Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

151–160 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#151

Earlier quoted context omitted.

Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards. This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

Okay, this doesn't answer the question on the vector but is another interesting example. Let's expand on that one then: Banks are offloading the trusted process of ID verification to an untrusted entity (end-user, merchant,...) and compensate for the loss of security by using a trusted service-provider (now Apple AND an iPhone 18 Pro). This is already happening today in two scenarios: 1. lower-risk scenarios (remotel…

Don't forget law enforcement, customs or any high(ish) stakes sector which needs to be able to trust the images they show as evidence as well.

Back in the day Canon and Nikon tried this with embedded private keys on their cameras, and with Sandisk's WORM SD cards. Then, somebody extracted the keys and it was game over.

While my iPhone 17 can't match a full frame mirrorless camera, it can take pretty impressive photos, so they are already more than adequate in detail and clarity department. So making these images trusted is a huge win for them.

Re: Apple Reference Image: A New Approach for Verified Photography

#152
post #56
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

This sounds like it could be done, but the costs for doing so are comparably high. I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage. That’s a tradeoff I can live with.

> but the costs for doing so are comparably high

You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar

Re: Apple Reference Image: A New Approach for Verified Photography

#153

The fundamental issue isn't technical. It's that people will see the "certified real" tag and just take the image for face value of whatever narrative someone wants to convey. They'll see the "Real Photo, Verified by Apple" and their brain will short circuit [0] I don't think we should have this, for that reason alone (but many others too). [0]: https://imgur.com/fVPkpuQ

I’m pretty sure “certified real” aren’t the words Apple will use, nor do they use it in this document. The words to describe the technology were chosen with care: semantic verification, attestation, tamper evident, etc.

But that’s not how the label will be interpreted in real life

Re: Apple Reference Image: A New Approach for Verified Photography

#154
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

> take a picture of an already edited image

I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter.

The "digital negative" in DNG format can be used to analyze the authenticity of the content.

Re: Apple Reference Image: A New Approach for Verified Photography

#155
post #130

Earlier quoted context omitted.

We have 99USD smartphones with 1080p+ AMOLEDs, massive 5k amp batteries and very performant SOCs (e.g. Galaxy A16) among other costly, but not vital niceties. I struggle to see how cost could be a factor here.

> I struggle to see how cost could be a factor here. Okay. In good faith, I'll go with you: If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)? Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013. The answer is COST: A camera-module with OIS is a more-expensive component tha…

Doesn't OIS increase the size of a sensor by roughly half and thus take some significant engineering and design cost to accommodate? At least it seems that way in the phones I've taken apart and looked at.

Also, OIS is a major mechanical add on (a literal motor) and even 1500usd smartphones lack it on some of their sensors, mainly because while it can have an advantage on an ultrawide, that tends to be more limited. Incidentally, most 99usd phones have one (actually usable) sensor which thus tends to have a larger width to compensate. I hope, in good faith, you see the difference, to something like ARI.

AMOLED, etc. are also a bit more expensive then OIS, but we get those into a sub 100usd BOM easily somehow. More so for 5g, certain features just become expected/required.

Your logic would lead to OEMs making SOCs without things like TEE and other things which started in the high-end but quickly became required and essentially free to implement.

Not saying it is free now, but that the upcoming gen of chips from Sony, Samsung, etc. will have it build in for such a minimal BOM impact, this will be an expected, common place feature across all prices.

To have a more serious, honest and accurate comparison than OIS, why do most new smartphone at 99usd include some form of an NPU? Or the trusted modules for biometrics, etc.?

Re: Apple Reference Image: A New Approach for Verified Photography

#156
they said the same thing about synth id didnt they? waiting for someone to reverse engineer this too lol. the future will include a lot of time spent trying to figure out what is real. and that may be good cause to truly enjoy something real, one will have to go out and stop being indoors.

Re: Apple Reference Image: A New Approach for Verified Photography

#157

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

> looking at the repost of a screenshot of the verification UI

I don't follow. It's my user agent that's verifying the image, and my device will tell me that it's not verified.

Re: Apple Reference Image: A New Approach for Verified Photography

#158

Earlier quoted context omitted.

Claim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult: https://image-ppubs.uspto.gov/dirsearch-public/print/downloa... The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.

Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth informa…

> all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information.

I think optics could be used to make each camera see a different image.

A video could show shake, which could be verified against readings from the phone's accelerometer -- but you could just hold it still and claim that it was on a tripod.

Re: Apple Reference Image: A New Approach for Verified Photography

#159
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

It's even easier than that. You just wait for someone else to figure out, some photography professional with fancy equipment and a hacker-y mindset, and you pay them to sign your photos for you.

Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed.

Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...")

It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.

Re: Apple Reference Image: A New Approach for Verified Photography

#160
I feel like for verified photography to be useful, it really needs a depth sensor so you can tell the difference between an actual scene and a photo of a photo. Granted, you could 3d print a scene from a photo, but at least for now it should be pretty obvious to tell the difference.
Post reply on HN