Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

251–260 of 440 posts

Re: The Problem with Perceptual Hashes

#251

Earlier quoted context omitted.

Even still this has to go to the FBI or other law enforcement agency, then it’s passed on to a prosecutor and finally a jury will evaluate. I have a tough time believing that false positives would slip through that many layers. That isn’t to say CASM scanning or any other type of drag net is OK. But I’m not concerned about a perceptual hash ruining someone’s life, just like I’m not concerned about a botched millimete…

>>I have a tough time believing that false positives would slip through that many layers. I don't, not in the slightest. Back in the days when Geek Squad had to report any suspicious images found during routine computer repairs, a guy got reported to the police for having child porn, arrested, fired from his job, named in the local newspaper as a pedophile, all before the prosecutor was actually persuaded by the defe…

> Back in the days when Geek Squad had to report any suspicious images [...] which turned out to be his own grand children

Do you have a link to sources for this case? I've had a look and can't see anything that matches right now.

Re: The Problem with Perceptual Hashes

#252

Earlier quoted context omitted.

> The opt out of this is to not use iCloud Photos. Wasn’t yesterday’s version of this sorry about how Apple is implementing this as a client side service on iPhones? https://news.ycombinator.com/item?id=28068741 I don’t know if the implication there is “don’t use the stock Apple camera app and photo albums”, or “don’t store any images on yours Phone any more” if they are scanning files from other apps for perceptual…

...yes, and the client-side check is only run before syncing to iCloud Photos, which is basically just shifting the hash check from before upload (client side) to after upload (server side).

Thanks for this clarification. This, I think, is an important aspect that seems to often get overlooked.

Apple's explanation:

Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the known CSAM hashes. This matching process is powered by a cryptographic technology called private set intersection, which determines if there is a match without revealing the result. The device creates a cryptographic safety voucher that encodes the match result along with additional encrypted data about the image. This voucher is uploaded to iCloud Photos along with the image.

Using another technology called threshold secret sharing, the system ensures the contents of the safety vouchers cannot be interpreted by Apple unless the iCloud Photos account crosses a threshold of known CSAM content. The threshold is set to provide an extremely high level of accuracy and ensures less than a one in one trillion chance per year of incorrectly flagging a given account.

https://www.apple.com/child-safety/

Re: The Problem with Perceptual Hashes

#253
post #125

Earlier quoted context omitted.

If images have cardinality N and hashes M and N > M, then yes, by pigeonhole principle you will have collisions regardless of hash function, f: N -> M. N is usually much bigger than M, since you have the combinatorial pixel explosion. Say images are 8 bit RGB 256x256, then you have 2^(8x256x256x3) bit combinations. If you have a 256-bit hash, then that’s only 2^256. So there is a factor of 2^(8x256x3) difference betw…

The number of possible different images doesn't matter, it's only the number of actually different images encountered in the world. This number cannot be anywhere near 2^256, that would be physically impossible.

But you cannot know that a-priori so it’s either an attack vector for image manipulation or straight up false positives.

Assume we had this perfect hash knowledge. I’d create a compression algorithm to uniquely map between images and the 256 bit hash space, which we probably agree is similarly improbable. It’s on the order of 1000x to 10000x more efficient than JPEG and isn’t even lossy.

Re: The Problem with Perceptual Hashes

#255
post #155

Earlier quoted context omitted.

Well, presumably at that point, someone in that position would just reveal their own files with the hash an prove to the public that they weren't illegal. Sure, it would be shitty to be forced to reveal your private information that way, but you would expose a government agency as fabricating evidence and lying about the contents of the picture in question to falsely accuse someone. It seems like that would be a scan…

Na they will ruin your life even if you are found innocent and pay no price for it. That's the problem: the terrible asymetry. The same one you find with TOS, or politicians working for lobbists.

Who would a company hire: the candidate with a trial for CP due to a false positive or the candidate without ?

And this is just to address the original concept of this scanning.

As many others have pointed out there is too much evidence pointing to other uses in the future.

Re: The Problem with Perceptual Hashes

#256

Earlier quoted context omitted.

The crypto here is for the private set intersection, not the hash. So your device has a list of perceptual (non-cryptographic) hashes of its images. Apple has a list of the hashes of known bad images. The protocol lets them learn which of your hashes are in the “bad” set, without you learning any of the other “bad” hashes, and without Apple learning any of the hashes of your other photos.

Well therein lies the problem: perceptual hashes don't produce an exact result. You need to compare something like the hamming distance (as the article mentions) of each hash to decide if it's a match. Is it possible to perform private set intersection where the comparison is inexact? I.e., if you have two cryptographic hashes, private set intersection is well understood. Can you do the same if the hashes are close,…

Would love to learn more about actual algorithms that could be used to do something like this (private set intersection with approximate matching) if they exist.

Re: The Problem with Perceptual Hashes

#257

Fortunately I have a cisco router and enough knowledge to block the 17.0.0.0/8 ip address range. This combined with an openvpn vpn will block all apple services from my devices. So basically my internet will look like this: Internet CISCO ASUS ROUTER with openvpn Network The cisco router will block the 17.0.0.0/8 ip address range and I will use spotify on all my computers.

And then they switch to using Akamai or AWS IP space (like Microsoft does), so you start blocking those as well?

Re: The Problem with Perceptual Hashes

#258

If I'm reading this right? Apple is saying they are going to flag CSAM they find on their servers. This article talks about finding a match for photos by comparing a hash of a photo you're testing with a hash you have, from a photo you have. Does this mean Apple had/has CSAM available to generate the hashes?

For the purposes of this they only have the hashes, which they receive from third parties.

> on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations

https://www.apple.com/child-safety/

(Now, I do wonder how secure those third parties are.)

Re: The Problem with Perceptual Hashes

#259
post #166

What is the ratio of consumers of child pornography to the population of iPhone users? In order of magnitude, is it 1%, 0.1%, 0.001%, 0.0001%? With all the press around the announcement, this is not exactly stealth technology. Wouldn't such consumers switch platforms, rendering the system pointless?

It's clearly a marketing exercise aimed to sell products to parents and other concerned citizens. It doesn't actually need to be effective to achieve this goal. (I am not saying whether it will or won't be, just that it doesn't need to be.)

Re: The Problem with Perceptual Hashes

#260

Earlier quoted context omitted.

We gotta stop with the China bogeyman every time a privacy issue comes up. This is a feature designed by an American company for American government surveillance purposes. China is perfectly capable of doing the same surveillance or worse on its own citizens, with or without Apple. China has nothing to do with why American tech is progressively implementing more authoritarian features in a supposedly democratic count…

Ok. How about the Saudi Arabian bogeymen then? Who took Jamal Kashoggi apart with bonesaws as he screamed? Or the Israeli bogeymen who exploited his phone for them? Or the Turkish bogeymen who also a customers of that Israeli phone exploitation company? (Or Facebook who wanted to buy those tools but got turned down, because Facebook is “too far” even for NSO who happily take Saudi and Turkish money?) There are withou…

The point is that all these bogeymen distract from the actual issue, because they make government surveillance sound like something that only happens in other places... We need to wake up and realize it's happening right here at home and has been for decades
Post reply on HN