Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

51–60 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#51
post #34
post #15

Earlier quoted context omitted.

Doing that would mean the NeuralHash would change though. And you'd have to not only get CLIP to identify CSAM in the generated image but also negate the parts of the generated image that are causing CLIP to label it as "generated" (while still colliding with the target NeuralHash). Unclear how hard this would actually be in practice (if I were going to attempt it, the first thing I'd try is to evolve a colliding ima…

Take 2 CSAM pictures, known. Combine into one image. Swing and a miss. Not in the CSAM dataset. Take two images. Encode alternating pixels. Decode to get the original image back. Convert to different encodings print to PDF or Postscript. Encode as base64 representations of the image file... Who are we trying to fool here? This is kiddie stuff. This is more about trying to implant scanning capabilities on client devic…

> This is more about trying to implant scanning capabilities on client devices.

Did we think they didn't already have that ability?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#52
Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible.

All of the slippery slope arguments have already been possible for nearly a decade now with the cloud.

Can someone illustrate something wrong with this that’s not already possible today.

Fundamentally unless you audited the client and the server yourself either (client or backend) scanning is possible, and therefore this “problem”.

Where’s the issue?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#53
This was never about protecting Children it seems. This was about the ability to create and install the infrastructure for the mass surveilling of people by smart device.

Hashes can be created for anything on a phone. And hash collisions enable the "Near match" of hashes (Similar items).

Lets pretend.. you use your face to log in to an iPhone, and there is a notice out for a certain person. If your face matches the hash, will you be part of the scan? You betcha.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#54

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

The problem isn't the idea of CASM, it's that what happens when they start scanning for "misinformation", or whatever else they want to come up with at that point.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#55
post #8

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

You can't ban encryption, it's practically impossible, it's like banning math.

The ban won't make encryption disappear. You can still have it. But if you're found using it, it's a felony.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#56

Earlier quoted context omitted.

Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.

Furthermore, it may well be possible to combine that blobby grey static with another image, manipulating it's visual hash to create a "sleeper" positive. If this was possible in a week , then it's going to be very interesting to watch the technology change/evolve over the next few years.

Doing so would create a positive that still doesn't pass Apple's human visual check against the (blurred) CSAM content associated with that checksum, and if it somehow did, it would still then also have to occur at qty.30 or more, and they'd have to pass a human visual check against the (unblurred) CSAM content by one of the agencies in possession of it. It's not possible to spoof that final test unless you possess real CSAM content, at which point you don't need to spoof that final test and you'll end up arrested for possession.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#57

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

>which would unilaterally banned E2E encryption in entirety

It did not do this. The bill was essentially asking for search warrants to become a part of the protocol. If you're only solution to allowing for search warrants to work is to stop encrypting data I feel you are intentionally ignoring other options to make this seem worse than it is.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#58
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

Yea by reading about this whole scandal I learned about perceptual hashes, because the whole time I kept thinking "can't they just alter one pixel and entirely change the hash" because I was only familiar with cryptographic hashes.

It's a huge, huge, huge distinction.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#59

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

Never let a good Apple controversy go to waste. Clickbait blogs are thrilled to have something like this.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#60
post #44

I think we're up for a new Apple CEO in a few days.

The turmoil of Apple abruptly booting the CEO who's overseen the most obscenely prosperous stretch in its history would cost the company vastly more than the current controversy about CSAM. I'm not saying this as a fan of either Cook or their anti-CSAM measures; I'm neither, and if anyone is ever wrongfully arrested because Apple's system made a mistake, Cook may well wind up in disgrace depending on how much blame h…

He's not Ballmer but Ballmer also presided over record profits even though MS barely did anything remotely interesting under his watch.

Just saying that money hides problems.

Post reply on HN