Top
Best
New

Posted by imwally 1 day ago

Apple Reference Image: A New Approach for Verified Photography(security.apple.com)
511 points | 341 commentspage 2
NeoByte 18 hours ago|
Canon tried this 20 years ago with DSLRs. Nikon had an authentication system. Both were broken. The keys ended up on Pastebin. Apple's hardware security is better, but history suggests this is a temporary advantage. The real question is whether the system will be revoked when (not if) it's broken, and whether Apple will have the guts to retroactively invalidate millions of "verified' photos"
tlhunter 18 hours ago||
In this case keys are per-sensor and revokable. So surely if someone spends a lot of money and extracts a sensor key it can only get minimal use before revocation?
iririririr 18 hours ago||
keys went public way after it was abandoned.

think for one second, who cares enough about image authenticity AND publishes raw photos directly from a camera with zero post production?

this was, is, and always will be useless and only serve the purpose it's fulfilling here: talk about the brand in a higher than thou privacy bastion.

saagarjha 1 day ago||
Seems kind of concerning that using this at all means you send your image to Apple’s PCC machines.
solenoid0937 1 day ago||
Presumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated.

PCC is quite good, about as close to private remote compute we can get without doing HME.

qazwsxedchac 1 day ago|||
If homomorphic encryption is not involved, how does Apple not have access to the raw image data being sent to PCC? (Genuine question)
mitxela 1 day ago||
It's something like SGX, which they pinky promise isn't breakable, even though intel stopped supporting SGX because it was too breakable.
politelemon 1 day ago|||
It would be incorrect to presume that.
wky 1 day ago||
Edit^2: On triple reread it sounds like the first pass ("Image Capture") sends the image metadata hash to be timestamped, whereas the second pass (Reference Image Development) sends the image itself but is not what actually creates the timestamp attestation. According to Apple[0][1] it sounds like the second pass (development) only happens when the reference image is actually viewed, which means that your image isn't sent if you never view the reference image?

[0] https://support.apple.com/guide/iphone/view-reference-images...

[1] https://www.apple.com/legal/privacy/data/en/reference-image/

> When you take a photo in Reference mode after tapping Reference Mode, your device will include reference image information in the photo’s metadata. If you then view that photo and tap the Reference badge on your iOS device or click it on your Mac, the device will send the raw photograph, metadata about the photograph like the sensor’s signatures and the time frame in which the photo was captured, as well as the sensor’s unique hardware identifiers to Private Cloud Compute.

Edit: On reread it seems they do in fact send the actual photographic data to PCC, which I presume has some reason over signing metadata on-device? Original mistaken post is below for transparency.

You can always not use the reference image mode, and according to the article you send a hash of the signature of the photograph, so all they would know is you took a photograph in reference image mode at some point in time before the request.

e28eta 1 day ago||
> some reason over signing metadata on-device

After my brief read, one of the main reasons they’re using PCC to produce the signed JPEGs, instead of doing everything on device, is that it maintains your privacy.

If you were signing with the iPhone, an attacker could then correlate photos taken with the same device.

Apple certainly has the data that “this sensor, in this device, took this exact photo” in PCC at the time of signing, but they discard that data.

clarkmoody 21 hours ago||
My comment on this idea from 9 years ago: https://news.ycombinator.com/item?id=16291641

First reply was exactly the same as most of the top-level comments here today: "That doesn’t prove anything. Make your fake video, point your phone camera at it, record."

Of course, I'm sure someone else had thought of something along these lines in the 90s, I just didn't have a citation to hand.

eutropia 21 hours ago||
I'm super excited for all the people saying "lol just point it at a genai photo" to make a blog post later about how they successfully subverted this approach and fooled people into believing their image was verified without detection as a fraudulent image. because that'll be a lot more interesting than a reflexive snarkpost about the first idea that came to mind to hypothetically defeat it.
wky 1 day ago||
The timestamp system seems like it provides more benefit than signing the image data itself, at least in terms of difficulty to fake. As long as rolling back the stored timestamp token is prevented, I would have to find a phone that never updated its timestamp after the time I want to fake. Of course you could potentially find a phone that last connected to Apple's servers with a plausible timestamp. Even then the upper bound of when it signs the photo after reconnecting to the internet will raise eyebrows if you take too long to find the phone and fake the photo, so it effectively raises the bar to having to take the fake photo roughly simultaneously with the time the event purportedly took place anyway.
scorpiosdayoff 1 day ago|
[dead]
dsign 1 day ago||
I think this is really good and kudos to Apple for implementing it. The first question that popped into my mind was "what new scenarios of government X forcing Apple to do 'terrible thing' to 'individual' this enables?", but I can't think of anything. It seems that all government attack vectors this feature enables are of the type "government X forces Apple to do 'terrible thing' to 'Apple'", i.e. a government can try to force Apple into certifying a narrative, and of course Apple is going to fight tooth and nail the lack of credibility that would result from that.
dsign 1 day ago||
Though, on second thought, "government X could force Apple to disable feature for members of group Y" seems possible. I'm sure you can come with "Y" quite easily, heard anything about Ed Sheeran's tour?
giancarlostoro 1 day ago|||
Apple would have to be the only company around and by the time Apple “loses” in court its too late.
bawolff 1 day ago||
I mean, the obvious one is that they can revoke certification of a photo despite it being real.

The harder one is they can force apple to certify a fake photo.

the part that would be very hard but not outside the realm of plausibility, is that gov could force apple to introduce a bug in its pcc platform to link photos to the photographer in order to track and arrest inconvenient people. Apple says there are a bunch of protections against that but ultimately you are trusting apple to do it the way they say they are.

This entire system relies on trusting apple

intrasight 1 day ago||
> This entire system relies on trusting apple

It does indeed, and that is a fundamental flaw. but as has been discussed here, it is better than the alternative, which is no verification.

During the pandemic, I outlined a scheme for using blockchain technology for image provenance and authenticity tracking. The idea was that instead of any one entity assigning authenticity that it would be done in a crowdsourced manner and that the device would overlay a score whenever an image or video is shown to a user.

My assumption was that the desire of users to see such scores would force all manufacturers to implement this open protocol. But my approach suffered from chicken and egg problem, which Apple's does not.

bawolff 1 day ago||
That blockchain approach doesn't really solve the problem. The point is to have a chain of trust.
itintheory 19 hours ago||
I just finished reading a scifi book called Venemous Lumpsucker which had this type of system as a minor plot point. An interesting twist was that there were essentially smart-contract based non-disclosure agreements that could effectively disable attestation for photos and videos on a specific device that had consented to the NDA.
SoftTalker 1 day ago||
A photograph by itself should never be considered proof of anything.
otterley 1 day ago|
Don’t know why this was downvoted but this is the right take. A photograph is evidence, but isn’t a proof in and of itself.
TZubiri 20 hours ago||
synonyms
jsrozner 1 day ago||
Seems to lead us down the slippery slope of requiring an Apple device, or a Google device (e.g., https://cybernews.com/privacy/google-qr-code-recaptcha-requi...), or the device of some other entity (that may be mostly non-aligned with democratic values) in order to participate in society.

The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.

demibabs 1 day ago|
> or via software-level jailbreak of the device.

I’m surprised that even Apple calls jailbreaking, jailbreaking. Doesn’t that imply their own software is a jail?

mitxela 1 day ago|
Jailbreaking is connoted as bad because it's something criminals do so they can do more crime.
More comments...