Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

701–710 of 725 posts

Re: Hash collision in Apple NeuralHash model

#701

Earlier quoted context omitted.

The difference is that now they confirmed that they do search your private images.

Why would that make it any likelier that they are also secretly searching your files, with another method? Seems completely orthogonal to me.

They showed that they are willing to do it in one case. Why not in other cases?

Re: Hash collision in Apple NeuralHash model

#702
post #70
post #18

How can you use it for targeted attacks? This is what would need to happen: 1. Attacker generates images that collide with known CSAM material in the database (the NeuralHashes of which, unless I'm mistaken, are not available) 2. Attacker sends that to innocent person 3. Innocent person accepts and stores the picture 4. Actually, need to run step 1-3 at least 30 times 5. Innocent person has iCloud syncing enabled 6.…

"How can you use it for targeted attacks?" Just insert a known CSAM image on target's device. Done. I presume this could be used against a rival political party to ruin their reputation - insert bunch of CSAM images on their devices. "Party X is revealed as an abuse ring". This goes oh-so-very-nicely with Qanon conspiracy theories which even don't require any evidence to propagate widely. Wait for Apple to find the i…

How is this different from server side scanning, the policy de jour that Apple was trying to move away from?

Re: Hash collision in Apple NeuralHash model

#703

Earlier quoted context omitted.

It only happens on Apple devices right before the content is uploaded to the service. How is that a meaningful difference for the stated end goals, that can explain the lack of precedent.

I think this is where a disconnect is occurring. In this specific case yes. That is what is supposed to happen. But Apple also sets the standard that this is just the beginning, not the end. They say as much on page 3 in bold, differentiated color ink https://www.apple.com/child-safety/pdf/Expanded_Protections_... And there’s nothing to stop them from scanning all images on a device. Or scanning all content for keywo…

>And there’s nothing to stop them from scanning all images on a device.

All images on your device have been scanned for years by ML models to detect things all sorts of things and make your photo library searchable regardless of whether you use an Android or Apple device. That's how you can go and search "dog", "revolver", "wife", etc and get relevant photos popping up.

Re: Hash collision in Apple NeuralHash model

#704

Earlier quoted context omitted.

So in your mind, because so far we've seen no evidence that this has been abused, it's nothing to worry about going forward? And that making an existing situation even more widespread is also completely OK?

> So in your mind, because so far we've seen no evidence that this has been abused, it's nothing to worry about going forward? Yeah, basically. It doesn't seem like people actually use CSAM to screw over innocent folks, so I don't think we need to worry about it. What Apple is doing doesn't really make that any easier, so it's either already a problem, or not a problem. > And that making an existing situation even mo…

And if it is a problem, not doing this doesn't resolve the problem.

If it were to become a problem in the future, it could become a problem regardless of whether or not the scanning is done at the time of upload on device or at the time of upload on server.

Re: Hash collision in Apple NeuralHash model

#705

Earlier quoted context omitted.

Possession of CSAM is a strict liability crime in most jurisdictions.

That is simply not true. There is no American jurisdiction where child pornography is a strict liability crime. On this topic, the Supreme Court has ruled in Dickerson v US that, in all cases, to avoid First Amendment conflicts, all child pornography statutes must be interpreted with at least a "reckless disregard" standard. Here is a typical criminal definition, from Minnesota, where a defendant recently tried to ar…

I tried to look up [Antonio] Dickerson v. US, but I don't see any SCOTUS decision on it, only a certiorari petition. Do you have a reference for the decision?

Re: Hash collision in Apple NeuralHash model

#706

Earlier quoted context omitted.

>Also, if Twitter, Google, Microsoft are already deploying CSAM scanning in their services .... why are we not hearing about all the "swatting"? >their services >T H E I R S E R V I C E S Because it's on their SERVICES, not on their user's DEVICES, for one. Also, regardless of swatting, that's why we have an issue with Apple.

