Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

241–250 of 725 posts

Re: Hash collision in Apple NeuralHash model

#241
post #149

Earlier quoted context omitted.

> All criminal accusations, including true ones, should be treated as false until the accused is proven guilty. No, they need to be treated as unproven, a very critical difference. Just to be clear, witness testimony, including testimony FROM THE VICTIM, is evidence of the crime. Just for some reason, in rape cases, we go all wonky with this principle.

1. By the public at large it should not be treated in any regard, false or not. 2. The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom. 3. The 'believe the victims' activists however are rightfully (IMHO) suggesting to break principle #2 because there is institutional and systemic supression of t…

> The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom.

This is completely wrong. If the state treated all accusations as untrue prior to conviction, they would not send armed men to haul you to prison, bar you from release unless you can bail yourself out (or sometimes not at all), and not have a prosecutor charge you with a crime.

This is no petty distinction. In order to function in its judiciary role, the state in fact must distinguish between plausibly true accusations and not plausible accusations, and must treat certain plausibly true accusations as "unproven" but not untrue, and take steps to make sure the accused does not flee into another country or commit further crimes.

Re: Hash collision in Apple NeuralHash model

#242
post #199

Earlier quoted context omitted.

> I’ve dumped the entire iOS ecosystem in the last week. Not to go off topic from your main point, but what did you move to?

Linux, dumbphone, DSLR. This was the final straw on a planned exit to be honest.

That's interesting, I may just do the same thing as well - the camera is the largest thing of why I want to be on an phone.

I may just go LineageOS.

Re: Hash collision in Apple NeuralHash model

#243
post #191

Earlier quoted context omitted.

Do you have access to darknet child pornography trading networks? I don't.

OK, now I'm curious. How does darknet stuff actually work? Is there some darknet search engine that you access over Tor and type whatever illegal thing you seek such as "child porn" or "stolen credit cards" or "heroin" or "money laundering" into and it points you to providers of those illegal goods and services reachable over some reasonably secure channel? Or is it one of those things where someone already using a p…

dark.fail indexes darknet markets, but all the ones I've seen ban CSAM

Re: Hash collision in Apple NeuralHash model

#245
post #138

Earlier quoted context omitted.

The speculation that I've seen here is that Apple is rolling this out ahead of a future announcement that iCloud uploads will be encrypted.

Are they not? I would've thought that with Apple advertising privacy and security they would at least encrypt iCloud uploads.

iCloud uploads are encrypted in transit and on their servers, but they are not E2E encrypted. Apple has the decryption keys

Re: Hash collision in Apple NeuralHash model

#246

Earlier quoted context omitted.

> and there is no law who requires them to "scan" on device Yet . The demands by "concerned parents" (aka fronts for secret services, puritans/other religious fundamentalists and law-and-order hardliners) to "do something against child porn" have grown ever more strong and insane over the last years. (And you can bet that what is used on CSAM will immediately be used to go after legal pornography, sex work, drug enfo…

Why would they extend the CSAM scanner? It would be much simpler to just use all the OCR and image classification functions they have already deployed. CSAM scanning is only useful for areas where Apple really doesn't want to even look at the actual material until they are extremely certain that it's a match. If they want to detect anti-government propaganda or something, there would be no such concerns, they would j…

>> useful for areas where Apple really doesn't want to even look at the actual material

Correct. It has plausible deniability built in. Apple is unable to verify that the images the government are looking for are actually CSAM. They could be political. They could be protest images. They could be Winnie the Pooh. Apple can plead ignorance as it blindly scans for whatever the requesting government asks it to scan for.

Nobody really minds that this system is going to be used for CSAM. What everyone recognizes is how ripe this system is for abuse, how easily it can be leveraged by oppressive governments. And Apple can play the innocent.

Re: Hash collision in Apple NeuralHash model

#247
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

> I’ve dumped the entire iOS ecosystem in the last week. Not to go off topic from your main point, but what did you move to?

I'm not the one you responded to, but did something similar and feel like sharing:

- Desktop: Manjaro Gnome, for that amazing macOS-like desktop. It even does the 3 finger swipe up to see all your apps with Apple's Touchpad.

- Phone: OnePlus 8T with microG variant of LineageOS (alternatives: Pixel line-up), because that allows me to still receive push notifications. I have over 40 apps and only found 1 that didn't work so far (which is Uber Eats, because they seem to require Google Advertisement ID). I pushed a modified Google Camera app to it, so my camera is better supported. I think only 3 out of 4 cameras are working, but I don't care.

- Watch: Amazfit GTR 2e with the official app. Alternatively it should work with Gadgetbridge if you don't want to use the offical app ("Zepp"). Amazfit GTR 2 is a better option if you want it to have WiFi and want to store music on it.

Re: Hash collision in Apple NeuralHash model

#248
post #106

Earlier quoted context omitted.

Don't feel bad at all. I dumped macOS entirely from production workflow. I cannot work on computer knowing that something is "scanning" me and I am glad that my "paranoid" feeling stopped me to upgrade all office macs. Billionaires at (Apple) don't give a flying f*ck about users privacy. It is all vertical integration in the name of world domination. How removed from reality they are. This is week after Pegasus/NSO a…

>> there is no law who requires them to "scan" on device. There is. Apple must comply with warrant requests. If they have a system for scanning files on customer devices they must, if presented with a warrant, allow police access to that system. We can quibble about jurisdictions and constitutional protections, but if the FBI shows up with a federal warrant demanding that Apple remotely scan Sandworm101's phone for a…

That's an incomplete statement.

Currently, they must comply with warranty requests by scanning if they have the ability to scan.

If they have no such ability (say, because they designed their phones from a privacy-first perspective), the law makes no requirement that they create such a capability.

And that's what pisses people off about this.

Re: Hash collision in Apple NeuralHash model

#250
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

It can't. No actions are taken on hashes alone. The procedure is, if an account uploads some number of images with matching hashes, those images are verified by a human. This can attack that system itself, though, by overloading those humans with too much work looking at random noise, but that requires quite a large organised effort. It also requires getting a hold of actual blacklisted hashes, which I doubt anyone h…

the blacklisted hashes are openly given to thousands of companies by a foundation called the National Center for Missing & Exploited Children, in both PhotoDNA and MD5 versions of the hashes.

Yes, I can't give you an open link, but I imagine at least hundreds of thousands of people have access to download them. Some companies with better security than others

It only takes 1 guy to sell it to an NSO-type company, who would then use it to target attacks for $$$

Post reply on HN