Apple Reference Image: A New Approach for Verified Photography
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Apple Reference Image: A New Approach for Verified Photography
Unofficial Hacker News client; not affiliated with Y Combinator.
tristanj · · focus · HN ↗
Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.
To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.
I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
amanj41 · · focus · HN ↗
tristanj · · focus · HN ↗
Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.
dd8601fn · · focus · HN ↗
I feel really dumb for not having thought of this.
amanj41 · · focus · HN ↗
Cthulhu_ · · focus · HN ↗
osy · · focus · HN ↗
> Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago.
Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.
BugsJustFindMe · · focus · HN ↗
It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened".
It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself.
Likewise in "distinguish between photographs that depict real events and...".
spiderice · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
The problem with this thinking is twofold:
1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.
2) It increases the potential value of a forgery because now your forgery is attested by Apple.
So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
porkshoe · · focus · HN ↗
Therefore because of your worry (which is based on remarkably little information), it's a bad technology?
Come the fuck on. That's beyond luddite bullshit.
otterley · · focus · HN ↗
You must be new around here. ;-)
BugsJustFindMe · · focus · HN ↗
phoghed · · focus · HN ↗
porkshoe · · focus · HN ↗
latexr · · focus · HN ↗
Then maybe let’s save those criticisms until this is in the hands of knowledgeable people who can actually test? I mean, I’m no fan of the direction Apple has gone under Tim Cook, but all else being equal I’m inclined to give them the benefit of the doubt that they may have thought this through over the time it took to build more than a random person speculating on HN who just read a blog post for the first time.
> (…) we see no details here about what scene information is used.
And you assume that everything in a post is the sum total of how it works?
> It increases the potential value of a forgery
By that token, should we also not be adding forgery deterrents to ID cards and bills? After all, if you can fake the preventive measures, “it increases the potential value of a forgery”.
brookst · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
[dead]
reader9274 · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
[dead]
bawolff · · focus · HN ↗
After all, if money is no object, you could just bribe every single apple employee involved in the project.
Gigachad · · focus · HN ↗
zimpenfish · · focus · HN ↗
Let me introduce you to Sir Arthur Conan Doyle and the Cottingley Fairies[0].
"Doyle was enthusiastic about the photographs, and interpreted them as clear and visible evidence of supernatural phenomena. [...] the photographs were faked, using cardboard cutouts of fairies copied from a popular children's book of the time"
[0] <a href="https://en.wikipedia.org/wiki/Cottingley_Fairies" rel="nofollow">https://en.wikipedia.org/wiki/Cottingley_Fairies
pndy · · focus · HN ↗
Which surely will be useful in ID verification on the Internet; Android devices most likely will follow with same or similar solution
pveierland · · focus · HN ