Live data from Hacker News

One Bad Apple

hackerfactor.com

411–420 of 557 posts

Re: One Bad Apple

#411

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

Thank you for those insights.

I've long held a grudge against Microsoft and NCMEC for not providing this technology, because I live in a country where reporting CSAM is ill-advised if you're not a commercial entity and law enforcement seizes first and asks questions later (_months_ later), so you end up just closing down a service if it turns out to be a problem.

This puts it into perspective. PhotoDNA seems fundamentally broken as a hashing technology, but it works just well enough with a huge NDA to keep people from looking too closely at it.

NCMEC needs a new technology partner. It's a shame they picked Apple, who are likely not going to open up this tech.

Without it, it's only a matter of time until small indie web services (think of the Fediverse) just can't exist in a lot of places anymore.

Re: One Bad Apple

#412
If this is true and content of pictures can be unhashed to a 26x26 picture this is ethically a total nightmare. Nobody wants to carry a phone with child porn with them, discusting if you think about it.

I don't even want to imagine what very religious people and countries will think about the iPhone then.

Re: One Bad Apple

#413
post #192

Earlier quoted context omitted.

> How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? “With the first link, the chain is forged. The first speech censured, the first thought forbidden, the first freedom denied, chains us all irrevocably. The first time any man's freedom is trodden on we're all damaged...."

This is melodramatic high school Hamlet-ism. It’s also silly - there has obviously been a case where the first speech was censured. It happened before civilizations. Are we all still damaged and bondaged by that? Look, speech is important. So is protecting the public good. But if one believes in absolutes, rather than takeoffs, they are IMO getting too high on their own supply. Let’s talk about the trade offs that we…

Does the fact that the NSA can comb your personal files and look at people's nude photographs not concern you? That's a present day reality brought to light by Snowden. Showing a colleague a 'good find' was considered a perk of the job.

We're lying to ourselves if we think this couldn't be abused and can implicitly be trusted. We should generally be sceptical of closed source at the best of times, let alone when it's inherently designed to report on us.

To your point of 'as a layman end user what is the cost to me?': more code running on your computer doing potentially anything which you have no way to audit -> compromising the security of whatever is on your computer, and an uptick in cpu/disk/network utilisation (although it remains to be seen if it's anything other than negligible).

My defeated mentality is partly - 'well they're already spying on us anyway'...

Re: One Bad Apple

#414

Earlier quoted context omitted.

So.. how well does "human review" work with copyright on youtube? This is basically fearmongering, and saying "if you're not a pedo, you have nothing to fear", installing the tech on all phones, and then using that tech to find the next wikileaks leaker (who was the first person with this photo), trump supporters (just add the trump-beats-cnn-gif to the hashes), anti-china protesters (winnie the pooh photos), etc. Th…

> just add the trump-beats-cnn-gif to the hashes They could literally do this right now server-side and nobody would ever know.

But noone uploads that to iCloud. That's why they must implement this feature client-side ("because if you're not a pedo, you have nothing to worry about"), and then enable it for on-phone-only photos too ("because if you're not a pedo, you have nothing to worry about"). Then use the same feature on OSX ("because if you're not a pedo, you have nothing to worry about").

Re: One Bad Apple

#415

Earlier quoted context omitted.

> About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. The problem is people use this perfectly legitimate problem to justify anything. They think it's okay to surveil the entire world because children are suffering. There are no limits they won't exceed, no lines they won't cross in the name…

This quote sums it up perfectly : “Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep ,his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval…

The consequences seem very simple - once this system is in place, it's only a matter of time until a state actor, be it China or US or Russia or pretty much anywhere goes to Apple and says "hey this hash matching algorithm you have there? If you want to keep operating in our country, you need to match hashes too, no, we won't tell you what they are and what they represent, but you have to report to our state agency who had those present on the device".

Once the technology exists it will be abused.

Re: One Bad Apple

#416
post #400

Earlier quoted context omitted.

The internet isn't the wild west, laws are very much enforced.

Stalking and harrasment isn't, at least over here. Victims are constantly left out in the cold. Same goes for fraud, most cases are not prosecuted. Especially if these cases cross state, and in the EU, nation borders. Because it becomes inconvenient, so police isn't really bothering. And if they do, the fraud is done. The stalking went on for years. And nothing really improved. Hell, do I miss the old internet. The o…

International fraud is a really interesting problem. I've proposed a mandatory international money transfer insurance that would pay out in case of court decided fraud. It would make doing business with corrupt countries that look the other way on fraud within their borders crack down to preserve their international market access.

Re: One Bad Apple

#417

> If someone were to release code that reverses NCMEC hashes into pictures, then everyone in possession of NCMEC's PhotoDNA hashes would be in possession of child pornography. Please correct me if I'm wrong, but wouldn't it be more correct to say they "would be in possession of images recognized by PhotoDNA as child pornography" rather than actual CP?

Technically not possible without severely grasping assumptions. It would be more likely you would create a collision and have calculated an image of a duck (south african whitenoise duck).

Problem with all this is that the images of naked children made by their parents is CP in the eyes of its consumers.

Perceptual AI is the best approach, but produces a certainty In my cryptography course I had a project about invisible watermarks and secret messages in imaging. The first hurdle was beating partial images and compression, so most early algorithms worked in the frequency domain. At that time it was basically an arms race between protection or deletion of said messages and I think that hasn't changed.

Conventional file hashes can be beaten by randomizing meta data since a quality hash function would immediatly create a completely different hash. Never mind just flipping or probably just resaving them.

If you create a polynomial approximation of frequencies or color histograms of an image, you have a relatively short key indicator. But you need a lot of those to even approach certainty. Could always be an image of a duck.

Re: One Bad Apple

#418
post #338
post #331

Earlier quoted context omitted.

As I said, incredibly naive.

You said it, but then you failed to back it up with anything other than your fears.

What reason do we have to trust that the NSA won't knock on the door of apple and ask for a small expansion, as a matter of national security + here is your NDA outlining that any canary tampering will result in jail time? It's a closed system so we would have no way of knowing.

Re: One Bad Apple

#419
post #416

Earlier quoted context omitted.

Stalking and harrasment isn't, at least over here. Victims are constantly left out in the cold. Same goes for fraud, most cases are not prosecuted. Especially if these cases cross state, and in the EU, nation borders. Because it becomes inconvenient, so police isn't really bothering. And if they do, the fraud is done. The stalking went on for years. And nothing really improved. Hell, do I miss the old internet. The o…

International fraud is a really interesting problem. I've proposed a mandatory international money transfer insurance that would pay out in case of court decided fraud. It would make doing business with corrupt countries that look the other way on fraud within their borders crack down to preserve their international market access.

I have hands on experience with, what I'd call at least attempted fraud, with crypto. Back when Sweden thought about state backed crypto, a lot of ads showed up where you could invest in that. I almost did, call centers used Austrian numbers. Not sure if there was even any coin behind that. I reported it to police, got a letter after a couple of months that the investigation led nowhere and was dropped, apparently Austrian authorities did find anything on the reported number.

A couple of hours online found

- the company behind that operated out of the UK - the call center was not in Austria but used local numbers for a while - company was known for that shady business but never even got a slap on the wrist

I decided to never count on authorities for that kind of fraud. Or report it, because that's just a waste of time, unless you lost a shitload of money.

Re: One Bad Apple

#420

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> Nearly 1 in 10 children in the US will be sexually abused before the age of 18.

This can only be hyperbole. How are you defining sexual abuse?

Post reply on HN