Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

121–130 of 440 posts

Re: The Problem with Perceptual Hashes

#121

> an Apple employee will then look at your (flagged) pictures. This means that there will be people paid to look at child pornography and probably a lot of private nude pictures as well.

Yes, private nude pictures of other people's children too, which do not necessarily constitute pornography. It was common when I was young for parents to take pictures of their kids doing things, clothes or not. Some still exist of me I'm sure.

So far as I know some parents still do this. I bet they'd be thrilled having Apple employees look over these.

Re: The Problem with Perceptual Hashes

#122
post #117

Earlier quoted context omitted.

I would really like people to start answering this: what exactly do you think has changed? e.g, >That’s very different from authorities taking a sneak peek into my stuff. To be very blunt: - The opt out of this is to not use iCloud Photos. - If you _currently_ use iCloud Photos, your photos are _already_ hash compared. - Thus the existing opt out is to... not use iCloud Photos. The exact same outcome can happen regar…

It makes even less sense, given that they are currently doing this with your iCloud photos. Now they have this tool that can match to a database of photos, how do we know they wouldn't use this to identify non-sexual photos? Maybe Tim Cook wouldn't, what about the next CEO? And the one after that?

The questions re: what the CEO would sign off on here don't really matter, as the question could apply whether it's server side or client side.

It _does_ make sense client side if you view it being done server side as a blocker for E2EE on iCloud. There is absolutely no world where Apple could implement that without keeping the ability to say "yes, we're blocking child porn".

Re: The Problem with Perceptual Hashes

#123
post #80
post #78

Earlier quoted context omitted.

So what are we going to do about it? I have a large user base on iOS. Considering a blackout protest.

IMHO, Unless everything being E2E encrypted becomes the law we can’t do anything about it because that’s not Apple’s initiative but comes from people whose job is to know things and they cannot resist keeping their hands out of these data collecting devices. They promise politicians that all the troubles will go away if we do that. Child pornography, Terrorism? Solve it the old way. I don’t know why citizens are obli…

> Solve it the old way.

In fairness, in the "old way" it was impossible for two random people to communicate in real-time between continents without the ability of authorities to observe/break it.

Privacy and security is quite important, but let's not lose track of the fact that there are many tools authorities have lost in the past few decades. In WWII major powers weren't able to have the same security of military communications as an idiot can today. And that's relative to codebreaking technology.

If I had a good solution, I'd tell you.

Re: The Problem with Perceptual Hashes

#124
post #72

The technical challenges aside, I’m very disturbed that my device will be reporting me to the authorities. That’s very different from authorities taking a sneak peek into my stuff. That’s like the theological concept of always being watched. It starts with child pornography but the technology is indifferent towards it, it can be anything. It’s always about the children because we all want to save the children. Soon t…

you have to realize though that the panopticon is limited only by the ability of "authority" to sift through it for whatever it is it is looking for.

as this article points out, the positive matches will still need an observe to confirm what it is and is not.

lastly, the very reason you have this device exposes you to the reality of either accepting a government that regulates these corporate overreaches or accepting private ownership thats profit motive is deeply personal.

you basically have to reverse society or learn to be a hermit, or more realistically, buy into a improved democratic construct that opts into transparent regulation.

but it sounds more like you want to live in a split brained world where your paranoia and antigovernment stance invites dark corporste policies to sell you out anyway

Re: The Problem with Perceptual Hashes

#125
post #2

> Even at a Hamming Distance threshold of 0, that is, when both hashes are identical, I don’t see how Apple can avoid tons of collisions... You'd want to look at the particular perceptual hash implementation. There is no reason to expect, without knowing the hash function, that you would end up with tons of collisions at distance 0.

If images have cardinality N and hashes M and N > M, then yes, by pigeonhole principle you will have collisions regardless of hash function, f: N -> M.

N is usually much bigger than M, since you have the combinatorial pixel explosion. Say images are 8 bit RGB 256x256, then you have 2^(8x256x256x3) bit combinations. If you have a 256-bit hash, then that’s only 2^256. So there is a factor of 2^(8x256x3) difference between N and M if I did my math right, which is a factor I cannot even calculate without numeric overflow.

Re: The Problem with Perceptual Hashes

#126

Earlier quoted context omitted.

what function does the word "even" perform in this sentence?

