Live data from Hacker News

One Bad Apple

hackerfactor.com

271–280 of 557 posts

Re: One Bad Apple

#271

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> Why haven't I made my whitepaper about PhotoDNA public? In my view, who would it help? It would help bad guys avoid detection and it will help malcontents manufacture false-positives. The paper won't help NCMEC, ICACs, or related law enforcement. It won't help victims. I have to respectfully disagree with that statement and the train of thought unfortunately. However, you should seek legal counsel before proceeding…

I would have agreed with this on principle, assuming motivated actors who are willing to read technical papers on PhotoDNA, keeping it unpublished is only delaying these actors.

Although there can be real value in delayed release, secrecy, and obfuscation, that is especially useful if the author can credibly convince NCMEC and other relevant parties to make use of the whitepaper while it is private.

If delaying gains little, secrecy is less helpful. Sunlight tends to be the best disinfectant.

As it stands, it is hard to judge how much progress is being made behind closed doors to improve PhotoDNA.

Re: One Bad Apple

#272
There is so much focus on the technical aspects such as probability of mismatch etc.

For me the risk is much more that through some mechanism outside my control real CSAM material becomes present on my device. Whether its a dodgy web site, a spam email, a successful hack attempt or something else like that, I feel like there's a significant chance some day I'll end up with this stuff injected onto my phone without me knowing. So I'm not at all concerned about the technical capacity to accurately match to CP etc. In fact I'm even more worried if its really accurate because then I know when this unfortunate event happens I face a huge risk of being immediately flagged before I even know about the content and then spending years extricating myself from a ruined reputation and a legal system that treats evidence like this with far more trust than it should have.

Re: One Bad Apple

#273

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

One way to interpret the macaque photo is that the database has already been subverted for uses other than catching CP.

Or it’s one of many test images, like EICAR, so people can test and validate the system without using abhorrent images.

Re: One Bad Apple

#274

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

I have no idea whether this statistic is true or not, but "nearly 1 in 10 children in the US will be sexually abused" is an incredibly high number.

I have no doubt that some cases of sexually abused children must have also existed in the environment where I have grown up as a child, in Europe, but I am quite certain that such cases could not have been significantly more than 1 per thousand children.

If the numbers would be really so high in USA, then something should definitely be done to change this, but spying on all people is certainly not the right solution.

Re: One Bad Apple

#275
post #272

There is so much focus on the technical aspects such as probability of mismatch etc. For me the risk is much more that through some mechanism outside my control real CSAM material becomes present on my device. Whether its a dodgy web site, a spam email, a successful hack attempt or something else like that, I feel like there's a significant chance some day I'll end up with this stuff injected onto my phone without me…

I still have WhatsApp on my phone and I have had issues in the past with backups so I have it set to save the media directly to my photos app.

I also have notifications off on it and check it when I need to.

All this needs is someone forwarding me something that’s in the DB.

Re: One Bad Apple

#276
post #225

Earlier quoted context omitted.

Reading carefully through the paper, an important part of their calculation for the "one in a trillion" claim seems to rest on the cryptographic threshold approach they are using. In particular, it seems likely to me that the number matches required for your account to be flagged is relatively high (perhaps a dozen). If that is the case, their hash collision likelihood could be "only" 1 in a million, but it would sti…

You're assuming that perceptual hashes are uniformly distributed, but that's not the case. If I post a picture of my kid at the beach I'm far, far more likely to generate perceptual hashes closer to the threshold. Not to mention intimate photos of/with my partner.

Good point about the possibility of capturing a bunch of distinct photos with the same perceptual hash, either by taking a burst of photos or by editing one photo a bunch of times. I guess a better implementation would never upload two different encryption keys for the same perceptual hash and just send dummy data instead, but I haven't seen any indication that they actually do that.

Re: One Bad Apple

#277
post #233
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

> More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. The mechanism doesn’t scan anything except images, and won’t trigger on a single bad image - only a set. Yes, that set could be something other than child porn, assuming Apple and NCMEC conspire, but this is not a general purpose backdoor.

Literally Apple could just add a different set to the set of hashes they push? That seems very naive.

Re: One Bad Apple

#278

I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the p…

Relatedly, I don't see much discussion around the nuances of what counts as cp. In my experience, the vast majority of cp people are likely to come into contact with is "consensual" (the definition of consent gets weird here) images taken by teenagers of themselves, not old men raping little kids. So what happens if a 17 year old girl takes pictures of herself, sends them to her partner, they break up, he posts them online as revenge porn, and a site moderator reports it as cp and its hash ends up in the db? Now police come after her because she has 25 similar images in her icloud and she gets treated like a criminal? She definitely did break the law I suppose, but there's so much more nuance there. I really feel like these are the kinds of people who are most likely to get flagged. I (hopefully) don't know anyone who keeps swaths of abusive cp on their iPhones, but I certainly have known a lot of underage kids with intimate pictures of themselves and their friends/partners.

Re: One Bad Apple

#279

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

Isn’t that an alleged memo from the NCMEC? I would sincerely doubt an official memo from any agency would use the term “shrieking minority”, it sounds like imaginative fiction of what a government agency would actually say.

Re: One Bad Apple

#280
post #277
post #233

Earlier quoted context omitted.

> More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. The mechanism doesn’t scan anything except images, and won’t trigger on a single bad image - only a set. Yes, that set could be something other than child porn, assuming Apple and NCMEC conspire, but this is not a general purpose backdoor.

Literally Apple could just add a different set to the set of hashes they push? That seems very naive.

What seems naive? Adding hashes will only match images, not other files, and even then only if a group is matched, not just one.
Post reply on HN