Earlier quoted context omitted.
Not sure if its what the poster above is talking about, but there's definitely a hash collision type attack that's common on Youtube with regards to classical music. The attacker in question uploads very standard renditions of thousands of pieces of classical music, and claims copyright on them. Content ID then flags any video using one of these pieces as potentially violating the rights of the rightholder. The attac…
I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.
Tainting the CSAM client-side scanning database
171–180 of 276 posts
Re: Tainting the CSAM client-side scanning database
#172Earlier quoted context omitted.
Angle brackets are traditionally used for actual quotes. > Step one, break cryptographically secure hashing system These "perceptual hashes" are not (and cannot be) cryptographically secure, and practical collision attacks have been tested and published . Did you actually read the main article at all? I don't think I'm even going to bother with the rest.
PhotoDNA doesn't use CS hashes, but others I've looked at do use them. But you're right, you probably don't wanna respond to my parody of you suggestion to trade in CSAM...
Re: Tainting the CSAM client-side scanning database
#173Earlier quoted context omitted.
Wow what a mess. At what point do we move on from copyright laws? Or more broadly intellectual property, in general. Even the words "intellectual property" sound ridiculous together when you think about it.
If you think deeper about it, the general concept of property is similarly ridiculous too. An arbitrary piece of land being ‘owned’ is similarly arbitrary human social concept, enforced by law and a registry
Re: Tainting the CSAM client-side scanning database
#174And since these hashes are presumably resistant to cropping and scaling, they might be able to target individual symbols, people or image macros, like the rainbow pride flag (you know /pol/ wouldn't be able to resist), politicians etc.
Re: Tainting the CSAM client-side scanning database
#175I am against the idea of scanning for the reason that the author pointed out: It's trivial to repurpose the technology to use it in dystopian ways. I however have precisely zero concerns about impersonating hashes: 1. It's trivial to deal with tainting the database: both secondary hashing and more invasive hashes deal with that problem. 2. It's trivial to deal with impersonated hashes, all positives can be scanned on…
Sorry, what does "more invasive hashes" mean?
> It's trivial to deal with impersonated hashes, all positives can be scanned on device in a second round with a different hash method.
The double hashing would definitely help. I doubt anybody's gotten a close collision for more than one hash at a time.
It's not inconceivable that they could do it, though. As far as I know, there are only two hash methods that get used for this, and I think both of them are based on sliding a window over a reduced version of the image and doing a DCT, so they're pretty similar. I wouldn't be surprised if somebody could fool both of them enough to at least force you to tighten up your similarity threhsholds. It would be safer to come up with something that worked on completely different principles. No idea how hard that would be.
I don't think that the second-stage backup, where you send the image off somewhere, is "privacy preserving" by any standard I'd be comfortable with. Well, OK, actually even completely foolproof client side scanning isn't privacy preserving enough for me, but I mean that's substantially worse.
I also don't think it'd be easy to find anybody to run that server. And it'd be a significant structural change from what's deployed now. It'd be much more disruptive than adding a second hash (which is isomorphic to just switching to a single composite hash). It took a long time to get the present system deployed, so that big a change doesn't seem "trivial".
> These systems have undisclosed minimums. A person sharing CSAM will be generating positive results at a significant rate. Receiving a few images with faked hashes won't set off alarms, and if a victim is suddenly receiving hundreds of images, that would already be obvious.
Minimum what? If you just say "undisclosed minimums", my mind immediately assumes you mean threshold similarity scores. But you seem to mean hit counts to trigger various actions.
Anyway, both of those are set by the service that's using the database. Those services vary in their strictness and clue level, so I'm not sure you can say anything very general about them.
> These articles over sensationalise what occurs when a positive match is found.
In the threat model of the original article, the people doing the review for false positives are most likely the same people who poisoned the database to begin with. They've corrupted it to give them hits on images they want to suppress, even though the system operators don't want to support them in suppressing those images. So that whole "reviewed by a human and discarded" step doesn't happen.
In the broader world, I suspect that the thresholds for "delete the file" tend to be very low... too low for there to be human review. The thresholds for "disable the user's account" probably aren't exactly stratospheric, either. You can have damaging consequences well short of midnight police raids.
