Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

191–200 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#191
post #184

Earlier quoted context omitted.

I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Android does not do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. It's not on-device scanning, but the effect is functionally identical: photos that are being uploaded to the cloud are being scanned for CSAM. The only real distinction is who owns the CPU which computes the hash. I d…

> Android doesn't do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. So did Apple, and pretty much all cloud hosting providers. This, on device, scanning is what's new, and very out of character for Apple. > If Apple's lobbyists can show that iPhones are already searching for CSAM, arguments for such laws get weaker. I'm not aware of any big anti-CSAM push being m…

> I'm not aware of any big anti-CSAM push being made by Congress.

Right now. The best time for Apple to do this is when cannot be painted as a defensive move against any specific legislation. The CSAM argument has been used many times in the past and it's certain to be used many more times in the future.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#192
post #179

Earlier quoted context omitted.

> You could be duped thinking you downloaded an image of a beautiful sunset If it was anything like the image used to demonstrate this technique on Github, it's unlikely that anyone would describe that sunset as "beautiful". They'd be more likely to describe it as "bugger, this JPEG file is corrupted."

Attacks never get worse over time. It was quite literally less than 24h from "Oh, hey, I can collide this grey blob with a dog!" to "Hey, this thing that looks like cat hashes to the same thing as this dog!" You really think this is going to end at this proof of concept stage?

Of course it will get better. But it's not going to end at "Hey, this photograph of a sunset is visually unchanged" while now matching CSAM. That's just not plausible. It's not how these classifiers work.

Regardless, this whole thing is moot because there are two classifiers, only one of which has been made public. Before any matches can make it to human review, photos in decrypted vouchers have to pass the CSAM match against a second classifier that Apple keeps to itself.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#193
post #184

Earlier quoted context omitted.

> Android doesn't do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. So did Apple, and pretty much all cloud hosting providers. This, on device, scanning is what's new, and very out of character for Apple. > If Apple's lobbyists can show that iPhones are already searching for CSAM, arguments for such laws get weaker. I'm not aware of any big anti-CSAM push being m…

We do know that Apple has been scanning email attachments sent via iCloud email. I don't think it's ever been claimed that Apple has ever scanned anyone's iCloud Photo Library. Ethics aside, on-device scanning has the benefit of Constitutional protection, at least in the USA. Because the searching is being performed on private property, any attempt by the Government to try to expand the scope of searches would be a c…

> Because the searching is being performed on private property,

It's it though? The device someone bought 2 years ago suddenly starts reporting them to the FBI's Anti-CSAM unit without the owners realistic consent does seem like a run-around to unpermissioned government searches. It's not reasonable to say "throw away your $1200 device if you don't consent", is it? Nor can a person reasonably avoid iOS updates that force this feature to be active.

> any attempt by the Government to try to expand the scope of searches

We've seen private companies willfully censor individuals at the government's behest under the current administration - will Apple begin expanding the search and reporting mechanisms just to stay in whatever administration's good grace?

Like I said, this is extremely out of character, and very off-brand for Apple. Why would someone trust Apple going forward? Even Google's Android doesn't snitch on it's owners to law enforcement... Setting aside all the ways for nefarious actors to abuse this system and sic LE on innocent individuals.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#194
post #14
post #11

Earlier quoted context omitted.

Well, you'd have to do it 30 times to trigger the system, and then someone at apple moderation would look at those 30 pictures of cats and hit "next" vs "supervisor"

Good that there’s some human supervision. But, I know I have more than 30 photos of my dog. Also don’t like the idea of false positives auto-sharing some of my camera roll.

Photos of your dog are not going to trigger it. Someone would need to engineer the 30 photos of your dog tweaked to hash to a particular value, and then convince you to save them to your device and then upload to iCloud. And then some portion/abstraction of the dog photo would need to convince a reviewer they were looking at CSAM.

The more likely path to trouble is legal NSFW material that's been engineered.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#195
post #112

Earlier quoted context omitted.