> Because it's on their SERVICES, not on their user's DEVICES, for one. Effectively the same for Apple. It’s only when uploading the photo. Doing it on device means the server side gets less information.

A server-side action is triggering a local action. The action is still local.

Re: Hash collision in Apple NeuralHash model

#707
post #171

Earlier quoted context omitted.

Love the relevant xkcd! And to reply to your point, simply sending unsolicited CSAM via iMessage doesn’t trigger anything. That message has to be saved to your phone then uploaded to iCloud. Someone else above said repeat this process 20-30 times so I presume it can’t be a single incident of CSAM. Seems really really hard to trigger this thing by accident or maliciously

People are saying that, by default, WhatsApp will save images directly to your camera roll without any interaction. That would be an easy way to trigger the CSAM detection remotely. There are many people who use WhatsApp so it's a reasonable concern.

Can you send images to people that are not on your friend list?

Re: Hash collision in Apple NeuralHash model

#708
post #24
post #7

That’s end game. Now you can use it for targeted attacks against innocent people. This needs to be shut down and disposed of immediately. There is no other outcome which is socially acceptable for Apple. I feel vindicated now. There are a lot of people saying that I’m insane as I’ve dumped the entire iOS ecosystem in the last week. But Craig was busy steamrolling out the marketing still only a couple of days back abo…

You are insane. 1. Dumping iOS ecosystem and pick what? You think Android is better and won't have this? iOS is the strongest mobile system in terms of privacy protection available to this date. Hell, the FBI doesn't even need to ask Google to decrypt an Android. 2. Theoretically you can target attacks against anyone. It is just a matter of efforts. If you are a political target, they can already implant spywares aro…

Your account has been breaking the site guidelines by using HN for political battle and also with personal attacks, like here and https://news.ycombinator.com/item?id=27686351. We ban such accounts, so please read and follow the rules if you want to keep posting here: https://news.ycombinator.com/newsguidelines.html.

(In case anyone is wondering, we don't enforce the rules based on political positions and I have no idea what this account's political positions actually are. It's faster for moderation to skim comments without looking at that.)

Re: Hash collision in Apple NeuralHash model

#709

Earlier quoted context omitted.

That is simply not true. There is no American jurisdiction where child pornography is a strict liability crime. On this topic, the Supreme Court has ruled in Dickerson v US that, in all cases, to avoid First Amendment conflicts, all child pornography statutes must be interpreted with at least a "reckless disregard" standard. Here is a typical criminal definition, from Minnesota, where a defendant recently tried to ar…

I tried to look up [Antonio] Dickerson v. US, but I don't see any SCOTUS decision on it, only a certiorari petition. Do you have a reference for the decision?

Yep, sorry, Dickerson was an appellant that cited the relevant case law, which is New York v Ferber.

Now, Dickerson rightfully lost and it's appropriate that SCOTUS rejected his case because he was involved in child porn production, not posession, so he can't rely on the Ferber precedent. He had the opportunity to ask the underage person in question their age, and chose not to, which would meet the reckless disregard standard anyway.

Re: Hash collision in Apple NeuralHash model

#710

Earlier quoted context omitted.

I think this is where a disconnect is occurring. In this specific case yes. That is what is supposed to happen. But Apple also sets the standard that this is just the beginning, not the end. They say as much on page 3 in bold, differentiated color ink https://www.apple.com/child-safety/pdf/Expanded_Protections_... And there’s nothing to stop them from scanning all images on a device. Or scanning all content for keywo…

>And there’s nothing to stop them from scanning all images on a device. All images on your device have been scanned for years by ML models to detect things all sorts of things and make your photo library searchable regardless of whether you use an Android or Apple device. That's how you can go and search "dog", "revolver", "wife", etc and get relevant photos popping up.

I don't think this is accurate. I don't use the Google Photos cloud service, and searching in the Photos app on my Android phone returns zero results for any search term.
Post reply on HN