Top
Best
New

Posted by imwally 1 day ago

Apple Reference Image: A New Approach for Verified Photography(security.apple.com)
512 points | 341 commentspage 3
ozlikethewizard 1 day ago|
Somewhat tangential but is "most secure consumer mobile device" actually correct? Does an iPhone beat out a grapheneOS android, or would that not be considered consumer because of aftermarket changes? Seems like a pretty bold claim but I know apple is pretty damn good with security (as long as you dont count Apple as a security risk themselves)
microtonal 4 hours ago|
From leaked Cellebrite presentations, it seems GrapheneOS is more secure. But it's easy for Apple marketing to move the goal posts by adding words like 'consumer'. They do this all the time in their marketing, like:

Force sensor with volume swipe arrives on AirPods 5, a first for the open-ear form factor, adding the ability to quickly adjust volume by swiping up or down on the stem.

Add some qualifiers so that you can call yourself 'first'.

walrus01 1 day ago||
so what happens if you display an extremely high res image of a 100% AI generated fake-something on an 8K display in a photo studio room and take a picture of it with the camera? it gets tagged as authentic.
petu 1 day ago||
Was photo not authentic? Think of it "as seen by an iPhone", not "this is authentic event" verification.

But Apple likely would reject such photo because of inappropriate depth map / LiDAR data.

Gigachad 1 day ago|||
The timestamp wouldn’t match the event being depicted and the geotag would show the studio. And the depth sensing would show the image as flat.
tobyhinloopen 1 day ago||
That’s a lot of money and effort for a fake photo
chaz6 1 day ago||
I feel like for verified photography to be useful, it really needs a depth sensor so you can tell the difference between an actual scene and a photo of a photo. Granted, you could 3d print a scene from a photo, but at least for now it should be pretty obvious to tell the difference.
etatester 1 day ago|
The iPhone Pros do have a depth sensor, I don’t think it's exported but it does stay in Photos' library.
Gigachad 1 day ago||
It’s stored in the exif data on the photos
Velocifyer 16 hours ago||
This will create a social problem of people discrediting images by a niche camera vendor or by a bootloader unlocked phone or from budget cameras or or from niche camera manufactuers from film cameras or from cameras that are old, while still allowing for advanced telecine attacks.
rasguanabana 1 day ago||
I wonder why they went for ECDSA and RSA and how a freshly initialised sensor obtains enough randomness to create an unrecoverable private key. Other than that the overall protocol looks very interesting.
londons_explore 1 day ago|
A camera has literally tens of millions of thermal noise sensors...
albert_e 21 hours ago||
Thinking aloud about failure modes / edge cases:

If i create a high quality deepfake image, project it on a large screen and take a photo of that image with an iPhone (+apple verified image secure tag) ... would that resulting image be considered "authentic" by default?

Would digital forensics accessible to lay people still be able to fact-check and call out misuse / fakery of the new secure tag.

MBCook 21 hours ago||
It is authentic, in a way. It’s exactly what you took a picture of.

I do wonder how easy that would be to detect, but I can’t help but think some sort of artefacting or something would show up.

mayhemducks 17 hours ago||
The system is not for detecting deepfakes. It is for proving that the data captured by an apple camera's sensor was not altered by some 3rd party hardware or software chain.
albert_e 4 hours ago||
Fair enough.

So the chain of trust is ...

Personal credibility of the person taking the photo with iPhone (till the moment picture is taken) + tamper-evident protection against unauthorized or anonymous edits and manipulation (after the iphone photo is published and circulated)

Apple cannot (of course) vouch for the former.

mrinterweb 16 hours ago||
I hope Apple contributes to an open standard for this, instead of keeping this proprietary. In the emerging world of generative AI, we need this more than ever. Not just iPhone, but ideally most camera systems will have some kind of verifiable capture mode.
icar 21 hours ago||
This is something I always had in my mind: sign at photo taken, at least you know it comes from a phone and it's not AI generated
asaddhamani 1 day ago||
I skimmed the whole article and I didn’t see a single image so I’m confused. Is there some watermark of some kind or where is this metadata integrated? Because if it’s just metadata then I need to parse each photo I come across manually, and if it’s a watermark it can be faked because I won’t manually validate every single image I come across to prove the watermark isn’t fake.
bawolff 1 day ago|
presumably the metadata reader app would be integrated into the photo viewer app which would verify the digital sigs.

I have my doubts about this scheme but this is not one of them. If the point is that someone in principle could verify, that is enough for it to be useful, even if not everyone does.

jithinsankar 1 day ago|
What if someone take the photo of the forged photo displayed on another device, doesn’t the forged photo become an authentic one?
brookst 1 day ago|
Sure, if it’s believable that the shot was perfectly flat at, what, 2 feet away?
More comments...