See also here: https://gist.github.com/unrealwill/c480371c3a4bf3abb29856c29...
All you need to do to cause trouble right now, would be to get a bad image, hash it yourself, make a collision and distribute that.
Let's say for the time being that the list hashes themselves will be server-side. You won't ever get that list, but you don't need it in order to cause a collision. You would need your own supply of CSAM to hash yourself, which while distasteful is clearly also not impossible.
Does that mean that Apple employs people who manually review images known to be child pornography 9-to-5? Is it legal?
Yes, although I'm sure a sufficiently motivated attacker can obtain some CSAM that they are reasonably sure is present in the database, and generate the NeuralHash themselves.
> At that point, you are reduced to the threat present in every other existing CSAM detection system.
A difference could be that server-side CSAM detection will verify the entire image, and not just the image derivative, before notifying the authorities.
Remind us what the attack is here? The neural hash and the visual derivative both have to match for an image to trigger detection.
* The photo itself is benign.
* The photo’s NeuralHash matches known CSAM.
* The photo’s image derivative is not benign. It looks visually like CSAM.
* The photo’s image derivative matches known CSAM per a private perceptual hash.
The above, combined, could have a victim reported to NCMEC without being aware they were targeted. Since Apple operates on image derivatives, they could be fooled unlike other cloud providers. That is the claim.
At that point, the victim could point law enforcement to the original CloudKit asset (safety vouchers include a reference to the associate asset) and clear their name. However, involving law enforcement can always be traumatic.
Afaik the image derivative isn’t checked for looking like CSAM. It’s checked for looking like the specific CSAM from the database.
If someone wanted to plant CSAM and had control of an iCloud account, it seems far easier to send some emails with those images since iCloud Mail is actively scanned and nobody checks their iCloud Mail account, especially not the sent folder.
The question is whether the visual derivatives are checked against derivatives from the database or just against abstract criteria. That seems to be an unknown.
> However, it’s not clear to me that you can pull off all three simultaneously
Agreed. People here seem to keep assuming that you can, but so far nobody has demonstrated that it is possible.
That someone will be law enforcement, and they will get a warrant for all of your electronic devices in order to determine if you actually have CSAM or not. It's literally their job to investigate whether crimes were committed or not. Those investigations alone can ruin lives, even more so if arrests are made based on the tips or suspicions.