Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

331–340 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#331

This approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification syste…

The approach assumes that most people don’t have the ability to directly attack the image sensor itself. It’s a little buried in the article, but creating reference images involves having the actual image sensor sign the raw data it captures using a key unique to that sensor. The rest of the device can’t tamper with data anymore.

I don’t think there any many people out there with the right equipment to carefully ablate the top of a sensor off, so they can directly inject their own data into the start of signing process. It’s not impossible, but it’s also not the kind of thing most people and organisations are going to be capable of doing.

> The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data.

Re: Apple Reference Image: A New Approach for Verified Photography

#332

Thinking aloud about failure modes / edge cases: If i create a high quality deepfake image, project it on a large screen and take a photo of that image with an iPhone (+apple verified image secure tag) ... would that resulting image be considered "authentic" by default? Would digital forensics accessible to lay people still be able to fact-check and call out misuse / fakery of the new secure tag.

The system is not for detecting deepfakes. It is for proving that the data captured by an apple camera's sensor was not altered by some 3rd party hardware or software chain.

Re: Apple Reference Image: A New Approach for Verified Photography

#333
post #288

Earlier quoted context omitted.

Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards. This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

ID document verification via NFC can't by itself replace also biometrically verifying the person purporting to be the one that the document belongs to. Without it, anyone with a stolen document can pass it. (I don't think there's a generally available database of stolen documents, so I suspect these usually remain valid until their regular date of epxiry.)

Generally, the information in our country is checked via multiple ways: NFC + Biometric data (checked against the data inside the ID card) (+ photo of the ID in some cases), or any combination of those.

Before deepfakes were dime a dozen, I remember my bank starting a video-call with me and required me to show my ID to them via camera. This was after a multi-factor check that I passed.

Making any of these factors more trustworthy is a win in my perspective, so having a trusted sensor is always better even if you do multi-factor authentication.

Our ID cards have a private-public key pair inside them, and it allows us to sign things amongst other things. Renewing your ID card for any reason revokes the digital signature of the previous one, so scanning it via NFC probably enough to check whether it's revoked. Same with photo (since machine readable part contains serial and check digits and such).

Re: Apple Reference Image: A New Approach for Verified Photography

#334
I hope Apple contributes to an open standard for this, instead of keeping this proprietary. In the emerging world of generative AI, we need this more than ever. Not just iPhone, but ideally most camera systems will have some kind of verifiable capture mode.

Re: Apple Reference Image: A New Approach for Verified Photography

#335

Earlier quoted context omitted.

> No, because images will be confirmed to have been taken on "this iPhone". Actually the description of Apple makes explicit statements AGAINST that: Quote: Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device

> an outside observer An inside observer can tho, and if they know or have it, cant they be subpoenaed and forced to disclose the identity? This sounds pretty bad for journalists/sources. Why is this needed now of all times?

I think it's great for journalists and journalism because maybe people will stop paying attention to crap on social media, which won't have such verification, and they'll be instead looking at legit journalism.

Re: Apple Reference Image: A New Approach for Verified Photography

#336

The power of marketing. EU wants Apple to implement digital fingerprinting to fight CSAM: overreach of power, total invigilation, nonono! Apple cannot comply! What about our privacy! Apple implements the feature and sells it nicely wrapped in a PR material: oh, that's cool, innovative!

These two things, fingerprinting to fight CSAM, and the Apple Reference Image, are not the same. They have completely different goals and completely different implementations.

Re: Apple Reference Image: A New Approach for Verified Photography

#337

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…

How is stealing/extracting a private key alien technology? Or even more simple, subpoena a private key to create fake authentic compromising pictures of pesky political opponents.

Re: Apple Reference Image: A New Approach for Verified Photography

#338
This will create a social problem of people discrediting images by a niche camera vendor or by a bootloader unlocked phone or from budget cameras or or from niche camera manufactuers from film cameras or from cameras that are old, while still allowing for advanced telecine attacks.

Re: Apple Reference Image: A New Approach for Verified Photography

#339
post #269

Earlier quoted context omitted.

> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…

> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. That the Apple Reference Image itself is not traceable to the device/user is b…

I think this is a good thing. Proof that an image is actually real is a valuable underpinning of society and being able to provide that is incredibly important.

Re: Apple Reference Image: A New Approach for Verified Photography

#340

Earlier quoted context omitted.

> an outside observer An inside observer can tho, and if they know or have it, cant they be subpoenaed and forced to disclose the identity? This sounds pretty bad for journalists/sources. Why is this needed now of all times?

I think it's great for journalists and journalism because maybe people will stop paying attention to crap on social media, which won't have such verification, and they'll be instead looking at legit journalism.

Not to contradict but that sounds overly rosy
Post reply on HN