273 points imwally 8 hours ago 199 comments
WalterGR 7 hours ago | parent
tristanj 7 hours ago | parent
Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.
To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.
I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
amanj41 7 hours ago | parent
tristanj 7 hours ago | parent
Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.
dd8601fn 6 hours ago | parent
I feel really dumb for not having thought of this.
osy 7 hours ago | parent
> Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago.
Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.
BugsJustFindMe 7 hours ago | parent
It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened".
It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself.
Likewise in "distinguish between photographs that depict real events and...".
spiderice 6 hours ago | parent
BugsJustFindMe 6 hours ago | parent
The problem with this thinking is twofold:
1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.
2) It increases the potential value of a forgery because now your forgery is attested by Apple.
So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
porkshoe 5 hours ago | parent
Therefore because of your worry (which is based on remarkably little information), it's a bad technology?
Come the fuck on. That's beyond luddite bullshit.
otterley 5 hours ago | parent
You must be new around here. ;-)
BugsJustFindMe 4 hours ago | parent
latexr 41 minutes ago | parent
Then maybe let’s save those criticisms until this is in the hands of knowledgeable people who can actually test? I mean, I’m no fan of the direction Apple has gone under Tim Cook, but all else being equal I’m inclined to give them the benefit of the doubt that they may have thought this through over the time it took to build more than a random person speculating on HN who just read a blog post for the first time.
> (…) we see no details here about what scene information is used.
And you assume that everything in a post is the sum total of how it works?
> It increases the potential value of a forgery
By that token, should we also not be adding forgery deterrents to ID cards and bills? After all, if you can fake the preventive measures, “it increases the potential value of a forgery”.
brookst 6 hours ago | parent
BugsJustFindMe 6 hours ago | parent
Used in a capacity as evidence? Uh, yes? Duh? Do you seriously believe otherwise? Anyway, that scenario is made worse not better by Apple promising captured veracity.
bawolff 4 hours ago | parent
After all, if money is no object, you could just bribe every single apple employee involved in the project.
Gigachad 3 hours ago | parent
pndy 2 hours ago | parent
Which surely will be useful in ID verification on the Internet; Android devices most likely will follow with same or similar solution
pveierland 7 hours ago | parent
https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...
The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.
BugsJustFindMe 7 hours ago | parent
gruez 7 hours ago | parent
BugsJustFindMe 7 hours ago | parent
But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all.
Anyway, one may presume that they've thought about this.
brookst 6 hours ago | parent
It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?
BugsJustFindMe 6 hours ago | parent
I think this will depend on how it gets used. I can imagine numerous outcomes where it's in fact worse than nothing (significantly more effective blackmail, for instance).
akersten 6 hours ago | parent
While that is not quite my bar of confidence when implementing wide-reaching technologies that have numerous unexplored knock-on effects, I guess the calculus must have been different on Infinite Loop recently.
dd8601fn 6 hours ago | parent
I’ve seen that type of argument a million times, and I’ll certainly reuse that.
MisterKent 5 hours ago | parent
The problem is that it makes it easier to fool people and provide "cryptographic" evidence of validity, backed by big tech.
It's purpose is to stop bad actors from passing of fake as real just as much as it is to prevent real images being dismissed as fake.
alwillis 5 hours ago | parent
Knowing Apple, they've been working on and testing Apple Reference Image for years.
It being perfect isn't the issue; it's that random people on the internet who are just learning about this assume Apple's engineers haven't already thought about everything (and more) mentioned in this thread.
archagon 3 hours ago | parent
ben_w 3 hours ago | parent
Given how many bugs there are in macOS and how long they have remained there, I (who have been writing iOS apps from the release of the first retina iPod touch until AI got good) functionally agree with such people; at best, I think Apple's engineers haven't actually solved everything (and more) mentioned in this thread, even if every one of these things may have come up in discussions and even reached an official backlog or task list or similar.
mitxela 44 minutes ago | parent
nomel 7 hours ago | parent
[1] https://commonlands.com/products/ir-cut-filters-csp650?srslt...
pveierland 7 hours ago | parent
BugsJustFindMe 6 hours ago | parent
> increasing the difficulty of producing a forgery
The problem with this thinking is twofold:
1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.
2) It increases the potential value of a forgery because now your forgery is attested by Apple.
