Earlier quoted context omitted.
And how would anyone know that those gray blobs match child porn?
Exactly, that’s the scary abuse scenario where people could send a whole load of this stuff to e.g a political enemy.
Hash collision in Apple NeuralHash model
461–470 of 725 posts
Re: Hash collision in Apple NeuralHash model
#462Earlier quoted context omitted.
Except that Apple will review the photos once you've matched 30 of them, so it's still not possible for the government to misuse it.
So some underpaid contractor reviewing "visual derivatives" that may or may not be CSAM completely prevents governments from misusing this in your mind?
Re: Hash collision in Apple NeuralHash model
#463Re: Hash collision in Apple NeuralHash model
#464Earlier quoted context omitted.
Sure! Lots! My Instagram account is mainly weed (legal in Canada) and Instagram censorship hits my content occasionally (because illegal cannabis selling on the platform is rampant).
And how many of those billions will Apple hash and check for?
Re: Hash collision in Apple NeuralHash model
#465Earlier quoted context omitted.
I'm not sure what you mean. If we are talking about Apple's new feature, they will not even be alerted until you have enough matches. And the police probably won't be using any neural hashes if they have access to your device, so I'm not sure what you are talking about.
That is an Apple current policy, not any sort of law. If the FBI wants to know if there are any collisions on a particular phone, that will be shared. If the FBI wants to know of all single collisions, that too must be shared. A corporation's internal policy decisions are nothing when faced with a government official carrying a warrant. If they have data indicating possible crimes, no matter how small, they can be fo…
Re: Hash collision in Apple NeuralHash model
#466I was curious how big of a deal this would be in a real-world attack (eg could someone use this to DDoS Apple's human reviewers?) so I ran the colliding images through another feature extraction model, OpenAI's CLIP, to see if they also fooled it. They don't; I think it'd be much harder to create an image that both matches the NeuralHash of a CSAM image and also fools a generic model like CLIP as a sanity check for b…
Remember, anything under 18 is treated the exact same way from a legal perspective, and once discovered Apple must report.
So there is an adversarial attack in that you find legal porn of say 18 year old pussy closeups, disturb it to match CSAM with the neural hash, and send it to your enemies.
The Apple employee will verify a match. The Feds will raid your target and imprison them, and reputationally tarnish them for life.
Now think about how Pegasus can remotely modify your photos. And think about Julian Assange's sexual assault allegations that were admitted to be fabrications by the accuser.
Re: Hash collision in Apple NeuralHash model
#467Re: Hash collision in Apple NeuralHash model
#468Earlier quoted context omitted.
I can guarantee nobody will see the inside of a courtroom, on charges of possession and distribution of child porn for possessing multiple images of grey noise (unless there is some steganography going on).
What if it is legal pornography of 21 year olds but disturbed to collide with CSAM? You are aware even defence lawyers are not allowed to look at alleged CSAM material in court right?
What if the legal porn of a 21 year old that triggered the collision match looked really really really close? So close that a human can not distinguish between the image of a 12 year old being raped that they have in their database and your image? Well then you might have a problem, legal and otherwise.
> defence lawyers are not allowed to look at alleged CSAM material in court right
I know this is not true in many countries, but cant speak for your country.
Re: Hash collision in Apple NeuralHash model
#469Earlier quoted context omitted.
A vulnerability by itself is not that dangerous, but in combination with a sophisticated attack, or another vulnerability can be disastrous. State actors have the resources to exploit a number of unknown bugs in combination with this collision to have Apple's systems flag persons of interest. This, combined with human error during the manual review process might result in someone getting reported. Seeing as twitter (…
> State actors have the resources You can end the conversation right there. If you are up against a state actor, you have already lost.
Re: Hash collision in Apple NeuralHash model
#470Earlier quoted context omitted.
Hash collisions dont need grey images You can take a perfectly normal image , play around with a range of its individual pixels, to get collisions too. So someone might forward you your personal pics from your meeting with them and its pixels might get edited by the messenger app you use to save the picture into your photos to specifically collide its hash with a csam image, while to you the image will look perfectly…
> So someone might forward you your personal pics from your meeting with them and its pixels might get edited by the messenger app you use to save the picture into your photos to specifically collide its hash with a csam image, while to you the image will look perfectly normal Ok, but then that image is already not private, if I've been sending it to someone that could do that. > This is one example , lets say you 10…
Youre right indeed , you can protect yourself from this , but all the measures you mentioned are settings which are non-default,
A lot of apps annoyingly turn it on by default , while HN users can turn it off , I doubt my grandparents will go through the same effort or understand it.
Question is , why should they ? Their phone was supposed to help them , not be a snitch and a snitch with flaws at that.
Why should my non-tech friends train to protect themselves from “their” phones.
Human society has always tried to place co-existence and trust on their fore frontier , their ideal wish for society.
This makes us and our devices act as snitches to each other.
Snitch for whom ? Apple ?
But yes youre right , that if its normal image it will stop at review level , (altho thats on the condition you trust apple employees who are reviewing them)
I just still dont think its a good idea to even reach till this step.
This just makes our computers feel more hostile