Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

521–530 of 725 posts

Re: Hash collision in Apple NeuralHash model

#521

First CP. Then leaked or unauthorized nudes will get filtered. Filters for terrorists, and terrorist imagery or symbols. Start scanning for guns and drugs. Drug dealers and criminals get added to the list. How long before before it’s dissidents, political opponents, and minorities in dictatorships? How long before Tim Cooks CP filters are used against LGBT groups abroad?

It's funny how it's always CP or terrorism we need to watch out for.... Never is it the politician who accidentally went to war with wrong country, or the tax return of the congressman, or a cop sleeping with somebody who's under arrest, or EPA employee who took a bribe to declare a chemical safe, or mysteriously malfunctioning cameras in a prison the night of an alleged suicide. Build surveillance to catch those peo…

>It's funny how it's always CP or terrorism we need to watch out for

Change the name on the box to something else, but same message.

https://i.imgur.com/TAHgUPy.jpg

Re: Hash collision in Apple NeuralHash model

#522
post #362
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

I actually want Apple to stand ground and implement this feature. Like you said the double down on PR and marketing was enough for me. I may not be dumping all iOS and Mac for now. But it was " the " definite signal and evidence this is no longer the old Steve Jobs's Apple. It is like watching Mark Zuckerberg talking about privacy when he doesn't understand anything about it. ( Or more like he has a different underst…

"Steve Jobs Apple"? I don't think Jobs would give a damn about people crying about Apple's decisions. I don't know why people thinks he would be a smidgen better than whoever managing apple after him.

Re: Hash collision in Apple NeuralHash model

#523
post #473

Earlier quoted context omitted.

There’s a significant leap from implementing something server side to on the consumer handheld devices themselves. Even if it’s just similar software it is regardless much more serious. I personally thought the unencrypted backups was enough of a death-knell as it provides everything on your phone but anything with real-time on device access is always a gold mine for surveillance hawks.

It's serious to you , but CSAM scanning is irrelevant to 99.99999% of Apple's customers, and Jobs would never have allowed an announcement about migrating CSAM scanning from uploads to the cloud to the device uploading to the cloud. That's an implementation detail that wouldn't be relevant to discuss with outsiders. Instead, I expect he would have presented it in a closed session to the FBI and/or Congress. Never to…

> CSAM scanning is irrelevant to 99.99999% of Apple's customers

How long until an group of governments tells Apple to add Tank Man to the list?

Re: Hash collision in Apple NeuralHash model

#524
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

What exactly is the targeted attack? To get a bunch of someone's random looking photos reviewed by a human?

Re: Hash collision in Apple NeuralHash model

#525
post #350

Earlier quoted context omitted.

Can a warrant compel them to develop the capability?

The law gets debatable here. The warrant can ultimately be served only to the owner/responsible party for the system. If apple decides that they own all iPhones, a claim they've loosely made for a long time re Flash etc. Then they could be served a warrant on the device. If they just sold the device to someone, then the police would have to issue a warrant to that individual. My understanding is that as an individual…

I haven't kept us with the latest cases, but I'm not sure where it falls on app-based SaaS.

I.e. If I use an app, on a system in which app updates are possible, which encrypts my data locally and stores it on their cloud, then the owner/responsible party for the app is...?

Re: Hash collision in Apple NeuralHash model

#526
post #489

Earlier quoted context omitted.

No, you couldn't. This is only checking images you upload to your iCloud photo library. Why would you save tons of gray blobs to your photo library? Why would gray blobs look like child porn? Why would Apple reviewers think gray blobs are child porn? Why would the NCMEC think gray blobs are child porn? Why would law enforcement spend time arresting someone for gray blobs?

The grey blob is a proof of concept. The existence of the original image is proof that not all images which produce the target hash are grey blobs. Since the grey blob exists, I believe it is fully possible to construct natural(-ish) images that have a selected hash. So, you should perhaps instead imagine attackers that modify lawful nude images to have matching hashes with child porn images. With that in mind, most…

And where would they get the CSAM hash they need to match?

Re: Hash collision in Apple NeuralHash model

#527
post #489

Earlier quoted context omitted.

No, you couldn't. This is only checking images you upload to your iCloud photo library. Why would you save tons of gray blobs to your photo library? Why would gray blobs look like child porn? Why would Apple reviewers think gray blobs are child porn? Why would the NCMEC think gray blobs are child porn? Why would law enforcement spend time arresting someone for gray blobs?

The grey blob is a proof of concept. The existence of the original image is proof that not all images which produce the target hash are grey blobs. Since the grey blob exists, I believe it is fully possible to construct natural(-ish) images that have a selected hash. So, you should perhaps instead imagine attackers that modify lawful nude images to have matching hashes with child porn images. With that in mind, most…

> Since the grey blob exists, I believe it is fully possible to construct natural(-ish) images that have a selected hash.

At the very least, there are large classes of images that, while not realistic photographs, people will willingly download, that should be very easy to craft collisions for:

Memes. In particular, given the distortions of surreal and deep-fried memes, it should be pretty easy to craft collisions there.

Re: Hash collision in Apple NeuralHash model

#528
post #472

Earlier quoted context omitted.

What? Why do you think gray blobs would hurt anyone?

No one is going to send gray blobs, they will be finding legal porn (like pussy close ups, tongue pics, whatever) and then disturbing it to trigger a CSAM hit. The low res derivative will match, perhaps even closely, because pussy closeups look similar to an apple employee when its grayscale 64 by 64 pixels (remember: it's illegal for Apple to transmit CSAM, so it must be so visually degraded to the point where it's…

And disturbing it enough to match CSAM would make it obvious it’s been tampered with. And how would the attacker obtain the CSAM hashes they’d need to match?

Re: Hash collision in Apple NeuralHash model

#529
"According to media reports, the cloud computing industry does not take full advantage of the existing CSAM screening toolsto detect images or videos in cloud computing storage. For instance, big industry players, such as Apple, do not scan their cloud storage. In 2019, Amazon provided only eight reports to the NCMEC, despite handling cloud storage services with millions of uploads and downloads every second. Others, such as Dropbox, Google and Microsoft perform scans for illegal images, but 'only when someone shares them, not when they are uploaded'." [1]

So I guess the question is what exactly "others" are doing, 'only when someone shares them, not when they are uploaded'. The whole discussion seems to center around what Apple intends to do on-device, ignoring what others are already doing in the cloud. Isn't this strange?

[1] https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/6593...

Re: Hash collision in Apple NeuralHash model

#530
post #269
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

Vindicated? This can’t be used for a targeted attack. It’s no different from the previous false posting making this claim.

Imagine if WhatsApp and other apps added received photos to iPhone's iCloud Photos gallery by default.. wait, they do.
Post reply on HN