11 ms·
Apple Reference Image: A New Approach for Verified Photography
- xeonmc 16d agoNFTs by another name...
- WalterGR 16d ago85 comments, 5 days ago: https://news.ycombinator.com/item?id=49649222 https://news.ycombinator.com/item?id=49649222
- tristanj 16d agoApple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape. I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
- nalekberov 16d agoExactly, a wave of “verified” fake images are coming.
- osy 16d agoIt also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve. > Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago. Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.
- BugsJustFindMe 16d ago> "But that's not the problem they're trying to solve." It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened". It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself. Likewise in "distinguish between photographs that depict real events and...".
- spiderice 16d agoThis is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.
- BugsJustFindMe 16d ago> This makes it like, a thousand times harder to fake a photo than it would otherwise be. The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forgery is attested by Apple. So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
- porkshoe 16d agoYou worry that a technology that you have never used nor evaluated might not work in practice... Therefore because of your worry (which is based on remarkably little information), it's a bad technology? Come the fuck on. That's beyond luddite bullshit.
- BugsJustFindMe 16d agoIs this you? https://news.ycombinator.com/item?id=49685271 https://news.ycombinator.com/item?id=49685271
- amanj41 16d agoSony's analogous solution (https://authenticity.sony.net/camera/en-us/ https://authenticity.sony.net/camera/en-us/) claims 3d depth information is built in, I'm sure Apple could do the same given at least some iPhone models have LiDAR on the back
- tristanj 16d agoThis would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances. Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.
- dd8601fn 16d ago> I do this frequently when I want to take a photo through a window. I feel really dumb for not having thought of this.
- amanj41 15d agoI see, yeah good point. Perhaps the lack of reliable depth data also be baked into some signed metadata property. Wouldn't tell you definitively if something were fake, but could be a context clue if a particular photo were dubious I suppose.
- Cthulhu_ 15d agoWhat they could do instead is record a video while taking a photo, the subtle movements (at least if handheld) might have enough information to get an approximation of depth (parallax).
- pveierland 16d agoClaim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult: https://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/20260268025 https://image-ppubs.uspto.gov/dirsearch-public/print/downloa... The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.
- geokon 16d agofurthermore, couldnt you do parallax from the multiple cameras as well as flicker the flash? seems pretty easy to make it sufficiently difficult to trick the system
- BugsJustFindMe 16d agoiPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.
- pveierland 16d agoStill, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.
- BugsJustFindMe 16d agohttps://news.ycombinator.com/item?id=49721878 https://news.ycombinator.com/item?id=49721878 > increasing the difficulty of producing a forgery The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forgery is attested by Apple. So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
- dinobones 16d agoIs this really that big of a flaw in this implementation? I don't think it's worth the additional complexity to address it. (Encoding depth information in some way, trying to detect "flat" surfaces, whatever). Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.
- BugsJustFindMe 16d agoYou mean that it is sometimes very easy. But it is also sometimes impossible. You seem to be thinking only of poor quality photos of poor quality prints, but there's no basis for assuming those characteristics.
- nvme0n1p1 16d agoYeah, such systems have been tried (and been hacked) for decades now. https://www.elcomsoft.com/news/428.html https://www.elcomsoft.com/news/428.html https://blog.elcomsoft.com/2011/04/nikon-image-authentication-system-compromised/ https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio... You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin. It's funny to see Apple fall into this same trap.
- Rohansi 16d agoTo be fair Apple of all companies have the best shot at pulling it off. They've been perfecting their hardware security for years for other reasons and this is just another way to take advantage of that work. But yes, if someone breaks it then the trust is gone and it casts doubt on all of the photos that were ever captured using the broken system.
- deleted 16d ago[deleted]
- srik 16d agoIt's less about proving a photo's truth than about attesting it.
- scorpiosdayoff 16d ago[dead]
- walrus01 16d ago> Paint the inside of the box using Vantablack But you're only allowed to do that if your name if Anish Kapoor
- zimpenfish 15d agoAlso I think if you're rich enough to be able to coat the inside of a cardboard box with Vantablack, you've probably much easier ways to get misinformation out to the public than photographing a monitor in a cardboard box...
- ricksunny 16d ago>I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge. There’s no such thing as a Golden Gate Bridge. Prove it.
- baxtr 16d agoThis sounds like it could be done, but the costs for doing so are comparably high. I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage. That’s a tradeoff I can live with.
- dgellow 16d ago> but the costs for doing so are comparably high You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar
- Glyptodon 16d agoI suspect they have ways to ID at least some things like this somehow in ways that will lead to key revocation.
- mw888 16d ago> I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge. While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified. It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.
- Gupie 16d agoWon't the focus length of the camera be wrong?
- est 16d ago> take a picture of an already edited image I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter. The "digital negative" in DNG format can be used to analyze the authenticity of the content.
