Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

121–130 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#122
Apple is scanning files locally before they are uploaded to iCloud in order to avoid storing unencrypted photos within iCloud but still discovering CSAM. All the other storage providers already scan all the images uploaded on their servers. I guess you can decide which is better. Here is Google's report on it:

https://transparencyreport.google.com/child-sexual-abuse-mat...

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#123
post #30

This is just getting wilder and wilder by the day, how spectacularly this move has backfired. As others have commented, at this point all you need is someone willing to sell you the CSAM hashes on the darknet, and this system is transparently broken. Until that day, just send known CSAM to any person you'd like to get in trouble (make sure they have icloud sync enabled), be it your neighbour or a political figure, an…

The "send known CSAM" attack has existed for a while but never made sense. However, this technology enables a new class of attacks: "send legal porn, collided to match CSAM perceptual hashes". With the previous status quo: 1. The attacker faces charges of possessing and distributing child pornography 2. The victim may be investigated and charged with child pornography if LEO is somehow alerted (which requires work, a…

Before they make it to human review, photos in decrypted vouchers have to pass the CSAM match against a second classifier that Apple keeps to itself. Presumably, if it doesn’t match the same asset, it won’t be passed along. This is explained towards the end of the threat model document that Apple posted to its website. https://www.apple.com/child-safety/pdf/Security_Threat_Model...

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#124
post #49
post #35

So, what does Apple get out of all this, except negative attention, erosion of their image, possible privacy lawsuits, etc? I just don't understand what Apple's motivation would have been here. Surely this fallout could have been anticipated?

The FBI off their back that they aren’t doing enough to stop the spread of CP.

It is more believable they are introducing this tech for larger international security reasons still kept under wraps.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#125
post #113

Earlier quoted context omitted.

I can't tell if you are being sarcastic. In case you are not, isn't the act of sending those pictures completely illegal?

People here are proposing intentionally creating image assets which collide with perceptual hashes of known CSAM (ignoring whether that is legal or ethical) and sharing those assets to effectively SWAT unaware targets.

Oh, I think I misunderstood you. I thought you meant instead of "sending images that collides with perceptual hashes of known CASM", why not "send actual CSAM in 'Facebook Messenger or Gmail or Dropbox', and since those services also use some other detection algorithm, it will also incriminate the receiver."

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#126
post #39

Earlier quoted context omitted.

A hash collision allows you to create material that matches CSAM signatures, without being CSAM. This opens up a new class of attacks. Specifically, many criminal actors don't touch CSAM because it's wrong. But some of these criminal actors will happily abuse legal systems, e.g. SWATTing.

I would gladly have a mobile phone full of memes that have been modified to match, just for the lulz. I honestly think every meme should be put through just to have "illegal memes"

Illegal memes. Finally. Illegal Pepe will be the crowning jewel of my rare Pepe collection.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#127
post #125

Earlier quoted context omitted.

People here are proposing intentionally creating image assets which collide with perceptual hashes of known CSAM (ignoring whether that is legal or ethical) and sharing those assets to effectively SWAT unaware targets.

Oh, I think I misunderstood you. I thought you meant instead of "sending images that collides with perceptual hashes of known CASM", why not "send actual CSAM in 'Facebook Messenger or Gmail or Dropbox', and since those services also use some other detection algorithm, it will also incriminate the receiver."

Those services will take your account through the same, if not more invasive, process if you are found with a hash match like the ones being proposed in these comments. Unlike Apple, they’ve built interfaces that surface all your account activity to reviewers.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#128

Earlier quoted context omitted.

What kind of social engineering would lead an innocent person to install malware on their devices? Or do you think people like that want to take part in an illegal DDoS botnet?

I think there’s a difference between “I’ll click this totally legit button to protect my computer from viruses” and “I’ll save this picture of a child being raped to my photo library.” A lot of people may not know how to avoid malware. But I don’t think very many of them would be so inept as to accidentally long press on child porn and tap “Add to Photos”.

... and "I'll save this picture of an hilarious kitten to my photo collection"...

Fixed it for you.

The image to be saved doesn't have to be disturbing at all to trigger a hash collision.

The linked repo has code to modify an image to generate a hash collision with another unrelated image.

That's the whole point.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#129
What are trying to prove here? It takes a human not noticing that a glitchy image of cat is not the same as picture of dog, 30 times.

Yea collisions are technically, possible. Apple has accounted for that. What is your point?

Hashes are at the core of a lot of tech, and collisions are way easier and more likely to happen in those in many cases, but suddenly this is an issue for ya'll?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#130

how long until they start scanning a device's framebuffer in realtime? why stop at CSAM? Pirated material like movies next?

> how long until they start scanning a device's framebuffer in realtime?

Some smart TVs do automated content recognition so the manufacturers can spy on what you're watching and sell the data to the highest bidders.

Post reply on HN