4 ms·
Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a hig
by tristanj 10d ago
Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image.
Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.
To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.
I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
- nalekberov 10d agoExactly, a wave of “verified” fake images are coming.
- osy 10d agoIt also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve. > Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago. Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.
- BugsJustFindMe 10d ago> "But that's not the problem they're trying to solve." It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened". It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself. Likewise in "distinguish between photographs that depict real events and...".
- spiderice 10d agoThis is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.
- BugsJustFindMe 10d ago> This makes it like, a thousand times harder to fake a photo than it would otherwise be. The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forgery is attested by Apple. So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
- porkshoe 10d agoYou worry that a technology that you have never used nor evaluated might not work in practice... Therefore because of your worry (which is based on remarkably little information), it's a bad technology? Come the fuck on. That's beyond luddite bullshit.
- BugsJustFindMe 10d agoIs this you? https://news.ycombinator.com/item?id=49685271 https://news.ycombinator.com/item?id=49685271
- Gigachad 10d agoThis has been possible since the beginning of photography and yet I can’t think of a single scenario where people have been tricked by a staged photo. Yet every day hundreds of millions of people are being fooled by AI generated photos.
- zimpenfish 9d ago> I can’t think of a single scenario where people have been tricked by a staged photo Let me introduce you to Sir Arthur Conan Doyle and the Cottingley Fairies[0]. "Doyle was enthusiastic about the photographs, and interpreted them as clear and visible evidence of supernatural phenomena. [...] the photographs were faked, using cardboard cutouts of fairies copied from a popular children's book of the time" [0] https://en.wikipedia.org/wiki/Cottingley_Fairies https://en.wikipedia.org/wiki/Cottingley_Fairies
- pndy 10d ago> This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". Which surely will be useful in ID verification on the Internet; Android devices most likely will follow with same or similar solution
- amanj41 10d agoSony's analogous solution (https://authenticity.sony.net/camera/en-us/ https://authenticity.sony.net/camera/en-us/) claims 3d depth information is built in, I'm sure Apple could do the same given at least some iPhone models have LiDAR on the back
- tristanj 10d agoThis would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances. Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.
- dd8601fn 10d ago> I do this frequently when I want to take a photo through a window. I feel really dumb for not having thought of this.
- amanj41 10d agoI see, yeah good point. Perhaps the lack of reliable depth data also be baked into some signed metadata property. Wouldn't tell you definitively if something were fake, but could be a context clue if a particular photo were dubious I suppose.
- Cthulhu_ 10d agoWhat they could do instead is record a video while taking a photo, the subtle movements (at least if handheld) might have enough information to get an approximation of depth (parallax).
- pveierland 10d agoClaim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult: https://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/20260268025 https://image-ppubs.uspto.gov/dirsearch-public/print/downloa... The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.
- geokon 10d agofurthermore, couldnt you do parallax from the multiple cameras as well as flicker the flash? seems pretty easy to make it sufficiently difficult to trick the system
- BugsJustFindMe 10d agoiPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.
- pveierland 10d agoStill, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.
- BugsJustFindMe 10d agohttps://news.ycombinator.com/item?id=49721878 https://news.ycombinator.com/item?id=49721878 > increasing the difficulty of producing a forgery The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forgery is attested by Apple. So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
- dinobones 10d agoIs this really that big of a flaw in this implementation? I don't think it's worth the additional complexity to address it. (Encoding depth information in some way, trying to detect "flat" surfaces, whatever). Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.
- BugsJustFindMe 10d agoYou mean that it is sometimes very easy. But it is also sometimes impossible. You seem to be thinking only of poor quality photos of poor quality prints, but there's no basis for assuming those characteristics.
- nvme0n1p1 10d agoYeah, such systems have been tried (and been hacked) for decades now. https://www.elcomsoft.com/news/428.html https://www.elcomsoft.com/news/428.html https://blog.elcomsoft.com/2011/04/nikon-image-authentication-system-compromised/ https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio... You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin. It's funny to see Apple fall into this same trap.
