Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

101–110 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#101
post #88
post #60

Earlier quoted context omitted.

Apple has outlined[1] multiple levels of protection in place for this: 1. You have to reach a threshold of matches before your account is flagged. 2. Once the threshold is reached, the matched images are checked against a different perceptual hash algorithm on Apple servers. This means an adversarial image would have to trigger a collision on two distinct hashing algorithms. 3. If both hash algorithms show a match, t…

Will the high-resolution images be collected and used as evidence? Or just the visual derivatives? That's not clear.

Currently, most likely.

I don’t believe Apple has said whether or not they send them in their initial referral to NCMEC, but law enforcement could easily get a warrant for them. iCloud Photos are encrypted at rest, but Apple has the keys.

(Many have speculated that this CSAM local scanning feature is a precursor to Apple introducing full end-to-end encryption for all of iCloud. We’ll see.)

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#102
post #54
post #31

Earlier quoted context omitted.

> If Apple's reviewers see 30 CSAM matches and the visual derivatives look like porn Even worse, just get a "teen" porn screengrab, pass it through the collider and you have pretty much a smoking gun

The "visual derivative" is not something any of us have been shown an example of either. Whatever it is, I suspect you only need to be vaguely in the same ballpark (I would wager humanoid shaped skin tones maybe). So I suspect it would be easier then that (particularly since this whole hashing scheme has been surrounded with a lot of clear garbage - "1 in a trillion" -> on demand collisions in a couple of weeks?

I think visual derivative is just a beating-around-the-bush way of saying “thumbnail.”

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#104

Earlier quoted context omitted.

What kind of social engineering would lead an innocent person to save known CSAM to their photo library?

What kind of social engineering would lead an innocent person to install malware on their devices? Or do you think people like that want to take part in an illegal DDoS botnet?

I think there’s a difference between “I’ll click this totally legit button to protect my computer from viruses” and “I’ll save this picture of a child being raped to my photo library.”

A lot of people may not know how to avoid malware. But I don’t think very many of them would be so inept as to accidentally long press on child porn and tap “Add to Photos”.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#105
post #99

I don't see how this is fixable on their end. Several people have suggested simply layering several different perceptual hash systems, with the assumption that it's difficult to find a colliding image in all of them. This is pretty suspect - there's a reason we hold a decades-long competition to select secure hash functions. Basically, a function can't generally achieve cryptographic properties (like collision-resist…

> First, as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possibility that the match threshold was exceeded due to non-CSAM images that were adversarially perturbed to cause false NeuralHash matches against the on-device encrypted CSAM database.

https://www.apple.com/child-safety/pdf/Security_Threat_Model...

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#106

Earlier quoted context omitted.

The sender would of course be charged with wasting police efforts, defamation attempts+++. In the case of false positives the receiver of course wouldn't be charged, it's more about the fact that this system can be manipulated with too much ease. Even if you're not charged, an investigation takes time away from already limited law enforcement resources. I'm also not interested in buying products from a company that b…

Do you mean charging the sender of the trick images or the receiver?

Well that depends on the situation. Regardless the sender would be charged if found, but if they were able to get legitimate CSAM on the receiver's phone the receiver could possibly be charged too, or at least investigated. Just the idea of getting investigated in these kinds of attacks, much less being exposed publicly as being under investigation is a horrible thought.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#107

This is just getting wilder and wilder by the day, how spectacularly this move has backfired. As others have commented, at this point all you need is someone willing to sell you the CSAM hashes on the darknet, and this system is transparently broken. Until that day, just send known CSAM to any person you'd like to get in trouble (make sure they have icloud sync enabled), be it your neighbour or a political figure, an…

[deleted]

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#108
post #103

Well done! Hopefully all of this progress toward demonstrating how easy it is to manipulate neural hash will get Apple to rollback the update...

Counter-point: hijinks like this are defeated by including the original image instead of the image derivative in associated data. At that point, the system works in the exact same way as the photo scanning status quo.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#109

Earlier quoted context omitted.

The parent was proposing to “just send known CSAM”. But OK, say someone sends you a sunset that fools the hasher. Then what? Of course one match won’t do anything, so you’d need to download however many matching sunsets. Then what? The Apple reviewer would see they’re sunsets and you’d challenge the flag saying they’re sunsets. And if somehow NCMEC got involved, they’d see they’re just sunsets. And if law enforcement…

The point isn't to trick NCMEC, but rather create a DoS attack so no actual triggers can get through the noise.

I thought the point was to SWAT some innocent person? The goal keeps changing.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#110
post #18

…and? Does OP think reviewers will think a picture of a cat is CSAM?

The input image is a parameter, so you could start with some image that would be easier to confuse at the low resolutions the reviewers use. The missing piece in this case is that the database of target hashes is unknown.

Easier to confuse, or even something like a pic of a 20 year old where it's effectively impossible to be sure from the image itself.
Post reply on HN