Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

221–230 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#221

Earlier quoted context omitted.

Of course it will get better. But it's not going to end at "Hey, this photograph of a sunset is visually unchanged" while now matching CSAM. That's just not plausible. It's not how these classifiers work. Regardless, this whole thing is moot because there are two classifiers, only one of which has been made public. Before any matches can make it to human review, photos in decrypted vouchers have to pass the CSAM matc…

Match the first classifier, and your file gets uploaded unencrypted to Apple. Which is fine if it's probable CSAM. But what if they switch efforts to combat, say, piracy?

That’s not how the technology works. The files are never decrypted. Instead, if enough hashes match, a “visual derivative” is revealed. What a “visual derivative” is hasn’t been explained, but most people seem to think it’s a low-res version of the file.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#222

Despite that Apple scanning our images is a horrible privacy practice, I don't get why 𝚜̶𝚘̶ ̶𝚖̶𝚊̶𝚗̶𝚢̶ some people think this is an ineffective idea. Surely you can easily fabricate innocent images whose NeuralHash matches the database. But in what way are you going to send them to victims and convince them to save them to their photo library? The moment you send it via WhatsApp FB will stop you because (they th…

Almost nobody is arguing the effectiveness of the idea. That would be missing the point entirely.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#223

Some people seem to be confused why a hash collision of a cat and a dog matters. Here's a potential attack: share (legal) NSFW pictures that are engineered to have a hash collision with CSAM to get someone else in trouble. The pictures are flagged as CSAM, and they also look suspicious to a human reviewer (maybe not enough context in the image to identify the subject's age). To show that this can be done with real NS…

Does Google Chrome scans downloaded images ?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#224

Earlier quoted context omitted.

Counter-question: At what point is child porn actually child porn, socially and statistically speaking? If I share that picture of my child with my friends and loved ones on Facebook - at what "scale" is it considered to be added to that database as child porn? 1k shares? 10k? Who's the one eligible to decide that? The judicatives? I think this scenario is a constitutional crisis because there's no good solution to i…

I think you're underestimating the severity of child abuse by orders of magnitude. CSAM is a database of child rape, not child nudity.

For now. You don't know what will be added next.

China will demand it to include pictures of the Tiananmen massacre.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#225

Earlier quoted context omitted.

Of course it will get better. But it's not going to end at "Hey, this photograph of a sunset is visually unchanged" while now matching CSAM. That's just not plausible. It's not how these classifiers work. Regardless, this whole thing is moot because there are two classifiers, only one of which has been made public. Before any matches can make it to human review, photos in decrypted vouchers have to pass the CSAM matc…

Match the first classifier, and your file gets uploaded unencrypted to Apple. Which is fine if it's probable CSAM. But what if they switch efforts to combat, say, piracy?

So your concern is that Apple will start doing something evil at any moment without your consent. That's been true of any computer platform since the advent of software updates. You can such hypotheticals with any company you like.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#226
post #57

Earlier quoted context omitted.

Give it a few days, and you'll probably find someone selling a list of CSAM neural hashes on darknet marketplaces.

Or tweeting out a bunch of them. They're just 12 byte numbers.

I bet there's a list of hashes already up in Pastebin.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#227

The integrity of this entire system now relies on the security of the CSAM hash database, which has just dramatically increased in value to potential attackers. All it would take now, is for one CSAM hash to be known to the public, then uploading collided iPhone wallpapers to wallpaper download sites. That many false positives will overload whatever administrative capacity there is to review reports in a matter of da…

No, there’s another private hash function that also has to match the known CSAM image for an image to be considered a match. That one can’t be figured out through this technique.

Which means all it takes now is one disillusioned Apple employee to leak the details of thay private hash function and the whole system is compromised.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#228
post #123
post #30

Earlier quoted context omitted.

The "send known CSAM" attack has existed for a while but never made sense. However, this technology enables a new class of attacks: "send legal porn, collided to match CSAM perceptual hashes". With the previous status quo: 1. The attacker faces charges of possessing and distributing child pornography 2. The victim may be investigated and charged with child pornography if LEO is somehow alerted (which requires work, a…

Before they make it to human review, photos in decrypted vouchers have to pass the CSAM match against a second classifier that Apple keeps to itself. Presumably, if it doesn’t match the same asset, it won’t be passed along. This is explained towards the end of the threat model document that Apple posted to its website. https://www.apple.com/child-safety/pdf/Security_Threat_Model...

How...exactly did they train that CSAM classifier? Seeing as that training data would be illegal. I'd be most interested in an answer on that one. They are willing to make that training data set a matter of public record on the first trial, yes?

Or are we going to say secret evidence is just fine nowadays? Bloody mathwashing.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#229

how long until they start scanning a device's framebuffer in realtime? why stop at CSAM? Pirated material like movies next?

They are not doing this for the fun of it. If they didn't have to, they would not do it at all. You have made a huge leap from scanning for pre-existing CSAM while in transit to a cloud service to scanning frame buffers on device in real-time. You should get some type of Olympic medal for such a leap. This tech is to catch the lowest possible hanging fruit of the dumbest of all CSAM-sharing/saving folks as required b…

Real-time framebuffer hashing might be a big leap, but what about local filesystem scanning built into the OS?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#230
post #30

This is just getting wilder and wilder by the day, how spectacularly this move has backfired. As others have commented, at this point all you need is someone willing to sell you the CSAM hashes on the darknet, and this system is transparently broken. Until that day, just send known CSAM to any person you'd like to get in trouble (make sure they have icloud sync enabled), be it your neighbour or a political figure, an…

The "send known CSAM" attack has existed for a while but never made sense. However, this technology enables a new class of attacks: "send legal porn, collided to match CSAM perceptual hashes". With the previous status quo: 1. The attacker faces charges of possessing and distributing child pornography 2. The victim may be investigated and charged with child pornography if LEO is somehow alerted (which requires work, a…

The attacker faces no charges because the colliding image can be a harmless meme.
Post reply on HN