Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

691–700 of 725 posts

Re: Hash collision in Apple NeuralHash model

#691

Earlier quoted context omitted.

I think you may have attracted less downvotes if the phrasing was changed to "Yes, just like false accusations of rape , it doesn't matter that you prove it was false afterwards." I also think that those downvoting you might've applied the principle of charity and taken the best interpretation of what you've written or at least ask .

> I also think that those downvoting you might've applied the principle of charity and taken the best interpretation of what you've written or at least ask. There are far too many people who assume/assert false accusations of rape are the norm for the principle of charity to apply here.

Is it the norm here? If not, then I suggest the principle should apply here.

Re: Hash collision in Apple NeuralHash model

#692

Earlier quoted context omitted.

The real world and the computer world intersect. This is precisely typified by what is being discussed, surely? Apple is trying to automate and computerise a process that was not automated previously, apply it to a huge number of people, and with disastrous potential consequences should their wonderful design be found lacking. And within days, they have already utterly failed to provide one of their own self-stated a…

The process of making accusations and arrests is not automatic. The Apple system sends flagged photos to reviewers, and if the reviewers find them suspicious, they send them to the poor souls at NCMEC, who will compare the flagged photo with the original illegal photo that's supposedly a match, and inform law enforcement if they are in fact a match. Nobody will get cops at their door because somebody sent them a grey…

What part of "they already totally fucked up how their own process is supposed to work" don't you understand?

Re: Hash collision in Apple NeuralHash model

#693

Not knowing too much of the NeuralHash model, but why are they using MD5 hash, they are known to have many collisions. We don't use MD5 for private/public keys for the same reason

What makes you think they're using MD5 anywhere? Even if they were, it wouldn't matter, because NeuralHash is non-cryptographic by design.

I looked at the link and looked at the output from the algorithm for the 2 images which was a MD5 hash. so from that :)

Re: Hash collision in Apple NeuralHash model

#694
post #138

Earlier quoted context omitted.

The speculation that I've seen here is that Apple is rolling this out ahead of a future announcement that iCloud uploads will be encrypted.

Are they not? I would've thought that with Apple advertising privacy and security they would at least encrypt iCloud uploads.

Apple has the decryption keys to iCloud... It is one of those things that many people assume the other way given Apple's marketing and PR stands.

I for one am aware of this with iCloud and am still using iCloud for convenience (and by choice). If I were in need of better privacy, I can always use the iPhone without iCloud, and it will work. After this "in phone" watchdog implementation, that will not be the case. I will assume that Apple is constantly watching all my unencrypted content in the worst case, on behalf of state actors and intelligence agencies.

We have seen Apple give in to the Chinese government spying because it is the law there. US government could easily ask for this and also apply a gag order preventing Apple from being able to tell the user. The best situation is to lack such a tool.

Re: Hash collision in Apple NeuralHash model

#695
post #683

Earlier quoted context omitted.

The more collisions, the more chances of a false positive by a (tired, underpaid) human. I don't envy the innocent person whose home gets raided by a SWAT team convinced they're busting a child sex trafficker.

The database is known to contain non-csam images like porn. I doubt the reviewer will be qualified to discern which is which.

Not that I doubt your motives, but can I get your source on this? It seems like a huge blunder if so.

Re: Hash collision in Apple NeuralHash model

#696
post #279

Earlier quoted context omitted.

That's interesting, I may just do the same thing as well - the camera is the largest thing of why I want to be on an phone. I may just go LineageOS.

If you have a Pixel, or are willing to buy one, CalyxOS [1] may be worth a look. It's a privacy-focused ROM that still integrates microG, so it's compatible with most apps (unlike the other popular privacy-focused ROM GrapheneOS [2] which doesn't support microG). The big advantage to CalyxOS or GrapheneOS versus Lineage is they support re-locking the bootloader, which means that verified boot still works - important…

> It's a privacy-focused ROM that still integrates microG, so it's compatible with most apps (unlike the other popular privacy-focused ROM GrapheneOS [2] which doesn't support microG).

