Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

161–170 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#161
post #127
post #75

I don't really get what this repository is trying to achieve and what's the point of collecting collisions. Collisions will happen, that's just how it is with hashes. It's already a public knowledge that Apple has 2 more systems (some server-side verification and a manual check later) to prevent false-positives. So what's the point of researching collisions in NeuralHash?

Are you fine with an apple employee looking at all your private pictures just because some hashing algorithm decided you're a pedophile? Personally, I'm not.

First, this doesn't change my opinion on CSAM, I still consider the thing way too intrusive until Apple announces E2E for iCloud.

Now, I can't really call something I voluntarily uploaded to Apple's servers a "private picture". But that's just a matter of perspective, and I understand that many people would disagree with me on this.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#162
post #157

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

Given the average user don't know what a url is and a pedophile can use the darknet, I'd say criminals are not all dumb.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#163
post #157

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

> Dumb is a pretty accurate description of a large fraction of criminals.

Is there any reading on that? I'd love it to be true.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#164
post #124

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

Perceptual hashes are only used to reduce the search space for human review. Apple doesn’t have images in the CSAM database to do a comparison, but if it’s just a picture of a door their going to reject it. Also, because human review is an expense Apple’s incentives are to minimize the number of times it happens, thus the requirement for multiple collisions.

Edit: I incorrectly claimed there wasn’t manual review - see below

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#165
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

There is an interesting constitutional quirk which arises from the scanning being done client side, specifically for US citizens. If the US Government forced Apple to add other entries to the hash table, this would constitute a warrantless Government search of the private physical property of US citizens. This is a clear-cut, unambiguous breach of the 4th Amendment. Whereas if the CSAM scanning was performed exclusiv…

This is already a warrantless search that’s effectively controlled by the government. Obviously there’s enough chaff in the air to prevent that from being legally useful in any way.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#166
post #157

Earlier quoted context omitted.

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

> Dumb is a pretty accurate description of a large fraction of criminals. Is there any reading on that? I'd love it to be true.

Selection bias? It _might_ be a pretty accurate description of a large fraction those who _get caught_.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#168
post #164
post #124

Earlier quoted context omitted.

Perceptual hashes are only used to reduce the search space for human review. Apple doesn’t have images in the CSAM database to do a comparison, but if it’s just a picture of a door their going to reject it. Also, because human review is an expense Apple’s incentives are to minimize the number of times it happens, thus the requirement for multiple collisions.

Edit: I incorrectly claimed there wasn’t manual review - see below

What is the basis for your understanding?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#169
post #165

Earlier quoted context omitted.

There is an interesting constitutional quirk which arises from the scanning being done client side, specifically for US citizens. If the US Government forced Apple to add other entries to the hash table, this would constitute a warrantless Government search of the private physical property of US citizens. This is a clear-cut, unambiguous breach of the 4th Amendment. Whereas if the CSAM scanning was performed exclusiv…

This is already a warrantless search that’s effectively controlled by the government. Obviously there’s enough chaff in the air to prevent that from being legally useful in any way.

Nope. It’s not controlled by the government, and it’s not warrantless, since it is opt-in.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#170
post #164

Earlier quoted context omitted.

Edit: I incorrectly claimed there wasn’t manual review - see below

What is the basis for your understanding?

Apologies, I was mistaken:

“ Only when the threshold is exceeded does the cryptographic technology allow Apple to interpret the contents of the safety vouchers associated with the matching CSAM images. Apple then manually reviews each report to confirm there is a match”

The design goal was no human review for individual matches.

Post reply on HN