Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

101–110 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#101
post #74

Earlier quoted context omitted.

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

From what I understand it's even more cut and dry than that. If you submit a report to the NCMEC you are generally required to (securely) keep a copy of the image(s) being reported and any related info for a period of time. That's part of the rules. You are also only compelled to report things that you know are bad, so verification before reporting makes sense. The idea that they would be charged with a crime for doi…

Thank you for a first hand report. All that makes sense - you clearly can't and shouldn't "pass around images" even in the office - so fair that it is super strict once something is confirmed as X.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#102
Would this work as an attack?

1. Get a pornographic picture involving young though legal actors and actresses.

2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again.

3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, presumably, it is not illegal for you to have this image as it is, in fact, legal pornography. You can now text this to anyone with an iPhone who will be referred by Apple to law enforcement.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#104

Earlier quoted context omitted.

Personally, I'd prefer no privacy intrusions at all. The issue is that Apple previously was not intruding into their user's privacy (at least publicly), but now they are. It sounds like your argument is that Apple could have been doing this all along and just not telling us. I find that unlikely mainly because they've marketed themselves as a privacy-focused company up until now.

I’m your situation can’t you just turn off the scanning? What’s the issue?

There are two different "features" being implemented - Messages scanning for minors on a family plan (which can be turned off) and iCloud Photo scanning (which can't be turned off, as far as I know). So no, you can't just turn it off.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#105
post #54

Earlier quoted context omitted.

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

The problem isn't the idea of CASM, it's that what happens when they start scanning for "misinformation", or whatever else they want to come up with at that point.

Then why not wait until that actual issue comes up. The look is so bad / awkward with this big protest over something that many people are not going to find at all objectionable.

Do you really think Apple's brand has been "destroyed" over this?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#106

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#107
post #8

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

You can't ban encryption, it's practically impossible, it's like banning math.

Well, we are already banning numbers (see: DeCSS), what’s the big difference?

In some countries even discussing the application of certain numbers is unlawful.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#108

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

EDIT: Parent edited his comment to clarify. I understand the point now. I'm wrong about similar images needing to have "similar" hashes. Those hashes either need to match exactly, or else not be considered at all. IGNORE THIS: I think that's the parent comment's point. These are definitely not cryptographic hashes, since they—by design and necessity—need to mirror hash similarity to the perceptual similarity of the i…

They are almost the opposite. The programs create different hashes (though very similar) depending on platform you run on even with SAME input. No crypto hash works even close to this.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#110
Is no one going to talk about how Apple is implementing this?

If Apple is training a neural network to detect this kind of imagery, I would imagine there to be thousands, if not millions of child pornography images on Apple's servers that are being used by their own engineers to train this system

Post reply on HN