So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
tristanj 7 hours ago | parent
A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information. The video files (Possibly audio too) could also be included with the verified image as additional verification.
They can also prevent photos if iPhone detects the LiDAR sensor is covered, similar to how Meta does it with their camera glasses.
pveierland 7 hours ago | parent
Similarly, LiDAR alone will help disqualify cases where someone is just taking a picture of e.g. a landscape target of the Golden Gate, but that it shown on a screen 1 meter away.
halestock 7 hours ago | parent
alwillis 5 hours ago | parent
TL;DR: What is C2PA in 60 seconds
What: An open technical standard for embedding cryptographically signed provenance data inside digital media files.
Who: Created by a coalition founded by Adobe, Arm, BBC, Intel, Microsoft, and Truepic in February 2021.
How: A C2PA Manifest (also called a Content Credential) travels inside the file and records who made it, when, and what tools were used.
Why: Deepfake incidents surged from 500,000 to 8 million cases between 2023 and 2025. Provenance gives media a verifiable chain of custody.
[1]: https://c2paviewer.com/articles/what-is-c2pasandcat_ 6 hours ago | parent
dylan604 5 hours ago | parent
I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?
Findecanor 1 hour ago | parent
I think optics could be used to make each camera see a different image.
A video could show shake, which could be verified against readings from the phone's accelerometer -- but you could just hold it still and claim that it was on a tripod.
geokon 7 hours ago | parent
seems pretty easy to make it sufficiently difficult to trick the system
dinobones 7 hours ago | parent
Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.
BugsJustFindMe 6 hours ago | parent
nvme0n1p1 6 hours ago | parent
https://www.elcomsoft.com/news/428.html
https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...
You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin.
It's funny to see Apple fall into this same trap.
Rohansi 6 hours ago | parent
srik 6 hours ago | parent
walrus01 6 hours ago | parent
But you're only allowed to do that if your name if Anish Kapoor
ricksunny 6 hours ago | parent
There’s no such thing as a Golden Gate Bridge.
Prove it.
baxtr 5 hours ago | parent
I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage.
That’s a tradeoff I can live with.
dgellow 1 hour ago | parent
You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar
Glyptodon 5 hours ago | parent
mw888 4 hours ago | parent
While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified.
It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.
nalekberov 4 hours ago | parent
Gupie 3 hours ago | parent
est 1 hour ago | parent
I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter.
The "digital negative" in DNG format can be used to analyze the authenticity of the content.
peri-cl 1 hour ago | parent
Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed.
Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...")
It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.
puppycodes 7 hours ago | parent
but im sure it will popular with 60 year olds watermarking their pictures of sunsets.
SXX 7 hours ago | parent
Scrapped in 3..2..1..
xeonmc 7 hours ago | parent
walrus01 6 hours ago | parent
tobyhinloopen 5 hours ago | parent
Gigachad 3 hours ago | parent
petu 3 hours ago | parent
But Apple likely would reject such photo because of inappropriate depth map / LiDAR data.
akersten 6 hours ago | parent
I don't think we should have this, for that reason alone (but many others too).
otterley 5 hours ago | parent
dgellow 1 hour ago | parent
hosteur 49 minutes ago | parent
HighGoldstein 13 minutes ago | parent
saagarjha 6 hours ago | parent
solenoid0937 6 hours ago | parent
PCC is quite good, about as close to private remote compute we can get without doing HME.
politelemon 4 hours ago | parent
qazwsxedchac 2 hours ago | parent
mitxela 39 minutes ago | parent
wky 5 hours ago | parent
[0] https://support.apple.com/guide/iphone/view-reference-images...
[1] https://www.apple.com/legal/privacy/data/en/reference-image/
> When you take a photo in Reference mode after tapping Reference Mode, your device will include reference image information in the photo’s metadata. If you then view that photo and tap the Reference badge on your iOS device or click it on your Mac, the device will send the raw photograph, metadata about the photograph like the sensor’s signatures and the time frame in which the photo was captured, as well as the sensor’s unique hardware identifiers to Private Cloud Compute.
Edit: On reread it seems they do in fact send the actual photographic data to PCC, which I presume has some reason over signing metadata on-device? Original mistaken post is below for transparency.
