Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

31–40 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#31
Please help me understand. Isn't this the reason why the process involved a final manual review? If so, isn't the point of having identical hashes moot? Or is the point that having more identical hashes means reviewing more personal pictures manually, leading to a privacy issue?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#32
post #10

Earlier quoted context omitted.

We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about

You (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.

There is a big difference, if say Apple tracking of what you run is problematic you get a bad user experience like apps starting after 1 minute of waiting, or if Apple App Store contains malware you will probably get some annoying issue while Apple will try to silently cleanup their mess BUT with this system there is a difference, this is designed not to serve you or protect you, it is designed to do some checks then if some specific rules match send some guys on you to destroy your life, today is FBI tomorrow other authoritarians.

Issues in any other Apple software will not send the police on you. Why would you install a software on your desktop/laptop that is designed to snitch on you, you would need to get some advantage or be forced by some law.

For now I see only disadvantages but please let me know of any real advantage and not speculation

Disadvantages:

- closed software with hidden db can't be trusted, so as a user you will always have a doubt that some non CP images are in the db(Apple always collaborates with governments)

- bugs in this stuff will cause you big problems(we seen in the past how false accusation destroyed peoples life) and we also seen bad actors abusing this kind of stuff.

- this is also clearly a beginning, now that Apple has the capability then even if they were saints a judge could force them to add new hashes, change the configs etc.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#33
Apple has yet to make a valid reason for implementing client side CSAM scanning.

According to Apple only images that will be uploaded to iCloud will be scanned.

If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server.

Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#34

I’m glad that people are trying to figure out any technical flaws in the system as best they can, but if I’m being honest I do trust Apple’s engineers to have built something that is solid from a technical stand point. Am I correct in that the primary reason folks are so upset is that the system could (probably) be easily modified such that -any- content could invoke legal action? That the main problem is really the…

Exactly that. The tech seems fine, but I live in a country with a government that has strong censorship laws, and I do not trust Apple to not bend to countries like China in extending this to political content.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#35
post #24
post #12

Earlier quoted context omitted.

It doesn't really matter whether all images are uploaded, or just 1 in x (for large value of x), due to the Panopticon effect.

Let's not forget what the alternative is: this is about images that are uploaded on icloud anyway. The alternative is to upload the image in clear (or with ane encryption key that apple controls), and let apple run the CSAM filter on their servers. Apple now has the ability to encrypt the images before sending them to icloud, with a private key you own. Except that some percentage of images that match the CSAM finger…

But if Apple really cares about children why they did not done this scans in iCloud like all the others? Did not care as much as Google or Facebook? Seems to me like Apple does not care at all and seems more like a dev with big ego wanted to add neural hashes to his CV but if you can explain how Apple cared for children all this years but only now are doing something I really want to see the explanation

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#36
post #3

Sigh, for the last time, it doesn't actually matter if the NeuralHash is identical. You need multiple images matching, and then the images are compared by another system on Apple's end, which you don't know anything about. The system is specifically designed so that colliding images does not pose a threat to the user. NeuralHash and the CSAM scanning is grotesque, but please, criticize it for what it is, not some bul…

Discussing the preimage attack on NeuralHash is not technical ignorance. Dismissing the preimage attack as irrelevant is. 0. Most importantly: the existence of a preimage attack makes Apple's system completely useless for its original purpose. The NeuralHash collider allows the producers and distributors of CSAM material to ensure that nearly all of the next generation of CSAM will suffer from hash collisions with pe…

That's a lot of words to say that you could sufficiently mangle an image that it could pass through all of Apple's algorithmic hurdles while not actually being CSAM. Of that I have no doubt. You could definitely generate a mangled image that fools multiple perceptual hash algorithms.

Let's set aside the questions of where you got all these hashes to generate collisions with, how you got 30 of these mangled images into your victim's camera roll without them noticing. And let's also set aside whether your victim's device is an iPhone with iCloud Photo Library enabled (and has sufficient storage). I still don't get what these mangled images have achieved, other than giving the manual review team something other than child porn to look at.

Seems to me like it'd be easier to just find actual child porn, print it out, place it somewhere in the victim's house and then report it to the police.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#37
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

Also they will be doing scanning in their server anyways as there are other ways to upload it in iCloud than using latest iOS.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#38
How are any of these "naturally occurring" when all (4) examples are things cut out of context on a white background.

Yeah two sticks (ski and nail) are visually similar on a white background. Why is this news to anyone?

EDIT: if you are going to downvote please leave a comment unless you are just downvoting for wrong think.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#39
post #24
post #12

Earlier quoted context omitted.

It doesn't really matter whether all images are uploaded, or just 1 in x (for large value of x), due to the Panopticon effect.

Let's not forget what the alternative is: this is about images that are uploaded on icloud anyway. The alternative is to upload the image in clear (or with ane encryption key that apple controls), and let apple run the CSAM filter on their servers. Apple now has the ability to encrypt the images before sending them to icloud, with a private key you own. Except that some percentage of images that match the CSAM finger…

They already have the decryption keys for iCloud. Undoubtedly they've already been running a similar CSAM filter server-side for ages. The only thing doing this stuff client side has done is reduce privacy and erode trust.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#40
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

One reason for client side could be to save on datacenter compute resources. That would seem like a perfectly valid reason, if that’s their reasoning.
Post reply on HN