Many apps are also compatible with GrapheneOS and installing https://grapheneos.org/usage#sandboxed-play-services provides broader app compatibility.

Re: Hash collision in Apple NeuralHash model

#697

Earlier quoted context omitted.

What makes you think they're using MD5 anywhere? Even if they were, it wouldn't matter, because NeuralHash is non-cryptographic by design.

I looked at the link and looked at the output from the algorithm for the 2 images which was a MD5 hash. so from that :)

But it isn't MD5. It's not even the same length as an MD5 hash. I am confused by your reasoning.

Re: Hash collision in Apple NeuralHash model

#698

Earlier quoted context omitted.

The process of making accusations and arrests is not automatic. The Apple system sends flagged photos to reviewers, and if the reviewers find them suspicious, they send them to the poor souls at NCMEC, who will compare the flagged photo with the original illegal photo that's supposedly a match, and inform law enforcement if they are in fact a match. Nobody will get cops at their door because somebody sent them a grey…

What part of "they already totally fucked up how their own process is supposed to work" don't you understand?

What part of it is fucked up? They never promised that their hashing algorithm was uncollidable. The process is specifically designed to be tolerant of hash collisions (and in fact wouldn't work otherwise, because the system needs to ignore small differences between copies of the illegal images, like one-pixel edits or color temperature differences or photocopies).

There are multiple stages of human review in the process and a high threshold for activation of the proccess because collisions are inevitable. The fact that collisions exist doesn't impact the safety of the product whatsoever.

I ask again, what is the sequence of events where a hash collision from a benign image can lead to any consequence at all for the user?

Re: Hash collision in Apple NeuralHash model

#699
post #666

Earlier quoted context omitted.

What kind of non-child-porn imagery is so similar to child porn that it fools the NCMEC investigator who is looking at it side-by-side with its maliciously-collisioned hash match, but is at the same time so so dissimilar from real child porn that, as you say, the target won't report its sudden appearance on their device and the the sender won't be at legal risk? Your scenario requires the image (not the hash, but the…

You're assuming that there is a side-by-side comparison with a hash matching image. I think that is an extremely big assumption which assumes facts not in evidence at all. As far as what kind of image would be believed to be child porn without a side-by-side with the supposed match: ordinary porn. Without context plenty would be hard to distinguish, especially with the popularity of waxed smooth bodies and explicit c…

You still haven't explained how an image can be at the same time so benign that the user doesn't delete it from their phone and cloud service and the sender is in no legal danger, and yet so obviously pornographic that a jury will be convinced beyond any reasonable doubt that it's child porn.

The entire point of this process is to catch only images from a known catalogue of existing images, of course there will be opportunity for side-by-side comparison. And if the side-by-side comparison can convince a jury that the images are the same, then the result is literally identical to if you had just sent the original image, the hash checking service hasn't impacted the attack whatsoever.

The idea that new images of nudity could be caught in it is because of a mixup by the press after it was announced, because people confused it with a different parental control feature that detects nudity in images taken by your kids' phones. This is not the same thing.

Re: Hash collision in Apple NeuralHash model

#700

Earlier quoted context omitted.

Where did you get this idea, scooby doo? It is not illegal to be an unwilling recipient of illegal material. If a package shows up at your door with a bomb, you're not gonna be thrown in jail for having a bomb.

Possession of CSAM is a strict liability crime in most jurisdictions.

That is simply not true. There is no American jurisdiction where child pornography is a strict liability crime.

On this topic, the Supreme Court has ruled in Dickerson v US that, in all cases, to avoid First Amendment conflicts, all child pornography statutes must be interpreted with at least a "reckless disregard" standard.

Here is a typical criminal definition, from Minnesota, where a defendant recently tried to argue that the statute was strict liability and therefore unconstitutional, and that argument was rejected by the courts because it is clearly written to require knowledge and intent:

> Subd. 4. Possession prohibited. (a) A person who possesses a pornographic work or a computer disk or computer or other electronic, magnetic, or optical storage system ․ containing a pornographic work, knowing or with reason to know its content and character, is guilty of a felony․

Post reply on HN