Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

221–230 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#221
post #157

Earlier quoted context omitted.

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

> Dumb is a pretty accurate description of a large fraction of criminals. Is there any reading on that? I'd love it to be true.

With the caveat already noticed for selection bias (maybe the smart criminals never get caught?), there's definitely some evidence to support this. https://law.jrank.org/pages/1363/Intelligence-Crime-Measurin...

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#222

Earlier quoted context omitted.

Because they're not CSAM? People don't seem to grasp what kind of images end up in the CSAM databases. They are most definitely not "leaked celebrity nude selfie" level stuff. Think of the most vile sexual thing you could do to a child and then times that by two and halve the child's age in your mind. That's the shit that gets in there. It's not something even 4chan weebaboos share. It's stuff that makes Liveleak reg…

How is the human reviewer expected to make that judgement call? They’re not allowed to see the original to compare with for obvious reasons.

They see a "visual derivative" of the original.

I think they can tell the difference between a naked celebrity and a molested child.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#223

Earlier quoted context omitted.

No, how would it?

Then why is it such a big deal on hackernews and elsewhere?

Because the headline says "Apple". It brings in the views and likes, which bring money.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#224

Earlier quoted context omitted.

Because they're not CSAM? People don't seem to grasp what kind of images end up in the CSAM databases. They are most definitely not "leaked celebrity nude selfie" level stuff. Think of the most vile sexual thing you could do to a child and then times that by two and halve the child's age in your mind. That's the shit that gets in there. It's not something even 4chan weebaboos share. It's stuff that makes Liveleak reg…

The issue is not that a celebrity photo might get into a CSAM database. It's that a true CSAM photo, which has been modified to have the same hash as a "leaked celebrity nude selfie", will probably get into a CSAM database.

The CSAM database is not generated by an AI. Actual people hand-pick the worst images to include in the list.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#225
post #157

Earlier quoted context omitted.

> It won't catch anything but the dumbest of dumb criminals Dumb is a pretty accurate description of a large fraction of criminals. For the most part you only get smart criminals when you are talking about crimes where you have to be smart to even plan and carry out the crime.

Given the average user don't know what a url is and a pedophile can use the darknet, I'd say criminals are not all dumb.

It is not so easily comparable. It’s all about your intrests and expectations.

Darknet might sound bit complex, but as darknet user, you literally just install different browser.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#226

Earlier quoted context omitted.

> Dumb is a pretty accurate description of a large fraction of criminals. Is there any reading on that? I'd love it to be true.

Selection bias? It _might_ be a pretty accurate description of a large fraction those who _get caught_.

So we must compare those statistics for unsolved mysteries to find the truth and correlation.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#227
post #160

Earlier quoted context omitted.

Clearly this is not a cryptographic hash, and hence it's known hashes are not uniformly distributed. Apple explained in their technical summary [0] that they'll only consider this an offence if a certain number of hashes match. They estimated the likelihood of false positives there (they don't explain which dataset was used, but it was non-CSAM naturally) is 1 out of a trillion [1] In the very unlikely event where th…

> they have manual operators to check each of these photos For now. But what will happen when there are thousands of false positives per day? Will they increase the staff? Or will they add another algorithmic layer? Or just up the threshold a bit? There's no guarantee. The only thing that's certain is that the NeuralHash doesn't inspire confidence.

Regardless of what Apple does, law enforcement must always manually review suspected CSAM before requesting a warrant based on it. So the idea that you could SWAT someone with some hash collisions on innocent images is just not possible.

At most you could maybe temporarily lock someone’s iCloud account. But again, the collisions would need to be multiple and all look like CSAM at reduced resolution.

In general, it seems not correct to think about NeuralHash like SHA or RSA. It’s not a cryptographic system and collisions are not a one-step endgame.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#228
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

There is an interesting constitutional quirk which arises from the scanning being done client side, specifically for US citizens. If the US Government forced Apple to add other entries to the hash table, this would constitute a warrantless Government search of the private physical property of US citizens. This is a clear-cut, unambiguous breach of the 4th Amendment. Whereas if the CSAM scanning was performed exclusiv…

Also Fifth Amendment. People are being compelled to testify against themselves by running this CSAM scanner. Apple's end-to-end encryption was sold to users as exactly that.

To all of a sudden introduce this scanner doesn't negate the expectation of privacy as that is how it was sold and marketed. There is an implied warranty of merchantability of how this service functions.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#229

My take on this is that the system is by and large useless. It won't catch anything but the dumbest of dumb criminals, because those who care about CSAM can surely figure out a better way to share images, or find a way to obfuscate their images enough to bypass the system (the lower the false positive rate, the easier it must be to trick the system). So what's left when all the criminals this is supposed to catch hav…

Sometimes the best way to catch the really smart or sophisticated criminals is to exploit their less smart and less sophisticated accomplices, co-conspirators, peers, acquaintances, or even their victims.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#230

Earlier quoted context omitted.

Per ATP: Apple will compare hashes of local photos with a national registry of child pornography photos. Once a certain (unknown) threshold is reached, let's say 20 hits, some kind of escalation occurs, with some kind of manual (human) review steps. Accidental Tech Podcast - A Storm of Asterisks https://atp.fm/443 I haven't listened to the follow up episode yet. I still have zero opinion on this photo scanning kerfuf…

I'm interested in the details of the manual review. Does Apple have access to the database of original images and will they use it compare? If not, I can imagine a scenario where a photo of a naked child is flagged as matching the database, the human reviewer sees that it is in fact a naked child and assumes this must mean the image has been legally determined to be child pornography. The case gets referred to author…

Law enforcement must manually review all suspected CSAM before seeking a warrant based on it. There is a whole process there, beyond whatever Apple has implemented, before a prosecution begins.

Understand that matching a file in the NCMEC database is not itself a crime. The whole CSAM-detecting ecosystem is just a tool for surfacing potential crimes. Having a few pics of your own child naked is not illegal and it’s pretty easy for law enforcement to figure out if that’s the case.

Post reply on HN