Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

721–725 of 725 posts

Re: Hash collision in Apple NeuralHash model

#721

Earlier quoted context omitted.

"Apple said that there is a one in one trillion chance of a false positive" https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni... Versus: https://blog.roboflow.com/nerualhash-collision/ Along with: https://github.com/anishathalye/neural-hash-collider Demonstrates blatant incompetence on the part of Apple's design. At this point, trust is broken. That's the end of credibility regarding any other claim made a…

Apple was talking about the chance of accidental false positives. There is a 1 in 4 billion chance that if I send a message to an IP address, it will be yours. The fact that I can know your IP address and send you a message intentionally does not make the previous statement false. > As Apple's hash algorithm is entirely broken and useless, a malicious actor can easily craft a NSFW, but otherwise legal image, that has…

No, the attacker is committing a crime with the attack you describe, but has plausible deniability that they are not with the Apple-nonsense enabled attack vector.

This is a huge difference as not only does Apple facilitate a gain-of-function in terms of potential detriment to the victim of an attack, the newly-enabled vector also indemnifies the attacker.

The effort required to come up with a hash collision in SHA256 is something on the order of the power output of a trillion suns for a billion years (or some other meaninglessly-prohibitively-large amount). Despite such metrics and off-the-shelf solutions being readily attainable within this field Apple has implemented a system that has resulted in a collision within days, followed by a free automated collision generation tool.

This demonstrates absolute gross incompetence in design, and permanently eliminates any trust any sensible individual can ever have in the system despite your protestations.

There is simply nothing you can say to convince any sane person otherwise, the situation has been factually described and it is what it is.

Re: Hash collision in Apple NeuralHash model

#722
post #687
post #686

Earlier quoted context omitted.

Uh? So his if statement is true?

Please read what is written right before that... You are taking something out of context.

Why do you keep posting links to this collider as though it means something?

As has been already pointed out the system is designed to handle attacks like this.

Here is the relevant paragraph from Apple’s documentation:

“as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possi- bility that the match threshold was exceeded due to non-CSAM images that were ad- versarially perturbed to cause false NeuralHash matches against the on-device en- crypted CSAM database. If the CSAM finding is confirmed by this independent hash, the visual derivatives are provided to Apple human reviewers for final confirmation.”

https://www.apple.com/child-safety/pdf/Security_Threat_Model...

Re: Hash collision in Apple NeuralHash model

#723
post #683

Earlier quoted context omitted.

The more collisions, the more chances of a false positive by a (tired, underpaid) human. I don't envy the innocent person whose home gets raided by a SWAT team convinced they're busting a child sex trafficker.

The database is known to contain non-csam images like porn. I doubt the reviewer will be qualified to discern which is which.

Known by whom to contain legal images? The "reviewer" might well be a retired Pediatrician who can identify the age of the subject by looking at the photographs and will be extremely accurate.

Re: Hash collision in Apple NeuralHash model

#724
post #149

Earlier quoted context omitted.

1. By the public at large it should not be treated in any regard, false or not. 2. The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom. 3. The 'believe the victims' activists however are rightfully (IMHO) suggesting to break principle #2 because there is institutional and systemic supression of t…

The legal system may have problems but that is about implementation , the fundamental principles of presumption of innocence, that no harm should come to the innocent, that all are equal before the law, and that truth comes before all other concerns; these are fine principles and I would say that problems with the legal system mostly stem from straying from these principles. Perhaps you disagree?

I somewhat disagree. It's indeed in the implemention of the principles where things go wrong, but I do believe that requires reform.

In between golden principles and everyday court are a lot of pragmatic laws and regulations. That is where I would like to see reform. To help the system full fill it's ideals and principles, especially the blindness of the justice.

Re: Hash collision in Apple NeuralHash model

#725

Earlier quoted context omitted.

IIRC they gave up the information AND they shut down

They handed over a hard copy of their private key, a printout. The FBI went to court to demand a machine-readable copy. Then they shut down.

Thanks for that! Didn't know.
Post reply on HN