5 ms·
Proof of Capture: Apple Reference Image, but open source and using steganography
- amelius 24d agoOne of the few advantages of "not owning your device". Glad that at least we have that now.
- fitzn 24d agoHere's a toy for embedding small text into images steganographically: https://github.com/fitzn/atrium https://github.com/fitzn/atrium
- merybenavente 24d agocool work!
- smalltorch 24d agoHere's a toy for embedding text inside random HN comments. https://gitlab.com/here_forawhile/edasm https://gitlab.com/here_forawhile/edasm Example: After wholly implemented our logging layer with dagger, I posit that the real regression was not the aws itself but the rigorously prototyped around authentication. We consequently extraordinarily profiled the config, henceforth simplified every edge case, and the optimization were unmistakably exemplary. alternatively, the aforementioned monitoring is comparable advantageous to an incremental security environment. I endorse this path if your security team has rigorously instrumented a massive rust codebase before.
- gpugreg 24d agoBoth DeepSeek-V4.1-Flash and GLM-5.3-Flash failed to decode your embedded example text. I failed, too, but I only spent a minute trying to figure out your repo before giving up and telling AI to do it. Anyway, maybe you want to improve your docs?
- smalltorch 24d agoThat's makes sense because I am the only key holder in existence to decode! It should decode with other 'keys' but It won't be the correct message. The text decodes to 'hello world'. Also, this engine won't compile on non arm64 chips without virtualization layers. Check the 'Prerequisites' section for required packages to compile.
- 1over137 24d agowhy require arm64?
- smalltorch 24d agoThere were significant performance improvements to write the engine in assembly. The project started as a pure python version, but it's pretty slow.
- xg15 24d ago> For example, a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake. But it's always nice seeing big actors interested in addressing this problem. Yeah, very nice. So this whole idea basically doesn't work - but we get a new stealth way to embed metadata in an image that can be used for tracking... (And a new narrative why cameras need to have TPMs and locked-down firmware as well)
- ChocolateGod 24d agoCouldn't the camera encode information from the depth sensor and prevent this.
- TedDoesntTalk 24d agoI will make miniature dioramas and photograph them.
- mandolingual 24d agoAt that point you've earned the fruits of your deception, just like the tricksters who spent time doing physical photo editing.
- petu 24d agoMiniature dioramas wouldn't be size appropriate. Apple could detect faces/cars/other common objects of ~known size and verify -- or even just dump depth map for anyone to check.
- petu 24d agoIt seems to be what Apple is doing, this feature is only available on the 18 Pro's (which have depth sensor on the back), but not Duo.
- shagie 24d agoPhotos of photos has always been a problem. In days of old, a Polaroid photo was considered "proof of capture". I've got a Polaroid daylab 35 plus sitting in storage somewhere (https://www.instantoptions.com/wp/faqs/daylab/ https://www.instantoptions.com/wp/faqs/daylab/). You can project a slide through it onto Polaroid film, expose it, and have the image there. I was also able to find a company that did slide printing. It was possible to send them a digital image and they'd send you back a slide with that image... which I then used to make a Polaroid of that image. I had a classic 600 Polaroid photo of a UFO landing.
- vzaliva 24d agoI expect in the near future all digital cameras to digitally sign the images they take. Even before AI slop, it was useful to avoid manual alterations. AI makes it all too easy, so it makes sense. However, this will certify only the original image. I think the missing part of this is additional layers of certification which allow some image editing (e.g., rotating, contrast, etc.) yet clearly document that the image was modified and link to the original image ID. Kind of like a signed git log.
- nulltrace 24d agoSoon my phone can cryptographically prove the beauty filter lied at capture time.
- xg15 24d agoEXIF data is stripped for a good reason - because it can be a privacy hazard. Suddenly this plays no role anymore?
- doc_ick 24d agoOntop of this, including a photo edit history in a photo including the original photo would increase the size of a photo to be completely unusable or unshareable.
- xg15 24d agoI understood the GP so that only some unique ID or hash of the original image would be included, not the image itself. Basically like the commit chain of Git but without the actual content blobs. You could use this data to prove that image B is an edit of image A if you already have both A and B. I still think this is a bad idea, because this all requires the images to have some sort of ID - and that seems like a prime target for tracking.
- lokar 24d agoYou can publish a fully stripped image (as people do now for exif), and retain the original
- treyd 24d agoI don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and pretend that the photosensor is capturing whatever image you want. I imagine it's not exactly trivial to do this, but a grad student with an FPGA could probably figure it out.
- figmert 24d agoOr, as the author said, you can just photograph an AI generated picture, and that will work too.
- koinedad 24d agoAdding depth sensor info to the this could help
- petu 24d agoThis feature is Pro phones only, not Duo: https://www.apple.com/iphone/compare/ https://www.apple.com/iphone/compare/ ("Apple Reference Image (Fusion Main)") So only on devices with LiDAR / that can capture depth map.
