Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

41–50 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#41
post #27

Earlier quoted context omitted.

Well, first, that's only expensive if you're poor. The world is absolutely full of people who can easily piss away your entire annual income throwing a house party. But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all. Anyway, one may presume that they've thought about this.

Thought about it and also are bright enough not to fall for the “if a single person dies wearing a seat belt, we should abandon seat belts because they do no good at all” fallacy. It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?

> maybe it’s better than nothing?

While that is not quite my bar of confidence when implementing wide-reaching technologies that have numerous unexplored knock-on effects, I guess the calculus must have been different on Infinite Loop recently.

Re: Apple Reference Image: A New Approach for Verified Photography

#42
post #5

Earlier quoted context omitted.

It also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve. > Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago. Photoshop has existed for decades and so has fake images. This is a low friction way to…

> "But that's not the problem they're trying to solve." It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened". It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself. Likewise in "distinguish between photographs that depict real e…

Yes, it is proving something actually happened, that is your monitor screen showing something you photographed.

Re: Apple Reference Image: A New Approach for Verified Photography

#43

Earlier quoted context omitted.

> "But that's not the problem they're trying to solve." It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened". It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself. Likewise in "distinguish between photographs that depict real e…

Yes, it is proving something actually happened, that is your monitor screen showing something you photographed.

[flagged]

Re: Apple Reference Image: A New Approach for Verified Photography

#44
The timestamp system seems like it provides more benefit than signing the image data itself, at least in terms of difficulty to fake. As long as rolling back the stored timestamp token is prevented, I would have to find a phone that never updated its timestamp after the time I want to fake. Of course you could potentially find a phone that last connected to Apple's servers with a plausible timestamp. Even then the upper bound of when it signs the photo after reconnecting to the internet will raise eyebrows if you take too long to find the phone and fake the photo, so it effectively raises the bar to having to take the fake photo roughly simultaneously with the time the event purportedly took place anyway.

Re: Apple Reference Image: A New Approach for Verified Photography

#45

Earlier quoted context omitted.

iPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.

Still, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.

https://news.ycombinator.com/item?id=49721878

> increasing the difficulty of producing a forgery

The problem with this thinking is twofold:

1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.

2) It increases the potential value of a forgery because now your forgery is attested by Apple.

So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.

Re: Apple Reference Image: A New Approach for Verified Photography

#46
post #27

Earlier quoted context omitted.

Well, first, that's only expensive if you're poor. The world is absolutely full of people who can easily piss away your entire annual income throwing a house party. But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all. Anyway, one may presume that they've thought about this.

Thought about it and also are bright enough not to fall for the “if a single person dies wearing a seat belt, we should abandon seat belts because they do no good at all” fallacy. It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?

I like that seatbelt argument example.

I’ve seen that type of argument a million times, and I’ll certainly reuse that.

Re: Apple Reference Image: A New Approach for Verified Photography

#47

Seems kind of concerning that using this at all means you send your image to Apple’s PCC machines.

Presumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated.

PCC is quite good, about as close to private remote compute we can get without doing HME.

Re: Apple Reference Image: A New Approach for Verified Photography

#48
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

Yeah, such systems have been tried (and been hacked) for decades now. https://www.elcomsoft.com/news/428.html https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio... You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin. It's funny to see Apple fall i…

To be fair Apple of all companies have the best shot at pulling it off. They've been perfecting their hardware security for years for other reasons and this is just another way to take advantage of that work. But yes, if someone breaks it then the trust is gone and it casts doubt on all of the photos that were ever captured using the broken system.

Re: Apple Reference Image: A New Approach for Verified Photography

#49
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

>I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.

There’s no such thing as a Golden Gate Bridge.

Prove it.

Re: Apple Reference Image: A New Approach for Verified Photography

#50
post #8
post #4

Earlier quoted context omitted.

Sony's analogous solution ( https://authenticity.sony.net/camera/en-us/ ) claims 3d depth information is built in, I'm sure Apple could do the same given at least some iPhone models have LiDAR on the back

This would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances. Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background…

> I do this frequently when I want to take a photo through a window.

I feel really dumb for not having thought of this.

Post reply on HN