Hacker News new | ask | show | jobs
by zionic 1780 days ago
How long until a hacker uses ML to generate collisions against those hashes?
2 comments

There is a minimum number of hash matches required, then images are made available to Apple who then manually checks that they are CSAM material and not just collisions. That's what the 9to5Mac story about this says: https://9to5mac.com/2021/08/05/apple-announces-new-protectio...
For what purpose? A collision doesn't mean that you found the source images. Not even close.
With a broader rollout to all accounts and simply scanning in iMessage rather than photos there's one possible scenario if you could generate images which were plausibly real photos: spam them to someone before an election, let friendly law enforcement talk about the investigation, and let them discover how hard it is to prove that you didn't delete the original image which was used to generate the fingerprint. Variations abound: target that teacher who gave you a bad grade, etc. The idea would be credibility laundering: “Apple flagged their phone” sounds more like there's something there than, say, a leak to the tabloids or a police investigation run by a political rival.

This is technically possible now but requires you to actually have access to seriously illegal material. A feasible collision process would make it a lot easier for someone to avoid having something which could directly result in a jail sentence.

So you can upload the colliding images to iCloud and get yourself reported for having child porn. Then after the law comes down on you, you can prove that you didn't ever have child porn. And you can sue Apple for libel, falsely reporting a crime, whatever else they did. It would be a clever bit of tech activism.
Find collisions, spam the colliding photos to people you don't like, watch the mayhem unfold.