Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

181–190 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#181
post #104

Earlier quoted context omitted.

As per opening paragraph of link, AI fakes are a thing. It's been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: https://news.ycombinator.com/item?id=9224 and https://en.wikiquote.org/wiki/Rob_Malda NVIDIA suggested A…

> That said, in the case of Apple, they're historically followers not leaders despite the public image they like to present about innovation While its true Apple usually isn't the first in a product category--not the first mp3 player, not the first smartphone, not the first tablet) but once they get there, they're quite innovative. When the iPhone 5s was released in 2013, it was the first smartphone with a 64-bit pro…

nobody actually needed that though

Re: Apple Reference Image: A New Approach for Verified Photography

#182
post #155

Earlier quoted context omitted.

> I struggle to see how cost could be a factor here. Okay. In good faith, I'll go with you: If COST is not a factor, why does the Galaxy A16 still have no OIS (Optical Image Stabilization)? Unlike this trusted-imaging service, OIS would be a feature for increased user-experience which is highly-matured and exists in Smartphones since 2013. The answer is COST: A camera-module with OIS is a more-expensive component tha…

Doesn't OIS increase the size of a sensor by roughly half and thus take some significant engineering and design cost to accommodate? At least it seems that way in the phones I've taken apart and looked at. Also, OIS is a major mechanical add on (a literal motor) and even 1500usd smartphones lack it on some of their sensors, mainly because while it can have an advantage on an ultrawide, that tends to be more limited.…

>Doesn't OIS increase the size of a sensor by roughly half

No, you can apply smartphone OIS-tech on any sensor, stabilization is achieved via the lens-array, not the sensor. The size of the module slightly increases but that's not a hindering factor. Cost/Benefit of OIS on ultra-wide lenses is not there, so it's usually not applied.

>Your logic would lead to OEMs making SOCs without things like TEE and other things which started in the highend but quickly became required for one and basically free to implement for two.

TEE became a mandatory requirement of the media industry for Smartphones in ~2010, as they announced plans to restrict media-playback on a device without measures to secure the DRM-keys. Google made it mandatory shortly after, because the entire ecosystem was built on media-consumption.

It didn't come for free to the players in the industry, it became a very expensive task to develop, support and maintain it, but that's another story.

Drawing a parallel here, I fail to see who should require cryptographic authentication of a taken image from end-user devices, to the point that no consumer devices without it will be built anymore.

>Not saying it is free now, but that the upcoming gen of chips from Sony, Samsung, etc. will have it build in for such a minimal BOM impact, this will be an expected, common place feature across all prices.

It will be supported in sensors for sure, but those will be premium-tier sensors, as a differentiation factor. Until today there was no premium sensor used in mass-tier devices.

Of course, again, if there is demand in the market or a regulation requiring it, it will create an incentive for the industry to follow, but I fail to see why either of this should happen in the coming years.

>To have a more serious, honest and accurate comparison than OIS, why can you not buy a single new smartphone at any price without some NPU?

I don't know why OIS is not a "serious, honest and accurate" comparison, can you elaborate?

As stated, it's a highly mature technology available for over a decade already, providing critical-mass observable end-user value, yet it didn't just naturally "trickle down" to every smartphone price-segment, simply because it comes with additional cost no matter which scale (and the Galaxy A1x tier has massive scale).

A NPU is just the evolution of a DSP, which exists in Smartphone SoC's for more than a decade now and is required for Audio and Image processing. DSP's used to run pre-calculated inference models for lens-correction, exposure, white-balance, etc., now these processes can run as models on an NPU.

---

You are trying to argue why that feature won't naturally become a commodity at basically no cost. I'm trying to answer why I don't see this happen, because I worked in this industry for more than 20 years.

The market doesn't get features as a default "easily somehow", features reach this commodity stage because of significant end-user demand (like Camera, Display, Battery), business-value (for the vendor, like Apple Pay) or industry-requirements (like TEE, Widevine example above).