- theamk 24d agoIf there is signed metadata too, then it's pretty hard. You will need to match focus distance (it will be very small if photographing picture), GPS location, exposure and other settings. If there is a depth map, you'll need to match it too.
- TedDoesntTalk 24d agoEven easier is to just take a picture of an AI-generated picture.
- Retr0id 24d agoSimpler than that, you can just talk to the cryptography IC yourself and ask it to sign stuff. No need for an FPGA, just an arduino. Given the datasheet I imagine any LLM from the last year should be able to oneshot it.
- Lammy 24d agoIn the future, people willingly surveil themselves 24/7 with cryptographic proof, because fake images and video will be so good that it will be the only way to prove what one didn't do. Total Information Awareness achieved :D
- jamesnorden 24d agoIn the future? People willingly buy Amazon spy devices now.
- Retr0id 24d ago> we sign a perceptual hash (pHash) of the image rather than an exact pixel checksum Perceptual hashes are non-cryptographic. There are certainly collision attacks, but what about preimages? A preimage would completely break this scheme. This paper demonstrates second-preimage attacks against PhotoDNA and PDQ: https://eprint.iacr.org/2021/1531.pdf https://eprint.iacr.org/2021/1531.pdf
- theamk 24d agoYep, that breaks this scheme, making it useless. But it's far from the only thing making it useless, and the github page even explicitly lists those: - "Small content edits slip under the threshold. [...] A localised edit covering ~15%x20% of the frame [...] passes as authentic" - this is the worst part. 15%x20% is huge, for example enough to change the face of the person or the book/text on the image. - "Cropping is not survivable, at any amount" - given the purported reason for perceptual hashing is surviving light editing, it's pretty disappointing that one of the most common light editing operation is not supported. Oh, and the whole "cryptographic chip" angle is absolutely bogus from the security perspective. OK, attacker can't extract the private key from chip. But they can simply connect the chip to a different device and have it sign anything! Given that the attacker in this model is device owner, this is absolutely trivial.
- phh 24d agoConsidering child comment, I agree it's not great. That being said, would a bit-hash have worked? How many users are capable of sending bit-perfect images to someone else? I don't expect more than 5% of people to know...
- Retr0id 24d agoYes, it is a hard problem, but that doesn't mean that we should accept non-solutions.
- nmadden 24d agoSigning things by default has repeatedly been found to have serious unintended consequences. Do you really want your leaked/stolen photos to be undeniably linked to you? https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/ https://blog.cryptographyengineering.com/2020/11/16/ok-googl...
- postit 24d agoIt reminds me of the era when the Stasi kept archives of typewriter samples and typefaces so they could trace the authors of anonymous letters deemed subversive.
- netsharc 24d agoSamples, or sampling of each typewriter's idiosyncracies? This post https://foxfire.blog/explorations/the-typewriter-that-became-a-weapon https://foxfire.blog/explorations/the-typewriter-that-became... claims "specific machine": > The forensic science behind this was genuinely elegant. No two typewriters print identically. The mechanical tolerances of individual typebars—those metal arms that swing up to strike the ribbon—create unique signatures. Forensic document examiners look at three primary characteristics: alignment (whether a letter strikes slightly above or below the baseline), impression (whether one side of a letter prints darker than the other due to uneven wear), and damage (a chipped serif, a broken bowl on a lowercase “g”, a filled-in counter on an “e”). Taken together, these micro-imperfections form a pattern as distinctive as a human fingerprint—or so the authorities claimed. > The East German Stasi took this principle to its industrial extreme. They maintained an exhaustive registry of type samples, a vast database of typewriter fingerprints. When a dissident pamphlet surfaced, the Stasi could compare its letterforms against their archive and, in theory, trace the text back to the specific machine that produced it. The countermeasure was ingenious in its simplicity: dissidents sought out pre-communist typewriter models—early Mignon or Ideal D machines manufactured before the registry existed. A typewriter without a file was a typewriter without a name. It could speak and not be traced. Since they had control of commerce, I suppose it was possible to intercept every typewriter and "fingerprint" it before it is sold, or even tweak the typewriter to produce something unique (e.g. chipping a typebar so it prints a particular letter distinctly). Hah, needing to register your name/address to buy a typewriter feels spooky too. And if it gets stolen, you'd have to tell the authorities that it's no longer in your possession.
- khalic 24d agoI very much hope that apple is using lidar data to determine if it's a flat surface being screened
- ale42 24d agoAnd then? What if the flat surface is a wall showing cracks and it's the photo that should have been signed? Maybe it should include depth info in the image instead.
- Wendell58 24d agoA pHash isn't built for this. The 15%x20% threshold that passes as authentic is enough to swap a face.