You can always not use the reference image mode, and according to the article you send a hash of the signature of the photograph, so all they would know is you took a photograph in reference image mode at some point in time before the request.
e28eta 5 hours ago | parent
After my brief read, one of the main reasons they’re using PCC to produce the signed JPEGs, instead of doing everything on device, is that it maintains your privacy.
If you were signing with the iPhone, an attacker could then correlate photos taken with the same device.
Apple certainly has the data that “this sensor, in this device, took this exact photo” in PCC at the time of signing, but they discard that data.
wky 6 hours ago | parent
0xWTF 5 hours ago | parent
ed_mercer 5 hours ago | parent
Hoftheater 5 hours ago | parent
otterley 5 hours ago | parent
account42 1 hour ago | parent
tgsovlerkhgsel 5 hours ago | parent
There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).
Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.
doctorpangloss 5 hours ago | parent
True.
> raises the bar but could be bypassed with enough effort.
Anyone can spoof this.
Apple cannot stop spam iMessages. They can't stop someone from rendering their privileged UI inside a browser viewport. People copy and paste remote script executions from convincing captchas.
This whole provenance thing is a red herring. You agree with me, but there's truly not a single application for this that won't be exploited.
itake 5 hours ago | parent
Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.
ben_w 3 hours ago | parent
It's been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: https://news.ycombinator.com/item?id=9224 and https://en.wikiquote.org/wiki/Rob_Malda
NVIDIA suggested AI fakes controlled with face tracking input as a compression technique just for reducing video call bandwidth requirements (to ~117 bytes per frame). They did that six years ago: https://www.dpreview.com/news/5756257699/nvidia-research-dev...
As we're now in an AI race, even NVIDIA's specific technique has flaws which all the current tools can detect, there's never any guarantee of this continuing to be the case.
That said, in the case of Apple, they're historically followers not leaders despite the public image they like to present about innovation, and I'd expect this method to be flawed from day one even if we weren't reading a corporate blog post written in a self-congratulatory tone I find almost as off-putting as when AI write.
itake 3 hours ago | parent
AI deepfake or edit video doesn’t pass liveliness checks without all the c2pa or reference image song and pony show.
Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive.
They could also just update their app to stop accepting photos from the album.
alwillis 2 hours ago | parent
While its true Apple usually isn't the first in a product category--not the first mp3 player, not the first smartphone, not the first tablet) but once they get there, they're quite innovative.
When the iPhone 5s was released in 2013, it was the first smartphone with a 64-bit processor, which caught Qualcomm off guard. Even when Qualcomm released a 64-bit processor the following year, it kinda didn’t matter because Android was still 32-bit.
mitxela 47 minutes ago | parent
mitxela 47 minutes ago | parent
bawolff 4 hours ago | parent
tempay 3 hours ago | parent
gambiting 2 hours ago | parent
RobotToaster 18 minutes ago | parent
The UK allows private prosecution, if it was a real problem the insurance companies would be using it, instead of attempting to make the state pay for it.
Telemakhos 3 hours ago | parent
Topfi 3 hours ago | parent
Why do you believe Android manufacturers and SOC makers like Qualcomm won’t be able to offer a similar solution?
rickdeckard 3 hours ago | parent
1. a public/private key exchanged during device-production (production-cost),
2. the capability to reboot in a cryptographic mode (R&D / component cost) and
3. a cloud-service which then processes the raw data to create a JPG (operational cost)
comes at a premium. Why should this premium be applied on a 99 USD Smartphone?
Which is my whole puzzle on this vector: If the big benefit is for insurance/ID-verification, which apply cost-saving by offloading their process to the untrusted customer, how much they can offload this by requiring their customer to own a 1000+ USD smartphone to provide THEIR service...?
The most I can imagine is insurances offloading their work to OTHER companies, NOT trusting them and therefore requiring them to own a 1000+ USD Smartphone. But even then, why not use a third party app that also runs on a 3y old iPhone and a 99 USD Android device...?
Topfi 2 hours ago | parent
rickdeckard 2 hours ago | parent
Okay. In good faith, I'll go with you:
If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)?
Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013.
The answer is COST: A camera-module with OIS is a more-expensive component than a module without it.
