Earlier quoted context omitted.
What happens if someone leaks or guesses the weights on that "secret" classifier? The whole system is so ridiculous even before considering the amount of shenanigans the FBI could pull by putting in non-CSAM hashes.
Can't they just make a new one and recompute the 2nd secret hash on the whole data set fairly easily? Also, the whole point is that it's fairly easy to create a fake image that collides with one hash, but doing it for 2 is exponentially harder. It's hard to see how you could have an image that collides with both hashes (of the same image mind you).
Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
231–240 of 363 posts
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#232Earlier quoted context omitted.
> If you're concerned about other forms of scanning, you didn't consent—so even if Apple complied, the search is invalid and cannot be used to prosecute you. This is a dangerously false understanding of the law. Stop giving legal advice. You are not a lawyer.
Are you saying that if the US Government compelled Apple to scans millions of citizen's private property for non-CSAM images, this would not be a clear-cut violation of the Fourth Amendment? I'm curious, do you think that the Third Party Doctrine applies here?
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#233Earlier quoted context omitted.
> If you enable iCloud backups, it's scans the entire shebang. Citation?
Do I need one? Where in iOS can you choose which folders to opt-into CSAM scanning? I only see an all-or-nothing option for iCloud photos.
From everything I've read, from Apple and other sources, if the photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#234Despite that Apple scanning our images is a horrible privacy practice, I don't get why 𝚜̶𝚘̶ ̶𝚖̶𝚊̶𝚗̶𝚢̶ some people think this is an ineffective idea. Surely you can easily fabricate innocent images whose NeuralHash matches the database. But in what way are you going to send them to victims and convince them to save them to their photo library? The moment you send it via WhatsApp FB will stop you because (they th…
Almost nobody is arguing the effectiveness of the idea. That would be missing the point entirely.
(In case you have problem with me saying "so many", that I can fix.)
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#235Earlier quoted context omitted.
No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.
Which means all it takes now is one disillusioned Apple employee to leak the details of thay private hash function and the whole system is compromised.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#236So, what does Apple get out of all this, except negative attention, erosion of their image, possible privacy lawsuits, etc? I just don't understand what Apple's motivation would have been here. Surely this fallout could have been anticipated?
Is it like other stories I hear on HN where one guy or team is trying to get a promotion so keeps pushing their project? And people were afraid to oppose it? I’m baffled how this kept going up to implementation even in the birthplace of the reality distortion field.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#237Earlier quoted context omitted.
No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.
But surely if they're doing this in anticipation of E2EE user data, that procedure becomes moot? So either they have no intention to actually protect user data, or the system is trivially broken; either way a pretty damning look for Apple.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#238Earlier quoted context omitted.
Do I need one? Where in iOS can you choose which folders to opt-into CSAM scanning? I only see an all-or-nothing option for iCloud photos.
Yes, you do need a citation, because I've not heard Apple (or anyone else) claim that iCloud Backups or iCloud Drive are being subject to CSAM scans. From everything I've read, from Apple and other sources, if the photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#239Earlier quoted context omitted.
There's no need for someone to get the entire CSAM database. If they go on the darknet and just find enough images (or hashes) that would trip Apple's system, that would be enough. I'd assume any publicly available image on the darknet would likely also be on CSAM.
Exactly. It would be trivial for anyone to compile a list of possible known CSAM hashes. It would be illegal to do so, but only one person has to do it, and then the list of probably positive hashes can be distributed legally around the web.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#240Earlier quoted context omitted.
I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Android does not do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. It's not on-device scanning, but the effect is functionally identical: photos that are being uploaded to the cloud are being scanned for CSAM. The only real distinction is who owns the CPU which computes the hash. I d…
> I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Where does this assumption come from? Because of iOS lower market share? Are you implying they are more prevalent in Android devices? In desktop computers? I don't understand the logic.
You don't have to be particularly tech savvy to know it's a bad idea to co-mingle your deepest darkest secrets alongside photos of your mum and last night's dinner. Especially when discovering those secrets would lead to estrangement, or prison.
As for the few who might be doing it currently, that's likely to plummet quickly. If you think Apple's move caused waves in the Hacker News crowd, just imagine how much it has blown up in the CSAM community right now. I dare say it's probably all they've been talking about for the past two weeks.