Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

281–290 of 440 posts

Re: The Problem with Perceptual Hashes

#282
post #276
post #246

Earlier quoted context omitted.

Corruption. Lack of evidence on some other cases. Personal revenge. Who knows, but list is big.

Ok but but what ends?

Imagine you’re a journalist uncovering corruption perpetrated by the police force or a politician. Can you see how they would be incentivised to arrest you on false charges to halt the investigation and protect themselves?

Re: The Problem with Perceptual Hashes

#283
post #110

The problem of hash or NN based matching is, the authority can avoid explaining the mismatch. Suppose the authority want to false-arrest you. They prepare a hash that matches to an innocent image they knew the target has in his Apple product. They hand that hash to the Apple, claiming it's a hash from a child abuse image and demand privacy-invasive searching for the greater good. Then, Apple report you have a file th…

> like the dogs which conveniently bark at police's secret hand sign This isn't necessary; the state of the art is for drug dogs to alert 100% of the time. They're graded on whether they ever miss drugs. It's easy to never miss.

Dogs are used to protect police from accusations of racism and profiling.

Re: The Problem with Perceptual Hashes

#284
post #244

Earlier quoted context omitted.

> Suppose the authority want to false-arrest you. Why would they want that?

Oh, sweet, naive child.

Be kind[1]. Not everyone will have a life experience or knowledge similar to yours. Someone looking to fill the gaps in their knowledge in good faith should be encouraged, not ridiculed.

[1]: https://news.ycombinator.com/newsguidelines.html

Re: The Problem with Perceptual Hashes

#285
post #271

> These cases will be manually reviewed. That is, according to Apple, an Apple employee will then look at your (flagged) pictures. I'm surprised this hasn't gotten enough traction outside of tech news media. Remember the mass celebrity "hacking" of iCloud accounts a few years ago? I wonder how those celebrities would feel knowing that some of their photos may be falsely flagged and shown to other people. And that we…

They wouldn't be falsely flagged. It doesn't detect naked photos, it detects photos matching real confirmed CSAM based on the NCMEC's database.

The article posted, as well as many others we've seen recently, demonstrate that collisions are possible, and most likely inevitable with the number of photos to be scanned for iCloud, and Apple recognizes this themselves.

It doesn't necessarily mean that all flagged photos would be of explicit content, but even if it's not, is Apple telling us that we should have no expectation of privacy for any photos uploaded to iCloud, after running so many marketing campaigns on privacy? The on-device scanning is also under the guise of privacy too, so they wouldn't have to decrypt the photos on their iCloud servers with the keys they hold (and also save some processing power, maybe).

Re: The Problem with Perceptual Hashes

#286

Earlier quoted context omitted.

Couldn't the hack just be as simple as sending someone an iMessage with the images attached? Or somehow identify/modify non-illegal images to match the perceptual hash -- since it's not a cryptographic hash.

Does iCloud automatically upload iMessage attachments?

Doesn't need to, the detection is client side at first.

Re: The Problem with Perceptual Hashes

#287
post #224

Earlier quoted context omitted.

You can reveal your files and people can accuse you you deleted the incriminating ones.

Not if you show the file that matches the perceptual hash that "caught" you.

So Apple-users can no longer delete any pictures since Apple might already have reported that photo you accidentally took of your thumb as CP.

Re: The Problem with Perceptual Hashes

#288
post #143

Apple’s documents said they require multiple hits before anything happens, as the article notes. They can (and have) adjusted that number to any desired balance of false positive to negatives. How can they say it’s 1 in a trillion? You test the algorithm on a bunch of random negatives, see how many positives you get, and do one division and one multiplication. This isn’t rocket science. So, while there are many argum…

I was unhappy to find this comment so far down and even unhappier to see it downvoted. I'm not a fan of the decrease in privacy Apple is creating with this move but I think this forum has gotten its feelings for Apple caught up with its response to a completely valid criticism of an anti-Apple article. To explain things even further, let's say that the perceptual algorithm makes a false positive 1% of the time. That…

At this point, the COVID vaccines seem to barely have majority support on HN, and “cancel culture” would win any survey on our times’ top problems, beating “women inventing stories of rape’ and “the black guy mentioning something borderline political at work, just because he’s paid 5/8th as much as others”.

An inability to follow even the most elementary argument from statistics isn’t really surprising. Although I can’t quite say if it’s actual inability, or follows from the fact that it supports the wrong outcome.

Re: The Problem with Perceptual Hashes

#290

Earlier quoted context omitted.

Do you really believe that if they scan your photo library at 10am and don't get any false positives, another scan five hours later, with no changes to the library, has the same chance of getting false positives as the first one, independent of that result?

Even if the library doesn’t change, doesn’t the possibility of the list of “bad” hashes changing exist? I.e., in your example, a new hash is added to by Apple to the list at 11:30am, and then checked against your unchanged library.

Oh god have mercy on whatever has happened to these people…
Post reply on HN