6 ms·
I don't understand the comment in the issue by an iPhone user. Can you see the hashes that the mobile generates for each image?? Why that is not "obfuscated" /
by kuu 5y ago
I don't understand the comment in the issue by an iPhone user. Can you see the hashes that the mobile generates for each image?? Why that is not "obfuscated" / hidden from the user? I mean, I would expect something complicated to validate that you have a collision.
- nulld3v 5y agoThey could have a jailbreak device.
- eptcyka 5y agoThey could just be a dev that work on the code and have toy apps to test it out.
- scandinavian 5y agoIt is hidden for the user. Obfuscation doesn't work. They probably just called the private API to generate a hash on a jailbroken phone. There's even a link to another piece of software that can do just that, only on macOS. https://github.com/KhaosT/nhcalc https://github.com/KhaosT/nhcalc
- cyanite 5y agoThe hash table is blinded on the device, and the device never knows if a given image is a hit or not. This is well documented.
- deleted 5y ago[deleted]
- jhugo 5y agoYou're holding the iPhone in your hand. You can inspect everything it does, the only thing that varies is the level of difficulty of inspecting it. Obfuscation doesn't work.
- jdlshore 5y agoYou're correct. The amount of misinformation in this thread (and in the other responses to you) is out of control. The database of CSAM hashes is blinded and no one has the hashes. Without the hashes, this attack is useless. It's also mitigated by a LOT of checks and balances. First they have to know 30 hashes to target (they're secret). They have to get 30 colliding images on your phone. The images have to be unnoticed by you (why not just infiltrate CSAM, then?) or sufficiently compelling that you don't just delete them. Thirty images have to pass human review at Apple. At least one has to pass human review by law enforcement. Then, and only then, will you be arrested and face a threat. Short version: If somebody wants to frame you for possessing CSAM, there are much easier ways. There is no new threat here. https://xkcd.com/538/ https://xkcd.com/538/
- cyanite 5y ago> The amount of misinformation in this thread (and in the other responses to you) is out of control. True it’s not perfect here, but you should see Reddit, then :p. People there hardly even know what they are mad about.