And that's ONLY the component-cost: A OIS-camera doesn't come with increased cost in device-production (it's just another component to place and assemble), no increased cost in R&D (the tech is very mature, all the SW is there) and no running costs (there are no cloud-services required to operate OIS)
socalgal2 2 hours ago | parent
rickdeckard 1 hour ago | parent
But the assumption that smartphone cameras, including those used in 99USD smartphones, will become 100% cryptographic cameras in a few years is highly unlikely, considering that those cameras didn't even gain OIS in the last 13 years despite the feature being highly matured and widely available.
Changing the topic to other features won't change that.
You seem to lack the understanding how this industry works, and assume that every development naturally just trickles down and becomes a commodity. This is not the case.
This cryptographic feature will definitely become available from camera sensor suppliers, first of all likely from Sony. But it will be a feature of premium sensors and will remain a differentiation factor.
Sony will not support cryptography to its sensors without additional cost. Device-vendors integrating those sensors then have additional cost in R&D, production AND operations. All this will not be waived and put in a 99USD device.
For the other assumption, that "If this type of thing becomes required", I fail to see how this should happen for a mass-market consumer: This feature doesn't authenticate the content of an image, it just authenticates the RAW data of the image sensor. It won't (and shouldn't!) make the user more trusted towards another entity (like Apple mentions themselves in the link)
Topfi 1 hour ago | parent
Also, OIS is a major mechanical add on (a literal motor) and even 1500usd smartphones lack it on some of their sensors, mainly because while it can have an advantage on an ultrawide, that tends to be more limited. Incidentally, most 99usd phones have one (actually usable) sensor which thus tends to have a larger width to compensate. I hope, in good faith, you see the difference, to something like ARI.
AMOLED, etc. are also a bit more expensive then OIS, but we get those into a sub 100usd BOM easily somehow. More so for 5g, certain features just become expected/required.
Your logic would lead to OEMs making SOCs without things like TEE and other things which started in the high-end but quickly became required and essentially free to implement.
Not saying it is free now, but that the upcoming gen of chips from Sony, Samsung, etc. will have it build in for such a minimal BOM impact, this will be an expected, common place feature across all prices.
To have a more serious, honest and accurate comparison than OIS, why do most new smartphone at 99usd include some form of an NPU? Or the trusted modules for biometrics, etc.?
rickdeckard 46 minutes ago | parent
No, you can apply smartphone OIS-tech on any sensor, stabilization is achieved via the lens-array, not the sensor. The size of the module slightly increases but that's not a hindering factor. Cost/Benefit of OIS on ultra-wide lenses is not there, so it's usually not applied.
>Your logic would lead to OEMs making SOCs without things like TEE and other things which started in the highend but quickly became required for one and basically free to implement for two.
TEE became a mandatory requirement of the media industry for Smartphones in ~2010, as they announced plans to restrict media-playback on a device without measures to secure the DRM-keys. Google made it mandatory shortly after, because the entire ecosystem was built on media-consumption.
It didn't come for free to the players in the industry, it became a very expensive task to develop, support and maintain it, but that's another story.
Drawing a parallel here, I fail to see who should require cryptographic authentication of a taken image from end-user devices, to the point that no consumer devices without it will be built anymore.
>Not saying it is free now, but that the upcoming gen of chips from Sony, Samsung, etc. will have it build in for such a minimal BOM impact, this will be an expected, common place feature across all prices.
It will be supported in sensors for sure, but those will be premium-tier sensors, as a differentiation factor. Until today there was no premium sensor used in mass-tier devices.
Of course, again, if there is demand in the market or a regulation requiring it, it will create an incentive for the industry to follow, but I fail to see why either of this should happen in the coming years.
>To have a more serious, honest and accurate comparison than OIS, why can you not buy a single new smartphone at any price without some NPU?
I don't know why OIS is not a "serious, honest and accurate" comparison, can you elaborate?
As stated, it's a highly mature technology available for over a decade already, providing critical-mass observable end-user value, yet it didn't just naturally "trickle down" to every smartphone price-segment, simply because it comes with additional cost no matter which scale (and the Galaxy A1x tier has massive scale).
A NPU is just the evolution of a DSP, which exists in Smartphone SoC's for more than a decade now and is required for Audio and Image processing. DSP's used to run pre-calculated inference models for lens-correction, exposure, white-balance, etc., now these processes can run as models on an NPU.