It's used to emphasize the concept that if anyone would have nudes of my wife, it would be me, her husband. Here's another example of "even" used as an emphasizing word. >I don't know how to answer that. >Even I don't know how to answer that. Hope that helps you with your ESL tests!

The parallel to the construction you used before would be "I don't even know how to answer that" which means something quite different from "Even I don't know how to answer that".

Re: The Problem with Perceptual Hashes

#128

Earlier quoted context omitted.

> I would really like people to start answering this: what exactly do you think has changed? e.g, Apple has announced they'll be doing this check? What exactly do you think is the same as before? > The exact same outcome can happen regardless of whether it's done on or off device. iCloud has _always_ been a known vector for authorities to peek. That's neither here, nor there. It's another thing to peak selectively wi…

>What exactly do you think is the same as before? The same checking when you synced things to iCloud. As has been repeated over and over again, this check happens for iCloud Photos. It's not running arbitrarily. Your photos were compared before and they're being compared now... if you're using iCloud Photos.

>The same checking when you synced things to iCloud. As has been repeated over and over again, this check happens for iCloud Photos. It's not running arbitrarily.

Who said it's running "arbitrarily"? Who said it's not about iCloud Photos?

>Your photos were compared before and they're being compared now... if you're using iCloud Photos.

They weren't always compared, they started being compared a few years ago, and they moved to comparing them with a new scheme now.

Both are bad, and not the responsibility of a company selling phones - and also a bad precedent (now it's "think of the children", tomorrow "think of the country", then "think of those with wrong ideas", then "think how much money insurance companies can save" and what have you).

As for your suggestions to just "stop using iCloud Photos", how about we get to enjoy the features we bought our devices for, without stuff we didn't ask for and don't want?

Re: The Problem with Perceptual Hashes

#129

Earlier quoted context omitted.

I would really like people to start answering this: what exactly do you think has changed? e.g, >That’s very different from authorities taking a sneak peek into my stuff. To be very blunt: - The opt out of this is to not use iCloud Photos. - If you _currently_ use iCloud Photos, your photos are _already_ hash compared. - Thus the existing opt out is to... not use iCloud Photos. The exact same outcome can happen regar…

> I would really like people to start answering this: what exactly do you think has changed? e.g, Apple has announced they'll be doing this check? What exactly do you think is the same as before? > The exact same outcome can happen regardless of whether it's done on or off device. iCloud has _always_ been a known vector for authorities to peek. That's neither here, nor there. It's another thing to peak selectively wi…

Responding in a separate comment since I either missed the second half, or it was edited in.

>That's neither here, nor there. It's another thing to peak selectively with a warrant of sorts, than to (a) peak automatically in everybody, (b) with a false-positive-prone technique, especially since the mere accusation on a false match can be disastrous for a person, even if they eventually are proven innocent...

I do not believe that iCloud CSAM server side matching ever required a warrant, and I'm not sure where you've gotten this idea. It quite literally is (a) peak automatically in everybody.

Regarding (b), with this way - thanks to them publishing details on it - there's more transparency than if it was done server side.

>especially since the mere accusation on a false match can be disastrous for a person

As noted elsewhere in this very thread, this can happen whether client or server side. It's not unique in any way, shape or form to what Apple is doing here.

Re: The Problem with Perceptual Hashes

#130

Given all the zero day exploits on iOS I wonder if it's now going to be viable to hack someone's phone and upload child porn to their account. Apple with happily flag the photos and then, likely, get those people arrested. Now they have to, in practice, prove they were hacked which might be impossible. Will either ruin their reputation or put them in jail for a long time. Given past witch hunts it could be decades be…

Someone is going to figure out how to make false positives, and then an entire genre of meme will be born from putting regular memes through a false positive machine, just for the lulz. Someone else could find a way to make every single possible mutation of false positive Goatse/Lemonparty/TubGirl/etc. Then some poor Apple employee has to check those out.

If Apple is indeed using CNNs, then I don’t see why any of the black-box adversarial attacks used today in ML wouldn’t work. It seems way easier than attacking file hashes, since there are many images in the image space that are viable (e.g., sending a photo of random noise to troll with such an attack seems passable).
Post reply on HN