Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

131–140 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#131

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

I don't understand the vector of this: An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted). Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this. Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to mak…

Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards.

This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

Re: Apple Reference Image: A New Approach for Verified Photography

#132
post #96

> Modern cameras rely on sophisticated image-processing algorithms to produce the final viewable image, so certifying that an image accurately reflects what a real camera sensor captured requires a chain of trust covering the sensor as well as the computational photography software that interpreted the capture. So if you jailbreak or root your phone what happens? Is this a trojan horse into making rooted phone camera…

You'd need to jailbreak the camera sensor chip and the phone's secure element. Which isn't exactly impossible either, but it's harder. I don't think it has been done yet (but I'm sure it will be at some point).

Re: Apple Reference Image: A New Approach for Verified Photography

#133
post #118

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

> […] the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". Why do you believe Android manufacturers and SOC makers like Qualcomm won’t be able to offer a similar solution?

A bunch of them already offer one. Have been a while, actually; the S25 and Pixel 10 came with exactly this.

The timestamping server is the hard part, especially with the verified compute component. It's just not something I see Samsung doing.

I expect Google to show up with a blog post titled "extending C2PA with timestamps for industry-leading authenticity confirmation" any time.

Re: Apple Reference Image: A New Approach for Verified Photography

#136

Seems kind of concerning that using this at all means you send your image to Apple’s PCC machines.

Presumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated. PCC is quite good, about as close to private remote compute we can get without doing HME.

If homomorphic encryption is not involved, how does Apple not have access to the raw image data being sent to PCC? (Genuine question)

Re: Apple Reference Image: A New Approach for Verified Photography

#137
post #104
post #76

Earlier quoted context omitted.

I don’t understand what this brings to the table beyond what we’re currently doing. Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.

As per opening paragraph of link, AI fakes are a thing. It's been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: https://news.ycombinator.com/item?id=9224 and https://en.wikiquote.org/wiki/Rob_Malda NVIDIA suggested A…

> That said, in the case of Apple, they're historically followers not leaders despite the public image they like to present about innovation

While its true Apple usually isn't the first in a product category--not the first mp3 player, not the first smartphone, not the first tablet) but once they get there, they're quite innovative.

When the iPhone 5s was released in 2013, it was the first smartphone with a 64-bit processor, which caught Qualcomm off guard. Even when Qualcomm released a 64-bit processor the following year, it kinda didn’t matter because Android was still 32-bit.

Re: Apple Reference Image: A New Approach for Verified Photography

#139

This is cool, but also seem really complex and i'm not sure it makes sense pragmatically. - it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact - i guess you need internet to take a picture. :( - You are puting a lot of trust in apple's private cloud compute platform. - apple can revoke certification of a picture. I understand the appeal…

> it sounds like its an optional mode you have to enable It’s opt-in because your photo is sent to Apple’s servers. Only if it were on-device should they even consider making it default. > i guess you need internet to take a picture Not really, internet is required to process the reference image, but that can happen later if you’re not currently connected. > are complex hardware attacks really that important? No, but…

I'm not sure i would describe the linked exploit as "trivial", but nonetheless point taken.

Ultimately though, i think all this might just mean we do not have a practical solution to this problem.

just to throw out some naive ideas, maybe the solution is to just sign the raw camera output and embed it in the metadata. If this is an optional feature meant for photojournalists, does file size really matter?

Re: Apple Reference Image: A New Approach for Verified Photography

#140

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

I think you’re on the ball, but also all KYC flows, photo proof for shipping returns (Chinese platforms were getting destroyed on this) etc. etc. It’s a very very clever solution and a very opportune time.
Post reply on HN