Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

21–30 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#21

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

> There really is no sound concept of "the more similar the hash." Perceptual hashes are not cryptographic hashes. Perceptual hashing systems do compare hashes using a distance metric like the Hamming distance. If two images have similar hashes, then they look kind of similar to one another. That's the point of perceptual hashing.

Except when you're not measuring the similarity you think you are, because NeuralNets are f&#@ing weird.

You know, let me put it this way. Yiu know that one really weird family member I'm pretty sure everyone either has or is?

Guess what? They're a neural net too.

This is what Apple is asking you to trust.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#22

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

This seems like speculation with no evidence. The government cares about more than just CSAM, they care about terrorism, human and drug trafficking, organized crime, gangs, fraud, drug manufacturing etc. This would only make sense if Apple intends to expand their CSAM detection and reporting system to detect and report those other things, as well.

The EARN IT Act would have basically legally mandated a backdoor in all services, with shifting recommendations, in the name of preventing the spread of CSAM. Sound familiar?

Also, there is another reason why there is the CSAM Detecting and Reporting system. With Apple CSAM Scan, that big "excuse" Congress was planning to use through EARN IT to ban E2E is diffused, meaning now Apple has the potential to add E2E to their iCloud service before Congress can figure out a different excuse.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#23
post #21

Earlier quoted context omitted.

> There really is no sound concept of "the more similar the hash." Perceptual hashes are not cryptographic hashes. Perceptual hashing systems do compare hashes using a distance metric like the Hamming distance. If two images have similar hashes, then they look kind of similar to one another. That's the point of perceptual hashing.

Except when you're not measuring the similarity you think you are, because NeuralNets are f&#@ing weird. You know, let me put it this way. Yiu know that one really weird family member I'm pretty sure everyone either has or is? Guess what? They're a neural net too. This is what Apple is asking you to trust.

I agree, I'm just talking about the difference between cryptographic hashes and other types of hashes.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#24

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

> There really is no sound concept of "the more similar the hash." Perceptual hashes are not cryptographic hashes. Perceptual hashing systems do compare hashes using a distance metric like the Hamming distance. If two images have similar hashes, then they look kind of similar to one another. That's the point of perceptual hashing.

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#25

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

CSAM scanning is only one type of scanning which is performed at the behest of governments and corporations around the world. This alone will not allow for end-to-end encryption of items in the cloud.

There would need to be end-device scanning for arbitrary objects, including full text search for strings including 'Taiwan', 'Tiananmen Square', '09 F9', and so forth to even begin looking at e2e encryption of your items in the cloud.

At which point… what's the point?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#27

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

EDIT: Parent edited his comment to clarify. I understand the point now. I'm wrong about similar images needing to have "similar" hashes. Those hashes either need to match exactly, or else not be considered at all. IGNORE THIS: I think that's the parent comment's point. These are definitely not cryptographic hashes, since they—by design and necessity—need to mirror hash similarity to the perceptual similarity of the i…

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#28
post #7

Earlier quoted context omitted.

Why can’t we have the alternative we already have, where we don’t have our phones scans and E2EE exists without compromise? Why do we have to accept it any other way? If you’re trying to frame this as “we need to prevent Congress from ever passing something like the EARN IT act”, I agree. Apple and other tech companies already lobby Congress. Why aren’t they lobbying for encryption?

They did, they lobbied heavily against EARN IT, and so did groups like the ACLU and EFF. However, it didn't stop Congress members from moving it along through the process - they were only stopped because Congress just ran out of time. It was clear that Congress was not interested in listening at all to the lobbyists on the issue. It's clear that EARN IT could literally be revived any day if Apple didn't do something…

It's clear that EARN IT could literally be revived any day if Apple didn't do something to say "we don't need it because we've already satisfied your requirements."

Alternatively, "Apple has shown that it's possible to do without undue hardship, so we should make everyone else do it too".

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#29
post #8

Earlier quoted context omitted.

You can't ban encryption, it's practically impossible, it's like banning math.

If you can get jailed for speech, you can get jailed for encryption.

Technically in the real world you can get jailed for anything as long as corruption exists and humans remain imperfect.

But you shouldn’t get jailed for protected speech and you shouldn’t get jailed for preserving your privacy (via encryption or otherwise.) As cynical as people may get, this is one thing that we have to agree on if we want to live in a free society.

And above all, most certainly, we shouldn’t allow being jailed over encryption to become codified as law, and if it does, we certainly must fight it and not become complacent.

Apathy over politics, especially these days, is understandable with the flood of terrible news and highly divisive topics, but we shouldn’t let the fight for privacy become a victim to apathy. (And yes, I realize big tech surveillance creep is a fear, but IMO we’re starting to get into more direct worst cases now.)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#30
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

No - the reporting is absolutely terrible here.

1) These are more share similar visual features than crypto hashes.

2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous.

3) This illustrates why apple's approach here (manual review after 30 images or so flagged) is not unreasonable. The push to say that this review is unnecessary is totally misguided.

4) They use words like "hash collision" for something that is not a hash. In fact, different devices will calculate DIFFERENT hashes for the SAME image at times.

One request I have - before folks cite legal opinions - those opinions should have the name of a lawyer on them. Not this "I talked to a lawyer" because we have no idea if you described things accurately.

Post reply on HN