---
You are trying to argue why that feature won't naturally become a commodity at basically no cost. I'm trying to answer why I don't see this happen, because I worked in this industry for more than 20 years.
The market doesn't get features as a default "easily somehow", features reach this commodity stage because of significant end-user demand (like Camera, Display, Battery), business-value (for the vendor, like Apple Pay) or industry-requirements (like TEE, Widevine example above).
I don't see this happen for this feature, because there is
1. no significant end-user value (unless the public narrative is massively skewed towards "everything is true when the image was signed"),
2. the business-value applies only for Apple's service-proposition for now (which will likely make this feature expand to the non-Pro iPhone tier), and for
3. the industry-requirement I don't see WHO would actually be able to enforce this, for WHICH actual benefit.
Topfi 32 minutes ago | parent
And despite that experience, you do not see the universal value in reliable, verifiable image attestation for any user? You cannot imagine why that may not just be very useful, but quickly become required, what the "end-user demand", "business-value" or "industry-requirements" could be?
rickdeckard 17 minutes ago | parent
There is universal value in many features, yet they didn't become a commodity in all smartphone-tiers.
I don't see how and why this feature should become a default in all smartphones, which you keep insisting on without apparently comprehending the industry and market aspects I am trying to explain.
Peace.
Topfi 12 minutes ago | parent
How is what I wrote (that you seem to not see universal benefit) in bad-faith (honestly trying to understand what you mean) if you then add:
> I don't see how and why this feature should become a default in all smartphones [...]
So, do you see universal value or not? Cause you again said you do not and that was precisely what I wrote, that you do not seem to despite it being obvious to anyone who thinks about why phones of any price have cameras.
Should I honestly start writing a list why private as well as business users of smartphones may want, even need this? Is that really required? Consider every use case of a camera on a phone, please, before I feel the need to do that.
jeroenhd 2 hours ago | parent
The timestamping server is the hard part, especially with the verified compute component. It's just not something I see Samsung doing.
I expect Google to show up with a blog post titled "extending C2PA with timestamps for industry-leading authenticity confirmation" any time.
Topfi 50 minutes ago | parent
rickdeckard 3 hours ago | parent
An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted).
Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this.
Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim?
Or is the insurance agent / mechanic an untrusted entity who will now be required to have an iPhone 18 Pro?
What is the fraud vector here, and how can the insurance service provider continue cost-saving on damage-assessment by offloading to the customer, if the customer is required to own a specific device?
yreg 3 hours ago | parent
In a couple of years it will be almost any iPhone instead of 18 Pro. And if it catches on, other phone vendors will provide a similar service.
rickdeckard 1 hour ago | parent
And then stop the 3rd party app which is vendor-agnostic and works on all devices?
I'd say that's unlikely.
IF that's an industry this Apple-feature will disrupt, it seems it will barely have an impact on the process of insurance companies themselves, but will actually disrupt the service-provider industry FOR insurances:
The insurance won't be able to stop their existing 3rd party cost-saving, as it provides the largest device-coverage for offloading to the customer.
Instead, either the insurance or the 3rd party service-provider will have to pay Apple in addition to make use of this feature, with the hopes that the provided data will reduce fraud.
Which brings me back to my actual question: What is the fraud-vector here?
Topfi 1 hour ago | parent
The industry has some extensive experience in independently verifying signatures, I don't see how the manufacturers factor in here. And for app features, just ask banks how integrating biometrics, payment services, etc. goes. Tends to be preferred, once Apple and Google Pay became fully available here in Austria, banks dropped their own NFC payment solutions in rapid succession.
rickdeckard 42 minutes ago | parent
bayindirh 2 hours ago | parent
This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.
rickdeckard 2 hours ago | parent
Banks are offloading the trusted process of ID verification to an untrusted entity (end-user, merchant,...) and compensate for the loss of security by using a trusted service-provider (now Apple AND an iPhone 18 Pro).
This is already happening today in two scenarios:
1. lower-risk scenarios (remotely) with trusted 3rd party service-providers and very low Hardware-requirements ("use this app on your phone to take a picture/video") and
2. higher-risk scenarios (on-site) with trusted 3rd party service-providers ("use THIS expensive device to take a picture/video of the customer/citizen")
Apple now potentially disrupts the service-provider industry of #2 (higher-risk scenarios) by
#a grabbing a part of this hardware/service market that MAY allow the end-user to be in control of the device and
#b replacing the on-site hardware/service with an iPhone "in a box".
