So from description, it seems that they have a 2 layer system, one synchronous one and an asynchronous one. The sync one filters images based on purely the md5 hashes, so basically a lookup-table check. Then the image goes to the async OCR service to have the text extracted, if being decided against the censorship, it will be write back to the front layer hash table.
Indeed, this is not very different from Facebook's auto face recognition/tagging features that has been enabled like forever. Just the volume of the system is pretty significant.
Also Adverisal Patch is a thing, so that could be applied to specifically distorted the system in a human invisible way to misguide the machine learning models.
Whether it will be retroactively deleted, it think there is a possibility. If WeChat periodically scan your image and find your image violating the censorship, it will probably delete it and report to the authority.
Again, some encryption needs to apply in this case. Just like in the old days.
Those found out to be using means to bypass image censoring will eventually see their 'social credit score' plummet and be kicked off WeChat and/or the 'net.
(Or whatever color RMB is associated with)
CityLab researchers exploited MD5's weakness to answer questions about the system. While not a real problem in practice, it seems clear MD5 was not an ideal choice.
From the article, the researchers generated forbidden and allowed images with a colliding hash to prove WeChat was using MD5. The allowed image was banned in the future as a result.
However, MD5 collision generation has some constraints. It's very hard make an image collide with a particular known hash, but it's feasible (5 hours with a large GPU) to take two images and modify them until their hashes collide. Practically this means exploitation opportunities are rather limited, but a forced collision being possible at all seems non-ideal for an adversarial use case. There's also the risk that future cryptanalysis will further weaken MD5. Seems clear to me WeChat just should have used something like sha256.
BLAKE2b would have been the perfect choice given the adversarial nature, as it much secure and faster than MD5. [2]
MD5 is so broken, it's really poor choice for any use case - cryptographic (fundamentally broken) or not (fundamentally slow).
[1] http://ticki.github.io/blog/seahash-explained/
[2] https://leastauthority.com/blog/BLAKE2-harder-better-faster-...
With a billion people using phones, "good enough" is probably good enough.
Given the scale and scope of the Chinese security apparatus, anyone capable of using a GPU to hash out collisions is probably already known to the state. And the handful of collisions are probably not important enough to worry about -- a stealthy Winnie The Poo image isn't a big deal.
When action is taken on the first image, the collided image could also be censored.
That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or banning both.
Yeah they did this - except the contraband was automatically recognised and both images were banned via hash.