Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

1–10 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#3
I created a proof of concept showing how OpenAI's CLIP model can function as a "sanity check" similar to how Apple says their server-side model works.

In order for a collision to get through to the human checkers, the same image would have to fool both networks independently:

https://blog.roboflow.com/apples-csam-neuralhash-collision/

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#4
For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdoor was child safety... even though AG Barr admitted that reducing the use of encryption had useful side effects.

If you are Apple, even though EARN IT failed... you know where Washington's heart lies. Is CSAM scanning a "better alternative", a concession, an appeasement, a lesser evil, in the hope this prevents EARN IT from coming back?

Also, many people forgot about the Lawful Access to Encrypted Data Act of 2020, or LAED, which would unilaterally banned E2E encryption in entirety and required that all devices featuring encryption must be unlockable by the manufacturer. That also was on the table.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#5
> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations.

“Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a fancy speak for “the closer two images look like, the more similar the hash”.

Vice and others keeps calling the cryptographic. Am I missing something here?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#6
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1]

Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system.

[1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#7

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

Why can’t we have the alternative we already have, where we don’t have our phones scans and E2EE exists without compromise? Why do we have to accept it any other way?

If you’re trying to frame this as “we need to prevent Congress from ever passing something like the EARN IT act”, I agree. Apple and other tech companies already lobby Congress. Why aren’t they lobbying for encryption?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#8

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

You can't ban encryption, it's practically impossible, it's like banning math.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#9
post #7

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

Why can’t we have the alternative we already have, where we don’t have our phones scans and E2EE exists without compromise? Why do we have to accept it any other way? If you’re trying to frame this as “we need to prevent Congress from ever passing something like the EARN IT act”, I agree. Apple and other tech companies already lobby Congress. Why aren’t they lobbying for encryption?

They did, they lobbied heavily against EARN IT, and so did groups like the ACLU and EFF. However, it didn't stop Congress members from moving it along through the process - they were only stopped because Congress just ran out of time. It was clear that Congress was not interested in listening at all to the lobbyists on the issue.

It's clear that EARN IT could literally be revived any day if Apple didn't do something to say "we don't need it because we've already satisfied your requirements."

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#10
post #8

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

You can't ban encryption, it's practically impossible, it's like banning math.

If you can get jailed for speech, you can get jailed for encryption.
Post reply on HN