Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

11–20 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#12
post #9

Earlier quoted context omitted.

Then let's get rid of the NeuralHash entirely, if it doesn't matter, right? If it's a critical part of the system, then it should be inspected thoroughly. If Apple claims a minuscule chance of a hash collision, and the reality is that collisions are relatively common, that significantly changes the requirements for the backend system, which Apple keeps secret. We have every right to believe, bbased oon ppublic info,…

The point in the NeuralHash and PSI system is to preserve user privacy as far as possible. From a technical standpoint, it is not essential - a NeuralHash function that returns 0x0000… for everything would still catch CSAM. It's just that it would upload every single image on the user's device. Now, how well this NeuralHash does preserve privacy is a different question, and /not/ one that is being answered by the ori…

It doesn't really matter whether all images are uploaded, or just 1 in x (for large value of x), due to the Panopticon effect.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#13
post #10

Earlier quoted context omitted.

We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about

You (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.

1. You can at least somewhat audit the software running on an iPhone, for example by means of reverse engineering. You can’t audit the server side.

2. It’s one thing to rely on proprietary services like Find My or Siri. It’s another thing to rely on a secret server-side app that has the power to destroy your life.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#14
post #10

Earlier quoted context omitted.

We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about

You (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.

afaik none of Apples other "proprietary software" is designed to pass my personal images to a human for visual inspection if it mistakenly outputs 2 high-enough numbers after a handful of convolution operations and matrix multiplications.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#15
post #10

Earlier quoted context omitted.

We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about

You (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.

Tell this to the victims of Pegasus. If anyone were able to get their hands on the "secret backend system" we wouldn't be talking about spy games, we'd be talking about people's lives being ruined

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#16
I’m glad that people are trying to figure out any technical flaws in the system as best they can, but if I’m being honest I do trust Apple’s engineers to have built something that is solid from a technical stand point.

Am I correct in that the primary reason folks are so upset is that the system could (probably) be easily modified such that -any- content could invoke legal action? That the main problem is really the scanning at all, and not the chances that it could be attacked by an individual actor but instead by a government?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#17
post #10

Earlier quoted context omitted.

We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about

You (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.

No. I trusted Apple’s proprietary software before this, because they maintained that they care about privacy, and there have been examples of that.

Now, I don’t trust them anymore.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#19
post #9

Earlier quoted context omitted.

Then let's get rid of the NeuralHash entirely, if it doesn't matter, right? If it's a critical part of the system, then it should be inspected thoroughly. If Apple claims a minuscule chance of a hash collision, and the reality is that collisions are relatively common, that significantly changes the requirements for the backend system, which Apple keeps secret. We have every right to believe, bbased oon ppublic info,…

The point in the NeuralHash and PSI system is to preserve user privacy as far as possible. From a technical standpoint, it is not essential - a NeuralHash function that returns 0x0000… for everything would still catch CSAM. It's just that it would upload every single image on the user's device. Now, how well this NeuralHash does preserve privacy is a different question, and /not/ one that is being answered by the ori…

The “actual argument” against the system that this provides is that Apple lied about the likelihood of hash collisions.

Therefore, why trust any of their other claims?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#20

I’m glad that people are trying to figure out any technical flaws in the system as best they can, but if I’m being honest I do trust Apple’s engineers to have built something that is solid from a technical stand point. Am I correct in that the primary reason folks are so upset is that the system could (probably) be easily modified such that -any- content could invoke legal action? That the main problem is really the…

I can’t speak for everyone, but that’s certainly a technical part of it. Another big part of the problem is that it’s insulting to presume everyone guilty, and make them to use their own resources (own phone, own battery cycles) to investigate them as if they were suspects. But that’s been discussed plenty on other threads here at HN.
Post reply on HN