Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

291–300 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#291

Despite that Apple scanning our images is a horrible privacy practice, I don't get why 𝚜̶𝚘̶ ̶𝚖̶𝚊̶𝚗̶𝚢̶ some people think this is an ineffective idea. Surely you can easily fabricate innocent images whose NeuralHash matches the database. But in what way are you going to send them to victims and convince them to save them to their photo library? The moment you send it via WhatsApp FB will stop you because (they th…

I really appreciate this comment, as anytime a new security issue creates a fuss, I feel like I'm the only one wondering what the real attack vector is. I'm genuinely glad people are so thoroughly investigating this new Apple policy, but at the same time I feel like I'm the only one dumb enough not to understand what I should be actually concerned about.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#292
A lot has been said about using this as an attack vector by possibly poisoning a victims iPhone with an image that matches a CSAM hash.

But could this not also be used to circumvent the CSAM scanning by converting images that are in the CSAM database to visually similar images that won't match the hash anymore? That would effectively defeat the CSAM scanning Apple and others are trying to put into place completely and render the system moot.

One could argue that these spoofed images could also be added to the CSAM database, but what if you spoof them to have hashes of extremely common images (like common memes)? Adding memes to the database would render the whole scheme unmanageable, no?

Or am I missing something here?

So we'd end up with a system that: 1. Can't be reliably used to track actual criminal offenders (they'd just be able to hide) without rendering the whole database useless. 2. Can be used to attack anyone by making it look like they have criminal content on their iPhones.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#293
post #184

Earlier quoted context omitted.

I agree CSAM isn't likely to be pervasive in the photo libraries on iOS devices. Android does not do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. It's not on-device scanning, but the effect is functionally identical: photos that are being uploaded to the cloud are being scanned for CSAM. The only real distinction is who owns the CPU which computes the hash. I d…

> Android doesn't do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. So did Apple, and pretty much all cloud hosting providers. This, on device, scanning is what's new, and very out of character for Apple. > If Apple's lobbyists can show that iPhones are already searching for CSAM, arguments for such laws get weaker. I'm not aware of any big anti-CSAM push being m…

CSAM can never be a policy issue with two sides, because everyone is in agreement that we need to protect children. The higher powers want to prevent child abuse, and CSAM is directly tied to child abuse. When people argue that "think of the children" can be weaponized to attack their freedoms, they wouldn't dare try to argue against the premise that children are harmed because of CSAM - not because the arguments will fall on the deaf ears of some governmental agents trying to push an agenda, but because the premise itself is sound.

As a result, people will focus their arguments instead on the technological flaws in the current implementation of on-device scanning or slippery slope arguments that are unlikely to become reality, the feature will be added anyway with no political opposition, and in the end Apple and/or the government will get what they want, for what they consider the greater good.

I think that absolute privacy in society as a whole isn't attainable with those values in place, and it raises many questions regarding to what extent the Internet should remain free from moderation. Are there really no kinds of information that are so fundamentally damaging that they should not be allowed to exist on someone's hard drive? If not, who will be in control of moderating that information? Maybe we will have to accept that some tradeoffs between privacy and stability need to be made for the collective good, in limited circumstances.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#294
post #103

Well done! Hopefully all of this progress toward demonstrating how easy it is to manipulate neural hash will get Apple to rollback the update...

Can they though? To the general public the optics of rolling back the update now would be that they are not fighting CSAM.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#295
post #268

Earlier quoted context omitted.

> First, as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possibility that the match threshold was exceeded due to non-CSAM images that were adversarially perturbed to cause false NeuralHash matches against the on-device encrypted CSAM database. https://www.apple.com/chi…

Honestly missed this. Is that security-through-obscurity? If the model and weights for the second hash function became public, then we could still construct a collision on both functions, right?

It’s not security through obscurity. The implementation is not necessarily a secret; it’s the model configuration which can only be differentiated if known. Since part of the threat is adversarial embeddings, it’s perfectly fine to assume you can keep a private model confidential that adversaries can’t differentiate.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#296
Can someone explain what is the profile of criminals they expect to catch with this system? People that are tech savy enough to go on the darknet and find CSAM content but simultaneously stupid enough to upload these images to iCloud?

And they think there are enough of these people to create this very complicated system and risk a PR disaster?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#297

Earlier quoted context omitted.

People here are proposing intentionally creating image assets which collide with perceptual hashes of known CSAM (ignoring whether that is legal or ethical) and sharing those assets to effectively SWAT unaware targets.

I haven't seen anyone proposing actually doing it, but I think a lot of people are rightly pointing out that bad actors, black hats and the Russian mob are going to have a field day with their ability to do so.

I’m not sure how you can conclude the speculation is “right” without engaging with the fact that this hypothetical is addressed directly in the threat model document and hasn’t been pulled off successfully against any of the other services which do similar scanning. Why can’t I buy compromat as a service for your Gmail account?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#299

Can someone explain what is the profile of criminals they expect to catch with this system? People that are tech savy enough to go on the darknet and find CSAM content but simultaneously stupid enough to upload these images to iCloud? And they think there are enough of these people to create this very complicated system and risk a PR disaster?

Facebook reported 68.1 million csam images last year. If these people were such criminal masterminds, why are Facebook’s numbers so high?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#300
post #184

Earlier quoted context omitted.

> Android doesn't do on-device scanning, but Google does scan photos after they are uploaded to their cloud photo service. So did Apple, and pretty much all cloud hosting providers. This, on device, scanning is what's new, and very out of character for Apple. > If Apple's lobbyists can show that iPhones are already searching for CSAM, arguments for such laws get weaker. I'm not aware of any big anti-CSAM push being m…

CSAM can never be a policy issue with two sides, because everyone is in agreement that we need to protect children. The higher powers want to prevent child abuse, and CSAM is directly tied to child abuse. When people argue that "think of the children" can be weaponized to attack their freedoms, they wouldn't dare try to argue against the premise that children are harmed because of CSAM - not because the arguments wil…

There is a lower limit to privacy (as a human right) – which after passing, societies would seize to be "free" (liberal democracies?). But that's not a discussion people seem to want to have, when talking about their good intentions of fighting against horrible things.
Post reply on HN