This where the "fog of war" kicks in. What with doors being busted down, police departments making press releases, etc. I can easily imagine that the victim could be prosecuted, convicted and sent away because no-one understood the subtlety that their legal porn was not in fact CSAM.

The fog of war is largely in the realm of post-puberty minors, photos of which are not being included in Apple's corpus of hashes. I find it difficult to believe that anyone could mistake or otherwise "fog of war" a photograph of an adult and a prepubescent minor. And that's assuming someone develops a hash collision which doesn't substantially mangle the photograph like the example offered on Github. Specifically, o…

I don't really want to do the research, so I'll take your word for it.

But by fog of war I was thinking more like the victim already has some sleazy (though marginally legal) stuff on their computer, or a search led to a find of pot in their house, or they lied to try and get out of the rap, or perhaps the FBI offered them a deal and they took it because they saw no way out, or perhaps they were simply an unlikable individual who the jury took a dislike to.

Basically that things are not always clear cut, and they come out of the wrong side of things, in a situation created by Apple's surveillance.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#196
post #193

Earlier quoted context omitted.

We do know that Apple has been scanning email attachments sent via iCloud email. I don't think it's ever been claimed that Apple has ever scanned anyone's iCloud Photo Library. Ethics aside, on-device scanning has the benefit of Constitutional protection, at least in the USA. Because the searching is being performed on private property, any attempt by the Government to try to expand the scope of searches would be a c…

> Because the searching is being performed on private property, It's it though? The device someone bought 2 years ago suddenly starts reporting them to the FBI's Anti-CSAM unit without the owners realistic consent does seem like a run-around to unpermissioned government searches. It's not reasonable to say "throw away your $1200 device if you don't consent", is it? Nor can a person reasonably avoid iOS updates that f…

> It's it though?

Yes. Your phone is your private property, just like your house or your car. Searching your private property requires a warrant or reasonable suspicion, otherwise it's a 4th Amendment violation.

This twitter thread is worth a read.

https://twitter.com/pwnallthethings/status/14248736290037022...

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#197

Earlier quoted context omitted.

I think you misread what was meant by "target". Yeah, Apple might be able to look at the uploaded image. But the reviewers don't have a copy of the original image added to the database , which is the "target".

You’re correct, but the uploaded image is sufficient as it would be obvious some that it isn’t CSAM material. If it was, then would it matter if it wasn’t the original ?

That’s the point; you can’t identify that an image is CSAM just by looking at it.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#198
post #193

Earlier quoted context omitted.

> Because the searching is being performed on private property, It's it though? The device someone bought 2 years ago suddenly starts reporting them to the FBI's Anti-CSAM unit without the owners realistic consent does seem like a run-around to unpermissioned government searches. It's not reasonable to say "throw away your $1200 device if you don't consent", is it? Nor can a person reasonably avoid iOS updates that f…

> It's it though? Yes. Your phone is your private property, just like your house or your car. Searching your private property requires a warrant or reasonable suspicion, otherwise it's a 4th Amendment violation. This twitter thread is worth a read. https://twitter.com/pwnallthethings/status/14248736290037022...

So, what does a person do if they do not consent to this search? Tough?

You can't realistically avoid the iOS update. Apple has effectively given consent on your behalf... How will that fly?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#199

Some people seem to be confused why a hash collision of a cat and a dog matters. Here's a potential attack: share (legal) NSFW pictures that are engineered to have a hash collision with CSAM to get someone else in trouble. The pictures are flagged as CSAM, and they also look suspicious to a human reviewer (maybe not enough context in the image to identify the subject's age). To show that this can be done with real NS…

Does anyone save porn to their personal photo libraries? Especially porn as suspicious as the image you posted?

The CSAM detection system supposes people save actual child porn to their personal photo libraries.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#200
post #65

Earlier quoted context omitted.

So, everyone is going to turn off their iCloud sync and they won’t be a target anymore?

It doesn't necessarily mean that it will stop them from being a target, because Apple says this[1]: > This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time. [1] https://www.apple.com/child-safety/

> This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time.

"Think of the children" is the most recognizable trope in TV and film. They couldn't have phrased that to be more Orwellian.

Post reply on HN