6 ms·
Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has 1. a public/private key exchanged during device-productio
by rickdeckard 19d ago
Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has
1. a public/private key exchanged during device-production (production-cost),
2. the capability to reboot in a cryptographic mode (R&D / component cost) and
3. a cloud-service which then processes the raw data to create a JPG (operational cost)
comes at a premium. Why should this premium be applied on a 99 USD Smartphone?
Which is my whole puzzle on this vector: If the big benefit is for insurance/ID-verification, which apply cost-saving by offloading their process to the untrusted customer, how much they can offload this by requiring their customer to own a 1000+ USD smartphone to provide THEIR service...?
The most I can imagine is insurances offloading their work to OTHER companies, NOT trusting them and therefore requiring them to own a 1000+ USD Smartphone. But even then, why not use a third party app that also runs on a 3y old iPhone and a 99 USD Android device...?
- Topfi 19d agoWe have 99USD smartphones with 1080p+ AMOLEDs, massive 5k amp batteries and very performant SOCs (e.g. Galaxy A16) among other costly, but not vital niceties. I struggle to see how cost could be a factor here.
- rickdeckard 19d ago> I struggle to see how cost could be a factor here. Okay. In good faith, I'll go with you: If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)? Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013. The answer is COST: A camera-module with OIS is a more-expensive component than a module without it. And that's ONLY the component-cost: A OIS-camera doesn't come with increased cost in device-production (it's just another component to place and assemble), no increased cost in R&D (the tech is very mature, all the SW is there) and no running costs (there are no cloud-services required to operate OIS)
- socalgal2 19d agoHow many smartphones have no camera? Zero? Bluetooth? Zero? But they could save cost by not having those. I think they are basically table stakes. If this type of thing becomes required for more and more things then no one will buy a phone that doesn't have them.
- rickdeckard 19d agoYes, the whole insurance self-service is built on smartphones having a camera. But the assumption that smartphone cameras, including those used in 99USD smartphones, will become 100% cryptographic cameras in a few years is highly unlikely, considering that those cameras didn't even gain OIS in the last 13 years despite the feature being highly matured and widely available. Changing the topic to other features won't change that. You seem to lack the understanding how this industry works, and assume that every development naturally just trickles down and becomes a commodity. This is not the case. This cryptographic feature will definitely become available from camera sensor suppliers, first of all likely from Sony. But it will be a feature of premium sensors and will remain a differentiation factor. Sony will not support cryptography to its sensors without additional cost. Device-vendors integrating those sensors then have additional cost in R&D, production AND operations. All this will not be waived and put in a 99USD device. For the other assumption, that "If this type of thing becomes required", I fail to see how this should happen for a mass-market consumer: This feature doesn't authenticate the content of an image, it just authenticates the RAW data of the image sensor. It won't (and shouldn't!) make the user more trusted towards another entity (like Apple mentions themselves in the link)
- coldtea 19d ago>But the assumption that smartphone cameras, including those used in 99USD smartphones, will become 100% cryptographic cameras in a few years is highly unlikely, considering that those cameras didn't even gain OIS in the last 13 years despite the feature being highly matured and widely available. Them becoming 70% cryptographic is enough. The people who need the feature, can get a compatible model. Nobody argued that smartphones sold for kids to game on for example should have it.
- fg137 19d agoWell, that's kind of like DRM and Widevine, which exists on every consumer device.
- rickdeckard 19d agoWell, that happened because in ~2011 the entire media industry announced that they will stop media playback on devices which didn't secure the DRM-keys. As media consumption was fundamental to the Smartphone ecosystem, Google made secure-boot and widevine mandatory. Sure, the same could happen here, but I don't know which industry (or other body) would demand that and have sufficient justification for it. After all, the feature doesn't really change that much for a consumer, the trust-chain is largely unchanged: If I send you a picture and tell you that's my dog, you still have to take my word for it, regardless whether Apple signed the picture or not.
- lotsofpulp 19d agoNot if Apple can identify the dog as belonging to someone else.
- rickdeckard 19d agoApple doesn't validate the content of the image, you will have to trust that it's my dog. You wanna buy it now or not? /s
- PunchyHamster 19d ago> comes at a premium. Why should this premium be applied on a 99 USD Smartphone? It's entirely software. It's R&D cost, with basically none of it in hardware (you technically just need the private key store which even very cheap devices have)