NeuralHash collisions are interesting, but the way Apple is implementing their scanner it's impossible to extract the banned hashes directly from the local database. There are other ways to guess what the hashes are, but I can't think of legal ones. > Matching-Database Setup. The system begins by setting up the matching database using the known CSAM image hashes provided by NCMEC and other child-safety organizations.…
Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
211–220 of 363 posts
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#212Earlier quoted context omitted.
They will be if you collide a low-res image that resembles CSAM. Why would person doing manual review risk his job in case if he’s unsure? Naturally he will just play it safe and report images.
Not resembles. The adversarial image has to match a private perceptual hash function of the same CSAM image that the NeuralHash function matched before a human reviewer ever looks at it.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#213Earlier quoted context omitted.
If you do not consent to having your photos scanned for CSAM, turn off iCloud Photo Library. Same as how you opt out of CSAM scanning of your photo library on Android. If you're concerned about other forms of scanning compelled by the Government, you never consented to the search. So even if Apple complied, the search is invalid and cannot be used to prosecute you.
> If you're concerned about other forms of scanning, you didn't consent—so even if Apple complied, the search is invalid and cannot be used to prosecute you. This is a dangerously false understanding of the law. Stop giving legal advice. You are not a lawyer.
I'm curious, do you think that the Third Party Doctrine applies here?
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#214Earlier quoted context omitted.
If you do not consent to having your photos scanned for CSAM, turn off iCloud Photo Library. Same as how you opt out of CSAM scanning of your photo library on Android. If you're concerned about other forms of scanning compelled by the Government, you never consented to the search. So even if Apple complied, the search is invalid and cannot be used to prosecute you.
It does not appear one can opt out certain folders from this scan. If you enable iCloud backups, it's scans the entire shebang. As previously mentioned, Android doesn't scan all photos on your device... Google scans content uploaded to their servers. Which is reasonable... It's their servers, they can host what they want. Your iPhone is your iPhone .
Citation?
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#215Earlier quoted context omitted.
I find it hard to believe CSAM was so pervasive on iDevices that they'd feel compelled to do something about it. As far as we know (and I'm sure lots of eyeballs are looking now) Android doesn't do this. And frankly, why would Apple care that the FBI isn't cozy with them. Their entire brand is "security and privacy", kind of goes against most 3 Letter Agencies anyway.
I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Android does not do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. It's not on-device scanning, but the effect is functionally identical: photos that are being uploaded to the cloud are being scanned for CSAM. The only real distinction is who owns the CPU which computes the hash. I d…
Where does this assumption come from? Because of iOS lower market share? Are you implying they are more prevalent in Android devices? In desktop computers? I don't understand the logic.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#216Earlier quoted context omitted.
The "send known CSAM" attack has existed for a while but never made sense. However, this technology enables a new class of attacks: "send legal porn, collided to match CSAM perceptual hashes". With the previous status quo: 1. The attacker faces charges of possessing and distributing child pornography 2. The victim may be investigated and charged with child pornography if LEO is somehow alerted (which requires work, a…
LEO is not alerted automatically, where’d you get that idea?
I did work in automating abuse detection years back, and the US govt clearly tells you are not to open/confirm suspected, reported, or happened upon cp. There's a lot of other seemingly weird laws and rules around it.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#217The integrity of this entire system now relies on the security of the CSAM hash database, which has just dramatically increased in value to potential attackers. All it would take now, is for one CSAM hash to be known to the public, then uploading collided iPhone wallpapers to wallpaper download sites. That many false positives will overload whatever administrative capacity there is to review reports in a matter of da…
No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.
So either they have no intention to actually protect user data, or the system is trivially broken; either way a pretty damning look for Apple.
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#218Earlier quoted context omitted.
> Because the searching is being performed on private property, It's it though? The device someone bought 2 years ago suddenly starts reporting them to the FBI's Anti-CSAM unit without the owners realistic consent does seem like a run-around to unpermissioned government searches. It's not reasonable to say "throw away your $1200 device if you don't consent", is it? Nor can a person reasonably avoid iOS updates that f…
> It's it though? Yes. Your phone is your private property, just like your house or your car. Searching your private property requires a warrant or reasonable suspicion, otherwise it's a 4th Amendment violation. This twitter thread is worth a read. https://twitter.com/pwnallthethings/status/14248736290037022...
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#219Earlier quoted context omitted.
It does not appear one can opt out certain folders from this scan. If you enable iCloud backups, it's scans the entire shebang. As previously mentioned, Android doesn't scan all photos on your device... Google scans content uploaded to their servers. Which is reasonable... It's their servers, they can host what they want. Your iPhone is your iPhone .
> If you enable iCloud backups, it's scans the entire shebang. Citation?
Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash
#220Earlier quoted context omitted.
I posted another comment that was misunderstood as well. Folks, no one is proposing to download actual CSAM images to your photo lib. You could be duped thinking you downloaded an image of a beautiful sunset which was carefully manipulated to match the hash of an actual CSAM image.
The parent was proposing to “just send known CSAM”. But OK, say someone sends you a sunset that fools the hasher. Then what? Of course one match won’t do anything, so you’d need to download however many matching sunsets. Then what? The Apple reviewer would see they’re sunsets and you’d challenge the flag saying they’re sunsets. And if somehow NCMEC got involved, they’d see they’re just sunsets. And if law enforcement…