Apple Reference Image: A New Approach for Verified Photography
301–310 of 359 posts
Re: Apple Reference Image: A New Approach for Verified Photography
#302Earlier quoted context omitted.
It doesn't, as it is run through an Oblivious HTTP relay run by a third party before getting to Apple's servers. So it has no IP information, and the requests use anonymous access tokens. It is probably possible for an entity to break it, but it would require live access to both Apple and the third party (Likely Cloudflare) servers. And that is assuming there is only one third party routing OHTTP requests, otherwise…
Apple gets the device-signed image and replaces with a PCC signature to preserve anonymity. > The final reference image is instead signed by Apple’s signing service, after validation by PCC. So, if compelled, Apple could theoretically tell someone if two images came from the same camera.
[1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation
Re: Apple Reference Image: A New Approach for Verified Photography
#303This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…
> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…
Re: Apple Reference Image: A New Approach for Verified Photography
#304Earlier quoted context omitted.
It doesn't, as it is run through an Oblivious HTTP relay run by a third party before getting to Apple's servers. So it has no IP information, and the requests use anonymous access tokens. It is probably possible for an entity to break it, but it would require live access to both Apple and the third party (Likely Cloudflare) servers. And that is assuming there is only one third party routing OHTTP requests, otherwise…
Apple gets the device-signed image and replaces with a PCC signature to preserve anonymity. > The final reference image is instead signed by Apple’s signing service, after validation by PCC. So, if compelled, Apple could theoretically tell someone if two images came from the same camera.
Re: Apple Reference Image: A New Approach for Verified Photography
#305Earlier quoted context omitted.
> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…
> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. That the Apple Reference Image itself is not traceable to the device/user is b…
If someone took a picture of a fake ID in the past, this method will bring no benefit, it will just add Apple as a paid service-provider.
It also doesn't change the trust-relationship between the two parties: If I need to prove my identity by uploading a government ID, _I_ am doing the photo attestation that this is the ID matching the data I provided, with or without an Apple Reference image.
Re: Apple Reference Image: A New Approach for Verified Photography
#306Earlier quoted context omitted.
Well, that happened because in ~2011 the entire media industry announced that they will stop media playback on devices which didn't secure the DRM-keys. As media consumption was fundamental to the Smartphone ecosystem, Google made secure-boot and widevine mandatory. Sure, the same could happen here, but I don't know which industry (or other body) would demand that and have sufficient justification for it. After all,…
Not if Apple can identify the dog as belonging to someone else.
You wanna buy it now or not? /s
Re: Apple Reference Image: A New Approach for Verified Photography
#307Earlier quoted context omitted.
> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…
> So… a nation-state can't really do anything here unless they acquire alien technology. At least for the image itself, using direct projection onto the sensor (in a way similar to a retinal projector or film recorder) would be difficult to detect I imagine?
But at the end of the day, even if you manage to get a fake reference image, it's still on the person making the claim to show that the content of the image is real. A reference image of a document is useless, the physical document could be a forgery. A photo of people could be refuted with alibis during the timestamp window (max 15 minutes it sounds like?). A photo of property damage doesn't prove how or when it happened.
Re: Apple Reference Image: A New Approach for Verified Photography
#308Earlier quoted context omitted.
> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…
Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you're willing to do it destructively. They can then sign their own fraudulent images.
That's not how this works.
Let's pretend they're able to extract the sensor key and the SEP key. Then what?
An attacker won't have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service.
When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device's secure boot manifest.
More encryption and checking happens until the secure digital negative is sent to Private Cloud Compute:
PCC recomputes the digest embedded in the frame and verifies the
sensor's signature over the pixels and that digest, verifying the
certificate chain back to the sensor CA. PCC also verifies the SEP
signature and chains it to the BAA CA, and it verifies the signature
on the device manifest and chains it to the CA that signs device
manifests at the factory. It then confirms that the sensor and SEP
named in those chains belong to the same device. Only if all these
checks pass does processing continue.
Only PCC can create an Apple Reference Image; an attacker having the image and sensor private keys doesn't enable them to create a reference image.Re: Apple Reference Image: A New Approach for Verified Photography
#309Earlier quoted context omitted.
> If they can verify an Apple Reference Image they can verify an NFC document Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.
ICAO doc 9303 validation is about 10 lines in Python (on top of importing the right packages) last time I did it around 2012. I doubt it has become harder since then.
I think processing that information is mandatory now, but probably was optional/largely unimplemented in 2012. But maybe I'm off by five years or so?
Re: Apple Reference Image: A New Approach for Verified Photography
#310Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…
I wouldn't be surprised if it's also possible to detect the differences between a photo of a real scene and a photo of a monitor or printout displaying a photo of a real scene, given they have the raw sensor output.
Not sure if they're doing anything like that.