An Analysis of WeChat’s Realtime Image Filtering in Chats
citizenlab.ca
citizenlab.ca
[1] https://torrentfreak.com/eu-members-approve-upload-filters-f...
[2] https://www.bloomberg.com/opinion/articles/2019-01-25/how-to...
Eh, that's too limited a definition of copyright. Technical implementation doesn't really matter to the law; only whether or not you are in fact transmitting copyrighted information. That is decidedly the case: the author is knowingly sending a certain piece of content, which the receiver can then access.
Here's a great article on it: https://ansuz.sooke.bc.ca/entry/23
The Copyright Directive is targeted at large "online content-sharing services" - in effect, services like YouTube, not messaging apps - and says that they are liable for what they host. This means that (1) they need to seek a license for any copyrighted content and (2) if they can't do that, find out a way to stop the copyrighted content from appearing.
Plus, member states are now in a two year period to get all this stuff into national law. So nothing is required right now, and chat apps are firmly and completely off limits for this legislation.
(Or whatever color RMB is associated with)
When action is taken on the first image, the collided image could also be censored.
That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or banning both.
Yeah they did this - except the contraband was automatically recognised and both images were banned via hash.
CityLab researchers exploited MD5's weakness to answer questions about the system. While not a real problem in practice, it seems clear MD5 was not an ideal choice.
From the article, the researchers generated forbidden and allowed images with a colliding hash to prove WeChat was using MD5. The allowed image was banned in the future as a result.
However, MD5 collision generation has some constraints. It's very hard make an image collide with a particular known hash, but it's feasible (5 hours with a large GPU) to take two images and modify them until their hashes collide. Practically this means exploitation opportunities are rather limited, but a forced collision being possible at all seems non-ideal for an adversarial use case. There's also the risk that future cryptanalysis will further weaken MD5. Seems clear to me WeChat just should have used something like sha256.
With a billion people using phones, "good enough" is probably good enough.
Given the scale and scope of the Chinese security apparatus, anyone capable of using a GPU to hash out collisions is probably already known to the state. And the handful of collisions are probably not important enough to worry about -- a stealthy Winnie The Poo image isn't a big deal.
BLAKE2b would have been the perfect choice given the adversarial nature, as it much secure and faster than MD5. [2]
MD5 is so broken, it's really poor choice for any use case - cryptographic (fundamentally broken) or not (fundamentally slow).
[1] http://ticki.github.io/blog/seahash-explained/
[2] https://leastauthority.com/blog/BLAKE2-harder-better-faster-...
So from description, it seems that they have a 2 layer system, one synchronous one and an asynchronous one. The sync one filters images based on purely the md5 hashes, so basically a lookup-table check. Then the image goes to the async OCR service to have the text extracted, if being decided against the censorship, it will be write back to the front layer hash table.
Indeed, this is not very different from Facebook's auto face recognition/tagging features that has been enabled like forever. Just the volume of the system is pretty significant.
Also Adverisal Patch is a thing, so that could be applied to specifically distorted the system in a human invisible way to misguide the machine learning models.
Whether it will be retroactively deleted, it think there is a possibility. If WeChat periodically scan your image and find your image violating the censorship, it will probably delete it and report to the authority.
Again, some encryption needs to apply in this case. Just like in the old days.
Those found out to be using means to bypass image censoring will eventually see their 'social credit score' plummet and be kicked off WeChat and/or the 'net.
> Moreover, we found that new accounts required approval from a second account that must have existed for over six months, be in good standing, and have not already approved any other accounts in the past month. Because of these requirements, we found that creating new WeChat accounts was prohibitively difficult.
I've noticed WeChat tightening up their accounts as well over the past months. I have been "lucky" to have created an account years ago, with a wallet still working as well (as a non-Chinese, that is) without having to link a Chinese bank account/card. Friends of mine who visited recently were no longer able to do so for their account.
It's like a black hole eating your messages without telling you.
I recently learned that Signal[0] works in China, are they forced to do the same?
Furthermore, just because it works in China doesn't mean that it won't cause your encrypted traffic to get flagged. This is why the threat model for a sophisticated network adversary, like the Chinese government, is difficult to model against.
I realize this is a little off topic, but since I work on something which has a big China presence, I'm always running into their BS, and censorship is just one little piece of it. VPN connectivity to your non-China offices is also problematic, running TLS over the Chinese internet is also problematic, unless you use officially provided certs and keys, etc.
[1] https://www.google.com/maps/place/Beijing,+China/@39.7616007... [2] https://map.baidu.com/@12957558.390456071,4804287.368277797,...
Regardless, it's difficult to work with. If you have a mapping license, you must also take serious precautions never to let the accurate map data leave China, or your Chinese employees are in deep trouble.
Obviously there's not a snowball's chance in hell that Open Whisper Systems would ever even consider complying with any demand from the PRC.
I just don't think PRC authorities really care about Signal. It's not popular, not available in the app stores available to the Chinese masses, and anyone using it is probably just going to tunnel out anyway. They tend to ban things that are competitive, and Signal just isn't. It's a niche app.
So, just add a random off-color pixel in your image and the system will fail.