Earlier quoted context omitted.
A vulnerability by itself is not that dangerous, but in combination with a sophisticated attack, or another vulnerability can be disastrous. State actors have the resources to exploit a number of unknown bugs in combination with this collision to have Apple's systems flag persons of interest. This, combined with human error during the manual review process might result in someone getting reported. Seeing as twitter (…
No one is going to send gray blobs, they will be finding legal porn (like pussy close ups, tongue pics, whatever) and then disturbing it to trigger a CSAM hit. The low res derivative will match, perhaps even closely, because pussy closeups look similar to an apple employee when its grayscale 64 by 64 pixels (remember: it's illegal for Apple to transmit CSAM, so it must be so visually degraded to the point where it's…
Hash collision in Apple NeuralHash model
601–610 of 725 posts
Re: Hash collision in Apple NeuralHash model
#602Earlier quoted context omitted.
Currently, the image would have to be imported into the photos library, and iCloud upload must be enabled.
This conversely means that all illegal content can be freely texted and this system won't even catch the distribution of CP unless those pictures are imported into the photos library and icloud updates enabled. There's a pretty good chance that it was inevitably going to get expanded to handle pictures arriving at the phone through other means.
Re: Hash collision in Apple NeuralHash model
#603I admit that I have not done enough research to have a strong opinion on this, but why is Apple taking this on themselves? As far as I can see, this outrage is because of "scanning on iPhone" that is wildly out of user's control. Why can't Apple be like others and say we scan the shit out of what you upload to iCloud(and it is in our Terms and Conditions to use iCloud)? Almost all tech people know that iCloud (or its…
My understanding is that iCloud reports orders of magnitudes less CSAM than other cloud services at a similar scale. My guess is that apple wanted a way to report the CSAM they are currently storing without having to decrypt/inspect every person's personal data (which necessarily opens vectors for e.g. rogue employees doing bad things with people's personal data) Hence why this approach was stated as a privacy win by…
Re: Hash collision in Apple NeuralHash model
#604Earlier quoted context omitted.
The speculation that I've seen here is that Apple is rolling this out ahead of a future announcement that iCloud uploads will be encrypted.
If so they flubbed it. If they are e2e encrypted they can't be distributed/shared without giving a key of some sort. Why not just scan them at time of distribution, and treat undistributed files the same as any local hard-drive (i.e. not their problem).
Re: Hash collision in Apple NeuralHash model
#605Any idea why Apple had to be too cute by half and not just scan these files server-side? Or why it doesn't change their plan to do that, given the backlash?
But this will be evident by reading and understanding the technical description.
Re: Hash collision in Apple NeuralHash model
#606Apple claimed 'one in a trillion' chance of a collision. This is a great example of why you should not trust such an assessment.
Re: Hash collision in Apple NeuralHash model
#607Expectation : Political rivals and enemies of powerful people will be taken out because c-ild pornography will be found in their phone. Pegasus can already monitor and exfiltrate every ounce of data right now, it won't be that hard to insert compromising images on the infected device. Any news about "c-ild porn" being found on someone's phone is suspect now. This has been done before : 1) https://www.deccanchronicle.…
I'm against this change from Apple but weren't they already doing this scanning in iCloud? Couldn't someone use it the same way against a "political rival and enemies of powerful people"?
Re: Hash collision in Apple NeuralHash model
#608Earlier quoted context omitted.
E.g. send them a whatsapp message that looks innocent
They can see the image - why would they import a random image into their library from someone they don’t know?
Re: Hash collision in Apple NeuralHash model
#609First CP. Then leaked or unauthorized nudes will get filtered. Filters for terrorists, and terrorist imagery or symbols. Start scanning for guns and drugs. Drug dealers and criminals get added to the list. How long before before it’s dissidents, political opponents, and minorities in dictatorships? How long before Tim Cooks CP filters are used against LGBT groups abroad?
Re: Hash collision in Apple NeuralHash model
#610I'm not in favor of assuming that everyone's guilty until proven innocent. But, as a side note... I get the feeling that a lot of people assume that the CSAM hashes are going to be stored directly on everyone's phone so it's easy to get a hold of them and create images that match those hashes. That does not seem to be the case. The actual CSAM hashes go through a "blinding" server-side step. https://www.apple.com/chi…