4 ms·
I think the chart exactly shows the weakness that some people have pointed out. Apple's PCC servers at some point in time know the signing identity for a photo
by microtonal 9d ago
I think the chart exactly shows the weakness that some people have pointed out. Apple's PCC servers at some point in time know the signing identity for a photo and Apple's generated replacement signature. The relevant steps from your chart:
- verifies each link and its certificate chain, sensor signature over pixels, SEP signature, device manifest signature
- PCC Submits the commitment (the JPEG hash) to Apple's signing service.
So, at some point in time, Apple's servers have both the original certificate chain and the new replacement signature. If this is recorded, Apple can deanonimize photos and check whether two photos were from the same device/sensor.
Apple's system protects against most state actors, except Apple and the US, unless you fully trust that their PCC is watertight.
(Remember that Apple was part of PRISM and probably also its successor.)
I don't think law enforcement needs it, because when sending/posting a picture, people leak so much metadata anyway.
But people outside the US should certainly distrust these systems.