Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

401–410 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#401
post #393

Earlier quoted context omitted.

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

When end-to-end encryption is done correctly, the answer is "we literally can't access it" as a matter of mathematics, whether the state accepts it or not. A state that does not accept it might retaliate against the entity giving that answer or forbid future use of end-to-end encryption without backdoors, but the truth of the answer doesn't depend on anyone's acceptance.

Isn't that when the state prohibits your service? So then no body cares about your mathematical proof because it's a crime to use it.

This is what has happened in many countries already.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#402

Earlier quoted context omitted.

That is the problem. CSAM is just smoke and mirrors paired with appeal to emotions to win approval more easily. I don't want anyone, neither Apple, nor Microsoft, Google and others to sneak into my files. Did anyone realize that in the 21st century our cellphone is essentially our wallet?

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

Exactly, and 100% Google and Microsoft have on device scanning as well. We are saying "Apple are bad for admitting it" what about the others that are not?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#403

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing. This is the difference between putting CSAM on a sign in y…

Only the safety tokens are generated on your device, the action triggering scan happens in the cloud (just like all the others) and then it goes to human review, so if it's a hash collision it'd be caught there when they review the images, and they can only review the images that matched CSAM.

I honestly can't find the uproar here. Google devices can face match photos offline... so they are applying a neural net (scanning) ON THE DEVICE! How is that not worse than what apple do?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#404
> Apple however told Motherboard in an email that that version analyzed by users on GitHub is a generic version, and not the one final version that will be used for iCloud Photos CSAM detection. Apple said that it also made the algorithm public.

When did they make NeuralHash public?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#405
post #393

Earlier quoted context omitted.

When end-to-end encryption is done correctly, the answer is "we literally can't access it" as a matter of mathematics, whether the state accepts it or not. A state that does not accept it might retaliate against the entity giving that answer or forbid future use of end-to-end encryption without backdoors, but the truth of the answer doesn't depend on anyone's acceptance.

Isn't that when the state prohibits your service? So then no body cares about your mathematical proof because it's a crime to use it. This is what has happened in many countries already.

Sure, but that's a case of "we're prohibited from providing end-to-end encryption and preserving user privacy so we can scan for prohibited content as mandated by authorities", not "we are keeping children safe while still preserving user privacy"

Legal terms such as "murder", "fraud" and "rape" do change as effect of regulatory changes. "Encryption" and "privacy" do not.

There's a limit to how much you can bend semantics in your PR before it breaks and you get backlash.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#406
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

This is one of the most common misunderstandings, both when people are arguing for or against.

People who understand tech well enough to recognize hashes like MD5 and SHA don't dive deep enough to understand that this is something completely different.

I even suspect this is deliberate from Apple's side when announcing and talking about these changes - making people wrongly believe that only exact matches will trigger, except possibly in extremely rare cases and under concious attacks.

They could have called it "fingerprint" or something but deliberately went with a technical term that even confuses technical people who know well enough what a hash usually means.

Vice is falling victim to this misunderstanding stemming from the conflation of "hash".

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#407

Earlier quoted context omitted.

Those are two almost identical images based off each other. I know that that "think of the children" is a meme, but I think this illustrates the point for apple. If you have a croped or modified image of CSA the system will identify it. As long as your image is different enough from CSA, you are safe. The point here is that Apple is specifically looking for matches against known CSA material. If someone can demonstra…

> If someone can demonstrate that a legal NSFW image (eg. regular old-fashioned pornography), can be collided with a legal, completely 100% SFW image then I'll be concerned. Look at this other collision: https://twitter.com/SarahJamieLewis/status/14282060881181491... An attacker can send you an innocent looking picture that embbed some CSA material and you get swatted the next day.

I think you are getting downvoted because thats the same image I replied to.

Looking at those two images its plain to see why they are identical.

And if someone is sending you CSA material, isn't that the point of this process. Apple identifies it as CSA, can give you a warning its sensitive, and identify they authorities that people are sending CSA.

Again - this seems like a win. If Apple can automatically identify CSA material, en-masse thats good.

edit: It looks like they are different URLs, but Twitter only allows people to see replies if they are logged in, so I can't see that example.

edit 2: On further thought, if someone can use CSA material and produce an innocuous image with a similar hash, if they send that image to you, its still proof that the sender had CSA material. Again, its still good.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#408
post #405

Earlier quoted context omitted.

Isn't that when the state prohibits your service? So then no body cares about your mathematical proof because it's a crime to use it. This is what has happened in many countries already.

Sure, but that's a case of "we're prohibited from providing end-to-end encryption and preserving user privacy so we can scan for prohibited content as mandated by authorities", not "we are keeping children safe while still preserving user privacy" Legal terms such as "murder", "fraud" and "rape" do change as effect of regulatory changes. "Encryption" and "privacy" do not. There's a limit to how much you can bend sema…

But if you're a company like apple, it'd be bad business to wait until large government bans your service/device before you respond to it. Much better to read the tea leaves and get a head of it.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#409

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Repeating myself from another thread but… China.

Conjecture, admittedly:

1. Apple cannot lose the Chinese market. Huge and more important fastest growing geo for the company.

2. China is self deprecating elements of its own tech sector (aggressive crackdowns on both established companies like tencent and Alibaba as well as individual web sites). They are clearly cleaning house from a surveillance and control perspective. Apple is not immune, but it’s an American behemoth, so open door crackdowns are impossible.

I don’t think Apple’s CSAM push and China’s crackdown are purely coincidental.

Who can argue with stemming child abuse? It’s the type of hot button issue that affords broad acceptance for intrusive tech.

The leap from scanning for abuse to scanning for anti regime content is more like a tiny step.

It seems obvious from afar that the company adamant about refusal to unlock a potential terrorist’s iPhone on privacy principles (with the attendant marketing benefits) would so suddenly force push (and therefore ensure collection massive training data with or without opt-in for Chinas v2.0) such a boldly invasive feature addition.

Turns out vertical integration is both gift and curse (dependent on the whims of the integrator) for on-device privacy and autonomy.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#410

Earlier quoted context omitted.

You don't have to be intelligent to know that CSAM is super illegal and you probably don't want them to be co-mingled with pictures of your mum and last night's dinner.

Except intelligence is clustered with other pathologies such as poor impulse control. Knowledge of the law is not the end-all-be-all of human behavior. Both the intelligent and unintelligent are capable of poor impulse control, but the unintelligent are statistically much more likely to exhibit a lack of impulse control, among other things such as difficulty in long-term reasoning and connecting one's actions with ad…

I've never lacked the impulse control to import regular porn into my photo library. And regular porn only comes with the risk of embarrassment, not prison.
Post reply on HN