Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

191–200 of 440 posts

Re: The Problem with Perceptual Hashes

#191
post #144

Earlier quoted context omitted.

What has changed is the inclusion of spyware technology on the device that can be weaponised to basically report on anything. Today it's only geared toward iCloud and CSAM. How many lines of codes do you think it will take before it scans all your local pictures? How hard do you think it will be for an authoritarian regime like China, that Apple bends over backwards to please, to start including other hashes that are…

We gotta stop with the China bogeyman every time a privacy issue comes up. This is a feature designed by an American company for American government surveillance purposes. China is perfectly capable of doing the same surveillance or worse on its own citizens, with or without Apple. China has nothing to do with why American tech is progressively implementing more authoritarian features in a supposedly democratic count…

Ok. How about the Saudi Arabian bogeymen then? Who took Jamal Kashoggi apart with bonesaws as he screamed? Or the Israeli bogeymen who exploited his phone for them? Or the Turkish bogeymen who also a customers of that Israeli phone exploitation company? (Or Facebook who wanted to buy those tools but got turned down, because Facebook is “too far” even for NSO who happily take Saudi and Turkish money?)

There are without doubt enough privacy bogeymen to go around, trying to derail a valid argument over its use of the Chinese as the placeholder bogeyman detracts from the discussion pointlessly.

Re: The Problem with Perceptual Hashes

#192

Earlier quoted context omitted.

> The same checking when you synced things to iCloud. As has been repeated over and over again, this check happens for iCloud Photos. It's not running arbitrarily. Who said it's running "arbitrarily"? Who said it's not about iCloud Photos? > Your photos were compared before and they're being compared now... if you're using iCloud Photos. They weren't always compared, they started being compared a few years ago, and t…

>Both are bad, and not the responsibility of a company selling phones Apple is not just a hardware company and there is no obligation for them to host offending contents on their servers - just as Dropbox, Google, and so on would maintain with theirs. >As for your suggestions to just "stop using iCloud Photos", how about we get to enjoy the features we bought our devices for, without stuff we didn't ask for and don't…

In this case, they're explicitly required by law to report this material if it shows up on their servers.

Re: The Problem with Perceptual Hashes

#193

Earlier quoted context omitted.

The post office scans your mail through various machines in transit. We accept that when we put the mail in the mailbox. What if the post office announced they were installing a man with a scanning machine in your home who would scan your letters before they left your house? It's the same outcome. The same process. Just inside your house instead of out in the mail system. They're exactly the same, except somehow it's…

This example changes with regards to emotional weight if you remove "a man" and leave it at just "a scanning machine". There is no human scanning your photos on an iPhone, so let's compares apples to apples here. If that scanning machine didn't reveal the contents of my mail, and then ensured that it wasn't able to be given out in-transit? Yeah, I'd potentially be fine with it - but I'll leave this answer as a hypoth…

But the barrier between “only happens for iCloud” and “happens for all photos on device” has been reduced to a very small barrier. Before it was the photos actually being sent to a separate server by my choice, now it’s Apple saying their on-device tool only runs given criteria X.

And on a second note I think people are allowed to be freshly concerned at the idea of Apple scanning photo libraries given a government-provided hash list, even if it was already happening before now.

Re: The Problem with Perceptual Hashes

#194
post #80
post #78

Earlier quoted context omitted.

So what are we going to do about it? I have a large user base on iOS. Considering a blackout protest.

IMHO, Unless everything being E2E encrypted becomes the law we can’t do anything about it because that’s not Apple’s initiative but comes from people whose job is to know things and they cannot resist keeping their hands out of these data collecting devices. They promise politicians that all the troubles will go away if we do that. Child pornography, Terrorism? Solve it the old way. I don’t know why citizens are obli…

That was a very well put together comment. Good one.

Re: The Problem with Perceptual Hashes

#195
post #172

Earlier quoted context omitted.

Did you literally not see a former president effectively get silenced in the public sphere by 3 corporations? How can you seriously believe that these corporations (who are not subject to the first amendment, and cannot be challenged in court) won't extend and abuse this technology to tackle "domestic extremism" but broadly covering political views?

> a former president effectively get silenced in the public sphere It's laughable that a man who can call a press conference at a moment's notice and get news coverage for anything he says can be "silenced" because private companies no longer choose to promote his garbage.

He's been completely silenced. If you don't believe me, you can hear it from him next week when he's on the largest news network talking about being silenced.

Re: The Problem with Perceptual Hashes

#196

I've also implemented perceptual hashing algorithms for use in the real world. Article is correct, there really is no way to eliminate false positives while still catching minor changes (say, resizing, cropping, or watermarking). I'm sure I'm not the only person with naked pictures of my wife. Do you really want a false positive to result in your intimate moments getting shared around some outsourced boiler room for…

Why would other people have a naked picture of your wife?

(joke)

Re: The Problem with Perceptual Hashes

#197
post #133

Given all the zero day exploits on iOS I wonder if it's now going to be viable to hack someone's phone and upload child porn to their account. Apple with happily flag the photos and then, likely, get those people arrested. Now they have to, in practice, prove they were hacked which might be impossible. Will either ruin their reputation or put them in jail for a long time. Given past witch hunts it could be decades be…

The "hack" might be very simple, since I'm sure it's possible to craft images that look like harmless memes but trigger the detection for CP.

Couldn't the hack just be as simple as sending someone an iMessage with the images attached? Or somehow identify/modify non-illegal images to match the perceptual hash -- since it's not a cryptographic hash.

Re: The Problem with Perceptual Hashes

#198
post #33

Given all the zero day exploits on iOS I wonder if it's now going to be viable to hack someone's phone and upload child porn to their account. Apple with happily flag the photos and then, likely, get those people arrested. Now they have to, in practice, prove they were hacked which might be impossible. Will either ruin their reputation or put them in jail for a long time. Given past witch hunts it could be decades be…

This is really a difficult problem to solve I think. However, I think most people who are prosecuted for CP distribution are hoarding it by the terabyte. It’s hard to claim that you were unaware of that. A couple of gigabytes though? Plausible. And that’s what this CSAM scanner thing is going to find on phones.

Why would they hoard it in the camera/iPhotos app? I assume that storage is mostly pictures taken with the device. Wouldn't this be the least likely place to find a hoard of known images?

Re: The Problem with Perceptual Hashes

#199

Earlier quoted context omitted.

> a former president effectively get silenced in the public sphere It's laughable that a man who can call a press conference at a moment's notice and get news coverage for anything he says can be "silenced" because private companies no longer choose to promote his garbage.

He's been completely silenced. If you don't believe me, you can hear it from him next week when he's on the largest news network talking about being silenced.

Yes, because we all trust him at this point /s

Re: The Problem with Perceptual Hashes

#200

Earlier quoted context omitted.

>What exactly do you think is the same as before? The same checking when you synced things to iCloud. As has been repeated over and over again, this check happens for iCloud Photos. It's not running arbitrarily. Your photos were compared before and they're being compared now... if you're using iCloud Photos.

The post office scans your mail through various machines in transit. We accept that when we put the mail in the mailbox. What if the post office announced they were installing a man with a scanning machine in your home who would scan your letters before they left your house? It's the same outcome. The same process. Just inside your house instead of out in the mail system. They're exactly the same, except somehow it's…

> The post office scans your mail through various machines in transit.

That is a totally bogus comparison.

The post office 100% does NOT can the content of every piece mail they handle.

Not even close to the same scenario as Apple/governments being able to continually and silently check your phone/photo library for images on their watch list.

Post reply on HN