Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

291–300 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#291
post #97

Earlier quoted context omitted.

If you can get exact collisions, this can be gamed. For example, suppose there are two rival gangsters. One wants to set the police on his rival. He knows that a certain (innocuous) image is on his rival's phone. So he pays someone to generate a fake child-porn image with the same neuralhash, and ensure that it gets into the child porn DB. Then, apple reports the rival to the police, and they come and investigate him…

If your enemy can get an image on your phone and in the “child porn DB”, I think they can easily get you in trouble without Apple’s help. they can either just send the police an anonymous message or set up a child porn web site and have it ‘accidentally’ leak its password database, and make sure your email address is in it.

The point is that they don't need to get an image on your phone. They can just choose one they know is there.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#292
post #246

Earlier quoted context omitted.

The simple answer is: password resets. I’m sure majority of people would be very upset if they lost everything by forgetting a password.

Doesn't the apple backup stuff work that way? The data is gone forever if you lose your password?

Some, but not all. And if you still have access to a Mac or iOS device which remains associated to this iCloud account, the amount that is lost can be even less.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#293

Earlier quoted context omitted.

It’s not per photo, it’s per photo library. But it’s per year, so on average once every 1000 years there will be a false positive for someone. They are communicating numbers. For example, they tested with 100 million photos and got 3 false positives. They also tested with 100 k normal porn photos and got 0 false positives.

I think their numbers are completely irrelevant, now that we know the visual hash can be gamed. Since it can be, it will be. Basically, that 1 in a trillion number has an implicit "assuming people aren't cheating", as most mathematical models do. But it's already evident people can cheat this system. I don't know what the odds will end up being, 1 in a trillion or 1 in 100, but they will not be based on statistical a…

All the other big players have been using similar algorithms for years, in the cloud. Why haven’t they been overwhelmed by false positive attacks?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#294
post #268

Earlier quoted context omitted.

Something like 40 percent of people use the default browser installed by the os. We're just in an echo chamber of people who know what JavaScript is, and that distorts our perception of the world.

Can you give source for that number? Regardless, browser is like any other app. If that amount of people don’t know how to install apps on their computers, then we have a either real dump people (or just lack of motivation) or great UX design failure in general.

Users are on average incompetent, not dumb.

It's a dauntins realisation that sinks in once you have to do support for a web site or app catering to the general population instead of a niche.

They don't read, don't know the diff between an app and a web site, don't know right click or drag and drop, think google or chrome is the internet and overall their startegy to solve any problem is as follow:

- look for something obvious that seems like the answer but is not scary

- click

- wait for it

- repeat 3 times until ok or give up and call someone or get angry or both

Working on a streaming video site really opened my eyes on this one. Most tickets we received were insults, some were incomprehensible garbage, a few were actionable request from someone not understanding anything about their computer.

This is nothing like your github ticket. Your parent number are being generous IMO.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#295
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

There is an interesting constitutional quirk which arises from the scanning being done client side, specifically for US citizens. If the US Government forced Apple to add other entries to the hash table, this would constitute a warrantless Government search of the private physical property of US citizens. This is a clear-cut, unambiguous breach of the 4th Amendment. Whereas if the CSAM scanning was performed exclusiv…

Are you a lawyer or legal scholar, or just guessing?

The government can't compel warrantless searches of Apple. 3rd party doctrine means Apple can search your iCloud, and can give it away if they choose. Same as how Apple can search your phone if you run their software, and can give away whatever they find if they choose.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#296

Earlier quoted context omitted.

There is an interesting constitutional quirk which arises from the scanning being done client side, specifically for US citizens. If the US Government forced Apple to add other entries to the hash table, this would constitute a warrantless Government search of the private physical property of US citizens. This is a clear-cut, unambiguous breach of the 4th Amendment. Whereas if the CSAM scanning was performed exclusiv…

Apple could also encrypt every upload to iCloud, and not have any scanning on the client, and still be able to say to the government "sure, you can have the files; we can't read them and neither can you". Apple wants to reduce your privacy from the government above and beyond what the law requires. The questions is: why?

Because Apple doesn't want to be a child porn storage service. This is not a secret.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#297

Earlier quoted context omitted.

Apple could also encrypt every upload to iCloud, and not have any scanning on the client, and still be able to say to the government "sure, you can have the files; we can't read them and neither can you". Apple wants to reduce your privacy from the government above and beyond what the law requires. The questions is: why?

Because Apple doesn't want to be a child porn storage service. This is not a secret.

That's not technically possible, though. Most tech companies don't take on impossible tasks, because it will take an infinite amount of money to realize it, and the shareholders will be bankrupt before the product is delivered.

Every piece of data is CSAM encrypted with a one-time pad. It's just that nobody knows the one-time pad.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#298

Earlier quoted context omitted.

Law enforcement must manually review all suspected CSAM before seeking a warrant based on it. There is a whole process there, beyond whatever Apple has implemented, before a prosecution begins. Understand that matching a file in the NCMEC database is not itself a crime. The whole CSAM-detecting ecosystem is just a tool for surfacing potential crimes. Having a few pics of your own child naked is not illegal and it’s p…

>Law enforcement must manually review all suspected CSAM before seeking a warrant based on it. Is this a legal statute or simply convention due to the ways things have historically worked (i.e. pre-hash matching at scale)? If warrants are granted based on probable cause, it seems easy to convince a judge that a hash match is sufficiently unlikely that it would exceed the threshold for probable cause. In the context o…

> Sure, matching a hash isn't a crime and you will eventually be exonerated.

s/will/might/

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#299
post #260
post #140

Earlier quoted context omitted.

I'd argue that the hash collisions (both natural and synthetic) that I've seen give me more confidence in the system, not less. On the natural hash collisions (of which there are two ), we have objects of similar shape against a solid background. It seems that a natural hash collision of a CSAM image would be unlikely (or if it does occur, it would be something that perhaps is also an infringing image). As for the sy…

> this is a sh*t picture in this meme and download something else. NO. Adversarial preimages can be created that look like perfectly normal images. Please stop repeating this falsehood. Here are some examples I generated (with a link to more): https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...

I saw two examples. The dog/girl one has obvious artifacts in the picture of the girl. The directly linked image doesn't have artifacts, but putting them side by side, I can see what got matched up and they're still very approximately the same picture in that they're both pictures of women and the eyes are in the same part of the picture which gives support to your perspective. I do still wonder whether it would be possible to take, say, a (legal) nude and turn it into an innocent-looking image that still matches the hashes or not. I'm more inclined to believe it now than before, but theoretical possibilities don't usually map to realistic concerns.¹

1. One example of this would be that theoretically, LaTeX's cross-reference mechanism can get caught in a cyclic state. This can only happen with page references and the most likely scenario is a reference to a roman-numeraled page number where if the page reference is output as ix the referenced location moves to page x and when the page reference is updated to x the referenced location moves to page ix (in practice, functioning examples required a shift between xcix and c, but either way, the probability of this happening in a real document is vanishingly small).

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#300

Earlier quoted context omitted.

CSAM on the server means the server is tainted and likely to be searched by governments. Good plan to keep it off eliminates that excuse.

I don't see how this scanning reduces the likelihood of a government searching their servers. Seems to me like this can only result in more court orders than they had before scanning.

If you’re Apple, and you’re throwing your weight around in the US bread and butter market to convince the FBI to not scan your servers for CSAM, which is more compelling: we check for it when it gets here, or we keep it off our servers using crypto hash magic?
Post reply on HN