Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

171–180 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#171
post #66

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Why are hash collisions relevent? There are atleast 2-3 further checks to account for this.

Because it's not a cryptographic hash where a one bit difference results in a completely different hash. It's a perceptual hash that operates on a smaller bitmap derived from the image so it's plausible that some innocuous images might result in similar derivations; and there might be intentionally crafted innocently-looking images that result in an offensive derivative.

Salvador Dali could do something similar by hand in 1973 in Gala Contemplating the Mediterranean Sea [1]

[1] https://en.wikipedia.org/wiki/Lincoln_in_Dalivision

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#172
post #124

Would this work as an attack? 1. Get a pornographic picture involving young though legal actors and actresses. 2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again. 3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, pre…

How would you know if it's a CSAM collision? I don't believe that database is publicly available anywhere, for obvious reasons.

Yes. That, plus it's unclear whether you can create a collision with a nonce. It's a perceptual hash, not a cryptographic one. Lastly, to compute that collision might be so expensive that you could instead compute small SHA-256 hashes, ie mine BTC, and use the money to obtain your sinister goals via other means.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#173

Earlier quoted context omitted.

In a certain sense it is cryptographic because the original CSAM images remains secret. While the hash is not useful for maintaining integrity it still provides confidentiality. Edit: this is apparently not true as demonstrated by researchers.

This has technically been proven false: > Microsoft says that the "PhotoDNA hash is not reversible". That's not true. PhotoDNA hashes can be projected into a 26x26 grayscale image that is only a little blurry. 26x26 is larger than most desktop icons; it's enough detail to recognize people and objects. Reversing a PhotoDNA hash is no more complicated than solving a 26x26 Sudoku puzzle; a task well-suited for computers…

PhotoDNA and NeuralHash are not the same thing.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#174
post #131

Earlier quoted context omitted.

That's what they're saying, the key difference is Apples happens on your device, not theirs.

Making it obviously and unquestionably more invasive.

I just don't get this. Say you're given two options when going through the TSA.

1. The TSA agent opens your luggage and searches everything for banned items.

2. The TSA agent hands you a scanner for you to wave over your luggage in private, it prints out a receipt of banned items it saw, and you present that receipt to the agent.

Which one is more invasive?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#175

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing. This is the difference between putting CSAM on a sign in y…

ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) is more private than doing the same scan on server where a single false positive can be misused by anyone who can get a subpoena.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#176

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

We will see. I've heard lots of these predictions and I don't buy them AT ALL. What I have seen is a selling point for apple products. I'd encourage folks to get out of the HN bubble on this - talk to a wife, a family especially those with kids.

Yeah, talk to people that know nothing on the issue besides that they want to “protect the kids”.

Why stop there? Get out of the HN bubble on the patriot act, instead ask your neighbor’s wife her thoughts on it. Get out of the HN bubble on immigration, go ask a stereotypical boomer conservative about it.

I think my sarcasm already made it overtly obvious but, this is horrible advice you are giving and the fact that you don’t seem to be aware that pedophilia and terrorism are the two most classic “this gives us an excuse to exert totalitarian control” topics betrays your own ignorance (or, worse, you are aware and just don’t care).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#177
post #147

Earlier quoted context omitted.

Yes, exactly. This is honestly nothing new.

This is new for Apple's customers. And its new in that the device you bought and paid for is nosing through your files. Apple is introducing a reverse 'Little Snitch' where instead of the app warning you what apps are doing on the network, the OS is scanning your photos. Introducing a 5th columnist into a device that you've bought and paid for is a huge philosophical jump from Apple's previous stances on privacy, whe…

Luckily for their customers it can be turned off. So, what’s the issue?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#178

Earlier quoted context omitted.

But you can tho…

Please show evidence where the feature can be turned off (without having to completely disable iCloud photos).

You turn it off by turning off iCloud photos, I never claimed otherwise.

If you don’t trust Apple why would you use iCloud anyway? Makes no sense.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#179
post #100

Earlier quoted context omitted.

Why prefer your owned device tattling on you to Apple looking at data you give them on their servers? The reason people don't like this, as opposed to, for example, Dropbox scanning your synced files on their servers, is that a compute tool you ostensibly own is now turned completely against you. Today, that is for CSAM, tomorrow, what else?

There’s no difference - all cloud services that aren’t encrypting your data is subject to the same thing. Dropbox could do the same thing tomorrow. If we’re talking about hypotheticals any vendor that handles your unencrypted files can do this now.

big difference: you're now paying for the compute load, instead of the cloud providers, for something that offers no direct benefit to you and will most likely betray you in unforeseen ways in the future (especially in less 'free' countries)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#180

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

>Personally I’d prefer this than no encryption and scanning in the cloud

How about neither? Just let people have their privacy. Some will misuse it. Thats life.

Post reply on HN