Also, "framing" people isn't necessarily the only thing you might use it for. For example, you could try to use it to drive the cost of running the system up to unsupportable levels.
Re: Tainting the CSAM client-side scanning database
#176Earlier quoted context omitted.
I wish that willful false copyright claims carried the same $250,000 penalty that copyright infringement does.
That would be ridiculous. But there are penalties for false claims. There is a fine for claiming copyright you don't own, and if you go further and ask for takedowns, you are also liable for damage. The problem is that these are rarely enforced. Even a $100 fine for a false claim on YouTube would be enough to weed out bots and click farms. And for the most serious cases, have the infringer pay damage and a bigger fin…
Why is it ridiculous, in a world where the penalty for sharing a single music file is $250,000?
Re: Tainting the CSAM client-side scanning database
#177[...] One could conclude that the abuse centre could thus easily spot the malicious entry in its database after a few of these reports all concerned with the same image, and delete the corresponding fingerprint from the database. If that were the case, this avenue of attack would not be a problem in practice. This assumes, however, that the abuse centre keeps track of such false positives over time to detect such mal…
okay, ill bite: yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities. however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating. CSAM is a propaganda word: 1. right wing uses it to push their agenda of punishing people for havi…
In the US alone, that would be ~30,000 people. Get back to me when you've read some legal cases or know anyone who's been abused to produce such material. Perhaps you'll learn some critical thinking and better manners along the way.
Re: Tainting the CSAM client-side scanning database
#178[...] One could conclude that the abuse centre could thus easily spot the malicious entry in its database after a few of these reports all concerned with the same image, and delete the corresponding fingerprint from the database. If that were the case, this avenue of attack would not be a problem in practice. This assumes, however, that the abuse centre keeps track of such false positives over time to detect such mal…
okay, ill bite: yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities. however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating. CSAM is a propaganda word: 1. right wing uses it to push their agenda of punishing people for havi…
Re: Tainting the CSAM client-side scanning database
#179[...] One could conclude that the abuse centre could thus easily spot the malicious entry in its database after a few of these reports all concerned with the same image, and delete the corresponding fingerprint from the database. If that were the case, this avenue of attack would not be a problem in practice. This assumes, however, that the abuse centre keeps track of such false positives over time to detect such mal…
okay, ill bite: yes, the blogger has tunnel vision, that's the only valid point in your post, he also missed the fact that anyone can poison the well, not just privileged entities. however your rhetoric is cancerous, although i'm aware that many people who use it are just sheep and have no idea what they're insinuating. CSAM is a propaganda word: 1. right wing uses it to push their agenda of punishing people for havi…
Your claims of things that don't happen are, unfortunately, false. Law enforcement agents whose jobs involve ever looking at CSAM basically cannot stand the mental toll of the job for any significant amount of time. Unthinkably horrible things happen to children to create these images. The idea that we would legalize it is not on the table, and suggesting such a thing is a great way to immediately lose support from everyone in the world.
We should not reject efforts to prevent the production and spread of CSAM unless we can show that the former group can abuse it. Unfortunately, so far, basically all suggested prevention mechanisms are vulnerable to abuse and corruption. It's an extremely difficult problem.
> i don't need a "privacy respecting solution to CSAM". what the hell do you think that would be? do we also need a freedom respecting solution to the murder problem? would you have my legs cut off and say i should just order door dash?
I don't think that analogy is hitting the way you're intending. Yes, we'd all love a "freedom-respecting solution to the murder problem". In fact convicted murderers still have some rights and freedoms, and balancing those against preventing murder and rehabilitating murderers is another difficult problem. Cutting off legs hasn't been seen as a reasonable punishment for a crime since the Bronze Age, so I'm not sure what that's supposed to mean.
Re: Tainting the CSAM client-side scanning database
#180I think it's pretty clear this is not about "CSAM", we have to stop using the term. It's just censorship, plain and simple. Client side means you'll pay from your own pocket for this wrongthing detector to work. It can even be automated so as soon as the detector gets triggered by anything, you'll get locked out of your bank accounts, until further notice I guess. If this thing gets a serious discussion in a parliame…