Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

601–610 of 725 posts

Re: Hash collision in Apple NeuralHash model

#601
post #476

Earlier quoted context omitted.

A vulnerability by itself is not that dangerous, but in combination with a sophisticated attack, or another vulnerability can be disastrous. State actors have the resources to exploit a number of unknown bugs in combination with this collision to have Apple's systems flag persons of interest. This, combined with human error during the manual review process might result in someone getting reported. Seeing as twitter (…

No one is going to send gray blobs, they will be finding legal porn (like pussy close ups, tongue pics, whatever) and then disturbing it to trigger a CSAM hit. The low res derivative will match, perhaps even closely, because pussy closeups look similar to an apple employee when its grayscale 64 by 64 pixels (remember: it's illegal for Apple to transmit CSAM, so it must be so visually degraded to the point where it's…

There is a lot of speculation about things that haven’t happened in that comment.

Re: Hash collision in Apple NeuralHash model

#602
post #203

Earlier quoted context omitted.

Currently, the image would have to be imported into the photos library, and iCloud upload must be enabled.

This conversely means that all illegal content can be freely texted and this system won't even catch the distribution of CP unless those pictures are imported into the photos library and icloud updates enabled. There's a pretty good chance that it was inevitably going to get expanded to handle pictures arriving at the phone through other means.

We can take that discussion if and when that happens.

Re: Hash collision in Apple NeuralHash model

#603

I admit that I have not done enough research to have a strong opinion on this, but why is Apple taking this on themselves? As far as I can see, this outrage is because of "scanning on iPhone" that is wildly out of user's control. Why can't Apple be like others and say we scan the shit out of what you upload to iCloud(and it is in our Terms and Conditions to use iCloud)? Almost all tech people know that iCloud (or its…

My understanding is that iCloud reports orders of magnitudes less CSAM than other cloud services at a similar scale. My guess is that apple wanted a way to report the CSAM they are currently storing without having to decrypt/inspect every person's personal data (which necessarily opens vectors for e.g. rogue employees doing bad things with people's personal data) Hence why this approach was stated as a privacy win by…

Yes, and if you read (and understand) the technical implementation, it certainly does offer more privacy. But yeah for people who don’t, it often seems much worse.

Re: Hash collision in Apple NeuralHash model

#604
post #138

Earlier quoted context omitted.

The speculation that I've seen here is that Apple is rolling this out ahead of a future announcement that iCloud uploads will be encrypted.

If so they flubbed it. If they are e2e encrypted they can't be distributed/shared without giving a key of some sort. Why not just scan them at time of distribution, and treat undistributed files the same as any local hard-drive (i.e. not their problem).

This system could still work with an e2e encrypted cloud library. However, it’s currently not e2e.

Re: Hash collision in Apple NeuralHash model

#605

Any idea why Apple had to be too cute by half and not just scan these files server-side? Or why it doesn't change their plan to do that, given the backlash?

I hope not, since doing the scans like this offers much more privacy for the user. Even when the user is too ignorant (sorry) to realize this.

But this will be evident by reading and understanding the technical description.

Re: Hash collision in Apple NeuralHash model

#606

Apple claimed 'one in a trillion' chance of a collision. This is a great example of why you should not trust such an assessment.

That’s a different scenario. That’s for it happening by chance, not on purpose. At any rate, the “matching” images are reviewed (or a “visual derivative” is).

Re: Hash collision in Apple NeuralHash model

#607
post #3

Expectation : Political rivals and enemies of powerful people will be taken out because c-ild pornography will be found in their phone. Pegasus can already monitor and exfiltrate every ounce of data right now, it won't be that hard to insert compromising images on the infected device. Any news about "c-ild porn" being found on someone's phone is suspect now. This has been done before : 1) https://www.deccanchronicle.…

I'm against this change from Apple but weren't they already doing this scanning in iCloud? Couldn't someone use it the same way against a "political rival and enemies of powerful people"?

All major cloud photo library providers do this scan server side, yes. This way offers more privacy for the end user… but evidently most people don’t realize that.

Re: Hash collision in Apple NeuralHash model

#608

Earlier quoted context omitted.

E.g. send them a whatsapp message that looks innocent

They can see the image - why would they import a random image into their library from someone they don’t know?

Whatsapp imports received images into camera roll by default, and icloud sync is on by default. So you just need to get into a WA group the victim is a member of, and have the victim use default settings.

Re: Hash collision in Apple NeuralHash model

#609

First CP. Then leaked or unauthorized nudes will get filtered. Filters for terrorists, and terrorist imagery or symbols. Start scanning for guns and drugs. Drug dealers and criminals get added to the list. How long before before it’s dissidents, political opponents, and minorities in dictatorships? How long before Tim Cooks CP filters are used against LGBT groups abroad?

Maybe we can worry about things when and if they are implemented? If you don’t trust Apple it’s a moot discussion anyway.

Re: Hash collision in Apple NeuralHash model

#610

I'm not in favor of assuming that everyone's guilty until proven innocent. But, as a side note... I get the feeling that a lot of people assume that the CSAM hashes are going to be stored directly on everyone's phone so it's easy to get a hold of them and create images that match those hashes. That does not seem to be the case. The actual CSAM hashes go through a "blinding" server-side step. https://www.apple.com/chi…

It seems to me that the vast majority of people in forums don’t actually know how this system is implemented. Although people definitely seem more informed here than on Reddit.
Post reply on HN