Earlier quoted context omitted.
Corruption. Lack of evidence on some other cases. Personal revenge. Who knows, but list is big.
Ok but but what ends?
The Problem with Perceptual Hashes
421–430 of 440 posts
Re: The Problem with Perceptual Hashes
#422The problem of hash or NN based matching is, the authority can avoid explaining the mismatch. Suppose the authority want to false-arrest you. They prepare a hash that matches to an innocent image they knew the target has in his Apple product. They hand that hash to the Apple, claiming it's a hash from a child abuse image and demand privacy-invasive searching for the greater good. Then, Apple report you have a file th…
Isn't this a problem generally with laws against entire classes of media?
Planting a child abuse image (or even simply claiming to have found one) is trivial. Even robust security measures like FDE don't prevent a criminal thumb-drive from appearing.
I think we probably need to envision a future in which there is simply no such concept under law as an illegal number.
Re: The Problem with Perceptual Hashes
#423It really all comes down to if Apple has and is willing to maintain the effort of human evaluations prior to taking action on the potentially false positives: > According to Apple, a low number of positives (false or not) will not trigger an account to be flagged. But again, at these numbers, I believe you will still get too many situations where an account has multiple photos triggered as a false positive. (Apple sa…
Then law enforcement, a prosecutor and a jury would get involved. Hopefully law enforcement would be the first and final stage if it was merely the case that a person pressed “ok” by accident.
Re: The Problem with Perceptual Hashes
#424Earlier quoted context omitted.
There's a big difference in the expectation of privacy between what someone posts on "Facebook, Youtube, et al" and what someone takes a picture of but doesn't share.
Odd, then, that Facebook reported 20.3 million photos to NCMEC last year, and Apple 265, according to the NYT that is.
Well I guess that explains a lot then - you're probably one of those that also voted for brexit, but now completely denies it - right?
Re: The Problem with Perceptual Hashes
#425Earlier quoted context omitted.
What about trolling. Assume 4chan figures out apples algorithm. What now happens when they start generating memes that happen to match known child pornography? Will anyone who saves those memes (or repost them to reddit/facebook) be flagged? What will apple do once flagged false positive photos go viral?
One way this hair-brained Apple program could end is to constantly generate an abundance of false positives, and try to render it useless. For those old enough to remember “Jam Echelon Day”, maybe it won’t have any effect. But what other recourse do we have other than to maliciously and intentionally subvert and break it?
Re: The Problem with Perceptual Hashes
#426Earlier quoted context omitted.
...yes, and the client-side check is only run before syncing to iCloud Photos, which is basically just shifting the hash check from before upload (client side) to after upload (server side).
Thanks for this clarification. This, I think, is an important aspect that seems to often get overlooked. Apple's explanation: Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the known CSAM hashes. This matching process is powered by a cryptographic technology called private set intersection, which determines if there is a match without revealing the result…
With the proviso that you have to trust the code they push onto your device actually does what they claim in the paper.
But it does, on the face of it, prevent the "cops adding the latest cop on black person murder viral image to the CSAM content hashes and easily seeing who has it on their device and when it showed up there" concern. They are at least going to need to add enough _other_ hashes to the list to get everybody with their target image over the threshold, then get it past whatever Apple has in place for their manual review and "visual derivatives". And surely that sort of abuse of the system would set off alarms instantly at Apple when a big list of hashes of images that are common enough to all push BLM activists and sympathisers over the CASM count threshold.
(I also wonder what those "visual derivatives" they get are, and how well they are going to work to filter out false positives, and how Apple are going to take care of whoever ends up doing that review work. While I have a fairly positive impression of the care and effort Apple put into ensuring my privacy, I have a somewhat less positive impression of how they treat outsourced or low-skill workers. I won't be _too_ surprised to hear the same sort of horror stories about both the work, and the management overseeing the workers that do this sort of job at Facebook... I can't imagine a worse job description than "review images to check if they are real child sexual abuse images", and doing that for minimum wage and no benefits with supervisors threatening to fire you if you take toilet breaks or miss your 150 images an hour targets - is sadly something I totally expect to read about in a year or two's time.)
Re: The Problem with Perceptual Hashes
#427Earlier quoted context omitted.
Someone is going to figure out how to make false positives, and then an entire genre of meme will be born from putting regular memes through a false positive machine, just for the lulz. Someone else could find a way to make every single possible mutation of false positive Goatse/Lemonparty/TubGirl/etc. Then some poor Apple employee has to check those out.
If Apple is indeed using CNNs, then I don’t see why any of the black-box adversarial attacks used today in ML wouldn’t work. It seems way easier than attacking file hashes, since there are many images in the image space that are viable (e.g., sending a photo of random noise to troll with such an attack seems passable).
Re: The Problem with Perceptual Hashes
#428Earlier quoted context omitted.
Free speech doesn't mean the speaker is immune from criticism or social consequences. If I call you a bunch of offensive names here, I'll get downvoted for sure. The comment might be hidden from most. I might get shadowbanned or totally banned, too. That was true of private spaces long before HN existed. If you're a jerk at a party, you might get thrown out. I'm sure that's been true as long as there have been partie…
> The only thing "the SJW crowd" has changed is which words are now seen as offensive. Well, that , and also bullying thousands of well-meaning projects into doing silly renamings they didn't want or need to spend energy on. Introducing thousands of silly little bugs and problems downstream, wasting thousands of productive hours.
[1] e.g.: https://www.wired.com/2017/06/diversity-open-source-even-wor...
Re: The Problem with Perceptual Hashes
#429Earlier quoted context omitted.
I would really like people to start answering this: what exactly do you think has changed? e.g, >That’s very different from authorities taking a sneak peek into my stuff. To be very blunt: - The opt out of this is to not use iCloud Photos. - If you _currently_ use iCloud Photos, your photos are _already_ hash compared. - Thus the existing opt out is to... not use iCloud Photos. The exact same outcome can happen regar…
What changed is we are not the masters of our technology anymore. If I tell my computer to do something, it should do it without question. It doesn't matter if it's a crime. The computer is supposed to be my tool and obey my commands. Now what's going to happen instead is the computer will report me to its real masters: corporations, governments. How is this acceptable in any way?
Re: The Problem with Perceptual Hashes
#430Earlier quoted context omitted.
So what are we going to do about it? I have a large user base on iOS. Considering a blackout protest.
Write an iCloud photo frontend that uploads only encrypted images to iCloud and decrypts on your phone only?