Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

121–130 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#122
Somewhat tangential but is "most secure consumer mobile device" actually correct? Does an iPhone beat out a grapheneOS android, or would that not be considered consumer because of aftermarket changes? Seems like a pretty bold claim but I know apple is pretty damn good with security (as long as you dont count Apple as a security risk themselves)

Re: Apple Reference Image: A New Approach for Verified Photography

#123
post #118

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

> […] the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". Why do you believe Android manufacturers and SOC makers like Qualcomm won’t be able to offer a similar solution?

Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has

1. a public/private key exchanged during device-production (production-cost),

2. the capability to reboot in a cryptographic mode (R&D / component cost) and

3. a cloud-service which then processes the raw data to create a JPG (operational cost)

comes at a premium. Why should this premium be applied on a 99 USD Smartphone?

Which is my whole puzzle on this vector: If the big benefit is for insurance/ID-verification, which apply cost-saving by offloading their process to the untrusted customer, how much they can offload this by requiring their customer to own a 1000+ USD smartphone to provide THEIR service...?

The most I can imagine is insurances offloading their work to OTHER companies, NOT trusting them and therefore requiring them to own a 1000+ USD Smartphone. But even then, why not use a third party app that also runs on a 3y old iPhone and a 99 USD Android device...?

Re: Apple Reference Image: A New Approach for Verified Photography

#125

Hey I predicted this awhile ago. Although it is kind of an obvious solution so I can’t claim much insight hehe. https://news.ycombinator.com/item?id=44135416

By the time you made your comment, such a system had already been invented, even partially rolled out: https://en.wikipedia.org/wiki/Content_Credentials

Apple's protocol differs in that it requires a timestamping server to sign the file and centralising Apple as the single arbiter of truth. An excellent addition, if you trust Apple and the governments they're friendly with (I don't, especially the latter part).

Re: Apple Reference Image: A New Approach for Verified Photography

#126

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

I don't understand the vector of this: An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted). Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this. Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to mak…

> Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim?

In a couple of years it will be almost any iPhone instead of 18 Pro. And if it catches on, other phone vendors will provide a similar service.

Re: Apple Reference Image: A New Approach for Verified Photography

#127

This is cool, but also seem really complex and i'm not sure it makes sense pragmatically. - it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact - i guess you need internet to take a picture. :( - You are puting a lot of trust in apple's private cloud compute platform. - apple can revoke certification of a picture. I understand the appeal…

> it sounds like its an optional mode you have to enable

It’s opt-in because your photo is sent to Apple’s servers. Only if it were on-device should they even consider making it default.

> i guess you need internet to take a picture

Not really, internet is required to process the reference image, but that can happen later if you’re not currently connected.

> are complex hardware attacks really that important?

No, but the floor shouldn’t be “trivially exploitable” like C2PA[0]. It’d be interesting if there were a middle ground but we don’t have anything like that as of now.

[0] https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html

Re: Apple Reference Image: A New Approach for Verified Photography

#128

This is so insanely complex and requires placing trust in the correctness of so many pieces, many of them closed-source. And uploading every verified "developed" image to Apple's servers. And giving up full control of the software and hardware you "own". All to achieve a goal of "verifying" photons, which is only a part of the real problem of verifying the truth of an event that was photographed. I hope that companie…

Because it’s impossible to implement this feature in open source and out in the open. It relies on a locked down image pipeline and hidden key.

That's also why the approach is fundamentally flawed. The open-ish C2PA protocol has been "defeated" by tricking phones into signing arbitrary data already. The even-more-closed Apple version can be defeated the same way and relies on Apple to be the sole arbiter of truth.

Re: Apple Reference Image: A New Approach for Verified Photography

#129
To me the weakest spot of this whole endeavor is how this will create false confidence in a story just because the accompanying images pass Apple's verification.

Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy.

Okay, fine. Will work for sure, this will disrupt the trusted-imaging market and moreover make Apple a service-provider in this industry (with the ramp-up cost paid by customers buying iPhones for entirely different purposes).

But creating this impression and media-buzz that Apple is now verifying more than just the digital authenticity of an image may shift the public scrutiny of MANY media/online statements:

There is a risk that random claims (and propaganda) will be given more credibility in the public eye just because they came with images that were confirmed to be "taken like this on an iPhone"

Re: Apple Reference Image: A New Approach for Verified Photography

#130
post #118

Earlier quoted context omitted.

> […] the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". Why do you believe Android manufacturers and SOC makers like Qualcomm won’t be able to offer a similar solution?

Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has 1. a public/private key exchanged during device-production (production-cost), 2. the capability to reboot in a cryptographic mode (R&D / component cost) and 3. a cloud-service which then processes the raw data to create a JPG (operational cost) comes at a premium. Why should this premium be applied on a 99 USD Smartp…

We have 99USD smartphones with 1080p+ AMOLEDs, massive 5k amp batteries and very performant SOCs (e.g. Galaxy A16) among other costly, but not vital niceties. I struggle to see how cost could be a factor here.
Post reply on HN