Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

351–360 of 440 posts

Re: The Problem with Perceptual Hashes

#351

Earlier quoted context omitted.

What about trolling. Assume 4chan figures out apples algorithm. What now happens when they start generating memes that happen to match known child pornography? Will anyone who saves those memes (or repost them to reddit/facebook) be flagged? What will apple do once flagged false positive photos go viral?

>> Will anyone who saves those memes (or repost them to reddit/facebook) be flagged? Shouldn't they be?

The point made was that there are always flaws in these sorts of approaches that lead to false positives. If you can discover the flawed pattern(s) that leads to false positives and engineer them into seemingly harmless images, you can quite literally do what OP I'd suggesting. It's a big IFF but it's not theoretically impossible.

The difference between this and hashes that require image data to be almost identical is that someone who accidently sees it can avoid and report it. If I can make cat photos that set off Apple's false positives, then there's a lot of people who will be falsely accused of propagating child abuse photos when they're really just sending cat memes.

Re: The Problem with Perceptual Hashes

#352
> At my company, we use “perceptual hashes” to find copies of an image where each copy has been slightly altered.

Kind of off topic, does anyone happen to know of some good software for doing this on a local collection of images? A common sequence of events at my company:

1. We're designing a website for some client. They send us a collection of a zillion photos to pull from. For the page about elephants, we select the perfect elephant photo, which we crop, lightly recolor, compress, and upload.

2. Ten years later, this client sends us a screenshot of the elephant page, and asks if we still have a copy of the original photo.

Obviously, absolutely no one at this point remembers the name of the original photo, and we need to either spend hours searching for it or (depending on our current relationship) nicely explain that we can't help. It would be really great if we could do something like a reverse Google image search, but for a local collection. I know it's possible to license e.g. TinEye, but it's not practical for us as a tiny company. What I really want is an open source solution I can set up myself.

We used Digicam for a while, and there were a couple of times it was useful. However, for whatever reason it seemed to be extremely crash-prone, and it frequently couldn't find things it really should have been able to find.

Re: The Problem with Perceptual Hashes

#353
post #247
post #155

Earlier quoted context omitted.

Well, presumably at that point, someone in that position would just reveal their own files with the hash an prove to the public that they weren't illegal. Sure, it would be shitty to be forced to reveal your private information that way, but you would expose a government agency as fabricating evidence and lying about the contents of the picture in question to falsely accuse someone. It seems like that would be a scan…

”Sorry, but collisions happen with all hashing algorithms, and you can’t prove otherwise. It is just a matter of time. Nothing to see here.”

Well, not all hashing algorithms but all interesting or considered useful hashing algorithms, probably.

When dealing with say countable infinite sets you can certainly create a provable unique hash for each item in that set. The hash won't be interesting or useful. E.g. a hash that indexes all the integers n with a hashing function h(n+1)... so every integer you hash will be that value plus one. But this just being pedantic and wanting to walk down the thought.

Re: The Problem with Perceptual Hashes

#355
post #271

> These cases will be manually reviewed. That is, according to Apple, an Apple employee will then look at your (flagged) pictures. I'm surprised this hasn't gotten enough traction outside of tech news media. Remember the mass celebrity "hacking" of iCloud accounts a few years ago? I wonder how those celebrities would feel knowing that some of their photos may be falsely flagged and shown to other people. And that we…

That really alarmed me. I don't think a hosting provider like Apple should have a right to access private pictures, especially just to enforce copyright.

Edit: I see now it's not about copyright, but still very disturbing.

Re: The Problem with Perceptual Hashes

#356

Earlier quoted context omitted.

In this case, they're explicitly required by law to report this material if it shows up on their servers.

Well, Jim Crow legislation was also a thing once.

This definitely feels like a bad solution provoked by a dubious law; the complaints should be directed at our elected officials, not Apple.

Re: The Problem with Perceptual Hashes

#357

> At my company, we use “perceptual hashes” to find copies of an image where each copy has been slightly altered. Kind of off topic, does anyone happen to know of some good software for doing this on a local collection of images? A common sequence of events at my company: 1. We're designing a website for some client. They send us a collection of a zillion photos to pull from. For the page about elephants, we select t…

https://pypi.org/project/ImageHash/

Re: The Problem with Perceptual Hashes

#358
post #285

Earlier quoted context omitted.

