Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

61–70 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#61

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Apple's management can also be prone to hubris. This is also very much a case where the engineers were left unbridled without any proper check from marketing and comms, I suspect because of the extreme complexity of the problem and the sheer impossibility of putting it into layman terms effectively.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#62

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

This. Also try contacting a lawyer who knows this area and asking to pay for a legal opinion brief so that you can post it online to be debated by legions of software developers.

Lawyers I know would politely decline that.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#63
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

Or how about they just don't scan my phone at all.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#64

it's kind of silly how this is treated like some deeply technical issue. Apple's 'one of a trillion' claim is either true and the software is useless, because I'm pretty sure pedophiles can figure out what a watermark or a gaussian blur in paint net is, or it's imprecise and actually detects things which is the very thing that makes it dangerous to the public. It's a direct trade-off and the error tolerance of any su…

Exactly right. The tech Apple uses can be one of two things:

1. It requires a perfect 1:1 match (their documentation says this is not the case); 2. Or it has some freedom in detecting a match, probably including a match with a certain percentage.

If it's the former, it's completely useless. A watermark or a randomly chosen pixel with a slightly different hue and the hash would be completely different.

So, it's not #1. It's going to be #2. And that's where it becomes dangerous. The government of the USA is going to look for child predators. The government of Saudi Arabia is going to track down known memes shared by atheists, and they will be put to death; heresy is a capital offence over there. And China will probably do their best to track down Uyghurs so they can make the process of elimination even easier.

It's not like Apple hasn't given in to dictatorships in the past. This tech is absolutely going to kill people.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#65
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.

I dont really think it'd be a valid second pre-image for this type of hash if they did look similar.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#66

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Why are hash collisions relevent?

There are atleast 2-3 further checks to account for this.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#67
post #8

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

You can't ban encryption, it's practically impossible, it's like banning math.

All they have to do is force Apple and Google to ban it and any apps that use it from their app store and they've effectively banned encryption for like 99% of people.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#68

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Because privacy stance is mostly PR to differentiate from Google. And while there're invalid reasons to get users data, there're also valid ones (at least from legal requirement point of view - let's not get into weeds about personal freedom here and if t…

In retrospect this makes sense to me. I don't like it, but I get it now. When Apple said "privacy" what they meant was "we don't like tracking cookies or hackers but everything else is fine".

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#69

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible.

Why is that the alternative? How about everything is encrypted and nothing is scanned.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#70

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

but there are legal opinions that law firms and various orgs(political or not) that wite on occasion from actual lawyers sharing a legal opinion, publicly(or not).

But it's the law, it's fuzzy at best, much like your HR department. It's only after a court decision has been reached on your particular issue that it's anywhere near "settled" case law, and even that's up for possible change tomorrow.

Post reply on HN