- peri-cl 16d agoIt's even easier than that. You just wait for someone else to figure out, some photography professional with fancy equipment and a hacker-y mindset, and you pay them to sign your photos for you. Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed. Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...") It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.
- deleted 16d ago[deleted]
- eutropia 15d agoI think the timestamp attestation of the digital negative puts a real hamper on this, because it puts a bounded time window on the photo as part of the cryptographic chain of evidence. So if you're the proud owner of "literally the only photo of a ridiculously unusual event in a highly public area" which is bounded to either a plausible 15-30 minute window or a sketchy March2026->Now window, people can do something like "hey, gee, did anyone else see that UFO over the golden gate bridge at 3pm?" plus, you know, the confidence score from their secret neural network, which has an unknown scoring function.
- rlt 15d ago"As part of developing the secure digital negative, PCC computes a confidence score that assesses whether the image has the physical characteristics expected of raw output from our camera sensors. Before the developed reference image is signed, PCC sends the photo GUID, sensor ID, and this confidence score to a companion service, which records them and updates the running score associated with that sensor." I wouldn't be surprised if it's also possible to detect the differences between a photo of a real scene and a photo of a monitor or printout displaying a photo of a real scene, given they have the raw sensor output. Not sure if they're doing anything like that.
- furyofantares 15d agoIt doesn't need to be bulletproof to be very valuable. However much effort is required to fake it - it's proof that the image is either legit or that much effort went in. There's TONS of cases where it's plausible for someone to have put in the effort to fake a photo with AI (nearly zero effort required) but not remotely plausible that they set up some elaborate high quality photo of a fake. It's also much more damning if you get caught faking it. Think of the examples where police have been caught posting altered images on social media. The lame excuse that some intern didn't realize it would do more than just upscale the image won't fly if some elaborate setup was required.
- HALtheWise 14d agoWe're talking about a 48MP camera here, so finding a sufficiently "high-resolution monitor" to pull this off is probably more difficult than you expect. Especially because without at least a few times as many pixels as the camera, it's likely that there will be detectable moire patterns in the image. My guess is that a physical print is more fruitful, but it's still a pretty tricky task to get high enough dynamic range and such to truly fool the sensor. This sort of concern is presumably why Apple says "Using a neural network with hidden weights, PCC computes a confidence score for the photograph." I'm assuming that things like moire-patterns from pointing the camera at a screen would be caught by that check. It's of course physically possible to fool the sensor, but at some point it becomes cheaper to just build a UFO and fly it over the actual Golden Gate Bridge.
- puppycodes 16d agoterrible idea... but im sure it will popular with 60 year olds watermarking their pictures of sunsets.
- SXX 16d agoWaiting for "Apple verified" photo of some important politician doing something wildly inappropriate. Scrapped in 3..2..1..
- jithinsankar 16d agoWhat if someone take the photo of the forged photo displayed on another device, doesn’t the forged photo become an authentic one?
- brookst 16d agoSure, if it’s believable that the shot was perfectly flat at, what, 2 feet away?
- SoftTalker 16d agoA photograph by itself should never be considered proof of anything.
- walrus01 16d agoso what happens if you display an extremely high res image of a 100% AI generated fake-something on an 8K display in a photo studio room and take a picture of it with the camera? it gets tagged as authentic.
- tobyhinloopen 16d agoThat’s a lot of money and effort for a fake photo
- Gigachad 16d agoThe timestamp wouldn’t match the event being depicted and the geotag would show the studio. And the depth sensing would show the image as flat.
- petu 16d agoWas photo not authentic? Think of it "as seen by an iPhone", not "this is authentic event" verification. But Apple likely would reject such photo because of inappropriate depth map / LiDAR data.
- HALtheWise 14d agoAn 8k monitor is typically 33 million pixels, and the sensor here is 48MP, so the resulting image is going to show at least strong moire patterns, and possibly individual pixels. Note that Apple does have a secret neural classifier on their servers looking for that kind of pattern. I also suspect that getting enough dynamic range out of a screen is tricky. None of this is impossible, but it could make it really expensive to produce an image that passes forensic analysis.
- sehw 16d ago[dead]
- akersten 16d agoThe fundamental issue isn't technical. It's that people will see the "certified real" tag and just take the image for face value of whatever narrative someone wants to convey. They'll see the "Real Photo, Verified by Apple" and their brain will short circuit [0] I don't think we should have this, for that reason alone (but many others too). [0]: https://imgur.com/fVPkpuQ https://imgur.com/fVPkpuQ
- otterley 16d agoI’m pretty sure “certified real” aren’t the words Apple will use, nor do they use it in this document. The words to describe the technology were chosen with care: semantic verification, attestation, tamper evident, etc.
- HighGoldstein 16d agoThe average person already does this with obvious AI slop.
