The Lemmy Club
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
refolde [she/her, any]@hexbear.net to the_dunk_tank@hexbear.netEnglish · 1 year ago

Yo automated KKKommunity note$$!?

hexbear.net

message-square
52
link
fedilink
153

Yo automated KKKommunity note$$!?

hexbear.net

refolde [she/her, any]@hexbear.net to the_dunk_tank@hexbear.netEnglish · 1 year ago
message-square
52
link
fedilink

https://x.com/babadookspinoza/status/1802442068125516148

  • Tabitha ☢️[she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    49
    ·
    1 year ago

    I wonder if you could engineer an unrelated image to have the same md5 or perceptual hash and get it to auto-debunk.

    • TrudeauCastroson [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      22
      ·
      1 year ago

      If you have access to a quantum computer you could do this easily. With current computing it’s hard.

      • git [he/him, comrade/them]@hexbear.net
        link
        fedilink
        English
        arrow-up
        19
        ·
        1 year ago

        This was a form of attack against Apple’s on-device CSAM detection that they scrapped, so it’s been possible for a while.

        • Neural hash collider: https://github.com/anishathalye/neural-hash-collider
        • Example collision: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issues/1
        • Script to generate collisions: https://gist.github.com/unrealwill/c480371c3a4bf3abb29856c29197c0be
        • Tainting the client side CSAM database: https://blog.xot.nl/2023/10/11/tainting-the-csam-client-side-scanning-database/index.html
        • TrudeauCastroson [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          6
          ·
          edit-2
          1 year ago

          Edit: wow I didn’t realize md5 matching a picture was that easy, looks like you can make any image look enough like that twitter-deboonked one to generate a fake match. How has no one done this yet.

          Thanks for the links, it’s pretty interesting stuff I haven’t kept up with for a while.

          I didn’t hear about that potential apple attack, I wonder if you could generate a collision with a pic that looks close enough to the twitter image they auto-deboonk and a pic that’s completely unrelated, got twitter to add your new similar image to the auto-deboonker, and then troll on twitter by posting the unrelated image.

          That’d be similar to that apple attack you linked, but it depends on how twitter auto-deboonking works and how easy you could get them to add a similar-but-different pic to their deboonker database.

      • bloubz@lemmygrad.ml
        link
        fedilink
        English
        arrow-up
        13
        ·
        1 year ago

        md5 They said md5

        • emizeko [they/them]@hexbear.net
          link
          fedilink
          English
          arrow-up
          10
          ·
          1 year ago

          mega deeznuts five

        • Chronicon@hexbear.net
          link
          fedilink
          English
          arrow-up
          7
          ·
          edit-2
          6 months ago

          deleted by creator

          • bloubz@lemmygrad.ml
            link
            fedilink
            English
            arrow-up
            6
            ·
            1 year ago

            You’re right

        • TrudeauCastroson [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 year ago

          I thought md5 is vulnerable to generating 2 colliding files, not to trying to generate a match to an existing file.

          • bloubz@lemmygrad.ml
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 year ago

            It’s definitely the easiest. But that’s why we stopped using it, because it’s proven we can have collision so it may be possible to generate a match on a real life file. I’m not sure about where we’re at on this in research (if there’s any)

            Also I was actually not trying to make a point, just pointing on md5 as a joke

            • TrudeauCastroson [he/him]@hexbear.net
              link
              fedilink
              English
              arrow-up
              3
              ·
              1 year ago

              If you’re using any hash smaller than your file (not just md5), then it’s always possible to have 2 different files that match. This is just from pigeonhole principle. No matter what you use there will be collision.

              md5 is just bad because it’s small so it’s easier to generate this match. It’s also a question of how easy is it to reverse engineer a match, which apparently md5 is worse for on pictures than I expected.

the_dunk_tank@hexbear.net

the_dunk_tank@hexbear.net

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]
lock
Community locked: only moderators can create posts. You can still comment on posts.

It’s the dunk tank.

This is where you come to post big-brained hot takes by chuds, libs, or even fellow leftists, and tear them to itty-bitty pieces with precision dunkstrikes.

Rule 1: All posts must include links to the subject matter, and no identifying information should be redacted.

Rule 2: If your source is a reactionary website, please use archive.is instead of linking directly.

Rule 3: No sectarianism.

Rule 4: TERF/SWERFs Not Welcome

Rule 5: No ableism of any kind (that includes stuff like libt*rd)

Rule 6: Do not post fellow hexbears.

Rule 7: Do not individually target other instances’ admins or moderators.

Rule 8: The subject of a post cannot be low hanging fruit, that is comments/posts made by a private person that have low amount of upvotes/likes/views. Comments/Posts made on other instances that are accessible from hexbear are an exception to this. Posts that do not meet this requirement can be posted to [email protected]

Rule 9: if you post ironic rage bait im going to make a personal visit to your house to make sure you never make this mistake again

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 9 users / week
  • 26 users / month
  • 122 users / 6 months
  • 6 local subscribers
  • 16K subscribers
  • 5.12K Posts
  • 134K Comments
  • Modlog
  • mods:
  • KiaKaha [he/him]@hexbear.net
  • MiraculousMM [he/him, undecided]@hexbear.net
  • corgiwithalaptop [any, love/loves]@hexbear.net
  • VILenin [he/him]@hexbear.net
  • replaceable [he/him]@hexbear.net
  • EmmaGoldman [she/her, comrade/them]@hexbear.net
  • CARCOSA [mirror/your pronouns]@hexbear.net
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org