3 ms·
I don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and prete
by treyd 16d ago
I don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and pretend that the photosensor is capturing whatever image you want. I imagine it's not exactly trivial to do this, but a grad student with an FPGA could probably figure it out.
- figmert 16d agoOr, as the author said, you can just photograph an AI generated picture, and that will work too.
- koinedad 16d agoAdding depth sensor info to the this could help
- petu 16d agoThis feature is Pro phones only, not Duo: https://www.apple.com/iphone/compare/ https://www.apple.com/iphone/compare/ ("Apple Reference Image (Fusion Main)") So only on devices with LiDAR / that can capture depth map.
- theamk 16d agoIf there is signed metadata too, then it's pretty hard. You will need to match focus distance (it will be very small if photographing picture), GPS location, exposure and other settings. If there is a depth map, you'll need to match it too.
- TedDoesntTalk 16d agoEven easier is to just take a picture of an AI-generated picture.
- Retr0id 16d agoSimpler than that, you can just talk to the cryptography IC yourself and ask it to sign stuff. No need for an FPGA, just an arduino. Given the datasheet I imagine any LLM from the last year should be able to oneshot it.
- hex4def6 16d agoif I imagine on apple silicon this is buried deep in silicon / ISP IP block, and isn't a discrete IC.
- whywhywhywhy 16d ago>a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake you don't need to do that just photograph a screen. This seems close to worthless in "identifying real photos vs AI" for someone actually wanting to do something bad with an AI image, although probably very useful at identifying which phone took a photo when ("the root of trust stays inside Apple's Private Cloud Compute") seen as it's not an entirely local solution a bad actor government could use their powers to completely abuse this.
- ares623 16d agoif geolocation data can be captured in the same signature, that would be a good enough approximation for most relevant cases I think.
- brainwad 16d agoGNSS signals can be relatively easily faked because the original signals are very weak so overpowering them doesn't require much broadcast power.
- ares623 16d agoah, damn.
- 15155 15d agoJamming them is easy, replaying them so as to trick unacquainted receivers is easy, but "faking" a network of signals so as to precisely control present a specific location is not easy or feasible. "Overpowering" (as to jam) inherently means detectable, these signals are arriving below the noise floor anyway. And if you aren't overpowering, the original signals will leak through. Also, depending on the sophistication of the receiver, your ability to present an implausibly different location may not exist at all (AGPS.)
- brainwad 15d agoIt seems feasible for state actors, at least: https://en.wikipedia.org/wiki/GNSS_spoofing#Ocurrences https://en.wikipedia.org/wiki/GNSS_spoofing#Ocurrences
- altairprime 16d agoBecause doing so does not materially devalue Apple’s product. Sure, a dedicated attacker could try to overcome it, but few will, and only people of such serious consequence that they can afford the effort of modification. By and large this puts Apple into direct competition with Nikon and it’s long overdue that someone ship this capability to a wider market than authorities. Also, remember how Touch ID sensors are cryptographically paired, and consider whether Apple could bake that into a camera sensor rather than a fingerprint sensor. If they can, then you can run wires all you want; the attestation chain will not be valid. I’d be shocked if they were willing to launch the product without that, and there’s a new hardware dependency or else they’d have released it for earlier phones.