- saagarjha 16d agoSeems kind of concerning that using this at all means you send your image to Apple’s PCC machines.
- solenoid0937 16d agoPresumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated. PCC is quite good, about as close to private remote compute we can get without doing HME.
- politelemon 16d agoIt would be incorrect to presume that.
- qazwsxedchac 16d agoIf homomorphic encryption is not involved, how does Apple not have access to the raw image data being sent to PCC? (Genuine question)
- mitxela 16d agoIt's something like SGX, which they pinky promise isn't breakable, even though intel stopped supporting SGX because it was too breakable.
- wky 16d agoEdit^2: On triple reread it sounds like the first pass ("Image Capture") sends the image metadata hash to be timestamped, whereas the second pass (Reference Image Development) sends the image itself but is not what actually creates the timestamp attestation. According to Apple[0][1] it sounds like the second pass (development) only happens when the reference image is actually viewed, which means that your image isn't sent if you never view the reference image? [0] https://support.apple.com/guide/iphone/view-reference-images-iphwvm89mgxhnqr/27/ios/27 https://support.apple.com/guide/iphone/view-reference-images... [1] https://www.apple.com/legal/privacy/data/en/reference-image/ https://www.apple.com/legal/privacy/data/en/reference-image/ > When you take a photo in Reference mode after tapping Reference Mode, your device will include reference image information in the photo’s metadata. If you then view that photo and tap the Reference badge on your iOS device or click it on your Mac, the device will send the raw photograph, metadata about the photograph like the sensor’s signatures and the time frame in which the photo was captured, as well as the sensor’s unique hardware identifiers to Private Cloud Compute. Edit: On reread it seems they do in fact send the actual photographic data to PCC, which I presume has some reason over signing metadata on-device? Original mistaken post is below for transparency. You can always not use the reference image mode, and according to the article you send a hash of the signature of the photograph, so all they would know is you took a photograph in reference image mode at some point in time before the request.
- wky 16d agoThe timestamp system seems like it provides more benefit than signing the image data itself, at least in terms of difficulty to fake. As long as rolling back the stored timestamp token is prevented, I would have to find a phone that never updated its timestamp after the time I want to fake. Of course you could potentially find a phone that last connected to Apple's servers with a plausible timestamp. Even then the upper bound of when it signs the photo after reconnecting to the internet will raise eyebrows if you take too long to find the phone and fake the photo, so it effectively raises the bar to having to take the fake photo roughly simultaneously with the time the event purportedly took place anyway.
- scorpiosdayoff 16d ago[dead]
- 0xWTF 16d agoHot damn. I've described this concept before, obviously not to this level of detail, but leaving this comment in here in case I can find my old comments. A bunch of people have poo-poo'd my proposals, but glad to see a serious actor really executing it. Probably no one at Apple ever read my posts, but it sure does feel good to see something executed. Hopefully it sticks.
- ed_mercer 16d agoLots of criticism here but I think this is extremely promising. When this tech is extended to videos and perhaps even other forms of media, I think it has the potential of stopping all slop!
- Hoftheater 16d agoAll slop? I'm sure that some "Shrimp Jesus" or "Talking Strawberry" was never considered to be authentic by anybody. There is a lot of useless AI generated content of which everybody knows it's AI generated littering the web. Having it marked as AI will not stop that.
- otterley 16d agoHow do you figure?
- account42 16d agoIt's extremely dystopian. This will result where you need an Apple or other big tech device in order for anyone to believe you.
- tgsovlerkhgsel 16d agoThis is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification). Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.
- doctorpangloss 16d ago> People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves. True. > raises the bar but could be bypassed with enough effort. Anyone can spoof this. Apple cannot stop spam iMessages. They can't stop someone from rendering their privileged UI inside a browser viewport. People copy and paste remote script executions from convincing captchas. This whole provenance thing is a red herring. You agree with me, but there's truly not a single application for this that won't be exploited.
- itake 16d agoI don’t understand what this brings to the table beyond what we’re currently doing. Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.
- 16d ago
- phkx 16d agoI‘ve been wondering whether the contact tracking features introduced for Covid 19 could be used to verify that pictures of an event where taken by people who were actually around the scene. That way you‘d have some reassurance that a given picture was actually from the event. Combined with pictures from different angles from different people and some kind of verified photography should make alterations harder.
- Gigachad 16d agoI’m fairly sure that the contact tracing feature has been removed now. And it wouldn’t be needed anyway, the iPhone location services are far more useful. I imagine the geotag could be included with the verification. Location services is quite hard to trick. To the point people have gone to the lengths of putting iPhones inside a microwave for RF shielding and setting up fake phone tower signals inside to trick the phone in to unlocking the hearing aid feature on AirPods for unapproved countries.
- phkx 16d agoIndeed, that may simply be it. You would want to verify time and date. When coming up with the thought I was looking for ways to crowd verify real world events.
