Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

231–240 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#231
post #151

Earlier quoted context omitted.

What happens if someone leaks or guesses the weights on that "secret" classifier? The whole system is so ridiculous even before considering the amount of shenanigans the FBI could pull by putting in non-CSAM hashes.

Can't they just make a new one and recompute the 2nd secret hash on the whole data set fairly easily? Also, the whole point is that it's fairly easy to create a fake image that collides with one hash, but doing it for 2 is exponentially harder. It's hard to see how you could have an image that collides with both hashes (of the same image mind you).

If you have both models it is easy. If Apple manages to keep the server model private then it is hard.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#232

Earlier quoted context omitted.

> If you're concerned about other forms of scanning, you didn't consent—so even if Apple complied, the search is invalid and cannot be used to prosecute you. This is a dangerously false understanding of the law. Stop giving legal advice. You are not a lawyer.

Are you saying that if the US Government compelled Apple to scans millions of citizen's private property for non-CSAM images, this would not be a clear-cut violation of the Fourth Amendment? I'm curious, do you think that the Third Party Doctrine applies here?

I think the realistic danger here is the US Government no longer needs to compel this type of activity. Reference Twitter and Facebook/Instagram voluntarily censorship per mere suggestion of the current administration/power party.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#233
post #219

Earlier quoted context omitted.

> If you enable iCloud backups, it's scans the entire shebang. Citation?

Do I need one? Where in iOS can you choose which folders to opt-into CSAM scanning? I only see an all-or-nothing option for iCloud photos.

Yes, you do need a citation, because I've not heard Apple (or anyone else) claim that iCloud Backups or iCloud Drive are being subject to CSAM scans.

From everything I've read, from Apple and other sources, if the photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#234

Despite that Apple scanning our images is a horrible privacy practice, I don't get why 𝚜̶𝚘̶ ̶𝚖̶𝚊̶𝚗̶𝚢̶ some people think this is an ineffective idea. Surely you can easily fabricate innocent images whose NeuralHash matches the database. But in what way are you going to send them to victims and convince them to save them to their photo library? The moment you send it via WhatsApp FB will stop you because (they th…

Almost nobody is arguing the effectiveness of the idea. That would be missing the point entirely.

The first comment algorithm choses to show me contains substring "and this system is transparently broken". Isn't that a remark on the effectiveness of the idea or I misread?

(In case you have problem with me saying "so many", that I can fix.)

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#235
post #227

Earlier quoted context omitted.

No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.

Which means all it takes now is one disillusioned Apple employee to leak the details of thay private hash function and the whole system is compromised.

One disillusioned employee that has access to the secret algorithm.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#236
post #35

So, what does Apple get out of all this, except negative attention, erosion of their image, possible privacy lawsuits, etc? I just don't understand what Apple's motivation would have been here. Surely this fallout could have been anticipated?

Is it like other stories I hear on HN where one guy or team is trying to get a promotion so keeps pushing their project? And people were afraid to oppose it? I’m baffled how this kept going up to implementation even in the birthplace of the reality distortion field.

Something this major, company brand changing, would have required a lot of executive sign-offs, presumably even Cook's personal blessing.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#237

Earlier quoted context omitted.

No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.

But surely if they're doing this in anticipation of E2EE user data, that procedure becomes moot? So either they have no intention to actually protect user data, or the system is trivially broken; either way a pretty damning look for Apple.

No, because the second hash is only performed after the first hash has already matched, and so, using the threshold secret sharing crypto, the server has learned the escrowed encryption key for the image. (Well, for its “visual derivative”, at any rate.)

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#238
post #219

Earlier quoted context omitted.

Do I need one? Where in iOS can you choose which folders to opt-into CSAM scanning? I only see an all-or-nothing option for iCloud photos.

Yes, you do need a citation, because I've not heard Apple (or anyone else) claim that iCloud Backups or iCloud Drive are being subject to CSAM scans. From everything I've read, from Apple and other sources, if the photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't.

How does one choose individual photos to not upload?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#239
post #81

Earlier quoted context omitted.

There's no need for someone to get the entire CSAM database. If they go on the darknet and just find enough images (or hashes) that would trip Apple's system, that would be enough. I'd assume any publicly available image on the darknet would likely also be on CSAM.

Exactly. It would be trivial for anyone to compile a list of possible known CSAM hashes. It would be illegal to do so, but only one person has to do it, and then the list of probably positive hashes can be distributed legally around the web.

Human doesn't need to see the material. One can automate this by crawling websites with known bad material and compute hash of all images. Surely some of those hashes are CSAM, we don't know which. But it's still equally dangerous.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#240

Earlier quoted context omitted.

I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Android does not do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. It's not on-device scanning, but the effect is functionally identical: photos that are being uploaded to the cloud are being scanned for CSAM. The only real distinction is who owns the CPU which computes the hash. I d…

> I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Where does this assumption come from? Because of iOS lower market share? Are you implying they are more prevalent in Android devices? In desktop computers? I don't understand the logic.

The assumption comes from a general observation that most normal people don't tend to use their photo library to store legal porn (other than home made) and I haven't seen any argument for why CSAM aficionados are expected to be any less careful. There are surely plenty of apps out there for keeping separately encrypted vaults of files/photos, and I'm sure many are very easy to use.

You don't have to be particularly tech savvy to know it's a bad idea to co-mingle your deepest darkest secrets alongside photos of your mum and last night's dinner. Especially when discovering those secrets would lead to estrangement, or prison.

As for the few who might be doing it currently, that's likely to plummet quickly. If you think Apple's move caused waves in the Hacker News crowd, just imagine how much it has blown up in the CSAM community right now. I dare say it's probably all they've been talking about for the past two weeks.

Post reply on HN