Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

481–490 of 725 posts

Re: Hash collision in Apple NeuralHash model

#481

Earlier quoted context omitted.

Why would they extend the CSAM scanner? It would be much simpler to just use all the OCR and image classification functions they have already deployed. CSAM scanning is only useful for areas where Apple really doesn't want to even look at the actual material until they are extremely certain that it's a match. If they want to detect anti-government propaganda or something, there would be no such concerns, they would j…

>> useful for areas where Apple really doesn't want to even look at the actual material Correct. It has plausible deniability built in. Apple is unable to verify that the images the government are looking for are actually CSAM. They could be political. They could be protest images. They could be Winnie the Pooh. Apple can plead ignorance as it blindly scans for whatever the requesting government asks it to scan for.…

What about the human reviewers at Apple? Those need to confirm matches, and they obviously look at the photos to do so. Apple can’t claim ignorance.

Also, it has to be two requesting governments.

Re: Hash collision in Apple NeuralHash model

#482

Earlier quoted context omitted.

> State actors have the resources You can end the conversation right there. If you are up against a state actor, you have already lost.

Very true, just wanted to paint a picture on how this could be abused.

It's not true at all. You're assuming state actors are in the same jurisdiction. This isn't always the case - think an oppressive authoritian regime wanting to get an American journalist arrested for child pornography.

It's always possible before, but client-side CSAM detection and alerting has weaponised this.

Previously, you always had to somehow alert an unfriendly jurisdiction. Now, you just use malware like Pegasus to drop CSAM, whether real or disturbed from legal porn, and watch as Apple tips off the Feds on your enemies.

Re: Hash collision in Apple NeuralHash model

#483
post #203
post #177

Earlier quoted context omitted.

I would think a Message with the attached photo from a burner phone/account would be enough.

Currently, the image would have to be imported into the photos library, and iCloud upload must be enabled.

Pegasus says hi.

Re: Hash collision in Apple NeuralHash model

#484

Earlier quoted context omitted.

I'd view a "grey blob" to be the MVP of hash collisions. I doubt that this will end with grey blobs - I see it ending with common images (memes would be great for this) being invisibly altered to collide with a CSAM hash.

If you need a judicial review to confim that a slightly altered Bernie in Coat and Gloves meme is not the same image as the picture of a child being raped that they have on file then we have way bigger problems.

Here's the thing with CSAM - it's illegal to view and transmit. So nobody, until the police have confiscated your devices, will actually be able to verify that it is a "child being raped."

They'll view visual hashes, look at descriptions, and so forth, but nobody from Apple will actually be looking at them, because then they are guilty of viewing and transmitting CSAM.

I noted in another comment, even the prosecutors and defense lawyers in the case typically only get a description of the content, they don't see it themselves.

Re: Hash collision in Apple NeuralHash model

#485

Earlier quoted context omitted.

Great on you , But i dont see my parents disabling the auto feature , nor do my friends. Youre right indeed , you can protect yourself from this , but all the measures you mentioned are settings which are non-default, A lot of apps annoyingly turn it on by default , while HN users can turn it off , I doubt my grandparents will go through the same effort or understand it. Question is , why should they ? Their phone wa…

Ok so your fear is someone will target your grandparents with child porn? If this was such a major problem why has no-one been targeted like this in the last decade when everyone else was scanning for it?

Here’s an example of exactly that

https://news.ycombinator.com/item?id=28221907

Re: Hash collision in Apple NeuralHash model

#486

Earlier quoted context omitted.

The principle is the defendant is innocent until proven guilty, NOT that the accuser is making a false accusation. There is a reason the verdict is "not guilty" instead of "innocent". After a not guilty verdict the legal system still does not assume the accuser was making a false accusation.

> There is a reason the verdict is "not guilty" instead of "innocent". Both verdicts exists, actually; the latter one is just far rarer (since it is both harder to prove and usually not what is argued about).

Yes, and almost always a either a case of mistaken identity or emerging malfeasance by either witnesses or prosecution.

Ironically, a provable case of false rape accusation might result in this verdict.

Re: Hash collision in Apple NeuralHash model

#488

Earlier quoted context omitted.

What are you actually claiming here? You stance is unclear.

That this is a contentious topic with biases on both sides. One group clearly benefits from any accusations being squashed before ever being investigated. Another benefits from never having to prove their accusations hold merit. This is why due process is important.

I see this a lot in these discussions. What do you think Trump or Cosby's accusers gained by their accusations holding merit?

Re: Hash collision in Apple NeuralHash model

#489
post #143

Earlier quoted context omitted.

That image planting virus concept is the scariest thing. Could you trigger this system and get the police alerted with spam mms with images or spam email with images, or targeted ads that get the gray blob images into your tmp files? Or does it have to be an actual script downloading images, say, one per week in secret until it triggers?

No, you couldn't. This is only checking images you upload to your iCloud photo library. Why would you save tons of gray blobs to your photo library? Why would gray blobs look like child porn? Why would Apple reviewers think gray blobs are child porn? Why would the NCMEC think gray blobs are child porn? Why would law enforcement spend time arresting someone for gray blobs?

The grey blob is a proof of concept. The existence of the original image is proof that not all images which produce the target hash are grey blobs.

Since the grey blob exists, I believe it is fully possible to construct natural(-ish) images that have a selected hash.

So, you should perhaps instead imagine attackers that modify lawful nude images to have matching hashes with child porn images.

With that in mind, most of your questions are answered, except perhaps for "Why would the NCMEC think"-- and the answer would be "because its porn and the computer says its child porn".

Of course, an attacker could just as well use REAL child porn. But there are logistic advantages in having to do less handling of unlawful material, and it's less likely that the target will notice. Imagine: if the target already has nude images on their host the attacker might use those as the templates. I doubt most people would notice if their nude image collection was replaced with noisier versions of the same stuff. And even if they did notice, "someone is trying to frame me for child porn" wouldn't be their first guess. :)

Re: Hash collision in Apple NeuralHash model

#490

Earlier quoted context omitted.

>> Every AV (antivirus) software system Mine doesn't. If Ubuntu or ClamAV is scanning all my photos and reporting the results to Canonical against my will then I will soon be having words with Mr. Linus.

If law enforcement can force software companies to adapt their software to serve law enforcement purposes, why aren’t Ubuntu or ClamAV doing so already? What makes them better at resisting requests from law enforcement than Apple?

Canonical and ClamAV aren't trying to curry favor with the US government to stave off antitrust action.
Post reply on HN