6 ms·
>The app reportedly scans for the MD5 digital signatures of media files in the phone, and matches them to a stored database of offending files classified by the
by zython 9y ago
>The app reportedly scans for the MD5 digital signatures of media files in the phone, and matches them to a stored database of offending files classified by the government as illegal "terrorist-related" media.
What a dumb way to scan for "illegal" content, considering the goverment already controls their portion of the internet. So instead of monitoring who is accessing what they decide to compare checksums of files which can be trivially changed which would result in a completely new hash value.
Seems like a very incompetent way of doing this.
- caseysoftware 9y agoYes, it does. But it could just be v1.. or it could be the govt describing a flawed approach so the resulting countermeasures are totally ineffective against the actual approach. For example, if the actual approach is extracting keyframes and comparing against a library of keyframes of existing content (legal and illegal) or doing object recognition within those frames, the "add a null byte!" countermeasures are meaningless.
- Hasknewbie 9y agoIn my opinion, in typical Beijing fashion the "competence" part of the equation is irrelevant. it's all about sending a message, loud and clear: "today we discriminate against YOU, by law, and there's nothing you can do about it". That the method used is laughably inefficient is not the point, it's all about keeping that boot in place on that throat, in a very visible manner.
- saimiam 9y agoCouldn't agree more. Same with airline security theater, identifying citizens using biometric markers (Aadhar card in India), pernicious internet monitoring in the UK...the list goes on. I guess the idea is to use the dragnet to catch or deter a majority of the population from thought crimes and preserve resources for the real big fish.
- jansho 9y agoNow now, let's not give any ideas shall we.
- toast0 9y agoThis is very competent. It identifies some people trafficking in prohibited files, and it also identifies the true danger to the state -- people willing to circumvent their rules; when you pick up someone for bad files, and he (or his phone) says his buddy sent them, but his buddy's friend didn't report in, his buddy is eligible for a lot more trouble.
- excalibur 9y ago> MD5 > This is very competent.
- kronos29296 9y agoReal men use CRC.
- CyberDildonics 9y agoNot to mention that it should be entirely possible to find offending files and create files that have MD5 collisions with them, causing false positives.
- blincoln 9y agoThere is no publicly-known "preimage" attack against MD5. One would need to craft an offensive file and a non-offensive file themselves so that the hashes would match, then somehow get the offensive file into the official database.
- blincoln 9y agoThis is actually what digital forensics specialists do as well, although they've probably moved on from MD5 by now. I know there's been talk of "fuzzy hashes" as well, in order to catch files with trivial modifications, but when I studied forensics (about four years ago), that was still in the future. Searching hundreds of thousands or millions of files by hand would be impractical and for many types of offensive content, the authorities don't want to have to distribute the actual offensive content to the people who are doing the detection. i.e. in the US, possession of child pornography is such a serious federal crime that if one happens to discover it on a PC they are servicing, they (or their employer) are legally obligated to contact the FBI immediately. Therefore, it doesn't make sense to distribute a detection tool that basically contains the original images (in order to do GIS-style "find similar images" searches), because that tool would violate the law it was designed to help enforce. Short hashes can't be used to recreate the original images, so they're "safe" in that sense. It's not an ideal approach, but it works pretty well and fits within common constraints of the field.
- jsjohnst 9y agoThere's a Microsoft product called PhotoDNA that does a fairly decent job of finding near matches. It's specifically used by several major image hosting places (Facebook and Tumblr I can specifically attest to using it, at least in the past) to find CP content uploaded by users. The hashes are shared among the services using PhotoDNA via NCMEC.
- intopieces 9y ago>which can be trivially changed Experiment: tomorrow, ask 5 people you know who are not software engineers how to change the MD5 checksum on a file that resides on their mobile device. Report the results here.