you can hash every image that goes through the firehose. minimal cpu required. fun stuff! then just throw pgvector on top and boom
4836
David Callies @dcallies.bsky.social · 10/04/2025
Sure did! Over time I've tried to copy out key portions into the various readmes. Now that hashing.pdf is cross linked in a lot of other places, I've been reluctant to touch it...
010
David Callies @dcallies.bsky.social · 10/04/2025
@hailey.at - make sure to filter out low quality score (<50) PDQ hashes! Most common mistake using PDQ, otherwise the results are random instead of perceptually clustered!
130
David Callies @dcallies.bsky.social · 26/03/2025
Awesome work, and super exciting! We debated whether to build this exact thing when we did HMA 1.0, tested it with Workplace instead (less exciting). cc @julietshen.bsky.social
010
David Callies @dcallies.bsky.social · 24/03/2025
I think my meeting load was lighter when I was a manager, but not by much :P
000
David Callies @dcallies.bsky.social · 24/03/2025
Earlier on in our teams work on HMA, we did some theorizing on this, we were calling it the "Safety Stack" (had logos picked out and everything). AT/AP are both good models because they imagine interoperable social media. Why not interoperable T&S?
141
David Callies @dcallies.bsky.social · 24/03/2025
We should connect on a potential roadmap. Maybe if we highlighted where the gaps were, focusing how theoretical systems might communicate, we can make some space for more tools to pop up that will be interoperable with the ROOST-verse. [1/2]
141
David Callies @dcallies.bsky.social · 23/03/2025
Pick something that you might conceivably use. I got my start editing the configs of games I played, then learned more to make my own games. My default rec is always python, but it should come with a project - raspberry pi is a good gateway for physical devices that uses it.
110
David Callies @dcallies.bsky.social · 23/03/2025
Not a lot of HMA or not a lot of other tools in the same vein?
110
David Callies @dcallies.bsky.social · 21/03/2025
Fridays are basically my only light day, 1h, leaving me mostly to learning my job is safe from LLMs, who are much worse at react than I am (and I'm bad). Don't talk to me about Tuesdays
100
David Callies @dcallies.bsky.social · 19/03/2025
The benefit of trimming the record by default for new partners catching up seemed to be worth optimizing for, and a belief that integrators sophisticated enough to use full history would be limited led to my belief that only sharing active records was preferable. History-less also seemed simpler 🤷
100
David Callies @dcallies.bsky.social · 19/03/2025
Agree on attack potentials, I think we have different conclusions on if we need a full immutable record history as a native functionality. We have some time limited history in ThreatExchange (only on harmful/not harmful), but we prune records after 90d. [1/2]
100
David Callies @dcallies.bsky.social · 19/03/2025
Full transitions add more transparency, but I've yet to want that from someone else from a T&S perspective, though I suppose a different background (academic) might. You can synthesize the full transition record if you have made it up to date on the replication.
100
David Callies @dcallies.bsky.social · 19/03/2025
To add more context to the question, retaining history seemed undesirable - if we are undoing a mistaken report on benign content it seemed better that content to be fully forgotten. The transitions add length to the record without necessarily adding functionality on the goal of replication.
100
David Callies @dcallies.bsky.social · 18/03/2025
Read some of the UUID docs, but why does it make sense to make the dataset append only? To make sure I have the right usecase, is the datasets we are talking about replicating trust and safety data?
100
David Callies @dcallies.bsky.social · 18/03/2025
When people ask me, I say (update_time, record_id) as the sort order, which relies on the record having both of those things. Is UUID being used to mask the underlying id?
100
David Callies @dcallies.bsky.social · 18/03/2025
The interface makes date pagination optional, but the ability to sort by date falls out of the requirement that the API detect updates and to have a correct output even if the items are being updated underneath you. The easiest way to do that is put new updates at the end.
100
David Callies @dcallies.bsky.social · 18/03/2025
E.g. here's the line of code for NCMEC: report.cybertip.org/hashsharing/... See also this issue: github.com/facebook/Thr...
report.cybertip.org
120
David Callies @dcallies.bsky.social · 18/03/2025
We're deferring to flask configs under the hood, and the config itself is fully executable python - the best way is to have a config.py and populate OMM_CONFIG env to the dir. It should be documented somewhere, but might be in code instead of the readme
010
David Callies @dcallies.bsky.social · 18/03/2025
Hmm, I personally haven't tried running it in the wild with a separate instance, I always run it in the dev container, but work with a few other people running it in the wild. Could be we're missing documentation - if you are willing to write an issue with how I can repo I'll give it a shot
010
David Callies @dcallies.bsky.social · 18/03/2025
I think resumable update streams is the approach that seems to have worked well in the wild over time, but there are others as well!
010
David Callies @dcallies.bsky.social · 18/03/2025
All the exchanges I wrote open source clients for have their documentation in the code - I only wrote exchange interfaced for ones where they were publicly documented or the author of the API contributed them. Feel free to spam issues as well for questions!
020
David Callies @dcallies.bsky.social · 13/03/2025
Cool stuff! I work on ThreatExchange at Meta, which is basically a federated safety exchange, and would love ending up in a world where the same capabilities were encoded right into AP. It's been a long while since I checked, is "Flag" and server blocks still the main fedi T&S concepts?
100
David Callies @dcallies.bsky.social · 13/03/2025
Some people want synchronous checks for photos to avoid persisting or showing harmful media at all, but it's impossible/inadvisable to try and do video synchronously in the same way. Your safety checks can piggyback on video transcoding, though!
121
David Callies @dcallies.bsky.social · 13/03/2025
If you are willing to do everything async in queues, it scales much better. The first version of HMA was all on async AWS lambda and it scaled well. We only went with the all-docker single instance-by-default design because our biggest feedback was HMA was hard to demo, and didn't want AWS lock-in
131
David Callies @dcallies.bsky.social · 12/03/2025
This is actually cheaper, because if everyone is scanning their incoming on AT, things are being scanned multiple times! If I can trust someone else's scans, we might be able to scan the minimum number of times.
020