Live data from Hacker News

ImageNet contains naturally occurring Apple NeuralHash collisions

blog.roboflow.com

201–210 of 530 posts

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#201
post #162

Earlier quoted context omitted.

Except that there's a threshold involved. A single matching file doesn't trigger an investigation; it takes multiple (10+, maybe more?) matches to do that.

In the interview Craig Federighi gave on Friday, he said 30.[1] I have no idea if he was just throwing a number out or if that's the actual threshold. [1]: https://tidbits.com/2021/08/13/new-csam-detection-details-em...

Either way, it's high enough that adding a single file to the set wouldn't be a useful way of finding people who have that file. One attack I can imagine would be to add a whole set of closely related photos (e.g. images posted online by a known dissident) to identify the person who took them, and even that would be a stretch.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#202
post #61

Earlier quoted context omitted.

That China would use heavy handed tactics to coerce a US tech company? Google for "Operation Aurora" Also see: https://www.reuters.com/article/us-china-apple-icloud-insigh... for a very similar situation to the one described up-thread.

Assuming you are American — where do you think your iCloud keys are stored? You do know Apple cooperates with US LE and intelligence? This is a nothing hamburger.

I concede that there are overlapping issues there. But if you're saying there aren't places China goes with this sort of info that's different from the US, I don't think any debate would change your mind.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#203

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

> If the CCP says "put these hashes in your database or we will halt all iPhone sales in China", what do you think Apple is going to do? Or maybe China already said "put in this CSAM check or you can't make or sell phones in China". Since Apple's position is contrary to their previous privacy policy and doesn't seem to make a lot of sense, it's quite possible extortion already happened (and not necessarily by China).

I'd honestly believe such pressure came from US domestic intelligence or law enforcement agencies just as easily as from China.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#204

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

The only way this matters [today] though is if apple turns it on for all pictures, not just icloud ones. Presumably "Chinese iCloud" already scans uploaded photos cloud side.

Unless the goal is to simply the effort/expense of scanning by making it a client process.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#205

Earlier quoted context omitted.

And what if the FBI demands a list of all Apple users who have matched even 1 CSAM photo for their own private watchlist?

And what if the FBI demands that Apple leadership genuflect toward an oil painting of J Edgar Hoover? The FBI can demand all sorts of things. In this case, Apple isn't tracking collisions as small as 1 photo.

[deleted]

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#206

It doesn’t matter if there are collisions if the two images don’t actually look the same. Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America? PhotoDNA has existed for over a decade doing the same thing with no instances that I have heard of. If some corrupt government wants to get you they don’t need this. They can just unilaterally say you’…

The damage is already done by the time it gets to the point of devices being confiscated.

If you don't actually have CSAM then the person at Apple who visually audits the collision set will not send your info to law enforcement, and nothing will be confiscated. Apple doesn't just take any instance of a collision and send it to the FBI.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#207

Earlier quoted context omitted.

Seems pretty trivial to have different servers sides per country, and put there a different db. EU, China, Iran, US: everyone gets to spy on their own children and forbid whatever they want.

Yeah, but if they tell us they're doing that, then it's pretty obvious what they're up to. And if they don't tell us they're doing that, but do it anyway - then they have to perpetually pay every developer involved in that upgrade enough money to keep their mouth shut indefinitely - knowing that the developers know that APPLE knows how much they'd lose in fines if they got caught. Which is an unreasonably large liabi…

> if they tell us they're doing that, then it's pretty obvious what they're up to.

didn't they already say the DB would be nation dependent?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#208

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

Of course Apple would do it. They’d look like fools for saying they want to stop CP, then refusing the listen to the government of nearly a billion people when it says “Please ban this newly produced material”.

At best, they would look biased. At worst, they would be sending a signal that they don’t care about Chinese children.

You wouldn’t even need government strong arming, mobs of netizens would happily tear Apple down.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#209

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

The only way this matters [today] though is if apple turns it on for all pictures, not just icloud ones. Presumably "Chinese iCloud" already scans uploaded photos cloud side. Unless the goal is to simply the effort/expense of scanning by making it a client process.

> The only way this matters though is if apple turns it on for all pictures,

And there’s no way the CCP would order Apple to do that.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#210

Earlier quoted context omitted.

We certainly have Apple's PR blunder to thank for that, but if PhotoDNA always held that potential for abuse due to its very nature, why did we remain silent for 13 years? Maybe it's because Google and Microsoft and others' policy of security through obscurity actually succeeded in preventing the details of PhotoDNA from coming to light, and it took Apple exposing their hashing model to reverse engineering by includi…

Considering I didn't know about: - PhotoDNA - CSAM scanning on cloud photo platforms - the acronym "CSAM" Before this whole Apple client-side scanning debacle... seems pretty likely. A lot of privacy-focused people also avoid Google and Microsoft cloud services like the plague and trusted Apple up to this point to protect their privacy. The fact that Apple was (and is) scanning iCloud Photos libraries for CSAM unbekn…

I think the actual issue is that Apple wasn't scanning enough user data, so the government or the FBI or some other external force was holding them accountable for it out of public view, and Apple was pressured into increasing the amount of scanning they conducted.

"U.S. law requires tech companies to flag cases of child sexual abuse to the authorities. Apple has historically flagged fewer cases than other companies. Last year, for instance, Apple reported 265 cases to the National Center for Missing & Exploited Children, while Facebook reported 20.3 million, according to the center’s statistics. That enormous gap is due in part to Apple’s decision not to scan for such material, citing the privacy of its users." [1]

[1] https://www.nytimes.com/2021/08/05/technology/apple-iphones-...

Post reply on HN