- Rohansi 10d agoTo be fair Apple of all companies have the best shot at pulling it off. They've been perfecting their hardware security for years for other reasons and this is just another way to take advantage of that work. But yes, if someone breaks it then the trust is gone and it casts doubt on all of the photos that were ever captured using the broken system.
- deleted 10d ago[deleted]
- srik 10d agoIt's less about proving a photo's truth than about attesting it.
- scorpiosdayoff 10d ago[dead]
- walrus01 10d ago> Paint the inside of the box using Vantablack But you're only allowed to do that if your name if Anish Kapoor
- zimpenfish 9d agoAlso I think if you're rich enough to be able to coat the inside of a cardboard box with Vantablack, you've probably much easier ways to get misinformation out to the public than photographing a monitor in a cardboard box...
- ricksunny 10d ago>I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge. There’s no such thing as a Golden Gate Bridge. Prove it.
- baxtr 10d agoThis sounds like it could be done, but the costs for doing so are comparably high. I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage. That’s a tradeoff I can live with.
- dgellow 10d ago> but the costs for doing so are comparably high You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar
- Glyptodon 10d agoI suspect they have ways to ID at least some things like this somehow in ways that will lead to key revocation.
- mw888 10d ago> I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge. While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified. It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.
- Gupie 10d agoWon't the focus length of the camera be wrong?
- est 10d ago> take a picture of an already edited image I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter. The "digital negative" in DNG format can be used to analyze the authenticity of the content.
- peri-cl 10d agoIt's even easier than that. You just wait for someone else to figure out, some photography professional with fancy equipment and a hacker-y mindset, and you pay them to sign your photos for you. Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed. Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...") It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.
- deleted 10d ago[deleted]
- eutropia 10d agoI think the timestamp attestation of the digital negative puts a real hamper on this, because it puts a bounded time window on the photo as part of the cryptographic chain of evidence. So if you're the proud owner of "literally the only photo of a ridiculously unusual event in a highly public area" which is bounded to either a plausible 15-30 minute window or a sketchy March2026->Now window, people can do something like "hey, gee, did anyone else see that UFO over the golden gate bridge at 3pm?" plus, you know, the confidence score from their secret neural network, which has an unknown scoring function.
- rlt 10d ago"As part of developing the secure digital negative, PCC computes a confidence score that assesses whether the image has the physical characteristics expected of raw output from our camera sensors. Before the developed reference image is signed, PCC sends the photo GUID, sensor ID, and this confidence score to a companion service, which records them and updates the running score associated with that sensor." I wouldn't be surprised if it's also possible to detect the differences between a photo of a real scene and a photo of a monitor or printout displaying a photo of a real scene, given they have the raw sensor output. Not sure if they're doing anything like that.
- furyofantares 10d agoIt doesn't need to be bulletproof to be very valuable. However much effort is required to fake it - it's proof that the image is either legit or that much effort went in. There's TONS of cases where it's plausible for someone to have put in the effort to fake a photo with AI (nearly zero effort required) but not remotely plausible that they set up some elaborate high quality photo of a fake. It's also much more damning if you get caught faking it. Think of the examples where police have been caught posting altered images on social media. The lame excuse that some intern didn't realize it would do more than just upscale the image won't fly if some elaborate setup was required.
- HALtheWise 9d agoWe're talking about a 48MP camera here, so finding a sufficiently "high-resolution monitor" to pull this off is probably more difficult than you expect. Especially because without at least a few times as many pixels as the camera, it's likely that there will be detectable moire patterns in the image. My guess is that a physical print is more fruitful, but it's still a pretty tricky task to get high enough dynamic range and such to truly fool the sensor. This sort of concern is presumably why Apple says "Using a neural network with hidden weights, PCC computes a confidence score for the photograph." I'm assuming that things like moire-patterns from pointing the camera at a screen would be caught by that check. It's of course physically possible to fool the sensor, but at some point it becomes cheaper to just build a UFO and fly it over the actual Golden Gate Bridge.