Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

141–150 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#141
post #106
post #93

Earlier quoted context omitted.

The main way we combat insurance fraud is by throwing people in jail who do it. I dont think AI faked photos is a major cause of fraud.

At least in the UK this seems to be a growing problem and jail isn't a scalable solution. See for example: https://www.bbc.com/news/articles/cm2rr9pg4jzo

Like a lot of things in the UK, the problem isn't the harshness of the law, it's the lack of prosecution. It doesn't matter what the punishment is when criminals know that the crime is extremely unlikely to be investigated or make it to trial.

Re: Apple Reference Image: A New Approach for Verified Photography

#142

Earlier quoted context omitted.

I don't understand the vector of this: An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted). Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this. Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to mak…

Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards. This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

Okay, this doesn't answer the question on the vector but is another interesting example. Let's expand on that one then:

Banks are offloading the trusted process of ID verification to an untrusted entity (end-user, merchant,...) and compensate for the loss of security by using a trusted service-provider (now Apple AND an iPhone 18 Pro).

This is already happening today in two scenarios:

1. lower-risk scenarios (remotely) with trusted 3rd party service-providers and very low Hardware-requirements ("use this app on your phone to take a picture/video") and

2. higher-risk scenarios (on-site) with trusted 3rd party service-providers ("use THIS expensive device to take a picture/video of the customer/citizen")

Apple now potentially disrupts the service-provider industry of #2 (higher-risk scenarios) by

#a grabbing a part of this hardware/service market that MAY allow the end-user to be in control of the device and

#b replacing the on-site hardware/service with an iPhone "in a box".

They can't disrupt #1 because their cost-saving can't mandate the end-user to buy a 1000+ USD device just for THEM to provide the contracted service. (They can add convenience if you have it, but they can't reject their service if you don't)

Which means they disrupt mainly #2: The industry providing trusted imaging solutions for higher-risk scenarios.

--> So it's the Watch Ultra game all over again.

On Watch Ultra they disrupted the diving-watch market by the sheer scale of selling their development to everyone buying a Watch Ultra, driving down the cost so much that they can undercut every diving-watch company on the market.

Now they use the sheer scale of iPhone 18 Pro sales to enter the trusted-imaging market-segment, undercutting every player there and take that market.

Re: Apple Reference Image: A New Approach for Verified Photography

#143
post #90

I think this is really good and kudos to Apple for implementing it. The first question that popped into my mind was "what new scenarios of government X forcing Apple to do 'terrible thing' to 'individual' this enables?", but I can't think of anything. It seems that all government attack vectors this feature enables are of the type "government X forces Apple to do 'terrible thing' to 'Apple'", i.e. a government can tr…

I mean, the obvious one is that they can revoke certification of a photo despite it being real.

The harder one is they can force apple to certify a fake photo.

the part that would be very hard but not outside the realm of plausibility, is that gov could force apple to introduce a bug in its pcc platform to link photos to the photographer in order to track and arrest inconvenient people. Apple says there are a bunch of protections against that but ultimately you are trusting apple to do it the way they say they are.

This entire system relies on trusting apple

Re: Apple Reference Image: A New Approach for Verified Photography

#144
post #96

> Modern cameras rely on sophisticated image-processing algorithms to produce the final viewable image, so certifying that an image accurately reflects what a real camera sensor captured requires a chain of trust covering the sensor as well as the computational photography software that interpreted the capture. So if you jailbreak or root your phone what happens? Is this a trojan horse into making rooted phone camera…

You'd need to jailbreak the camera sensor chip and the phone's secure element. Which isn't exactly impossible either, but it's harder. I don't think it has been done yet (but I'm sure it will be at some point).

On top of that, they have a revocation system in place to try and deal with that eventuality.

Re: Apple Reference Image: A New Approach for Verified Photography

#145

That's a lot of words to say "we re-invented C2PA but made worse by getting our servers involved somehow". Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. The timestamping server is a nice idea (though I don't see why they can't just use a normal timestamping server, I guess to keep control over the protocol) but it doesn't solve the fundam…

It looks like the reason for the custom timestamp setup is to assert and upper and lower bound on time. A normal timestamp server can asset it saw the image at a certain time but not that the image wasn’t created much earlier. This setup, the image processing pipeline can immediately attach the last seen timestamp to the photo as a lower bound, and then connect to the network to get the upper bound time. If there is…

The lower bound is specified by the device, you don't need support from the timestamping server for that. Determining if this timestamp is or isn't suspicious can be done at verification time. The timestamping feature itself makes sense from a verification perspective (though the privacy implications are questionable, of course), but I don't think it necessitates an Apple-specific setup.

