The problem of hash or NN based matching is, the authority can avoid explaining the mismatch. Suppose the authority want to false-arrest you. They prepare a hash that matches to an innocent image they knew the target has in his Apple product. They hand that hash to the Apple, claiming it's a hash from a child abuse image and demand privacy-invasive searching for the greater good. Then, Apple report you have a file th…
Well, presumably at that point, someone in that position would just reveal their own files with the hash an prove to the public that they weren't illegal. Sure, it would be shitty to be forced to reveal your private information that way, but you would expose a government agency as fabricating evidence and lying about the contents of the picture in question to falsely accuse someone. It seems like that would be a scan…
The Problem with Perceptual Hashes
211–220 of 440 posts
Re: The Problem with Perceptual Hashes
#212Earlier quoted context omitted.
The "hack" might be very simple, since I'm sure it's possible to craft images that look like harmless memes but trigger the detection for CP.
Couldn't the hack just be as simple as sending someone an iMessage with the images attached? Or somehow identify/modify non-illegal images to match the perceptual hash -- since it's not a cryptographic hash.
Re: The Problem with Perceptual Hashes
#213Librarians: "It is unthinkable that we would ever share a patron's borrowing history!"
Post office employees: "Letters are private, only those commie countries open the mail their citizens send!"
Police officers: "A search warrant from a Judge or probable cause is required before we can search a premises or tap a single, specific phone line!"
The census: "Do you agree to share the full details of your record after 99 years have elapsed?"
The world in the 2000s:
FAANGs: "We know everything about you. Where you go. What you buy. What you read. What you say and to whom. What specific type of taboo pornography you prefer. We'll happily share it with used car salesmen and the hucksters that sell WiFi radiation blockers and healing magnets. Also: Cambridge Analytica, the government, foreign governments, and anyone who asks and can pony up the cash, really. Shh now, I have a quarterly earnings report to finish."
Device manufacturers: "We'll rifle through your photos on a weekly basis, just to see if you've got some banned propaganda. Did I say propaganda? I meant child porn, that's harder to argue with. The algorithm is the same though, and just how the Australian government put uncomfortable information leaks onto the banned CP list, so will your government. No, you can't check the list! You'll have to just trust us."
Search engines: "Tiananmen Square is located in Beijing China. Here's a cute tourist photo. No further information available."
Online Maps: "Tibet (China). Soon: Taiwan (China)."
Media distributors: "We'll go into your home, rifle through your albums, and take the ones we've stopped selling. Oh, not physically of course. No-no-no-no, nothing so barbaric! We'll simply remotely instruct your device to delete anything we no longer want you to watch or listen to. Even if you bought it from somewhere else and uploaded it yourself. It matches a hash, you see? It's got to go!"
Governments: "Scan a barcode so that we can keep a record of your every movement, for public health reasons. Sure, Google and Apple developed a secure, privacy-preserving method to track exposures. We prefer to use our method instead. Did we forget to mention the data retention period? Don't worry about that. Just assume... indefinite."
Re: The Problem with Perceptual Hashes
#214This article focusses too much on the individual case, and not enough on the fact that Apple will need multiple matches to report someone. Images would normally be distributed in sets I suspect, so it is going to be easy to detect when someone is holding an offending set because of multiple matches. I don't think Apple are going to be concerned with a single hit. Here in the news offenders are reported as holding man…
If it does, you could download the wrong zip and instantaneously be over their threshold.
Re: The Problem with Perceptual Hashes
#215Earlier quoted context omitted.
The post office scans your mail through various machines in transit. We accept that when we put the mail in the mailbox. What if the post office announced they were installing a man with a scanning machine in your home who would scan your letters before they left your house? It's the same outcome. The same process. Just inside your house instead of out in the mail system. They're exactly the same, except somehow it's…
> The post office scans your mail through various machines in transit. That is a totally bogus comparison. The post office 100% does NOT can the content of every piece mail they handle. Not even close to the same scenario as Apple/governments being able to continually and silently check your phone/photo library for images on their watch list.
I agree that data content scanning is more invasive than physical scanning. It was an intentionally simplistic example not meant to defend Apple.
Re: The Problem with Perceptual Hashes
#216Earlier quoted context omitted.
What has changed is the inclusion of spyware technology on the device that can be weaponised to basically report on anything. Today it's only geared toward iCloud and CSAM. How many lines of codes do you think it will take before it scans all your local pictures? How hard do you think it will be for an authoritarian regime like China, that Apple bends over backwards to please, to start including other hashes that are…
We gotta stop with the China bogeyman every time a privacy issue comes up. This is a feature designed by an American company for American government surveillance purposes. China is perfectly capable of doing the same surveillance or worse on its own citizens, with or without Apple. China has nothing to do with why American tech is progressively implementing more authoritarian features in a supposedly democratic count…
We're talking about China taking advantage of this integrated technology to increase control over its population through backdoors like these.
China already imposes that all data from Chinese users be located in China and readily accessible and mined by the authorities[1].
Apple is willing to bow to these regimes because it has substantial supply-chain interests there and it sells hundred of millions of devices. A boon to both Apple and the local government.
[1]:https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
Re: The Problem with Perceptual Hashes
#217The problem of hash or NN based matching is, the authority can avoid explaining the mismatch. Suppose the authority want to false-arrest you. They prepare a hash that matches to an innocent image they knew the target has in his Apple product. They hand that hash to the Apple, claiming it's a hash from a child abuse image and demand privacy-invasive searching for the greater good. Then, Apple report you have a file th…
Well, presumably at that point, someone in that position would just reveal their own files with the hash an prove to the public that they weren't illegal. Sure, it would be shitty to be forced to reveal your private information that way, but you would expose a government agency as fabricating evidence and lying about the contents of the picture in question to falsely accuse someone. It seems like that would be a scan…
That's the problem: the terrible asymetry. The same one you find with TOS, or politicians working for lobbists.
Re: The Problem with Perceptual Hashes
#218Re: The Problem with Perceptual Hashes
#219This article focusses too much on the individual case, and not enough on the fact that Apple will need multiple matches to report someone. Images would normally be distributed in sets I suspect, so it is going to be easy to detect when someone is holding an offending set because of multiple matches. I don't think Apple are going to be concerned with a single hit. Here in the news offenders are reported as holding man…
Does it scan files within archives? If it does, you could download the wrong zip and instantaneously be over their threshold.
Re: The Problem with Perceptual Hashes
#220Earlier quoted context omitted.
This example changes with regards to emotional weight if you remove "a man" and leave it at just "a scanning machine". There is no human scanning your photos on an iPhone, so let's compares apples to apples here. If that scanning machine didn't reveal the contents of my mail, and then ensured that it wasn't able to be given out in-transit? Yeah, I'd potentially be fine with it - but I'll leave this answer as a hypoth…
But the barrier between “only happens for iCloud” and “happens for all photos on device” has been reduced to a very small barrier. Before it was the photos actually being sent to a separate server by my choice, now it’s Apple saying their on-device tool only runs given criteria X. And on a second note I think people are allowed to be freshly concerned at the idea of Apple scanning photo libraries given a government-p…
I'm just very tired of people (not necessarily you) spouting off as if the functionality is new. It dilutes an otherwise important conversation. So many of the threads on this site are just people privacy LARPing.