Earlier quoted context omitted.
Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
> If they can verify an Apple Reference Image they can verify an NFC document Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.
Apple Reference Image: A New Approach for Verified Photography
291–300 of 359 posts
Re: Apple Reference Image: A New Approach for Verified Photography
#292Canon tried this 20 years ago with DSLRs. Nikon had an authentication system. Both were broken. The keys ended up on Pastebin. Apple's hardware security is better, but history suggests this is a temporary advantage. The real question is whether the system will be revoked when (not if) it's broken, and whether Apple will have the guts to retroactively invalidate millions of "verified' photos"
Re: Apple Reference Image: A New Approach for Verified Photography
#293Earlier quoted context omitted.
As per opening paragraph of link, AI fakes are a thing. It's been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: https://news.ycombinator.com/item?id=9224 and https://en.wikiquote.org/wiki/Rob_Malda NVIDIA suggested A…
You don’t even need an AI deepfake to edit a video. AI deepfake or edit video doesn’t pass liveliness checks without all the c2pa or reference image song and pony show. Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive. They could also just update their app to stop accepting photos f…
All of this data can be spoofed if it's not somehow authenticated.
> They could also just update their app to stop accepting photos from the album.
Doesn't help at all if the spoofed data is arriving via spoofed hardware.
Re: Apple Reference Image: A New Approach for Verified Photography
#294Re: Apple Reference Image: A New Approach for Verified Photography
#295This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…
> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…
> a nation-state can't really do anything here unless they acquire alien technology.
Alien technology such as NSLs or supply chain attacks against Apple?
Re: Apple Reference Image: A New Approach for Verified Photography
#296And why does someone have to trust Apple? Everything "security"-related that comes out of Apple lately somehow always assumes that Apple is to be unquestionably trusted. And, yeah, I'm incredibly tired of this whole concept of a device you own acting in someone else's interests. This needs to stop and it needs to happen 10 years ago.
Every time they say "trust us" they publish a whitepaper with technical details explaining why and how they can be trusted. They're generally very good about these things.
Re: Apple Reference Image: A New Approach for Verified Photography
#297Re: Apple Reference Image: A New Approach for Verified Photography
#298Earlier quoted context omitted.
Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
> If they can verify an Apple Reference Image they can verify an NFC document Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.
Re: Apple Reference Image: A New Approach for Verified Photography
#299Earlier quoted context omitted.
Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
How exactly am I expected to upload my nfc chip to my insurance company’s website?
The phone is just a relay to a remote server here, as newer ICAO machine readable travel documents intentionally don't support signatures/non-repudiation anymore, so you have to run the entire exchange against a component you trust (i.e. your server, not so much your app on a rooted/manipulated phone).
Re: Apple Reference Image: A New Approach for Verified Photography
#300Earlier quoted context omitted.
> You'll still need an iPhone, the verification is linked to the specific iPhone, and the specific iPhone is linked to you. Unless you use a friend's iPhone, or an iPhone you 'rented' for 5 minutes for $20 from someone on Craigslist or Facebook Marketplace to take a picture on and then Airdrop to you.
If they airdrop it to you that typically requires you to have an iphone or a mac and airdrop users are able to be identified and tracked so the photo could still be linked to your device. The EU forced apple to use Wi-Fi Aware though, so unless that's similarly vulnerable people in the EU might be able to avoid those issues.
Or you could just email/WhatsApp/... it.