Back to the episode map

Evergreen

How NCII Hash Matching Works and Where It Fails

See how on-device NCII hashing lets participating platforms look for known images without receiving the original through submission, plus the limits from edits and encryp

Aug 4, 20265 min readBy Dalton Anderson

How NCII Hash Matching Works and Where It Fails

NCII hash services create a digital fingerprint from an intimate image or video on the user's device. The original file does not leave the device through that hashing step. Participating platforms receive the fingerprint, look for matching material on supported surfaces, and apply their policies.

The privacy benefit is meaningful. The limitation is equally important: a hash cannot scan every service, reach encrypted content, recognize every edit, find an unknown file that was never submitted, or guarantee deletion from the internet.

The file stays on the device during submission

NCMEC Take It Down and StopNCII are designed so the hashing computation occurs locally. The service receives the fingerprint, not the image or video itself, through that step.

A fingerprint is a derived value used for comparison. Participating platforms can compare it with fingerprints produced from content they can inspect. When the system finds a match, the platform reviews or acts according to the service arrangement and its policy.

flowchart LR
    A["Eligible file already on the user's device"] --> B["Fingerprint generated on the device"]
    B --> C["Hash submitted to the service"]
    C --> D["Hash shared with participating platforms"]
    D --> E["Supported platform surface is scanned"]
    E --> F{"Match and policy decision"}
    F -->|Match| G["Platform action under its policy"]
    F -->|No match| H["No action from this fingerprint"]

The workflow reduces the need to upload the original file to a central hash-service submission system. It does not mean that every other part of the platform or support process has the same privacy design. Read the current privacy terms before using a service.

Age determines the appropriate service

NCMEC's Take It Down FAQ says the service applies when the depicted person was under 18 when the image or video was taken. A person who is now an adult can still use it for material created while they were a minor.

The file must already be on the device. NCMEC explicitly says not to download the material or ask another person to send it merely to use Take It Down.

StopNCII's eligibility rules currently require that the user be the depicted person, be an adult now, have been 18 or older in the image, and have access to the file. The service can also accept qualifying synthetic or deepfake material when the person depicted has access to it.

SituationCurrent service path
Depicted person was under 18 when the material was createdNCMEC Take It Down
Depicted person was 18 or older and is currently an adultCheck StopNCII eligibility
File is not already on the deviceDo not download or request a copy merely to use a hash tool
Immediate danger, threats, or material involving a minorUse qualified current safety and specialist guidance

Not every hash behaves the same way

The word hash can refer to different technical approaches.

A cryptographic hash changes when the underlying file changes. It is useful for identifying the same bytes but generally cannot recognize a visually similar re-encoding.

A perceptual matching system tries to produce comparable fingerprints for visually similar content. Its behavior depends on the algorithm, implementation, threshold, media type, and transformation.

StopNCII currently says it uses PDQ or PhotoDNA for photos and MD5 for videos. The same FAQ warns that cropping, filters, or clipping a video can keep the original fingerprint from recognizing the edited asset.

The safest public explanation is therefore operational: the service can help partners recognize supported matches, but edited versions may need separate handling. Do not promise a level of transformation tolerance that the service itself does not promise.

Participation sets the boundary

NCMEC says participating platforms may scan public or unencrypted services. Its tool does not work on encrypted platforms or surfaces.

StopNCII says it works only with participating platforms and cannot remove content from the whole internet. Partner action also depends on platform policy.

A service's participant list can change. Check it before assuming that a particular social network, messaging service, host, or forum is covered.

A match is not universal deletion

Hash matching has at least six practical boundaries.

BoundaryWhy it matters
Unknown assetA platform cannot match a fingerprint it has never received
Edited versionCrops, filters, overlays, clips, or re-encodes may change the match
Unsupported surfaceThe partner may not scan every product feature or historical store
EncryptionA service cannot compare content it cannot inspect
Nonparticipating platformThe hash list has no direct reach there
Offline or private copyRemoving a platform copy does not erase material held elsewhere

False or disputed matches also need a governed review and correction path. A platform should know which tool produced the signal, what threshold was applied, what content surface was scanned, and who made the final decision.

Hashing and the TAKE IT DOWN Act are related but different

The TAKE IT DOWN Act requires covered platforms to remove an identified depiction after a valid request and make reasonable efforts to identify and remove known identical copies within the statutory period.

The FTC recommends considering hashing to reduce reappearance and suggests sharing appropriate hashes with NCMEC Take It Down or StopNCII.

That recommendation does not turn one hash service into the sole legally required method. A platform remains responsible for its actual notice, intake, timing, removal, copy-search, privacy, and evidence process.

For a person seeking removal, hashing can complement a direct platform request. It does not replace the request when the content is already visible on a covered service. [[How to Request Removal of Nonconsensual Intimate Imagery]] connects the two paths.

This page is a technical overview, not individualized safety, privacy, legal, or evidence advice. Service eligibility, participants, algorithms, privacy terms, and platform policies can change. It was reviewed against current NCMEC and StopNCII documentation on July 28, 2026.

This article was developed with AI assistance and reviewed against the official service documentation linked above. Dalton Anderson is responsible for the final editorial judgment.

Sources

Follow the evidence.

  1. consumer.ftc.gov: what will ftcs enforcement take it down act mean youconsumer.ftc.gov
  2. takeitdown.ftc.govtakeitdown.ftc.gov
  3. stopncii.org: faqstopncii.org
  4. daltonanderson.ghost.io: fighting deepfakes how the take it down act protects youdaltonanderson.ghost.io
  5. justice.gov: sharing intimate images without consent know your rightsjustice.gov
  6. ftc.gov: tools address known exploitation immobilizing technological deepfakes websites networks act take itftc.gov
  7. open.spotify.com: 4kThXy2NeCAUtGzH1MbsmMopen.spotify.com
  8. congress.gov: PLAW 119publ12congress.gov
  9. daltonanderson.net: fighting deepfakes how the take it down act protects youdaltonanderson.net
  10. youtu.be: JMf253z5VEYyoutu.be
  11. takeitdown.ncmec.orgtakeitdown.ncmec.org
  12. ftc.gov: complying take it down actftc.gov
  13. takeitdown.ncmec.org: faqtakeitdown.ncmec.org
  14. stopncii.org: how it worksstopncii.org
  15. stopncii.orgstopncii.org
How NCII Hash Matching Works and Where It Fails