This approach does have one benefit, which is that Apple gets all the (meta)data to determine if something is or isn't "real", rather than letting the verifier decide beforehand.

I can only imagine the outrage if Google or Microsoft added a "upload all of your photos to us and we will mark them are real or fake" protocol, even with all of the verified compute gaff.

Re: Apple Reference Image: A New Approach for Verified Photography

#146

Earlier quoted context omitted.

You'd need to jailbreak the camera sensor chip and the phone's secure element. Which isn't exactly impossible either, but it's harder. I don't think it has been done yet (but I'm sure it will be at some point).

On top of that, they have a revocation system in place to try and deal with that eventuality.

It all depends on when or if Apple actually activates this system. Unless Apple can prove when a compromise first took place, they would have to retro-actively classify all iPhone pictures taken before discovery of such an exploit as "potentially fake".

Plenty of certification bodies refuse to revoke their given certifications because of brand damage or effects on their customers. That's why cryptographic verification of things like Secure Boot are basically broken on most systems by default.

If an independent security researcher does it and Apple rolls out fixes a month later, I can see it happening. If it turns out a government agency hacked the platform "at some point", I have my doubts Apple will retroactively reject all of their iPhones' signatures.

Re: Apple Reference Image: A New Approach for Verified Photography

#147
post #130

Earlier quoted context omitted.

Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has 1. a public/private key exchanged during device-production (production-cost), 2. the capability to reboot in a cryptographic mode (R&D / component cost) and 3. a cloud-service which then processes the raw data to create a JPG (operational cost) comes at a premium. Why should this premium be applied on a 99 USD Smartp…

We have 99USD smartphones with 1080p+ AMOLEDs, massive 5k amp batteries and very performant SOCs (e.g. Galaxy A16) among other costly, but not vital niceties. I struggle to see how cost could be a factor here.

> I struggle to see how cost could be a factor here.

Okay. In good faith, I'll go with you:

If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)?

Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013.

The answer is COST: A camera-module with OIS is a more-expensive component than a module without it.

And that's ONLY the component-cost: A OIS-camera doesn't come with increased cost in device-production (it's just another component to place and assemble), no increased cost in R&D (the tech is very mature, all the SW is there) and no running costs (there are no cloud-services required to operate OIS)

Re: Apple Reference Image: A New Approach for Verified Photography

#148
post #130

Earlier quoted context omitted.

We have 99USD smartphones with 1080p+ AMOLEDs, massive 5k amp batteries and very performant SOCs (e.g. Galaxy A16) among other costly, but not vital niceties. I struggle to see how cost could be a factor here.

> I struggle to see how cost could be a factor here. Okay. In good faith, I'll go with you: If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)? Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013. The answer is COST: A camera-module with OIS is a more-expensive component tha…

How many smartphones have no camera? Zero? Bluetooth? Zero? But they could save cost by not having those. I think they are basically table stakes. If this type of thing becomes required for more and more things then no one will buy a phone that doesn't have them.

Re: Apple Reference Image: A New Approach for Verified Photography

#149
post #5
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

It also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve. > Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago. Photoshop has existed for decades and so has fake images. This is a low friction way to…

> This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it".

Which surely will be useful in ID verification on the Internet; Android devices most likely will follow with same or similar solution

Re: Apple Reference Image: A New Approach for Verified Photography

#150
post #126

Earlier quoted context omitted.

I don't understand the vector of this: An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted). Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this. Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to mak…

> Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim? In a couple of years it will be almost any iPhone instead of 18 Pro. And if it catches on, other phone vendors will provide a similar service.

So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung?

And then stop the 3rd party app which is vendor-agnostic and works on all devices?

I'd say that's unlikely.

IF that's an industry this Apple-feature will disrupt, it seems it will barely have an impact on the process of insurance companies themselves, but will actually disrupt the service-provider industry FOR insurances:

The insurance won't be able to stop their existing 3rd party cost-saving, as it provides the largest device-coverage for offloading to the customer.

Instead, either the insurance or the 3rd party service-provider will have to pay Apple in addition to make use of this feature, with the hopes that the provided data will reduce fraud.

Which brings me back to my actual question: What is the fraud-vector here?

Post reply on HN