Live data from Hacker News

ImageNet contains naturally occurring Apple NeuralHash collisions

blog.roboflow.com

311–320 of 530 posts

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#311

Earlier quoted context omitted.

You're adding quite a lot of technobabble gloss to an "attack vector" that boils down to "people can send you images that are visually indistinguishable from known CSAM". Guess what, they can already do this but worse by just sending you actual illegal images of 17.9 year olds. While it would be bad to be subjected to such an attack, and there is a small chance it would lead to some kind of interaction with law enfor…

I suggest you reread the comment, because "people can send you images that are visually indistinguishable from known CSAM" is not what is being said at all. Where did you even get that from? The point is precisely that people can become victims of various new attacks, without ever touching photos that are actual "known CSAM". For Christ's sake, half the comments here are about how adversaries can create and spread po…

Can you explain how these theoretical political memes hash-match to an image in the NCMEC database, and then also pass the visual check?

> "No, this misses the point completely. You cannot easily trigger any automated systems merely by taking photos of 17.9 year olds and sending them to people."

Did I say "taking"? I am talking about sending (theoretical) actual images from the NCMEC database. This is functionally identical to the "attack" you describe.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#312
post #293

Earlier quoted context omitted.

> Because they don't know who to arrest yet. The idea isn't to fabricate a charge, it's to locate people sharing politically sensitive images that the government hasn't already identified. And maybe even identify avenues for sharing that they haven't already identified and monitored/controlled (e.g. some encrypted chat app they haven't blocked yet).

China does not really need Apple to do much. They already make installation of some apps mandatory by law. Also, some communication must be done with WeChat and so on. They have pretty good grip already.

> They already make installation of some apps mandatory by law. Also, some communication must be done with WeChat and so on.

Can you give some examples of this on the iPhone?

Also, it seems like on the spying front [1] (at least publicly, with Apple), they've preferred more "backdoor" ways to get access over more overt ones, so this scanning feature might encourage asks that they wouldn't have otherwise made.

[1] this contrasts with the censorship front, where they've been very overt

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#313

Earlier quoted context omitted.

If the CCP says “put this arbitrary software into your next iPhone software update or we will halt all iPhone sales in China,” what do you think Apple is going to do? Isn’t the answer to both questions the same?

What makes us think that that isn’t exactly what this is already?

This is already happening to phones. The baseband blobs are proprietary and most devices permit DMA.

Nobody really knows what the blobs do. They likely have paved the way for Stingrays and other devices.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#314

It doesn’t matter if there are collisions if the two images don’t actually look the same. Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America? PhotoDNA has existed for over a decade doing the same thing with no instances that I have heard of. If some corrupt government wants to get you they don’t need this. They can just unilaterally say you’…

> Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America?

being on a government maintained secret list of CSAM flagged would probably have a lot of consequences in your life going forward without you knowing about that. It may be just one innocent image which accidentally matched the hash, yet without any procedure to get you off that list or even just to learn whether you're on that list ...

>If some corrupt government wants to get you they don’t need this.

it isn't corrupt government which is a threat here. It is a well intended well functioning relatively uncorrupt government which spends a lot of effort to protect its society from terrorism, child porn, sex trafficking, drugs, etc. In case of corrupt government the situation is kind of easier - you can always learn and correct necessary things through the corrupt government officials by paying a corresponding "fee".

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#315
post #300

Earlier quoted context omitted.

> citizens are spied on by a country that is not them I thought countries often have under the table agreements with one another to explicitly spy on each others citizens, since its illegal for the country to spy on its own citizens. It's illegal for the other country too, but it's a lot easier to turn a blind eye to it.

The EU is not spying on any of its citizen. If you think otherwise, please link to some sources. Otherwise these are baseless rumors. These "everyone is doing it" statements are nonsense. Not everything is doing it.

You’re probably right.

The USA is probably doing it for them.

NSA tapped German Chancellery for decades, WikiLeaks claims

NSA spying row: Denmark accused of helping US spy on European officials

US caught spying on EU ‘allies’ AGAIN…not like the Europeans will do anything about it

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#316

> Apple now has over 1.5 billion users so we are talking about a large pool of users at stake which increases the likelihood of even a low probability event manifesting This is an extremely good point. If the whole system, end to end, after all safeguards (e.g. human reviewers which can also make mistakes) has a one-in-a-billion chance to ruin a user's life, then statistically, we can expect 1-2 users to have their l…

They didn’t say one in a billion, they said 2 in 2 trillion.

A billion users with a thousand photos each would only be one trillion photos.

So a chance someone inadvertently has to look at a photo and … not prison, but, “nah, not this photo”.

Probability seems rather higher that the global suspicion-less and warrantless search will generate more positive PR results and systemic downstream negative privacy impacts than that chance of a subsequently easily avoided adverse result.

Odds are decent this all turns out seeming to normals like a “no downsides” implementation. If anyone wants to screech, better screech before it all proves perfectly splendid.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#317

Earlier quoted context omitted.

> they could literally just tell Apple to issue a software update that streams all desired private data to Chinese government servers. Uh...this already happened. [0][1] [0] https://www.macrumors.com/2021/05/17/apple-security-compromi... [1] https://support.apple.com/en-us/HT208351

Not quite. Those are still ostensibly servers located in China but not directly controlled by the government (edit: apparently the hosting company is owned by Guizhou provincial government) . But yes, this is precisely my point. Any slippery slope argument about Apple software on iPhones is equivalent to any conceivable slippery slope argument about Apple software on iPhones. If you're making one of these arguments,…

China's laws are such that there's no need for them to obtain a warrant for data housed on servers of Chinese companies. Not only do they not need a warrant but companies are required to facilitate their access. While the servers aren't controlled by the Chinese government, government law enforcement and intelligence agencies have essentially free access to that data.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#318
post #275

Earlier quoted context omitted.

Exactly. Apple can already ship literally any conceivable software to iPhones. Do people really think their plan was to sneak functionality into this update and then update the CSAM database later, and they would have gotten away with it if it weren't for the brilliant privacy advocates pointing out that this CSAM database could be changed over time? That's pretty ludicrous. If the Chinese government wanted to (and t…

So your argument boils down to since Apple can already install software without us knowing, we shouldn't worry about a new client-side system that makes it substantially easier for nation states to abuse? I don't find that argument the least bit compelling.

I’m not saying that we shouldn’t be concerned with Apple actually launching things that are bad. I’m saying we shouldn’t make arguments of the form “this isn’t bad yet, but they could change this later to make it bad.” Because obviously they can change anything later to be bad. If the system as currently described is a violation of privacy, or can be abused by governments, etc. then just make that argument.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#319
post #285

Earlier quoted context omitted.

If the CCP says “put this arbitrary software into your next iPhone software update or we will halt all iPhone sales in China,” what do you think Apple is going to do? Isn’t the answer to both questions the same?

So we should simply accept systems with a high potential for abuse because of the possibility that something bad is already being done?

What has more potential for abuse than the fact that Apple can push any software they want to iPhones at any time?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#320

It doesn’t matter if there are collisions if the two images don’t actually look the same. Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America? PhotoDNA has existed for over a decade doing the same thing with no instances that I have heard of. If some corrupt government wants to get you they don’t need this. They can just unilaterally say you’…

Well there is this here

https://en.wikipedia.org/wiki/Paul_Reubens#2002_pornography_...

Post reply on HN