Top
Best
New

Posted by imwally 1 day ago

Apple Reference Image: A New Approach for Verified Photography(security.apple.com)
514 points | 343 commentspage 5
dom96 1 day ago|
How is this different to Content Credential and why isn’t Apple implementing that?
cedws 1 day ago||
I’m fine with such technology so long as the courts don’t treat “verified” images as truth.
SeriousM 1 day ago||
As sexy as apple can be: the blog post just shows how unsexy security is for apple.
bawolff 1 day ago||
This is cool, but also seem really complex and i'm not sure it makes sense pragmatically.

- it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact

- i guess you need internet to take a picture. :(

- You are puting a lot of trust in apple's private cloud compute platform.

- apple can revoke certification of a picture. I understand the appeal of this, all security systems eventually have failures, so its important to be robust against this. However if the point is to prove a picture is real (especially politically damaging ones), this is giving a lot of power to apple.

Its meant to be in competition with C2PA, and i guess the idea is its much more secure against complex hardware attacks. However i think its worth asking who the target audience is and what threats they face. The primary issue with AI is it makes fake photos easy, not that it invented fake photos. Even Stalin manipulated photos back in the day. It is not a new thing, the problem is just being overwhelmed with them.

with that in mind, are complex hardware attacks really that important? We just need to increase the difficulty floor, not solve fake photos for all time. No matter what you do, people can still use practical effects.

It seems like this is almost trying to thwart spies and nation state adversaries, well forgetting that such well funded groups have the budget to fake photos the old fashioned way or if they really cared, bribe their way into apple.

calmingsolitude 1 day ago|
> it sounds like its an optional mode you have to enable

It’s opt-in because your photo is sent to Apple’s servers. Only if it were on-device should they even consider making it default.

> i guess you need internet to take a picture

Not really, internet is required to process the reference image, but that can happen later if you’re not currently connected.

> are complex hardware attacks really that important?

No, but the floor shouldn’t be “trivially exploitable” like C2PA[0]. It’d be interesting if there were a middle ground but we don’t have anything like that as of now.

[0] https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html

bawolff 1 day ago||
I'm not sure i would describe the linked exploit as "trivial", but nonetheless point taken.

Ultimately though, i think all this might just mean we do not have a practical solution to this problem.

just to throw out some naive ideas, maybe the solution is to just sign the raw camera output and embed it in the metadata. If this is an optional feature meant for photojournalists, does file size really matter?

preetx 20 hours ago||
I'm just checking, how it's work technically
antifarben 1 day ago||
I'm waiting for next year's talk at the CCC about it.
rockbruno 1 day ago||
"iPhone 18 Pro and iPhone 18 Pro Max"

So the iPhone Duo won't have it?

petesergeant 1 day ago||
I feel a little discomfort about this: moving towards a world where photos were plausibly deniable felt good for privacy, this feels like a step further away.
lwhi 19 hours ago||
Maybe the solution is even simpler.

Use film.

mayhemducks 19 hours ago|
I had the same thought. Like if it's really that critical to make sure an image was not altered, go analog. You can't photoshop something that doesn't have pixels!
pmlnr 1 day ago|
At this point it'd be easier to return to film.
jamil7 1 day ago|
Some of us never left :D
More comments...