The article posted, as well as many others we've seen recently, demonstrate that collisions are possible, and most likely inevitable with the number of photos to be scanned for iCloud, and Apple recognizes this themselves. It doesn't necessarily mean that all flagged photos would be of explicit content, but even if it's not, is Apple telling us that we should have no expectation of privacy for any photos uploaded to…

Apple already use the same algorithm on photos in email, because email is unencrypted. Last year Apple reported 265 cases according to the NYT. Facebook reported 20.3 million. Devolving the job to the phone is a step to making things more private, not less. Apple don’t need to look at the photos on the server (and all cloud companies in the US are required to inspect photos for CSAM) if it can be done on the phone, r…

Am I missing something? Apple says they literally scan stuff locally on your iCrap now and call the police on you if you have $badstuff. Nobody should be having their data scanned in the first place. Is iCloud unencryped? Such a thing exists in 2021? I've been using end to end crypto since 2000. I don't understand why consumers want their devices to do all kinds of special non-utilitarian stuff (I mean I totally understand, it's called politics).

This new iCrap is like a toaster that reports you if you put illegally imported bread in it. It will be just like the toaster which will have no measureable impact on illegal imports. Even if $badguys are so dumb to continue using the tech (iCloud???) and lots go to jail, lots more will appear and simply avoid the exact specific cause that sent previous batch to jail. They do not even thave to think.

The problem with all this is that everyone is applauding Apple for their bullshit, and so they will applaud the government when they say "oh no, looks like criminals are using non-backdoored data storage methods, what a surprise! we need to make it illegal to have a data storage service without going through a 6 month process to setup a government approved remote auditing service".

Then there's also the fact that this is all a pile of experimental crypto [1] being used to solve nothing. Apple has created the exact situation of Cloudflare Pass: they pointlessly made $badip solve a captcha to view a read-only page, and provided a bunch of experimental crypto in a browser plugin to let him use one captcha for multiple domains (they would normally each require their own captcha and corresponding session cookie). They later stopped blocking $badip all together after they realized they are wrong (this took literally 10 years).

1. https://www.apple.com/child-safety/ "CSAM detection" section

Re: The Problem with Perceptual Hashes

#359

Earlier quoted context omitted.

Airport baggage drug dogs must obviously have far fewer false positives than that. So alerting on everything can't be the state of the art.

https://reason.com/2021/05/13/the-police-dog-who-cried-drugs... > Similar patterns abound nationwide, suggesting that Karma's career was not unusual. Lex, a drug detection dog in Illinois, alerted for narcotics 93 percent of the time during roadside sniffs, but was wrong in more than 40 percent of cases. Sella, a drug detection dog in Florida, gave false alerts 53 percent of the time. Bono, a drug detection dog in Vi…

I was pulled over in West Baton Rouge in 2009, we were driving east in an empty rental box truck after helping a friend move back to Tx. It was 1am, we were pulled over on a BS pretense (weaving across lanes when we signaled a lane change because they had someone else pulled over, so we obeyed the law of pulling over a lane to give them room). I denied their request to search the truck, they had no reason. They called the drug dog, who after the third walk around, "signaled" drugs at the right front tire (after having thir leash jerked). They then "had cause" to search the truck. After finding two small suitcases with clothes (exactly what we told them they'd find), the main cop got really angry with me for "making a mockery of the south", threw the keys at me and told us to GTFO.

I'm 100% convinced drug dogs are trained to "signal" falsely at certain things like a leash tug. It's all BS.

Re: The Problem with Perceptual Hashes

#360
post #216

Earlier quoted context omitted.

We gotta stop with the China bogeyman every time a privacy issue comes up. This is a feature designed by an American company for American government surveillance purposes. China is perfectly capable of doing the same surveillance or worse on its own citizens, with or without Apple. China has nothing to do with why American tech is progressively implementing more authoritarian features in a supposedly democratic count…

No-one was suggesting that China was behind this move. We're talking about China taking advantage of this integrated technology to increase control over its population through backdoors like these. China already imposes that all data from Chinese users be located in China and readily accessible and mined by the authorities[1]. Apple is willing to bow to these regimes because it has substantial supply-chain interests…

> We're talking about China taking advantage of this integrated technology to increase control over its population through backdoors like these. ... A boon to both Apple and the local government.

But still: Secondary. The main effect of even mentioning it is to deflect attention away from Apple.

Post reply on HN