Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

541–550 of 725 posts

Re: Hash collision in Apple NeuralHash model

#541

Yes, just like rape accusations. It doesn't matter that you prove it was false afterwards. Edit : well that was a hint to Assange of course. Probably not true in general. So yes, I mean false accusations.

We detached this subthread from https://news.ycombinator.com/item?id=28219243.

Re: Hash collision in Apple NeuralHash model

#542
post #18

How can you use it for targeted attacks? This is what would need to happen: 1. Attacker generates images that collide with known CSAM material in the database (the NeuralHashes of which, unless I'm mistaken, are not available) 2. Attacker sends that to innocent person 3. Innocent person accepts and stores the picture 4. Actually, need to run step 1-3 at least 30 times 5. Innocent person has iCloud syncing enabled 6.…

We detached this subthread from https://news.ycombinator.com/item?id=28219296 (it had become massive and this one can stand on its own).

Re: Hash collision in Apple NeuralHash model

#543
post #489

Earlier quoted context omitted.

No, you couldn't. This is only checking images you upload to your iCloud photo library. Why would you save tons of gray blobs to your photo library? Why would gray blobs look like child porn? Why would Apple reviewers think gray blobs are child porn? Why would the NCMEC think gray blobs are child porn? Why would law enforcement spend time arresting someone for gray blobs?

The grey blob is a proof of concept. The existence of the original image is proof that not all images which produce the target hash are grey blobs. Since the grey blob exists, I believe it is fully possible to construct natural(-ish) images that have a selected hash. So, you should perhaps instead imagine attackers that modify lawful nude images to have matching hashes with child porn images. With that in mind, most…

The other thread demonstrates a similar attack with pictures of dogs.

The same questions still apply. Why would you save tons of pictures of dogs to your photo library? Why would pictures of dogs look like child porn? Why would Apple reviewers think pictures of dogs are child porn? Why would the NCMEC think pictures of dogs are child porn? Why would law enforcement spend time arresting someone for pictures of dogs?

What is the scenario where someone can be harmed reputationally or criminally because of a hash collision attack, where the same attack could not be performed more easily and causing more damage by actually using real CSAM images?

Re: Hash collision in Apple NeuralHash model

#544

Why is this meaningfully different than, say, what Google Photos has been doing for years? If you can get rooting malware on the target device then you could 1. Produce actual CSAM rather than a hash collision 2. Produce lots of it 3. Sync it with Google Photos This attack has been available for many years and does not need convoluted steps like hash collisions if you have the means to control somebody's phone with a…

(We detached this subthread from https://news.ycombinator.com/item?id=28219296.)

Re: Hash collision in Apple NeuralHash model

#545
post #456
post #372

Some people here in comments believe that whoever gonna check reported material on Apple side will never ever flag false-positive. We already know that NCMEC database itself don't exclusively contain child porn, but also some other photos that closely related ot CSAM. Even if those photos don't have actual CSAM on them. But let's ignore this fact. Do people who believe in behevolent Apple understand that CSAM don't a…

I guarantee you out of millions of alleged CSAM images hapzardly added by local police and intetnet reports, thousands are legal porn of consenting adults.

I totally sure it's very much possible, but even if this database only exclusively contained CSAM it's still very much possible for human to match false-positive since Apple can only show their snoops your photos and likely they will be compressed to some 360x360 or whatever.

Re: Hash collision in Apple NeuralHash model

#546
post #149

Earlier quoted context omitted.

1. By the public at large it should not be treated in any regard, false or not. 2. The state is the only authorized monopoly of violence and they should treat unproven and untrue as identical, and the only place where that decision is made is in a courtroom. 3. The 'believe the victims' activists however are rightfully (IMHO) suggesting to break principle #2 because there is institutional and systemic supression of t…

Sorry, don't see how 3 in your "syllogism" is remotely true. If 10 employees of yours come to you and accuse another employee of sexual harassment and you fire that employee, at no point were you acting as the state or using violence.