- tjpnz 16d agoToo much potential for revealing the identities of others there.
- phkx 16d agoThe functionality included time-based rotation of the identifier that supposedly at least notably increased the effort to identify/track people over a longer time frame. I never dug into the details, but I figure that works better with short-term contacts and may break if you are in contact with many people over a longer time frame. Also, like contact tracking, it should be opt-in, so that you explicitly could act as ‚eyewitness‘.
- jsrozner 16d agoSeems to lead us down the slippery slope of requiring an Apple device, or a Google device (e.g., https://cybernews.com/privacy/google-qr-code-recaptcha-requires-approved-phone/ https://cybernews.com/privacy/google-qr-code-recaptcha-requi...), or the device of some other entity (that may be mostly non-aligned with democratic values) in order to participate in society. The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.
- modeless 16d agoThis is so insanely complex and requires placing trust in the correctness of so many pieces, many of them closed-source. And uploading every verified "developed" image to Apple's servers. And giving up full control of the software and hardware you "own". All to achieve a goal of "verifying" photons, which is only a part of the real problem of verifying the truth of an event that was photographed. I hope that companies and governments don't start forcing us to use this stuff by requiring it for their services.
- Gigachad 16d agoBecause it’s impossible to implement this feature in open source and out in the open. It relies on a locked down image pipeline and hidden key.
- jeroenhd 16d agoThat's also why the approach is fundamentally flawed. The open-ish C2PA protocol has been "defeated" by tricking phones into signing arbitrary data already. The even-more-closed Apple version can be defeated the same way and relies on Apple to be the sole arbiter of truth.
- kingleopold 16d agoany other similar approach is also dead on arrival, I can't believe so many apple engineers fails to see it? it's like siri 2012 all over again
- PunchyHamster 15d agoIncorrect. There is nothing here requiring closed source. Only private keys need to be kept private for obvious reasons
- mcfedr 15d agoits impossible in closed source. there is no reason to believe it does what it says it does. only private keys in the chain need to remain secret.
- codetiger 16d agoAm wondering why no one is talking about traceability of Photos. Ex: CSAM which Apple was fighting for a long time. I thought this feature was the answer to provide proof of who shot the picture.
- codetiger 16d agoOr have I understood the feature's capability completely wrong?
- bawolff 16d agoI dont think this is relavent to that use case. It seems like this proposal would be an optional off by default feature. They also seem to be going to lengths to make it privacy first so the verified photos cannot be linked to a specific photographer.
- rickdeckard 16d agoAccording to the description in the article, "an outside observer cannot determine whether any pair of reference images were taken by the same device." and they "avoid even implicit public association between different photos taken by the same sensor" Whatever that means in detail...
- Gigachad 16d agoNothing stops you not verifying, or simply stripping the verification off. What you are prevented from doing is adding a verification to a photo outside of the iOS image pipeline, or modifying the photo with the verification still in tact.
- asaddhamani 16d agoI skimmed the whole article and I didn’t see a single image so I’m confused. Is there some watermark of some kind or where is this metadata integrated? Because if it’s just metadata then I need to parse each photo I come across manually, and if it’s a watermark it can be faked because I won’t manually validate every single image I come across to prove the watermark isn’t fake.
- bawolff 16d agopresumably the metadata reader app would be integrated into the photo viewer app which would verify the digital sigs. I have my doubts about this scheme but this is not one of them. If the point is that someone in principle could verify, that is enough for it to be useful, even if not everyone does.
- gmueckl 16d agoApple has to allownpost-manufacruring exchanges of camera due ton right of repair legislation. This requires them to publish pairing tools that are to be used during the repair process to update all the cryptographic vérification chains in the device. Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?
- dsign 16d agoI think this is really good and kudos to Apple for implementing it. The first question that popped into my mind was "what new scenarios of government X forcing Apple to do 'terrible thing' to 'individual' this enables?", but I can't think of anything. It seems that all government attack vectors this feature enables are of the type "government X forces Apple to do 'terrible thing' to 'Apple'", i.e. a government can try to force Apple into certifying a narrative, and of course Apple is going to fight tooth and nail the lack of credibility that would result from that.
- giancarlostoro 16d agoApple would have to be the only company around and by the time Apple “loses” in court its too late.
- dsign 16d agoThough, on second thought, "government X could force Apple to disable feature for members of group Y" seems possible. I'm sure you can come with "Y" quite easily, heard anything about Ed Sheeran's tour?
