Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

381–390 of 725 posts

Re: Hash collision in Apple NeuralHash model

#381

Earlier quoted context omitted.

Since, as I have read, Microsoft and Google already do this, where are all the illicit cop take-downs? I have not heard of any.

They are scanning images on online accounts, stuff that is stored on their systems and system files on machines (files they own). They are not, from what I have read, scanning customer-owned images stored on customer-owned devices.

Every AV (antivirus) software system scans customer-owned files on customer-owned devices. So the question is the same: if it’s easy for law enforcement to deputize such a system, where is the flood of cases built off of evidence gathered this way?

Re: Hash collision in Apple NeuralHash model

#382
post #362
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

I actually want Apple to stand ground and implement this feature. Like you said the double down on PR and marketing was enough for me. I may not be dumping all iOS and Mac for now. But it was " the " definite signal and evidence this is no longer the old Steve Jobs's Apple. It is like watching Mark Zuckerberg talking about privacy when he doesn't understand anything about it. ( Or more like he has a different underst…

[deleted]

Re: Hash collision in Apple NeuralHash model

#383

Neuralhashes are far from my area of expertise, but I've been following Apple closely ever since its foundation and have probably watched every public video of Craig since the NeXT take over and here is my take: I've never seen him so off balance before as in his latest interview with Joanna Stern. Not even in the infamous “shaking mouse hand close up” of the early days. Whatever you say about Apple, they are an extr…

Can you link the interview please?

Re: Hash collision in Apple NeuralHash model

#384
post #255

Earlier quoted context omitted.

Why even keep Apple in the loop? Why not just allow government to submit scanning models directly? Which Apple will dutifully install and run, because they're required by local laws.

> " Which Apple will dutifully install and run, because they're required by local laws. " Which Apple have stated that they won't do, and have designed the system so they can't do that without it being found out: https://news.ycombinator.com/item?id=28221082 Can't you at least post accurate information about this system and support outrage based on facts instead of fantasy?

> Which Apple have stated that they won't do

For your random off-of-the-mill dictatorship, yes.

For the US? EU? China? India? No way they can refuse such a request from these markets. And if they could and get away with it, it would be a very worrying situation in itself regarding (democratic) control of government over global mega corporations.

Re: Hash collision in Apple NeuralHash model

#385

Earlier quoted context omitted.

Who cares that Bad Company XYZ already well known for not caring about customer privacy does it? Wouldn't you want to push back against even more increasing surveillance? Apply was beating the drum of privacy while it was convenient, wouldn't you want to hold their feet to the fire now that they seemed to do a U-turn?

Their point is that the attack vector being described isn’t new, as CSAM could already be weaponized against folks, and we never really ever hear if that happening. So the OP is simply saying that perhaps it’s not an issue we need to worry about. I happen to agree with them.

So in your mind, because so far we've seen no evidence that this has been abused, it's nothing to worry about going forward? And that making an existing situation even more widespread is also completely OK?

Re: Hash collision in Apple NeuralHash model

#386
post #362
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

I actually want Apple to stand ground and implement this feature. Like you said the double down on PR and marketing was enough for me. I may not be dumping all iOS and Mac for now. But it was " the " definite signal and evidence this is no longer the old Steve Jobs's Apple. It is like watching Mark Zuckerberg talking about privacy when he doesn't understand anything about it. ( Or more like he has a different underst…

Chances are by the next sales report it will be forgotten. Let's see how deep the memory hole goes.

Re: Hash collision in Apple NeuralHash model

#387
post #78

Earlier quoted context omitted.

Right. So, sending actual CSAM would also work as an attack, but would be detected by the victim and could be corrected (delete images). But a conceivable novel avenue of attack would be to find an image that: 1. Does not look like CSAM to the innocent victim in the original 2. Does match known CSAM by NeuralHash 3. Does look like CSAM in the "visual derivative" reviewed by Apple, as you highlight.

Reading the imagine scaling attack article, it’s looks like it’s pretty easy to manufacture an image that: 1. Looks like an innocuous image, indeed even an image the victim is expecting to receive. 2. Downscales in such a way to produce a CSAM match. 3. Downscales for the derivative image to create actual CSAM for the review process. Which is a pretty scary attack vector.

Where does it say anything that indicates #1 and #3 are both possible?

Re: Hash collision in Apple NeuralHash model

#388

Earlier quoted context omitted.

It’s incredibly stupid because your Apple ID will get terminated for abusing Apple services.

There are applications which automatically save images sent to you to your camera roll (such as Whatsapp, IIRC). How can Apple prove you put them there intentionally? Granted, they most likely won't care, but it's a legitimate attack vector.

You’re right that it’s a valid attack upon the people Apple pays to review matched images before invoking law enforcement, but no harm comes to the recipient in that model, unless they receive real legitimate CSAM and don’t report it to the authorities themselves.

Attempted entrapment and abuse of computing systems, which is an uncomfortable way to phrase the WhatsApp scenario, would be quite sufficient cause for a discovery warrant to have WhatsApp reveal the sender’s identity to Apple. Doesn’t mean they’d be found guilty, but WhatsApp will fold a lot sooner than Apple, especially if the warrant is sealed by the court to prevent the sender from deleting any CSAM in their possession.

A hacker would say that’s all contrived nonsense and anyways it’s just SWATting, that’s no big deal. A judge would say that’s a reasonable balance of protecting the sender from being dragged through the mud in the press before being indicted and permitting the abused party (Apple) to pursue a conviction and damages.

I am not your lawyer, this is not legal advice, etc.

Re: Hash collision in Apple NeuralHash model

#389

Earlier quoted context omitted.

If Apple launches a system for comparing iCloud uploads to a third-party hash list, then adding the ability to do targeted scans for arbitrary additional law-enforcement-provided hashes would also be a form of creating capability. The people getting pissed off about this have not, so far as I’ve seen, demonstrated why the law would require Apple to add the capability for targeted scans of arbitrary hashes. Police can…

>> They can’t use a warrant to force you to videotape someone Maybe in the narrow context of US domestic child pornography investigations. In the wider world it is very possible for police to force such things. Even in the US, CALEA demands that certain companies develop abilities that they would not normally want (interception). The principal that US companies need not actively participate in police investigations d…

Can you explain why you think CALEA would apply to what Apple announced?

And why such application would have had to wait until Apple announced this? In other words, if the law can force Apple to do things in general, why does the law need to wait for Apple to announce certain capabilities first?

Re: Hash collision in Apple NeuralHash model

#390

Earlier quoted context omitted.

Yes. Lavabit. Those warrants demanded that Lavabit alter its system to capture passwords and/or decrypt stored email. Lavbit instead decided to stop operating and delete everything rather than comply. Such warrants have not been fully tested in courts but they do exist.

IIRC they gave up the information AND they shut down

They handed over a hard copy of their private key, a printout. The FBI went to court to demand a machine-readable copy. Then they shut down.
Post reply on HN