Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

201–210 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#201
post #169
post #165

Earlier quoted context omitted.

This is already a warrantless search that’s effectively controlled by the government. Obviously there’s enough chaff in the air to prevent that from being legally useful in any way.

Nope. It’s not controlled by the government, and it’s not warrantless, since it is opt-in.

Since the govt. supplies the hashes in an unauditable way, it absolutely is controlled by the government. What's to stop them from using hashes of non CSAM material?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#202

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

> It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). Given the reported numbers of illegal images detected by similar systems within Facebook and Google, I think it is very clear…

Facebook and google are not catching 20m people a year, they're mostly flagging and removing tor/proxy-based throwaway accounts.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#203

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

its only been about getting the Surveillance architecture in place... nothing else.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#204
post #124

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

Perceptual hashes are only used to reduce the search space for human review. Apple doesn’t have images in the CSAM database to do a comparison, but if it’s just a picture of a door their going to reject it. Also, because human review is an expense Apple’s incentives are to minimize the number of times it happens, thus the requirement for multiple collisions.

Apple's human review is largely useless.

Trolls will be able to easily use tools slightly modify ambiguous adult porn to collide with a "known CP hash".

A human reviewer will see a blurry grayscale derivative of adult pornographic content and hit "report" every time.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#205

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

> Is it really worth turning personal devices into snitches that don't even do a good job of protecting children?

Yes, because the point is not to protect children. It's to get everyone used to the idea that their content is being monitored. Once that is accomplished, other forms of monitoring can and will be added.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#206
post #74

A very relevant point on this entire discourse about Apple’s on-device CSAM scanning: According to the U.S. law, key snippets of which are quoted on the Stratechery blog (by Ben Thompson), Apple isn’t obligated to scan for CSAM. It’s only obligated to act on CSAM if it finds them. While it’s good for Apple to scan on its systems (iCloud) like Facebook, Google and other companies do on their servers, it’s inappropriat…

They say only if they find 30 matching images, they'd act. So if they find 20 or 29 and don't report them, they are actually breaking the law!! I am wondering why they chose that magical number!

Just getting a match on the neural hash is not sufficient to declare an image CSAM. It just flags it as a candidate for review. Apple is not required to report it unless it can be verified to be CSAM. there is a multi-step process involving multiple processes and organizations to do so.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#207

Why are exact collisions interesting? They are not intended to be compared exactly. This algorithm doesn't even give exact matches for the same image on different hardware. https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX Note: Neural hash generated here might be a few bits off from one generated on an iOS device. This is expected since different iOS devices generate slightly different hashes anyway. The reason…

Per ATP: Apple will compare hashes of local photos with a national registry of child pornography photos. Once a certain (unknown) threshold is reached, let's say 20 hits, some kind of escalation occurs, with some kind of manual (human) review steps. Accidental Tech Podcast - A Storm of Asterisks https://atp.fm/443 I haven't listened to the follow up episode yet. I still have zero opinion on this photo scanning kerfuf…

I'm interested in the details of the manual review. Does Apple have access to the database of original images and will they use it compare? If not, I can imagine a scenario where a photo of a naked child is flagged as matching the database, the human reviewer sees that it is in fact a naked child and assumes this must mean the image has been legally determined to be child pornography. The case gets referred to authorities and the innocent victim's life is upended for potentially years until the case plays out.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#208
Isn't a hash collision from similar images the point of the whole thing?

At any rate, IANAL, but I'm pretty sure you can't be convicted based on a hash alone. If you get busted for possession of a picture of a nematode and you can show the jury it's just a picture of an axe that has the same value when run through this algorithm, you'll be fine. And there's a decent chance prosecutors won't chase down individuals who will just have a single collision in their photo library with this tech in the first place - people who have dozens or hundreds will be much more interesting.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#209
post #55

Earlier quoted context omitted.

Presumably, it’s done this way so they can say computers other than your personal device do not scan photos and “look” at decrypted and potentially innocent photos. And technically the original image is never decrypted in iCloud by Apple - if 30 images are flagged they are then able to decrypt the CSAM scan meta data which contains resized thumbnails, for confirmation. In summary, I’m guessing they tried to invent a…

calling resized thumbnails metadata is a bit of a stretch imo. Surely that's just the data, but resized?

Resized thumbnails aren't a stretch... they're a scale. Bum dum tiss.... I'll let myself out

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#210
post #104
post #74

A very relevant point on this entire discourse about Apple’s on-device CSAM scanning: According to the U.S. law, key snippets of which are quoted on the Stratechery blog (by Ben Thompson), Apple isn’t obligated to scan for CSAM. It’s only obligated to act on CSAM if it finds them. While it’s good for Apple to scan on its systems (iCloud) like Facebook, Google and other companies do on their servers, it’s inappropriat…

"While it’s good for Apple to scan on its systems (iCloud) like Facebook, Google and other companies do on their servers, it’s inappropriate to do it on individual devices" I would even challenge the justification to do this on servers, unless the data is public. If it's behind a personal login, you might as well consider it personal property/data. I find the distinction of where data is stored not very meaningful. A…

Absolutely. If I own my data, someone processing this data on my behalf has no right or obligation to scan it for illegal content. The fact that this data sometimes sits on hard drives owned by another party just isn't a relevant factor. Presumably I still own my car when it sits in the garage at the shop. They have no right or obligation to rummage around looking for evidence of a crime. I don't see abstract data as any different.

Our major privacy blunder was accepting scanning of private data in any context. The fight should be for the absolute privacy of personal data. Where the scanning happens is mostly irrelevant.

Post reply on HN