- bawolff 16d agoI mean, the obvious one is that they can revoke certification of a photo despite it being real. The harder one is they can force apple to certify a fake photo. the part that would be very hard but not outside the realm of plausibility, is that gov could force apple to introduce a bug in its pcc platform to link photos to the photographer in order to track and arrest inconvenient people. Apple says there are a bunch of protections against that but ultimately you are trusting apple to do it the way they say they are. This entire system relies on trusting apple
- intrasight 16d ago> This entire system relies on trusting apple It does indeed, and that is a fundamental flaw. but as has been discussed here, it is better than the alternative, which is no verification. During the pandemic, I outlined a scheme for using blockchain technology for image provenance and authenticity tracking. The idea was that instead of any one entity assigning authenticity that it would be done in a crowdsourced manner and that the device would overlay a score whenever an image or video is shown to a user. My assumption was that the desire of users to see such scores would force all manufacturers to implement this open protocol. But my approach suffered from chicken and egg problem, which Apple's does not.
- jeroenhd 16d agoThat's a lot of words to say "we re-invented C2PA but made worse by getting our servers involved somehow". Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. The timestamping server is a nice idea (though I don't see why they can't just use a normal timestamping server, I guess to keep control over the protocol) but it doesn't solve the fundamental problem that defeated C2PA.
- Gigachad 16d agoIt looks like the reason for the custom timestamp setup is to assert and upper and lower bound on time. A normal timestamp server can asset it saw the image at a certain time but not that the image wasn’t created much earlier. This setup, the image processing pipeline can immediately attach the last seen timestamp to the photo as a lower bound, and then connect to the network to get the upper bound time. If there is too much of a gap between the upper and lower bounds then the image becomes suspicious.
- jeroenhd 16d agoThe lower bound is specified by the device, you don't need support from the timestamping server for that. Determining if this timestamp is or isn't suspicious can be done at verification time. The timestamping feature itself makes sense from a verification perspective (though the privacy implications are questionable, of course), but I don't think it necessitates an Apple-specific setup. This approach does have one benefit, which is that Apple gets all the (meta)data to determine if something is or isn't "real", rather than letting the verifier decide beforehand. I can only imagine the outrage if Google or Microsoft added a "upload all of your photos to us and we will mark them are real or fake" protocol, even with all of the verified compute gaff.
- dagaci 15d agothis already happened -> https://news.ycombinator.com/item?id=49421158 https://news.ycombinator.com/item?id=49421158 -> My passing comment mentioning Apple Reference Image in the same thread was moderated down into oblivion for some reason!
- djtango 16d ago> Modern cameras rely on sophisticated image-processing algorithms to produce the final viewable image, so certifying that an image accurately reflects what a real camera sensor captured requires a chain of trust covering the sensor as well as the computational photography software that interpreted the capture. So if you jailbreak or root your phone what happens? Is this a trojan horse into making rooted phone cameras unverified? Just like how Linux machines can't watch Netflix in 4K
- deleted 16d ago[deleted]
- Gigachad 16d agoIt seems like the two signatures on device are processed on the camera sensor itself, and then post processing is signed by the SEP. Neither of these would be compromised even if you have a full jailbreak.
- jeroenhd 16d agoYou'd need to jailbreak the camera sensor chip and the phone's secure element. Which isn't exactly impossible either, but it's harder. I don't think it has been done yet (but I'm sure it will be at some point).
- bawolff 16d agoOn top of that, they have a revocation system in place to try and deal with that eventuality.
- jeroenhd 16d agoIt all depends on when or if Apple actually activates this system. Unless Apple can prove when a compromise first took place, they would have to retro-actively classify all iPhone pictures taken before discovery of such an exploit as "potentially fake". Plenty of certification bodies refuse to revoke their given certifications because of brand damage or effects on their customers. That's why cryptographic verification of things like Secure Boot are basically broken on most systems by default. If an independent security researcher does it and Apple rolls out fixes a month later, I can see it happening. If it turns out a government agency hacked the platform "at some point", I have my doubts Apple will retroactively reject all of their iPhones' signatures.
- rvz 16d agoMore sales to Apple, to prove that your image is real. Hardware wins.
- bawolff 16d agoThis is cool, but also seem really complex and i'm not sure it makes sense pragmatically. - it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact - i guess you need internet to take a picture. :( - You are puting a lot of trust in apple's private cloud compute platform. - apple can revoke certification of a picture. I understand the appeal of this, all security systems eventually have failures, so its important to be robust against this. However if the point is to prove a picture is real (especially politically damaging ones), this is giving a lot of power to apple. Its meant to be in competition with C2PA, and i guess the idea is its much more secure against complex hardware attacks. However i think its worth asking who the target audience is and what threats they face. The primary issue with AI is it makes fake photos easy, not that it invented fake photos. Even Stalin manipulated photos back in the day. It is not a new thing, the problem is just being overwhelmed with them. with that in mind, are complex hardware attacks really that important? We just need to increase the difficulty floor, not solve fake photos for all time. No matter what you do, people can still use practical effects. It seems like this is almost trying to thwart spies and nation state adversaries, well forgetting that such well funded groups have the budget to fake photos the old fashioned way or if they really cared, bribe their way into apple.
