Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

551–560 of 725 posts

Re: Hash collision in Apple NeuralHash model

#551
post #149

Earlier quoted context omitted.

1. By the public at large it should not be treated in any regard, false or not. 2. The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom. 3. The 'believe the victims' activists however are rightfully (IMHO) suggesting to break principle #2 because there is institutional and systemic supression of t…

> The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom. This is completely wrong. If the state treated all accusations as untrue prior to conviction, they would not send armed men to haul you to prison, bar you from release unless you can bail yourself out (or sometimes not at all), and not have a…

You are right. There is a lot more too it.

Although arresting and jailing someone is not being justice being administered, it is facilitating justice and fact finding and it itself is indeed an act of violence.

Re: Hash collision in Apple NeuralHash model

#552

Second preimage attacks are trivial because of how the algorithm works. The image goes through a neural network (one to which everyone has access), the output vector is put through a linear transformation, and that vector is binarized, then cryptographically hashed. It's trivial to perturb any image you might wish so as to be close to the original output vector. This will result in it having the same binarization, he…

Wouldn’t it also just be possible to turn a jailbroken iDevice into a CSAM cleaner/hider?

You could take actual CSAM, check if it matches the hashes and keep modifying the material until it doesn’t (adding borders, watermarking, changing dimensions etc.). Then just save it as usual without any risk.

Re: Hash collision in Apple NeuralHash model

#553

Earlier quoted context omitted.

That’s already how app reviews work.

I think rejecting one of million apps and angering one developer is a bit different than reporting someone about a child pornography/abuse, ruining their life and making a global scandal that can put future iPhone sales in jeopardy.

Barely anyone ever cared about privacy. Convenience, no matter how insignificant, always wins. I will be surprised if this is the last straw that finally gets the masses to care about privacy. In reality there might be a few scandals but at some point no one will care anymore and Apple will remain popular.

Re: Hash collision in Apple NeuralHash model

#554

Earlier quoted context omitted.

The big difference is that cloud providers do the scanning on their own infrastructure. If you don't want something scanned, you don't upload it to the could, that simple. But here, your own device is snitching on you.

But the discussion at hand is about malicious actors causing innocent people to trip the alarms. Given the clear capabilities of tools like Pegasus, "just don't enable cloud syncing" is obviously not sufficient to protect against a malicious actor who wants to plant illegal content on your device and trip the alarms.

OK, and so what? "Tripping the alarms" in this case means somebody looks at the pictures that were put on your device without your knowledge, sees that they're all grey blobs, and flags it as a false alarm, case closed.

Re: Hash collision in Apple NeuralHash model

#555
post #414

Earlier quoted context omitted.

> The warrant would properly only be to search iCloud, iCloud is encrypted, so that warrant is useless. They need to unlock and search the device.

Yes, it's encrypted, but part of this anti-CSAM strategy is a threshold encryption scheme that allows Apple to decrypt photos if a certain number of them have suspicious hashes.

No, the threshold encryption only allows for the 30+ cryptographic “vouchers” to be unlocked, which contain details about the hash matching as well as a “visual derivative” of the image. We don’t know any details about the visual derivative.

Re: Hash collision in Apple NeuralHash model

#556
post #337

Earlier quoted context omitted.

The collisions are supposedly reviewed, my concern is that the process for photodna isn't going to always be the same, and we don't actually have any knowledge as to whether their claims are true. Eventually they will phase out human intervention and replace with gameable AI. 3 letter agencies don't need to review the actual images, they can easily get federal warrants based on some numbers. Apple is content with put…

One thing about this is that we are farther and farther away from "if there is evidence for a crime a jury can understand it and rationally decide what do with it" and we are getting closer to "if this lightbulb is glowing the machine says they are guilty, so better trust us". This kind of stuff should not be evidence, if anything it should be a indicator where to look.

In what case do you think the hash will be introduced as evidence, where the actual image being hashed, which is a grey blob, cannot?

Re: Hash collision in Apple NeuralHash model

#557
post #523

Earlier quoted context omitted.

It's serious to you , but CSAM scanning is irrelevant to 99.99999% of Apple's customers, and Jobs would never have allowed an announcement about migrating CSAM scanning from uploads to the cloud to the device uploading to the cloud. That's an implementation detail that wouldn't be relevant to discuss with outsiders. Instead, I expect he would have presented it in a closed session to the FBI and/or Congress. Never to…

> CSAM scanning is irrelevant to 99.99999% of Apple's customers How long until an group of governments tells Apple to add Tank Man to the list?

Why would they bother? That's a terrible way to approach it.

Just pass legislation requiring in-country datacenters that can be decrypted by thoughtcrime enforcers, like Russia and China are doing. Trying to get this done via a CSAM list that's absurdly closely audited would be a huge waste of time and not provide any significant benefit, and if such a request were ever made public, would likely result in severe political and economic sanctions.

That's what everyone's missing in this argument. There's no need to be all underhanded and secretive when you can just pass laws and conduct military-backed demands upon companies using those laws. Trying to exploit the CSAM process would be a horrifically bad idea, and would result in public exposure and humiliation, rather than the much more useful outcome that simply passing a law would provide.

Re: Hash collision in Apple NeuralHash model

#558

Earlier quoted context omitted.

> Just insert a known CSAM image on target's device. Or maybe thirty. You have to surpass the threshold. Also, if Twitter, Google, Microsoft are already deploying CSAM scanning in their services .... why are we not hearing about all the "swatting"?

>Also, if Twitter, Google, Microsoft are already deploying CSAM scanning in their services .... why are we not hearing about all the "swatting"? >their services >T H E I R S E R V I C E S Because it's on their SERVICES, not on their user's DEVICES, for one. Also, regardless of swatting, that's why we have an issue with Apple.

It only happens on Apple devices right before the content is uploaded to the service.

How is that a meaningful difference for the stated end goals, that can explain the lack of precedent.

Re: Hash collision in Apple NeuralHash model

#560

Earlier quoted context omitted.

Here's the thing with CSAM - it's illegal to view and transmit. So nobody, until the police have confiscated your devices, will actually be able to verify that it is a "child being raped." They'll view visual hashes, look at descriptions, and so forth, but nobody from Apple will actually be looking at them, because then they are guilty of viewing and transmitting CSAM. I noted in another comment, even the prosecutors…

Where did you get this idea, scooby doo? It is not illegal to be an unwilling recipient of illegal material. If a package shows up at your door with a bomb, you're not gonna be thrown in jail for having a bomb.

In theory, sure.

At the very least, you'd be one of the primary suspects, and if you somehow got a bad lawyer, all bets are off.

https://hongkongfp.com/2021/08/12/judges-criticise-hong-kong...

Post reply on HN