They can't disrupt #1 because their cost-saving can't mandate the end-user to buy a 1000+ USD device just for THEM to provide the contracted service. (They can add convenience if you have it, but they can't reject their service if you don't)
Which means they disrupt mainly #2: The industry providing trusted imaging solutions for higher-risk scenarios.
--> So it's the Watch Ultra game all over again.
On Watch Ultra they disrupted the diving-watch market by the sheer scale of selling their development to everyone buying a Watch Ultra, driving down the cost so much that they can undercut every diving-watch company on the market.
Now they use the sheer scale of iPhone 18 Pro sales to enter the trusted-imaging market-segment, undercutting every player there and take that market.
bayindirh 1 hour ago | parent
Back in the day Canon and Nikon tried this with embedded private keys on their cameras, and with Sandisk's WORM SD cards. Then, somebody extracted the keys and it was game over.
While my iPhone 17 can't match a full frame mirrorless camera, it can take pretty impressive photos, so they are already more than adequate in detail and clarity department. So making these images trusted is a huge win for them.
devonsolomon 2 hours ago | parent
intrasight 1 hour ago | parent
I don't follow. It's my user agent that's verifying the image, and my device will tell me that it's not verified.
alwillis 1 hour ago | parent
You have it all wrong.
Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.
There's no way to link a reference image to a person; it's also not possible to determine if a pair of images came from the same device.
> And while "a nation state actor can spoof this" is a problem for the journalism use case
This is incorrect:
When the image sensor is first initialized in the factory, it creates a
cryptographic signing identity, sharing only the public key with the
factory. The SEP similarly creates a separately-attested signing
identity. These identities are bound together into the device manifest,
allowing us to later check whether a particular sensor and SEP are from
the same device.
The final signature on a reference image is a composite post-quantum
signature combining RSA-3072 and ML-DSA-87. To our knowledge, Apple
Reference Image is the only image provenance system that provides
quantum-secure defenses.
So… a nation-state can't really do anything here unless they acquire alien technology. If something crazy happens (solar flare or EMP?), a fraudulent reference image can be revoked.> Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.
I would imagine there will be a way to confirm an Apple Reference Image on the web. Pretty soon, 3rd parties will be able to verify the image themselves:
Reference images can be viewed in the Photos app alongside the main
image, like a digital negative, to visually compare the two assets and
determine if any edits were made. APIs are available in iOS, iPadOS, and
macOS 27 for third-party apps to enable viewing of these reference images.Retr0id 1 hour ago | parent
setopt 34 minutes ago | parent
Yup, you don’t even need nukes: https://en.wikipedia.org/wiki/Explosively_pumped_flux_compre...
iugtmkbdfil834 1 hour ago | parent
I think you have a point. I would only note that just because it is not explicitly designed as one, does not mean it will not be effectively utilized in that manner.
mitxela 49 minutes ago | parent
layer8 32 minutes ago | parent
It’s possible for Apple, as stated in the blog post (e.g. “which lets the device later produce signatures that Apple can attribute to that specific phone”).
RobotToaster 21 minutes ago | parent
At least for the image itself, using direct projection onto the sensor (in a way similar to a retinal projector or film recorder) would be difficult to detect I imagine?
layer8 37 minutes ago | parent
phkx 5 hours ago | parent
Gigachad 4 hours ago | parent
Location services is quite hard to trick. To the point people have gone to the lengths of putting iPhones inside a microwave for RF shielding and setting up fake phone tower signals inside to trick the phone in to unlocking the hearing aid feature on AirPods for unapproved countries.
tjpnz 1 hour ago | parent
jsrozner 4 hours ago | parent
The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.
modeless 4 hours ago | parent
I hope that companies and governments don't start forcing us to use this stuff by requiring it for their services.
Gigachad 4 hours ago | parent
jeroenhd 3 hours ago | parent
codetiger 4 hours ago | parent
codetiger 4 hours ago | parent
bawolff 4 hours ago | parent
rickdeckard 4 hours ago | parent
Whatever that means in detail...