- calmingsolitude 16d ago> it sounds like its an optional mode you have to enable It’s opt-in because your photo is sent to Apple’s servers. Only if it were on-device should they even consider making it default. > i guess you need internet to take a picture Not really, internet is required to process the reference image, but that can happen later if you’re not currently connected. > are complex hardware attacks really that important? No, but the floor shouldn’t be “trivially exploitable” like C2PA[0]. It’d be interesting if there were a middle ground but we don’t have anything like that as of now. [0] https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html
- bawolff 16d agoI'm not sure i would describe the linked exploit as "trivial", but nonetheless point taken. Ultimately though, i think all this might just mean we do not have a practical solution to this problem. just to throw out some naive ideas, maybe the solution is to just sign the raw camera output and embed it in the metadata. If this is an optional feature meant for photojournalists, does file size really matter?
- ErneX 16d agoIt only works in one of the 3 lenses though.
- RandomGerm4n 16d agoThis approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification system for a company that the manufacturer claimed was absolutely secure. All it took was rooting the smartphone and bypassing the root detection. After that, you could play any pre recorded video, which would then be recognized as camera input. Under those conditions, it was easy to manipulate a video so that a company employee would consider it real enough to verify the test subject. It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
- bayindirh 16d agoHow do you plan to replace the sensor of your phone's main camera (with a device you need), and let it authenticated by the OS, and then create authenticated photographs with it? Apple/iOS already have part authentication pipeline on its security sensitive devices (TouchID/FaceID). How can camera sensor can't be considered one of those and needs attestation before enabling? From the document: > Apple Reference Image leverages custom-designed image sensors in iPhone 18 Pro and iPhone 18 Pro Max to ensure reliable capture of image data, and relies on Private Cloud Compute, which provides a computational environment for secure photographic processing that cannot be subverted even in the case of device compromise. (emphasis mine)
- berkes 16d agoVery much agreed. I believe many of the problems we have, need social and human solutions, especially when the technical solutions are hard or impossible. Like here, where we can no longer trust images to depict reality and act as proof. While its admirable that people look for technical solutions, the obvious social solution is to admit that images are no longer absolute proof and will become less and less trustworthy¹. And, by admitting that, change our relation to these artifacts. Sure, that will change journalism, police work, legal systems, etc etc. But pretending that we can rely on images might allow journalists, police, judges to continue relying on them as if they're authentic, which is a far bigger problem over a longer period. Social solutions require effort, demand flexibility, take time and are messy. But this is what humans are and do. Not everything has a technical solution. Not every technical solution is the best option. ¹ we already saw this when people claimed "someone must have hacked my iphone and put it there". For decades we've seen this with images that are deliberately taken in a way to spin a story (like the illusion of a large crowd or spacious room through carefull angles or fancy lenses). And I predict we will see this with security footage, "live streams" or even bodycams with "ai enhancement". Just imagine a bodycam or a dashcam that manipulates the output to benefit the owner. "A dashcam that will prove your innocence in assumed traffic violations" or such.
- keiferski 16d agoHey I predicted this awhile ago. Although it is kind of an obvious solution so I can’t claim much insight hehe. https://news.ycombinator.com/item?id=44135416 https://news.ycombinator.com/item?id=44135416
- jeroenhd 16d agoBy the time you made your comment, such a system had already been invented, even partially rolled out: https://en.wikipedia.org/wiki/Content_Credentials https://en.wikipedia.org/wiki/Content_Credentials Apple's protocol differs in that it requires a timestamping server to sign the file and centralising Apple as the single arbiter of truth. An excellent addition, if you trust Apple and the governments they're friendly with (I don't, especially the latter part).
- keiferski 16d agoOh yeah I’m sure it was already a thing. Just cool to see that it’s become more mainstream.
- ozlikethewizard 16d agoSomewhat tangential but is "most secure consumer mobile device" actually correct? Does an iPhone beat out a grapheneOS android, or would that not be considered consumer because of aftermarket changes? Seems like a pretty bold claim but I know apple is pretty damn good with security (as long as you dont count Apple as a security risk themselves)
- microtonal 15d agoFrom leaked Cellebrite presentations, it seems GrapheneOS is more secure. But it's easy for Apple marketing to move the goal posts by adding words like 'consumer'. They do this all the time in their marketing, like: Force sensor with volume swipe arrives on AirPods 5, a first for the open-ear form factor, adding the ability to quickly adjust volume by swiping up or down on the stem. Add some qualifiers so that you can call yourself 'first'.
- petesergeant 16d agoI feel a little discomfort about this: moving towards a world where photos were plausibly deniable felt good for privacy, this feels like a step further away.
