The problem of hash or NN based matching is, the authority can avoid explaining the mismatch. Suppose the authority want to false-arrest you. They prepare a hash that matches to an innocent image they knew the target has in his Apple product. They hand that hash to the Apple, claiming it's a hash from a child abuse image and demand privacy-invasive searching for the greater good. Then, Apple report you have a file th…
Well, presumably at that point, someone in that position would just reveal their own files with the hash an prove to the public that they weren't illegal. Sure, it would be shitty to be forced to reveal your private information that way, but you would expose a government agency as fabricating evidence and lying about the contents of the picture in question to falsely accuse someone. It seems like that would be a scan…
The Problem with Perceptual Hashes
161–170 of 440 posts
Re: The Problem with Perceptual Hashes
#162Re: The Problem with Perceptual Hashes
#163Earlier quoted context omitted.
You don't plan to ever use 4G/5G again?
I have openvpn so the block will remain in effect. I don't plan to use apple services ever again but the hard ware is pretty good.
Re: The Problem with Perceptual Hashes
#164Earlier quoted context omitted.
Rookie mistake. Three rules to live by: 1) Always pay your taxes 2) Don’t talk to the police 3) Don’t take photographs with your clothes off
I might amend #2 a bit to read "Be friends with the police" as that has historically been more beneficial to those who are.
Police Officers exist in a career field that is riddled with incidents of Tunnel Vision. The sibling comment posts a video about not talking to police from a law professor. I'd heed that advice.
Re: The Problem with Perceptual Hashes
#165The method Apple is using looks more like a cryptographic hash. That's entirely different (and more secure) than a perceptual hash. From https://www.apple.com/child-safety/ "Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the known CSAM hashes. This matching process is powered by a cryptographic technology called private set intersection, which determines…
The crypto here is for the private set intersection, not the hash. So your device has a list of perceptual (non-cryptographic) hashes of its images. Apple has a list of the hashes of known bad images. The protocol lets them learn which of your hashes are in the “bad” set, without you learning any of the other “bad” hashes, and without Apple learning any of the hashes of your other photos.
Is it possible to perform private set intersection where the comparison is inexact? I.e., if you have two cryptographic hashes, private set intersection is well understood. Can you do the same if the hashes are close, but not exactly equal?
If the answer is yes, that could mean you would be able to derive the perceptual hashes of the CSAM, since you're able to find values close to the original and test how far you can drift from it before there's no longer a match.
Re: The Problem with Perceptual Hashes
#166Re: The Problem with Perceptual Hashes
#167The technical challenges aside, I’m very disturbed that my device will be reporting me to the authorities. That’s very different from authorities taking a sneak peek into my stuff. That’s like the theological concept of always being watched. It starts with child pornography but the technology is indifferent towards it, it can be anything. It’s always about the children because we all want to save the children. Soon t…
With you up to here, but this is jumping the shark > I bet you, after the next election in the US your device will be reporting you for spreading far right or deep state lies, depending on who wins. The US is becoming less stable, sure [1], but there is still a very strong culture of free speech, particularly political speech. I put the odds that your device will be reporting on that within 4 years as approximately 0…
In my opinion, that culture has been rapidly dying, chipped away by a very sizable and growing chunk that doesn't value it at all, seeing it only as a legal technicality to be sidestepped.
Re: The Problem with Perceptual Hashes
#168> an Apple employee will then look at your (flagged) pictures. This means that there will be people paid to look at child pornography and probably a lot of private nude pictures as well.
Apple, with all those Apple == Privacy billboards plastered everywhere, is going to have a full-time staff of people with the job of looking through it's customers' private photos.
Re: The Problem with Perceptual Hashes
#169Earlier quoted context omitted.
With you up to here, but this is jumping the shark > I bet you, after the next election in the US your device will be reporting you for spreading far right or deep state lies, depending on who wins. The US is becoming less stable, sure [1], but there is still a very strong culture of free speech, particularly political speech. I put the odds that your device will be reporting on that within 4 years as approximately 0…
Apple has a shitty record wrt free speech. Apple hates free speech. Apple likes “curation”. They canned Parler in a heartbeat; they also police the App Store for anything naughty.
Re: The Problem with Perceptual Hashes
#170The technical challenges aside, I’m very disturbed that my device will be reporting me to the authorities. That’s very different from authorities taking a sneak peek into my stuff. That’s like the theological concept of always being watched. It starts with child pornography but the technology is indifferent towards it, it can be anything. It’s always about the children because we all want to save the children. Soon t…
I would really like people to start answering this: what exactly do you think has changed? e.g, >That’s very different from authorities taking a sneak peek into my stuff. To be very blunt: - The opt out of this is to not use iCloud Photos. - If you _currently_ use iCloud Photos, your photos are _already_ hash compared. - Thus the existing opt out is to... not use iCloud Photos. The exact same outcome can happen regar…
This is different. This is your own device doing that thing, out of your control. Alright sure, it's doing the same thing as the other server did and under the same circumstances* so maybe functionally nothing has changed. But the philosophical difference is quite huge between somebody else's server watching over what you upload and your own device doing it.
I'm struggling to come up with a good analogy. The closest I can really think of is the difference between a reasonably trusted work friend and your own family member reporting you to the authorities for suspicious behavior in your workplace and home respectively. The end result is the same, but I suspect few people would feel the same about those situations.
* There is no inherent limitation for your own device to only be able to check photos you upload to iCloud. There is however such a limitation for the iCloud servers. A very reasonably and potentially functional difference is the ability for this surveillance to be easily expanded beyond iCloud uploads in the future.