Gigachad 4 hours ago | parent
What you are prevented from doing is adding a verification to a photo outside of the iOS image pipeline, or modifying the photo with the verification still in tact.
asaddhamani 4 hours ago | parent
bawolff 4 hours ago | parent
I have my doubts about this scheme but this is not one of them. If the point is that someone in principle could verify, that is enough for it to be useful, even if not everyone does.
gmueckl 4 hours ago | parent
Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?
dsign 4 hours ago | parent
giancarlostoro 4 hours ago | parent
dsign 4 hours ago | parent
bawolff 2 hours ago | parent
The harder one is they can force apple to certify a fake photo.
the part that would be very hard but not outside the realm of plausibility, is that gov could force apple to introduce a bug in its pcc platform to link photos to the photographer in order to track and arrest inconvenient people. Apple says there are a bunch of protections against that but ultimately you are trusting apple to do it the way they say they are.
This entire system relies on trusting apple
intrasight 1 hour ago | parent
It does indeed, and that is a fundamental flaw. but as has been discussed here, it is better than the alternative, which is no verification.
During the pandemic, I outlined a scheme for using blockchain technology for image provenance and authenticity tracking. The idea was that instead of any one entity assigning authenticity that it would be done in a crowdsourced manner and that the device would overlay a score whenever an image or video is shown to a user.
My assumption was that the desire of users to see such scores would force all manufacturers to implement this open protocol. But my approach suffered from chicken and egg problem, which Apple's does not.
bawolff 33 minutes ago | parent
jeroenhd 4 hours ago | parent
Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. The timestamping server is a nice idea (though I don't see why they can't just use a normal timestamping server, I guess to keep control over the protocol) but it doesn't solve the fundamental problem that defeated C2PA.
Gigachad 3 hours ago | parent
If there is too much of a gap between the upper and lower bounds then the image becomes suspicious.
jeroenhd 2 hours ago | parent
This approach does have one benefit, which is that Apple gets all the (meta)data to determine if something is or isn't "real", rather than letting the verifier decide beforehand.
I can only imagine the outrage if Google or Microsoft added a "upload all of your photos to us and we will mark them are real or fake" protocol, even with all of the verified compute gaff.
djtango 4 hours ago | parent
So if you jailbreak or root your phone what happens? Is this a trojan horse into making rooted phone cameras unverified? Just like how Linux machines can't watch Netflix in 4K
Gigachad 3 hours ago | parent
jeroenhd 2 hours ago | parent
bawolff 2 hours ago | parent
jeroenhd 2 hours ago | parent
Plenty of certification bodies refuse to revoke their given certifications because of brand damage or effects on their customers. That's why cryptographic verification of things like Secure Boot are basically broken on most systems by default.
If an independent security researcher does it and Apple rolls out fixes a month later, I can see it happening. If it turns out a government agency hacked the platform "at some point", I have my doubts Apple will retroactively reject all of their iPhones' signatures.
mitxela 40 minutes ago | parent
rvz 4 hours ago | parent
Hardware wins.
bawolff 3 hours ago | parent
- it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact
- i guess you need internet to take a picture. :(
- You are puting a lot of trust in apple's private cloud compute platform.
- apple can revoke certification of a picture. I understand the appeal of this, all security systems eventually have failures, so its important to be robust against this. However if the point is to prove a picture is real (especially politically damaging ones), this is giving a lot of power to apple.
Its meant to be in competition with C2PA, and i guess the idea is its much more secure against complex hardware attacks. However i think its worth asking who the target audience is and what threats they face. The primary issue with AI is it makes fake photos easy, not that it invented fake photos. Even Stalin manipulated photos back in the day. It is not a new thing, the problem is just being overwhelmed with them.
with that in mind, are complex hardware attacks really that important? We just need to increase the difficulty floor, not solve fake photos for all time. No matter what you do, people can still use practical effects.
It seems like this is almost trying to thwart spies and nation state adversaries, well forgetting that such well funded groups have the budget to fake photos the old fashioned way or if they really cared, bribe their way into apple.
calmingsolitude 3 hours ago | parent
It’s opt-in because your photo is sent to Apple’s servers. Only if it were on-device should they even consider making it default.
> i guess you need internet to take a picture
Not really, internet is required to process the reference image, but that can happen later if you’re not currently connected.
> are complex hardware attacks really that important?
