3 ms·
Hash matching proposals for the Online Safety Act's implementation are dangerous
- olestr 3y agoThe example they provide for false positives is haunting
- jjgreen 3y agoNot just false positives. You won't get the original images with the hashes of course, so no problem for a hostile state to slip in a few hashes of other things it doesn't like: document on off-colour politics, criticism of the prime-minister, ...
- demondemidi 3y agoThere’s no such thing as “similar enough” with a hash. One bit change in the source imagine creates as large a Hamming distance as possible in the hash bits - that’s literally the point. Unless I’m missing something that seems ludicrous to consider a hash as close enough to be a reason for probably cause.
- jjgreen 3y agoFuzzy hashing is a thing ...
- halJordan 3y agoWait until they find out about fuzzy logic
- gpderetta 3y agoLocality Sensitive Hashing and other sim-hash setups.
- mjhay 3y agoThen you'd run into a lot more false positives, which ought to make LSH a non-starter for this application.
- sigilis 3y agoIn this case, a false positive might be a good thing from their perspective. If they can show that you have a close match it means they have an excuse to investigate you more thoroughly should they desire even if the real reason is that they suspect you of something else.
- demondemidi 3y agoThat's fascinating. Thanks. I've only encountered cryptographic hashes, or hashes for data structures that are limited by address size.
- hiAndrewQuinn 3y agoThis reminds me that I should really publish that blog post about using hashes to send documents "into the future" (really just to prove you wrote them at an earlier date) at some point. >Hash matching, or hash scanning, compares certain pieces of content such as videos, pictures or text, to a database of illegal content. It is done by turning the content into “hashes”, a sample of the content a bit like a fingerprint. The hashes of content stored or shared by a specific user are then compared to the hashes of known illegal content in a database and result in a match if the software deems that the hashes are identical or similar enough. Because one of the things I realized while writing it is that there's an interesting contrapositive to keeping your own public list of hashes online somewhere: 1. By putting a hash on your public hash list, you are making a claim that you have access to a particular document at a particular time. 2. If someone else posts a hash on your hash list, say to a well-known document like the HTML source of example.com, they have in effect proven that you are not the sole person who can edit that hash list, and 3. Therefore your claim to access of anything on that hash list is repudiable and hence the entire list must be thrown out. So... Maybe there's a similar counterjamming method available here? E.g. stuff the hash of "Hello world" into one of these illegal databases, then show it's there, to call into question the idea that everything on these databases is illegal and thereby get them thrown out of court. (P.S., I'm almost positive you can use keypair encryption to get around this, but I haven't taken a bus ride long enough to puzzle out the details of how yet.)
- lstodd 3y agoLooks like you're not familiar with how these sorts of government databases are usually run. It is as follows: 1. nothing ever gets deleted for any reasonable reason. 2. bribes and connections will suffice to delete or include anything 3. even so, it's a slow-as-molasses mess that just gets in everyone's way 4. but still it can't be uprooted because budgets won't spend themselves IDK what UK wants with this shit. As the examples of China and lately Russia show, this just does not work against the savvy, and the rest are adequately blinded with conventional propaganda already, so what's the point?
- hiAndrewQuinn 3y ago