Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

181–190 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#181
post #149

Earlier quoted context omitted.

Apple inspects every file on the local device Before its uploaded. It’s just pinky promise only matched with the on device database when an upload is intended.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

Should they even be doing that though? It seems like a matter of time before it's possible to SWAT somebody by sending them a series of hash colliding image files given how not cryptographically secure the hash algorithm is.

I think I'm not the only one who'd rather not have my devices call the cops on me in a country where the cops are already way too violent.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#182

Earlier quoted context omitted.

Furthermore, it may well be possible to combine that blobby grey static with another image, manipulating it's visual hash to create a "sleeper" positive. If this was possible in a week , then it's going to be very interesting to watch the technology change/evolve over the next few years.

Doing so would create a positive that still doesn't pass Apple's human visual check against the (blurred) CSAM content associated with that checksum, and if it somehow did, it would still then also have to occur at qty.30 or more, and they'd have to pass a human visual check against the (unblurred) CSAM content by one of the agencies in possession of it. It's not possible to spoof that final test unless you possess r…

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#183
post #66

Earlier quoted context omitted.

Why are hash collisions relevent? There are atleast 2-3 further checks to account for this.

Because it's not a cryptographic hash where a one bit difference results in a completely different hash. It's a perceptual hash that operates on a smaller bitmap derived from the image so it's plausible that some innocuous images might result in similar derivations; and there might be intentionally crafted innocently-looking images that result in an offensive derivative. Salvador Dali could do something similar by ha…

This is a great answer but that’s not actually the GP’s contention. Their argument is essentially “so what if there’s a collision, the human review will catch it”. And to that I’d say that the same is supposed to occur for the no-fly list and we all know how that works in practice.

The mere accusal itself of possessing CSAM can be life ruining if it gets to that stage. More importantly, a collision will effectively allow warrantless searches, at least of the collided images.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#184

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Right now, it seems like there are two specific groups of people that are upset with Apple: Freedom evangelists (e.g. EFF) and tech futurists (e.g. HN). They're saying, essentially:

"Apple does not have my permission to use my device to scan my iCloud uploads for CSAM"

and

"This is a slippery slope that could result in Apple enforcing thoughtcrimes"

Neither of these viewpoints are particularly agreeable to the general public in the US, as far as I can determine from my non-tech farming city. Once the fuss in tech dies down, I expect Apple will see a net increase in iCloud adoption — all the fuss we're generating is free advertising for their efforts to stop child porn, and the objections raised are too domain-specific to matter.

It's impossible to say for certain which of your outcomes will occur, but there's definitely two missing from your list. Corrected, it reads:

"Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust, or Apple sees no effect whatsoever on consumer trust, or Apple sees a permanent boost in consumer trust."

I expect it'll be "no effect", but if I had to pick a second guess, it would be "permanent boost", well offsetting any losses among the tech/free/lib crowd.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#185

Earlier quoted context omitted.

This seems like a common deflection, but get back to me when either company puts programs in my pocket that scan my data for crimes and snitch on me to authorities.

>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... You don't consider the contents of your email account or the files you mirror to a cloud drive to be your own private data?

There are worlds between. One case is about pictures on your device. The other case is about pictures on Googles "devices" or network. You had to upload it to Google. EMail is also nothing like a letter anyway. It's a postcard. Everybody can read it.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#186

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

Most people don't pay attention to whether or not their stuff is being scanned. Those of us who do pay attention have known for a long time that it's being scanned. Especially by Google and Facebook. Basically anyone whose business model is based off of advertising. My default assumption is anything I upload is scanned.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#187

Earlier quoted context omitted.

Exactly right. The tech Apple uses can be one of two things: 1. It requires a perfect 1:1 match (their documentation says this is not the case); 2. Or it has some freedom in detecting a match, probably including a match with a certain percentage. If it's the former, it's completely useless. A watermark or a randomly chosen pixel with a slightly different hue and the hash would be completely different. So, it's not #1…

What? Why would memes be on the CSAM list?

They got to scan for whatever the local law requires them to scan.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#188
post #149

Earlier quoted context omitted.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

Because now Apple confirmed themselves that this promise is not kept.

What is "this promise"? Because I would consider it "we will only scan files that you upload to iCloud". That was true a month ago and that would be true under this new system. The only part that is changing is that the scanning happens on your device before upload rather than on an Apple server after upload. I don't view that as a material difference when Apple already controls the hardware and software on both ends. If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#189
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.

They actually do look alike to my eye, but in a “the way the algorithm sees it” kind of way. I can see the obvious similarity. But to your point it’s not like it’s two very slightly different photos of dogs.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#190
post #174

Earlier quoted context omitted.

Making it obviously and unquestionably more invasive.

I just don't get this. Say you're given two options when going through the TSA. 1. The TSA agent opens your luggage and searches everything for banned items. 2. The TSA agent hands you a scanner for you to wave over your luggage in private, it prints out a receipt of banned items it saw, and you present that receipt to the agent. Which one is more invasive?

[deleted]
Post reply on HN