Hi, this looks interesting but I have no idea what this all means lol Is this some way of hiding a picture within a picture, or am I way off the mark?
Apple began scanning for CSAM with Neuralhash. This allows you to turn an image into a specific neuralhash thus possibly triggering its (automatic) CSAM detection. Imagine if a picture of a cat could cause Apple to think you have CP on your device.
Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
11–20 of 363 posts
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#12Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#13Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#14Earlier quoted context omitted.
Apple began scanning for CSAM with Neuralhash. This allows you to turn an image into a specific neuralhash thus possibly triggering its (automatic) CSAM detection. Imagine if a picture of a cat could cause Apple to think you have CP on your device.
Well, you'd have to do it 30 times to trigger the system, and then someone at apple moderation would look at those 30 pictures of cats and hit "next" vs "supervisor"
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#15Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#16Earlier quoted context omitted.
Well, you'd have to do it 30 times to trigger the system, and then someone at apple moderation would look at those 30 pictures of cats and hit "next" vs "supervisor"
Good that there’s some human supervision. But, I know I have more than 30 photos of my dog. Also don’t like the idea of false positives auto-sharing some of my camera roll.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#17There are other ways to guess what the hashes are, but I can't think of legal ones.
> Matching-Database Setup. The system begins by setting up the matching database using the known CSAM image hashes provided by NCMEC and other child-safety organizations. First, Apple receives the NeuralHashes corresponding to known CSAM from the above child-safety organizations. Next, these NeuralHashes go through a series of transformations that includes a final blinding step, powered by elliptic curve cryptography. The blinding is done using a server-side blinding secret, known only to Apple. The blinded CSAM hashes are placed in a hash table, where the position in the hash table is purely a function of the NeuralHash of the CSAM image. This blinded database is securely stored on users’ devices. The properties of elliptic curve cryptography ensure that no device can infer anything about the underlying CSAM image hashes from the blinded database.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#18…and? Does OP think reviewers will think a picture of a cat is CSAM?
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#19NeuralHash collisions are interesting, but the way Apple is implementing their scanner it's impossible to extract the banned hashes directly from the local database. There are other ways to guess what the hashes are, but I can't think of legal ones. > Matching-Database Setup. The system begins by setting up the matching database using the known CSAM image hashes provided by NCMEC and other child-safety organizations.…
It's also possible for someone (Attacker A) to go on the darknet and get a list of 96-bit neural hashes, and then publish or sell this list somewhere to another party, Attacker B. The second party would never have to interact with CSAM.
Imagine Ransomware v2: We have inserted 29 photos of CSAM-matching material into your photo library. Pay X monero to this address in 30 minutes, or we will insert 2 additional photos, which will cross the threshold and may result in serious and life-changing consequences to you[1].
The difference here (versus the status quo) is that an easily-broken perceptual hashing enables the attacker to never send or possess any CSAM images[2]. From my experiences with being victims of various hackers, I know a lot of them won't touch CSAM because they know it's wrong, but they'll salivate at an opportunity to weaponise automated CSAM scanning.
[1]: If you think Apple's human review will mitigate this attack, you can permute legal pornography to match CSAM signatures. If Apple's reviewers see 30 CSAM matches and the visual derivatives look like porn, they will be legally required to report to to NCMEC (a statutory quasi-government agency staffed by the FBI), even if all the photos are actually consensual adults.
[2]: If you never possess nor touch CSAM, it might be harder for you to get charged with CP charges. You might be looking at CFAA, blackmail or extortion charges; while your victim faces child pornography charges. This is basically an "amplification attack" on the real world judicial system.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#20Ok so now all we have to do is get a phone, load it with adversarial images that have hashes from the CSAM database and we wait and see what happens. Basically a honeypot. Get some top civil rights attorneys involved. Take the case to the Supreme Court. Get precedence set right. Lawfare