Here is the relevant paragraph from Apple’s documentation:
“as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possibility that the match threshold was exceeded due to non-CSAM images that were adversarially perturbed to cause false NeuralHash matches against the on-device encrypted CSAM database. If the CSAM finding is confirmed by this independent hash, the visual derivatives are provided to Apple human reviewers for final confirmation.”
https://www.apple.com/child-safety/pdf/Security_Threat_Model...
Does this mean, that they have another perceptual hashing algorithm, and this is happening purely on the server side?
Because that could be quite genius. It would be really hard to adversarially fool two different algorithms.
The arguments have been stated before, the principal one being that scanning the users device goes against the wish of users and what Apple until now has stood for.
I think Apple fails to see the seriousness of this.
But i don't consider it E2EE if you are scanning content on the device first.
Apple has a billboard right outside my office. Up until last week it said "privacy" in big letters. Now there's no mention of privacy at all.
The comment chain I was responding to is about the claim that neuralhash is broken so the system is dangerous.
This claim has been repeated multiple times in this forum. Indeed it is one of the loudest two arguments against the system and is simply false.
The sum of elements which are false is still false now matter how many you have.
It’s certainly not universally true that scanning the device goes against the wish of the users. There are many users who are quite happy to have their devices scanned if it is part of making life harder for child abusers. I have spoken to such people.
Therein lies the problem. This system really doesn’t do anything harmful, and it really does just make the tool less useful for collecting child pornography.
There is no simple argument against it, hence all of the misrepresentations about its purported technical problems.
I strongly dislike the feature, and would rather they don’t do it.
My arguments are that I don’t want to be, even in principle, suspected of something I haven’t done. And that trust should be mutual. If Apple wants me to trust them, I want them to trust me.
I don’t see how we help make the world better by using false narratives about technical issues to get what we want.
1. There is a possibility, however tiny, that an innocent image will still match both hashes. The probability is not zero. It can't be. They're hashes.
2. By telling people that there is no chance of an innocent image matching both hashes you are forcing the burden of proof on to the victim. If someone is unfortunate enough to have an image that matches both hashes they will be dragged into a law enforcement office and told to explain "why the foolproof, perfect, impossible-to-cheat system said there was child porn on their phone". It will be on them to explain why the system isn't correct. The presumption of innocence is lost when too much faith is placed on technology.
That is why this is dangerous. Arguably it's a well-designed system that safeguards children and catches despicable criminals, but unless people understand it isn't infallible, and stop arguing that it is, then it could cost an innocent person their freedom. That's a high price to pay.
"Unlikely possibility" shows either blatant facetiousness or blatant ignorance. Who couldn't predict the explosion of collision-generating projects?
Yeah it's not like there are a lot of people on the darknet that do illegal things all the time. /s
You only need one of them to compute the neural hashes of the images and then upload them. For others, it is not illegal to have or distribute the neural hashes.
How many of them are developers with enough knowledge compared to all developers in world with enough knowledge? And willing to touch CSAM material?
I think there is a quite difference. And they have better things to do than pranking some people. Because you are not getting jailed from hash collisions in the country with working judicial system. You have bigger problems if judicial system is not working.
As other comments note, that's not a huge increase in difficulty for an adversary willing to deal in actual CSAM.
Isn’t this exactly like that? Or am I missunderstanding something.
https://twitter.com/ghidraninja/status/1428269674912002048?s...
Quoting the tweet for those who dislike twitter:
> The procedure for this was pretty simple:
> - Started with a placeholder image
> - Got the hash of it
> - Changed text of the image to match the hash
> - Then used
> @anishathalye great neural-hash-collider which took only 1-2 iterations
N.B. it starts with 'started with an image, and the hash of it'
[0]: https://twitter.com/ghidraninja/status/1428270675010199554