Live data from Hacker News

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

71–80 of 359 posts

Re: Apple Reference Image: A New Approach for Verified Photography

#71

Earlier quoted context omitted.

Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth informa…

This approach makes me wonder if the future is actually going to move towards visual cryptography.

Um… that's already a thing [1]:

    TL;DR: What is C2PA in 60 seconds

    What: An open technical standard for embedding cryptographically signed provenance data inside digital media files.

    Who: Created by a coalition founded by Adobe, Arm, BBC, Intel, Microsoft, and Truepic in February 2021.

    How: A C2PA Manifest (also called a Content Credential) travels inside the file and records who made it, when, and what tools were used.

    Why: Deepfake incidents surged from 500,000 to 8 million cases between 2023 and 2025. Provenance gives media a verifiable chain of custody.
[1]: https://c2paviewer.com/articles/what-is-c2pa

Re: Apple Reference Image: A New Approach for Verified Photography

#72

Earlier quoted context omitted.

Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth informa…

> it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos. I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?

Paint the stopper vantablack then.

Re: Apple Reference Image: A New Approach for Verified Photography

#73
post #52

Seems kind of concerning that using this at all means you send your image to Apple’s PCC machines.

Edit^2: On triple reread it sounds like the first pass ("Image Capture") sends the image metadata hash to be timestamped, whereas the second pass (Reference Image Development) sends the image itself but is not what actually creates the timestamp attestation. According to Apple[0][1] it sounds like the second pass (development) only happens when the reference image is actually viewed, which means that your image isn't…

> some reason over signing metadata on-device

After my brief read, one of the main reasons they’re using PCC to produce the signed JPEGs, instead of doing everything on device, is that it maintains your privacy.

If you were signing with the iPhone, an attacker could then correlate photos taken with the same device.

Apple certainly has the data that “this sensor, in this device, took this exact photo” in PCC at the time of signing, but they discard that data.

Re: Apple Reference Image: A New Approach for Verified Photography

#74
post #3

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image. Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image. To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the m…

I suspect they have ways to ID at least some things like this somehow in ways that will lead to key revocation.

Re: Apple Reference Image: A New Approach for Verified Photography

#75

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

> People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

True.

> raises the bar but could be bypassed with enough effort.

Anyone can spoof this.

Apple cannot stop spam iMessages. They can't stop someone from rendering their privileged UI inside a browser viewport. People copy and paste remote script executions from convincing captchas.

This whole provenance thing is a red herring. You agree with me, but there's truly not a single application for this that won't be exploited.

Re: Apple Reference Image: A New Approach for Verified Photography

#76

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do…

I don’t understand what this brings to the table beyond what we’re currently doing.

Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.

Re: Apple Reference Image: A New Approach for Verified Photography

#77

Earlier quoted context omitted.

> This makes it like, a thousand times harder to fake a photo than it would otherwise be. The problem with this thinking is twofold: 1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used. 2) It increases the potential value of a forgery because now your forge…

You worry that a technology that you have never used nor evaluated might not work in practice... Therefore because of your worry (which is based on remarkably little information), it's a bad technology? Come the fuck on. That's beyond luddite bullshit.

Is this you? https://news.ycombinator.com/item?id=49685271

Re: Apple Reference Image: A New Approach for Verified Photography

#78
Seems to lead us down the slippery slope of requiring an Apple device, or a Google device (e.g., https://cybernews.com/privacy/google-qr-code-recaptcha-requi...), or the device of some other entity (that may be mostly non-aligned with democratic values) in order to participate in society.

The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.

Re: Apple Reference Image: A New Approach for Verified Photography

#79
This is so insanely complex and requires placing trust in the correctness of so many pieces, many of them closed-source. And uploading every verified "developed" image to Apple's servers. And giving up full control of the software and hardware you "own". All to achieve a goal of "verifying" photons, which is only a part of the real problem of verifying the truth of an event that was photographed.

I hope that companies and governments don't start forcing us to use this stuff by requiring it for their services.

Post reply on HN