Nor was justice being served at any point. Depending on the terms of the employment contract, firing anyone is just business as usual.

The problematic part is that sexual harassment is a crime though. Both the act and accusation warrant court. Not to fire someone from their job, but to prosecute them under criminal law.

Re: Hash collision in Apple NeuralHash model

#547
post #477

Earlier quoted context omitted.

>If someone sends CSAM using Federal Express, is FedEx legally liable for "possessing and distributing" that material? Yes: https://www.dea.gov/press-releases/2014/07/18/fedex-indicted... That was for drugs but conceptually the same for CSAM.

This is not at all conceptually the same. FedEx was not held liable simply because their service was used to mail illegal drugs. They were held liable because not only did they know about the specific instances in which it was mailed, they allegedly conspired with the shippers to facilitate the mailings. They were knowingly mailing packages to parking lots where drug dealers would wait to pick them up: > According to…

>They were held liable because not only did they know about the specific instances in which it was mailed, they allegedly conspired with the shippers to facilitate the mailings.

Apple knows that CSAM is being sent and conspires to do so (i.e. transmits the image). Conceptually they are the same.

The rest of your post details the practical differences between sending physical packages and digital images.

Re: Hash collision in Apple NeuralHash model

#548

Earlier quoted context omitted.

> All criminal accusations, including true ones, should be treated as false until the accused is proven guilty. No, they need to be treated as unproven, a very critical difference. Just to be clear, witness testimony, including testimony FROM THE VICTIM, is evidence of the crime. Just for some reason, in rape cases, we go all wonky with this principle.

This is bonkers. We are innocent until proven guilty, not "unproven". Witness testimony on its own is circumstantial evidence in general. Witnesses are very unreliable.

We are innocent until proven guilty, I never disputed that.

I'm saying the accusation, the witness testimony, is NOT assumed false, the accusation is simply unproven.

If the jury/judge believes the testimony, they may convict on that testimony. Then the accused is proven guilty.

That the accusation started off being false and then magically became true when when the jury believed it is the bonkers belief here.

The fact that witness testimony is unreliable is a big part of WHY the accused is presumed innocent.

Re: Hash collision in Apple NeuralHash model

#549
post #2

I don't understand the comment in the issue by an iPhone user. Can you see the hashes that the mobile generates for each image?? Why that is not "obfuscated" / hidden from the user? I mean, I would expect something complicated to validate that you have a collision.

You're correct. The amount of misinformation in this thread (and in the other responses to you) is out of control.

The database of CSAM hashes is blinded and no one has the hashes. Without the hashes, this attack is useless.

It's also mitigated by a LOT of checks and balances. First they have to know 30 hashes to target (they're secret). They have to get 30 colliding images on your phone. The images have to be unnoticed by you (why not just infiltrate CSAM, then?) or sufficiently compelling that you don't just delete them. Thirty images have to pass human review at Apple. At least one has to pass human review by law enforcement. Then, and only then, will you be arrested and face a threat.

Short version: If somebody wants to frame you for possessing CSAM, there are much easier ways. There is no new threat here. https://xkcd.com/538/

Re: Hash collision in Apple NeuralHash model

#550

Earlier quoted context omitted.

If you need a judicial review to confim that a slightly altered Bernie in Coat and Gloves meme is not the same image as the picture of a child being raped that they have on file then we have way bigger problems.

Here's the thing with CSAM - it's illegal to view and transmit. So nobody, until the police have confiscated your devices, will actually be able to verify that it is a "child being raped." They'll view visual hashes, look at descriptions, and so forth, but nobody from Apple will actually be looking at them, because then they are guilty of viewing and transmitting CSAM. I noted in another comment, even the prosecutors…

Where did you get this idea, scooby doo?

It is not illegal to be an unwilling recipient of illegal material. If a package shows up at your door with a bomb, you're not gonna be thrown in jail for having a bomb.

Post reply on HN