4 ms·
I think, since it's a database of hashes, it's non-reversible. Access to the database gives you nothing but a way to detect the files, and even if a file happen
by SolarNet 10y ago
I think, since it's a database of hashes, it's non-reversible. Access to the database gives you nothing but a way to detect the files, and even if a file happens to have the same hash (which would be exceedingly rare) it's easy to see that it's a false positive. Actually a pretty good win for cryptography in fighting the problem (as it doesn't require the illegal material to detect the illegal material - regardless of how irresponsible it is to have a concept of illegal information).
- fareesh 10y agoIf someone were to crop an arbitrary side of the image by 1-2 pixels would that defeat a system like this? Extending that thinking a bit further, would it be trivial to just build out an Apache extension like Google Pagespeed that sort of did this randomly?
- davmre 10y ago"This hash is computed such that it is resistant to alterations in the image, including resizing and minor color alterations." (https://en.wikipedia.org/wiki/PhotoDNA https://en.wikipedia.org/wiki/PhotoDNA)
- fareesh 10y agoThanks!
- gcb0 10y agowhich makes collision with the incrimination intent described above much easier.
- ignoramous 10y agoDeep Neural Nets might solve the problem better than hashes
- devishard 10y agoUgh, this is not how you do crypto. Crypto algorithms have to be understood with regards to what guarantees they provide and in what context. Your approach here is basically ZOMG COLLISIONS ARE BAD when in fact collision-resistance was never a property of this hash function and a collision doesn't provide an attacker with any power they didn't already have. If an attacker has the power to create a non-CP file that has the same hash as a CP file and plant it without detection, they have the power to plant a CP file without detection. Why would they go to the effort to create a collision with a non-CP file? It's wasted effort.
- khc 10y agoSo that they don't need to obtain a copy of the image in the first place? Also a much lesser crime if they get caught.
- DanBC 10y agoBob is found with a file of pseudo random data that matches a hash on the database. There's no evidence of other images of child sexual abuse on his machine; there's no history of sites that distribute images of child sexual abuse; there's no history of the file being opened by Bob; Bob claims that he didn't know the file was there and he doesn't know what it is. How does that benefit an attacker? How does that benefit an attacker more than just taking actual images of child sexual abuse and putting those on Bob's computer?
- mdpopescu 10y agoI don't know the laws in the US; is the police obligated to respond if someone warns them of this event? (Bob has a file matching a "bad hash".) How seriously - will there be a polite guy knocking on the door, or a SWAT team at 3 am? If nothing is found, and another such event occurs next month, will they have to check again? People can come up with crazy scenarios for anything :)
- voxic11 10y ago
- voxic11 10y agoIt not like a md5 hash. The hashing function is designed such that similar images will produce similar hashs. But yes if you modify it enough it will not match, you will have to modify it much more then just cropping though. They usually do very well with that.