- rickdeckard 16d agoTo me the weakest spot of this whole endeavor is how this will create false confidence in a story just because the accompanying images pass Apple's verification. Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy. Okay, fine. Will work for sure, this will disrupt the trusted-imaging market and moreover make Apple a service-provider in this industry (with the ramp-up cost paid by customers buying iPhones for entirely different purposes). But creating this impression and media-buzz that Apple is now verifying more than just the digital authenticity of an image may shift the public scrutiny of MANY media/online statements: There is a risk that random claims (and propaganda) will be given more credibility in the public eye just because they came with images that were confirmed to be "taken like this on an iPhone"
- intrasight 16d ago> images that were confirmed to be "taken like this on an iPhone" No, because images will be confirmed to have been taken on "this iPhone". The New York Times will be able to publish an article and to attest that the photographs shown were taken by their journalists, and then your user agent will verify that provenience.
- rickdeckard 16d ago>No, because images will be confirmed to have been taken on "this iPhone". Actually the description of Apple makes explicit statements AGAINST that: Quote: Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device
- Obscurity4340 16d ago> an outside observer An inside observer can tho, and if they know or have it, cant they be subpoenaed and forced to disclose the identity? This sounds pretty bad for journalists/sources. Why is this needed now of all times?
- demibabs 16d ago> or via software-level jailbreak of the device. I’m surprised that even Apple calls jailbreaking, jailbreaking. Doesn’t that imply their own software is a jail?
- mitxela 16d agoJailbreaking is connoted as bad because it's something criminals do so they can do more crime.
- pmlnr 16d agoAt this point it'd be easier to return to film.
- jamil7 16d agoSome of us never left :D
- 9shrey 16d agothey said the same thing about synth id didnt they? waiting for someone to reverse engineer this too lol. the future will include a lot of time spent trying to figure out what is real. and that may be good cause to truly enjoy something real, one will have to go out and stop being indoors.
- chaz6 16d agoI feel like for verified photography to be useful, it really needs a depth sensor so you can tell the difference between an actual scene and a photo of a photo. Granted, you could 3d print a scene from a photo, but at least for now it should be pretty obvious to tell the difference.
- rockbruno 16d ago"iPhone 18 Pro and iPhone 18 Pro Max" So the iPhone Duo won't have it?
- rasguanabana 16d agoI wonder why they went for ECDSA and RSA and how a freshly initialised sensor obtains enough randomness to create an unrecoverable private key. Other than that the overall protocol looks very interesting.
- londons_explore 16d agoA camera has literally tens of millions of thermal noise sensors...
- throw1234567891 16d agoThe power of marketing. EU wants Apple to implement digital fingerprinting to fight CSAM: overreach of power, total invigilation, nonono! Apple cannot comply! What about our privacy! Apple implements the feature and sells it nicely wrapped in a PR material: oh, that's cool, innovative!
- mayhemducks 15d agoThese two things, fingerprinting to fight CSAM, and the Apple Reference Image, are not the same. They have completely different goals and completely different implementations.
- cedws 16d agoI’m fine with such technology so long as the courts don’t treat “verified” images as truth.
- grishka 16d agoAnd why does someone have to trust Apple? Everything "security"-related that comes out of Apple lately somehow always assumes that Apple is to be unquestionably trusted. And, yeah, I'm incredibly tired of this whole concept of a device you own acting in someone else's interests. This needs to stop and it needs to happen 10 years ago.
- fckgw 15d agoEvery time they say "trust us" they publish a whitepaper with technical details explaining why and how they can be trusted. They're generally very good about these things.
- grishka 15d agoYou still have to trust the parts you can neither observe nor reverse engineer. So, everything organizational and everything that happens on their infrastructure.
- EmbarrassedHelp 15d agoApple's failed attempt at adding client side scanning for illegal content should have made everyone weary of trusting them when it comes to security and privacy. The idea should have been killed long before it even became public.
- SeriousM 16d agoAs sexy as apple can be: the blog post just shows how unsexy security is for apple.
- RRRA 16d agoWhen is this turned into an RFC?
- VortexLain 16d agoI already can see this to be used in an effort to force everyone to use smartphones with proprietary corporate spyware.
- tantalor 16d ago1. Generate fake photo 2. Take a photo of it with iPhone 3. Apple's fancy reference image thing now says "omg it's real you guys"
- clarkmoody 15d agoMy comment on this idea from 9 years ago: https://news.ycombinator.com/item?id=16291641 https://news.ycombinator.com/item?id=16291641 First reply was exactly the same as most of the top-level comments here today: "That doesn’t prove anything. Make your fake video, point your phone camera at it, record." Of course, I'm sure someone else had thought of something along these lines in the 90s, I just didn't have a citation to hand.
- hashhar 14d agothey should pay you
- dom96 15d agoHow is this different to Content Credential and why isn’t Apple implementing that?
- antifarben 15d agoI'm waiting for next year's talk at the CCC about it.
