4 ms·
“This means that when the features are rolled out, a version of the NCMEC CSAM database will be uploaded onto every single iPhone.” So every iPhone will now ho
by edison112358 5y ago
“This means that when the features are rolled out, a version of the NCMEC CSAM database will be uploaded onto every single iPhone.”
So every iPhone will now host the explicit images from the National Center for Missing & Exploited Children database.
- spiznnx 5y agoThe database contains perceptual hashes, not images.
- pgoggijr 5y agoNo, they will host the hashes computed from those images.
- hartator 5y agoYes, everyone in jail! It’s probably just the md5 or something like that, but I don’t like it either.
- joshstrange 5y ago> So every iPhone will now host the explicit images from the National Center for Missing & Exploited Children database. It's hashes, not the images themselves.
- cblconfederate 5y agoAnd how did the user end up with the hashes? He hashed the original images which he then deleted, your honor! BTW this is going to be a major target for smearing people that the US doens't like
- joshstrange 5y agoI'm sorry but this is the most ridiculous thing I've read today. Hashes have never and probably will never be used "smear" someone the US doesn't like. We can speculate about them planting evidence but trying to prosecute based on hashes baked into the OS used by millions? That's absurd.
- kevincox 5y agoI'm pretty sure this is a non-tech way of saying "a machine learning model" or other parameters which is not a particularly useful form of this database.
- artimaeis 5y ago> No user receives any CSAM photo, not even in encrypted form. Users receive a data structure of blinded fingerprints of photos in the CSAM database. Users cannot recover these fingerprints and therefore cannot use them to identify which photos are in the CSAM database. Source (PDF): https://www.apple.com/child-safety/pdf/Technical_Assessment_of_CSAM_Detection_Benny_Pinkas.pdf https://www.apple.com/child-safety/pdf/Technical_Assessment_...
- zionic 5y agoHow long until a hacker uses ML to generate collisions against those hashes?
- outworlder 5y agoFor what purpose? A collision doesn't mean that you found the source images. Not even close.
- bingidingi 5y agoI guess in theory you could poison the well by widely sharing many false positives?
- ursugardaddy 5y agoImproved swatting, it's going to all make for a badass october surprise next election
- __david__ 5y agoFind collisions, spam the colliding photos to people you don't like, watch the mayhem unfold.
- acdha 5y agoWith a broader rollout to all accounts and simply scanning in iMessage rather than photos there's one possible scenario if you could generate images which were plausibly real photos: spam them to someone before an election, let friendly law enforcement talk about the investigation, and let them discover how hard it is to prove that you didn't delete the original image which was used to generate the fingerprint. Variations abound: target that teacher who gave you a bad grade, etc. The idea would be credibility laundering: “Apple flagged their phone” sounds more like there's something there than, say, a leak to the tabloids or a police investigation run by a political rival. This is technically possible now but requires you to actually have access to seriously illegal material. A feasible collision process would make it a lot easier for someone to avoid having something which could directly result in a jail sentence.
- octopoc 5y ago