528 points by imwally 4 days ago | 352 comments | View on ycombinator
tgsovlerkhgsel 4 days ago |
tristanj 4 days ago |
Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.
To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.
I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
modeless 4 days ago |
I hope that companies and governments don't start forcing us to use this stuff by requiring it for their services.
akersten 4 days ago |
I don't think we should have this, for that reason alone (but many others too).
rickdeckard 4 days ago |
Like with the Watch Ultra (attacking the diving-watch market with the sheer volume-scale of selling the development to everyone buying a Watch Ultra), Apple is attacking the trusted-imaging market with the same strategy.
Okay, fine. Will work for sure, this will disrupt the trusted-imaging market and moreover make Apple a service-provider in this industry (with the ramp-up cost paid by customers buying iPhones for entirely different purposes).
But creating this impression and media-buzz that Apple is now verifying more than just the digital authenticity of an image may shift the public scrutiny of MANY media/online statements:
There is a risk that random claims (and propaganda) will be given more credibility in the public eye just because they came with images that were confirmed to be "taken like this on an iPhone"
jeroenhd 4 days ago |
Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. The timestamping server is a nice idea (though I don't see why they can't just use a normal timestamping server, I guess to keep control over the protocol) but it doesn't solve the fundamental problem that defeated C2PA.
RandomGerm4n 4 days ago |
It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
phkx 4 days ago |
djtango 4 days ago |
So if you jailbreak or root your phone what happens? Is this a trojan horse into making rooted phone cameras unverified? Just like how Linux machines can't watch Netflix in 4K
grishka 4 days ago |
And, yeah, I'm incredibly tired of this whole concept of a device you own acting in someone else's interests. This needs to stop and it needs to happen 10 years ago.
saagarjha 4 days ago |
NeoByte 4 days ago |
wky 4 days ago |
SoftTalker 4 days ago |
dsign 4 days ago |
jsrozner 4 days ago |
The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.
clarkmoody 4 days ago |
First reply was exactly the same as most of the top-level comments here today: "That doesn’t prove anything. Make your fake video, point your phone camera at it, record."
Of course, I'm sure someone else had thought of something along these lines in the 90s, I just didn't have a citation to hand.
eutropia 4 days ago |
petesergeant 4 days ago |
demibabs 4 days ago |
I’m surprised that even Apple calls jailbreaking, jailbreaking. Doesn’t that imply their own software is a jail?
itintheory 4 days ago |
ozlikethewizard 4 days ago |
walrus01 4 days ago |
chaz6 4 days ago |
nxtfari 3 days ago |
I am curious if the PCC processing makes it resilient to the method from a couple years ago of fingerprinting the microdistortions in an individual phone lens to tell when two photos were taken by the same phone.
rasguanabana 4 days ago |
albert_e 4 days ago |
If i create a high quality deepfake image, project it on a large screen and take a photo of that image with an iPhone (+apple verified image secure tag) ... would that resulting image be considered "authentic" by default?
Would digital forensics accessible to lay people still be able to fact-check and call out misuse / fakery of the new secure tag.
icar 4 days ago |
asaddhamani 4 days ago |
Velocifyer 4 days ago |
jithinsankar 4 days ago |
mrinterweb 4 days ago |
keiferski 4 days ago |
codetiger 4 days ago |
int32_64 4 days ago |
WalterGR 4 days ago |
gmueckl 4 days ago |
Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?
gcanyon 4 days ago |
VortexLain 4 days ago |
tantalor 4 days ago |
2. Take a photo of it with iPhone
3. Apple's fancy reference image thing now says "omg it's real you guys"
dsalzman 4 days ago |
9shrey 4 days ago |
bawolff 4 days ago |
- it sounds like its an optional mode you have to enable. That kind of defeats the point if you need to prove something after the fact
- i guess you need internet to take a picture. :(
- You are puting a lot of trust in apple's private cloud compute platform.
- apple can revoke certification of a picture. I understand the appeal of this, all security systems eventually have failures, so its important to be robust against this. However if the point is to prove a picture is real (especially politically damaging ones), this is giving a lot of power to apple.
Its meant to be in competition with C2PA, and i guess the idea is its much more secure against complex hardware attacks. However i think its worth asking who the target audience is and what threats they face. The primary issue with AI is it makes fake photos easy, not that it invented fake photos. Even Stalin manipulated photos back in the day. It is not a new thing, the problem is just being overwhelmed with them.
with that in mind, are complex hardware attacks really that important? We just need to increase the difficulty floor, not solve fake photos for all time. No matter what you do, people can still use practical effects.
It seems like this is almost trying to thwart spies and nation state adversaries, well forgetting that such well funded groups have the budget to fake photos the old fashioned way or if they really cared, bribe their way into apple.
cedws 4 days ago |
dom96 4 days ago |
SeriousM 4 days ago |
antifarben 4 days ago |
rockbruno 4 days ago |
So the iPhone Duo won't have it?
preetx 4 days ago |
pmlnr 4 days ago |
throw1234567891 4 days ago |
EU wants Apple to implement digital fingerprinting to fight CSAM: overreach of power, total invigilation, nonono! Apple cannot comply! What about our privacy!
Apple implements the feature and sells it nicely wrapped in a PR material: oh, that's cool, innovative!
ErneX 4 days ago |
Roark66 4 days ago |
RRRA 4 days ago |
lwhi 4 days ago |
Use film.
bsenftner 4 days ago |
rvz 4 days ago |
Hardware wins.
ed_mercer 4 days ago |
manso_ilands 4 days ago |
sehw 4 days ago |
xeonmc 4 days ago |
puppycodes 4 days ago |
but im sure it will popular with 60 year olds watermarking their pictures of sunsets.
SXX 4 days ago |
Scrapped in 3..2..1..
0xWTF 4 days ago |
There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).
Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.