Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

281–290 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#281

Earlier quoted context omitted.

> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". You have it all wrong. Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by…

Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you're willing to do it destructively. They can then sign their own fraudulent images.

The NSA has probably already forced Apple to hand the keys over to them.

Re: Apple Reference Image: A New Approach for Verified Photography

#282
Canon tried this 20 years ago with DSLRs. Nikon had an authentication system. Both were broken. The keys ended up on Pastebin. Apple's hardware security is better, but history suggests this is a temporary advantage. The real question is whether the system will be revoked when (not if) it's broken, and whether Apple will have the guts to retroactively invalidate millions of "verified' photos"

Re: Apple Reference Image: A New Approach for Verified Photography

#283
post #269

Earlier quoted context omitted.

> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. That the Apple Reference Image itself is not traceable to the device/user is b…

Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.

> If they can verify an Apple Reference Image they can verify an NFC document

Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.

Re: Apple Reference Image: A New Approach for Verified Photography

#284

Canon tried this 20 years ago with DSLRs. Nikon had an authentication system. Both were broken. The keys ended up on Pastebin. Apple's hardware security is better, but history suggests this is a temporary advantage. The real question is whether the system will be revoked when (not if) it's broken, and whether Apple will have the guts to retroactively invalidate millions of "verified' photos"

keys went public way after it was abandoned.

think for one second, who cares enough about image authenticity AND publishes raw photos directly from a camera with zero post production?

this was, is, and always will be useless and only serve the purpose it's fulfilling here: talk about the brand in a higher than thou privacy bastion.

Re: Apple Reference Image: A New Approach for Verified Photography

#285

Earlier quoted context omitted.

> You'll still need an iPhone, the verification is linked to the specific iPhone, and the specific iPhone is linked to you. Unless you use a friend's iPhone, or an iPhone you 'rented' for 5 minutes for $20 from someone on Craigslist or Facebook Marketplace to take a picture on and then Airdrop to you.

If they airdrop it to you that typically requires you to have an iphone or a mac and airdrop users are able to be identified and tracked so the photo could still be linked to your device. The EU forced apple to use Wi-Fi Aware though, so unless that's similarly vulnerable people in the EU might be able to avoid those issues.

What? Just send the photo using literally any other method. Am I missing something, or did everyone just waste two minutes of their lives reading this?

Re: Apple Reference Image: A New Approach for Verified Photography

#286

Earlier quoted context omitted.

Those are two fundamentally different things: 1. OIS (optical stabilization) ensures that the light photons consistently hit the same pixel, removing the blur caused by camera-shake during exposure. 2. EIS (electrical stabilization) via cropping compensates camera-shake on video(!) recording by applying the same shake to the crop-canvas within the frame. --> EIS can fix a shaky video but not a blurry photo.

It's 2026, with cleaner high ISOs even in phone sized sensors giving the ability to raise the shutter speed as needed, we hadn't had much of an issue with blurry photos for a decade now, with or without OIS. There have been several expensive cameras with no OIS, like Ricoh GR and (and v2), or ZVE10 (and v2). It's video where people care about these days. Does anybody complain about blurry S12 photos?

Might be boring, but in 2026 "clean high ISOs" in phone-sized sensors mainly comes from image post-processing (stuff like multi-frame merging is done even when shooting "RAW"). Post-processing requires a stable (albeit noisy) image, otherwise it'll be garbage-in/garbage-out.

--> OIS actually became MORE important for Smartphones in the past years, because while post-processing produces better and better results, it massively depends on usable input data. OIS is one of the very few methods to improve the INPUT-quality for post-processing.

>"There have been several expensive cameras with no OIS, like Ricoh GR and (and v2), or ZVE10 (and v2)."

That's a apples and oranges comparison. A quick Google search tells me the size of a pixel on the Ricoh GR sensor is 4.81 µm, which is ~8 times larger than the pixel in recent smartphones (~0,6µm). It is not only physically capable to capture 8x more light, it is also much less affected by minor shaking than sensors with smaller pixel-sizes.

>"Does anybody complain about blurry S12 photos?"

Not sure what's a "S12", but:

- On flagship phones with OIS: Not so much. Maybe in low-light scenarios, because, you know, not much light...

- On cheaper devices without OIS: Yes! Oh yes, constantly.

People assume that the picture-quality of a e.g. 2026 Galaxy A16 must be comparable or better than the picture of a 8-year old Galaxy S9. It's not, the S9 is still better in everyday shooting.

Just check user-reviews of mass-tier smartphones without OIS, like Samsung Galaxy A series...

Re: Apple Reference Image: A New Approach for Verified Photography

#287
post #269

Earlier quoted context omitted.

> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. That the Apple Reference Image itself is not traceable to the device/user is b…

Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.

There are tons of online services that require you to take pictures of your face, driver’s licenses, passports, etc.

Re: Apple Reference Image: A New Approach for Verified Photography

#288

Earlier quoted context omitted.

I don't understand the vector of this: An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted). Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this. Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to mak…

Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards. This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

ID document verification via NFC can't by itself replace also biometrically verifying the person purporting to be the one that the document belongs to.

Without it, anyone with a stolen document can pass it. (I don't think there's a generally available database of stolen documents, so I suspect these usually remain valid until their regular date of epxiry.)

Re: Apple Reference Image: A New Approach for Verified Photography

#289

Earlier quoted context omitted.

If they airdrop it to you that typically requires you to have an iphone or a mac and airdrop users are able to be identified and tracked so the photo could still be linked to your device. The EU forced apple to use Wi-Fi Aware though, so unless that's similarly vulnerable people in the EU might be able to avoid those issues.

What? Just send the photo using literally any other method. Am I missing something, or did everyone just waste two minutes of their lives reading this?

Only wasted two minutes if you read really slowly

Re: Apple Reference Image: A New Approach for Verified Photography

#290
post #269

Earlier quoted context omitted.

> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. That the Apple Reference Image itself is not traceable to the device/user is b…

Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.

How exactly am I expected to upload my nfc chip to my insurance company’s website?
Post reply on HN