I don't see this happen for this feature, because there is

1. no significant end-user value (unless the public narrative is massively skewed towards "everything is true when the image was signed"),

2. the business-value applies only for Apple's service-proposition for now (which will likely make this feature expand to the non-Pro iPhone tier), and for

3. the industry-requirement I don't see WHO would actually be able to enforce this, for WHICH actual benefit.

Re: Apple Reference Image: A New Approach for Verified Photography

#183

Earlier quoted context omitted.

Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth informa…

> it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?

I think the plan is to block the emitter, not the emitter and the receiver together

Re: Apple Reference Image: A New Approach for Verified Photography

#184
post #27

Earlier quoted context omitted.

Well, first, that's only expensive if you're poor. The world is absolutely full of people who can easily piss away your entire annual income throwing a house party. But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all. Anyway, one may presume that they've thought about this.

Thought about it and also are bright enough not to fall for the “if a single person dies wearing a seat belt, we should abandon seat belts because they do no good at all” fallacy. It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?

It's bad to begin with that Apple should be the arbiters of reality.

Re: Apple Reference Image: A New Approach for Verified Photography

#185

To me the weakest spot of this whole endeavor is how this will create false confidence in a story just because the accompanying images pass Apple's verification. Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy. Okay, fine. Will work for sure, this…

> images that were confirmed to be "taken like this on an iPhone" No, because images will be confirmed to have been taken on "this iPhone". The New York Times will be able to publish an article and to attest that the photographs shown were taken by their journalists, and then your user agent will verify that provenience.

>No, because images will be confirmed to have been taken on "this iPhone".

Actually the description of Apple makes explicit statements AGAINST that:

Quote: Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device

Re: Apple Reference Image: A New Approach for Verified Photography

#187

To me the weakest spot of this whole endeavor is how this will create false confidence in a story just because the accompanying images pass Apple's verification. Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy. Okay, fine. Will work for sure, this…

> images that were confirmed to be "taken like this on an iPhone" No, because images will be confirmed to have been taken on "this iPhone". The New York Times will be able to publish an article and to attest that the photographs shown were taken by their journalists, and then your user agent will verify that provenience.

And then every anonymous source gets revealed, and the government bombs then for the greater good.

Re: Apple Reference Image: A New Approach for Verified Photography

#188
post #173

Earlier quoted context omitted.

So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung? And then stop the 3rd party app which is vendor-agnostic and works on all devices? I'd say that's unlikely. IF that's an industry this Apple-feature will disrupt, it seems it will barely have an impact on the process of insurance companies themselves, but will actual…

> So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung? The industry has some extensive experience in independently verifying signatures, I don't see how the manufacturers factor in here. And for app features, just ask banks how integrating biometrics, payment services, etc. goes. Tends to be preferred, once Apple and G…

Me neither, so your reply should be on the parent, because it states "And if it catches on, other phone vendors will provide a similar service."

Re: Apple Reference Image: A New Approach for Verified Photography

#189

Earlier quoted context omitted.

This is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.

> This makes it like, a thousand times harder to fake a photo than it would otherwise be. The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forge…

> Whether it actually meaningfully increases the difficulty of a forgery remains to be seen.

Then maybe let’s save those criticisms until this is in the hands of knowledgeable people who can actually test? I mean, I’m no fan of the direction Apple has gone under Tim Cook, but all else being equal I’m inclined to give them the benefit of the doubt that they may have thought this through over the time it took to build more than a random person speculating on HN who just read a blog post for the first time.

> (…) we see no details here about what scene information is used.

And you assume that everything in a post is the sum total of how it works?

> It increases the potential value of a forgery

By that token, should we also not be adding forgery deterrents to ID cards and bills? After all, if you can fake the preventive measures, “it increases the potential value of a forgery”.

Re: Apple Reference Image: A New Approach for Verified Photography

#190

I wonder why they went for ECDSA and RSA and how a freshly initialised sensor obtains enough randomness to create an unrecoverable private key. Other than that the overall protocol looks very interesting.

A camera has literally tens of millions of thermal noise sensors...
Post reply on HN