- Roark66 15d agoThat is actually a pretty good idea.
- lern_too_spel 15d agoAn even better idea would have been to integrate it as an extension for C2PA, which already has an ecosystem developed around it. The capture portion of the ecosystem has lots of problems, and this is one potential improvement.
- eutropia 15d agoI'm super excited for all the people saying "lol just point it at a genai photo" to make a blog post later about how they successfully subverted this approach and fooled people into believing their image was verified without detection as a fraudulent image. because that'll be a lot more interesting than a reflexive snarkpost about the first idea that came to mind to hypothetically defeat it.
- int32_64 15d agoI would also like the reference image from the sensor instead of the blown out HDR monstrosity Apple removed the ability to turn off after the iPhone 12.
- deltoidmaximus 15d agoThis is another interesting point. iPhone's do a bunch of post processing to improve image quality. What exactly are we signing as real and not AI manipulated here? How much image processing is allowed before it isn't verified? (do panoramic stitched photos count?)
- heddhunter 15d agoThere are myriad 3rd party camera apps that will give you RAWs straight off the sensor. Apple also has its "ProRAW" format which is a nice middle ground.
- albert_e 15d agoThinking aloud about failure modes / edge cases: If i create a high quality deepfake image, project it on a large screen and take a photo of that image with an iPhone (+apple verified image secure tag) ... would that resulting image be considered "authentic" by default? Would digital forensics accessible to lay people still be able to fact-check and call out misuse / fakery of the new secure tag.
- MBCook 15d agoIt is authentic, in a way. It’s exactly what you took a picture of. I do wonder how easy that would be to detect, but I can’t help but think some sort of artefacting or something would show up.
- deleted 15d ago[deleted]
- mayhemducks 15d agoThe system is not for detecting deepfakes. It is for proving that the data captured by an apple camera's sensor was not altered by some 3rd party hardware or software chain.
- albert_e 15d agoFair enough. So the chain of trust is ... Personal credibility of the person taking the photo with iPhone (till the moment picture is taken) + tamper-evident protection against unauthorized or anonymous edits and manipulation (after the iphone photo is published and circulated) Apple cannot (of course) vouch for the former.
- icar 15d agoThis is something I always had in my mind: sign at photo taken, at least you know it comes from a phone and it's not AI generated
- bsenftner 15d agoNow I want to learn about "Apple Reference Video" and learn how to work with that to create verifiable video for journalists, news, documentary and other non-entertainment forms of media.
- preetx 15d agoI'm just checking, how it's work technically
- itintheory 15d agoI just finished reading a scifi book called Venemous Lumpsucker which had this type of system as a minor plot point. An interesting twist was that there were essentially smart-contract based non-disclosure agreements that could effectively disable attestation for photos and videos on a specific device that had consented to the NDA.
- NeoByte 15d agoCanon tried this 20 years ago with DSLRs. Nikon had an authentication system. Both were broken. The keys ended up on Pastebin. Apple's hardware security is better, but history suggests this is a temporary advantage. The real question is whether the system will be revoked when (not if) it's broken, and whether Apple will have the guts to retroactively invalidate millions of "verified' photos"
- iririririr 15d agokeys went public way after it was abandoned. think for one second, who cares enough about image authenticity AND publishes raw photos directly from a camera with zero post production? this was, is, and always will be useless and only serve the purpose it's fulfilling here: talk about the brand in a higher than thou privacy bastion.
- tlhunter 15d agoIn this case keys are per-sensor and revokable. So surely if someone spends a lot of money and extracts a sensor key it can only get minimal use before revocation?
- NeoByte 12d ago[dead]
- manso_ilands 15d ago[flagged]
- dsalzman 15d agoReality verification is a very important problem and I'm glad Apple and others are working on it.
- gcanyon 15d agoWe need this for video and audio, with metadata baked in. “I didn’t say that.” “This recording says you did.”
- lwhi 15d agoMaybe the solution is even simpler. Use film.
- mayhemducks 15d agoI had the same thought. Like if it's really that critical to make sure an image was not altered, go analog. You can't photoshop something that doesn't have pixels!
- mrinterweb 15d agoI hope Apple contributes to an open standard for this, instead of keeping this proprietary. In the emerging world of generative AI, we need this more than ever. Not just iPhone, but ideally most camera systems will have some kind of verifiable capture mode.
- Velocifyer 15d agoThis will create a social problem of people discrediting images by a niche camera vendor or by a bootloader unlocked phone or from budget cameras or or from niche camera manufactuers from film cameras or from cameras that are old, while still allowing for advanced telecine attacks.
- nxtfari 14d ago> Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device. Image contents are not exposed to Apple or anyone else. I am curious if the PCC processing makes it resilient to the method from a couple years ago of fingerprinting the microdistortions in an individual phone lens to tell when two photos were taken by the same phone.