Posted by imwally 1 day ago
Apple's protocol differs in that it requires a timestamping server to sign the file and centralising Apple as the single arbiter of truth. An excellent addition, if you trust Apple and the governments they're friendly with (I don't, especially the latter part).
Whatever that means in detail...
What you are prevented from doing is adding a verification to a photo outside of the iOS image pipeline, or modifying the photo with the verification still in tact.
2. Take a photo of it with iPhone
3. Apple's fancy reference image thing now says "omg it's real you guys"
Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?