No, but the floor shouldn’t be “trivially exploitable” like C2PA[0]. It’d be interesting if there were a middle ground but we don’t have anything like that as of now.
bawolff 2 hours ago | parent
Ultimately though, i think all this might just mean we do not have a practical solution to this problem.
just to throw out some naive ideas, maybe the solution is to just sign the raw camera output and embed it in the metadata. If this is an optional feature meant for photojournalists, does file size really matter?
ErneX 3 hours ago | parent
RandomGerm4n 3 hours ago | parent
It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
bayindirh 3 hours ago | parent
Apple/iOS already have part authentication pipeline on its security sensitive devices (TouchID/FaceID). How can camera sensor can't be considered one of those and needs attestation before enabling?
From the document:
> Apple Reference Image leverages custom-designed image sensors in iPhone 18 Pro and iPhone 18 Pro Max to ensure reliable capture of image data, and relies on Private Cloud Compute, which provides a computational environment for secure photographic processing that cannot be subverted even in the case of device compromise. (emphasis mine)
berkes 56 minutes ago | parent
I believe many of the problems we have, need social and human solutions, especially when the technical solutions are hard or impossible.
Like here, where we can no longer trust images to depict reality and act as proof. While its admirable that people look for technical solutions, the obvious social solution is to admit that images are no longer absolute proof and will become less and less trustworthy¹.
And, by admitting that, change our relation to these artifacts. Sure, that will change journalism, police work, legal systems, etc etc.
But pretending that we can rely on images might allow journalists, police, judges to continue relying on them as if they're authentic, which is a far bigger problem over a longer period.
Social solutions require effort, demand flexibility, take time and are messy. But this is what humans are and do. Not everything has a technical solution. Not every technical solution is the best option.
¹ we already saw this when people claimed "someone must have hacked my iphone and put it there". For decades we've seen this with images that are deliberately taken in a way to spin a story (like the illusion of a large crowd or spacious room through carefull angles or fancy lenses). And I predict we will see this with security footage, "live streams" or even bodycams with "ai enhancement". Just imagine a bodycam or a dashcam that manipulates the output to benefit the owner. "A dashcam that will prove your innocence in assumed traffic violations" or such.
keiferski 3 hours ago | parent
jeroenhd 3 hours ago | parent
Apple's protocol differs in that it requires a timestamping server to sign the file and centralising Apple as the single arbiter of truth. An excellent addition, if you trust Apple and the governments they're friendly with (I don't, especially the latter part).
keiferski 49 minutes ago | parent
ozlikethewizard 3 hours ago | parent
petesergeant 3 hours ago | parent
rickdeckard 2 hours ago | parent
Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy.
Okay, fine. Will work for sure, this will disrupt the trusted-imaging market and moreover make Apple a service-provider in this industry (with the ramp-up cost paid by customers buying iPhones for entirely different purposes).
But creating this impression and media-buzz that Apple is now verifying more than just the digital authenticity of an image may shift the public scrutiny of MANY media/online statements:
There is a risk that random claims (and propaganda) will be given more credibility in the public eye just because they came with images that were confirmed to be "taken like this on an iPhone"
intrasight 1 hour ago | parent
No, because images will be confirmed to have been taken on "this iPhone". The New York Times will be able to publish an article and to attest that the photographs shown were taken by their journalists, and then your user agent will verify that provenience.
rickdeckard 43 minutes ago | parent
Actually the description of Apple makes explicit statements AGAINST that:
Quote: Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device
mitxela 42 minutes ago | parent
demibabs 2 hours ago | parent
I’m surprised that even Apple calls jailbreaking, jailbreaking. Doesn’t that imply their own software is a jail?
mitxela 38 minutes ago | parent
9shrey 1 hour ago | parent
chaz6 1 hour ago | parent
rockbruno 1 hour ago | parent
So the iPhone Duo won't have it?
rasguanabana 42 minutes ago | parent
londons_explore 41 minutes ago | parent
throw1234567891 19 minutes ago | parent
EU wants Apple to implement digital fingerprinting to fight CSAM: overreach of power, total invigilation, nonono! Apple cannot comply! What about our privacy!
Apple implements the feature and sells it nicely wrapped in a PR material: oh, that's cool, innovative!
cedws 5 minutes ago | parent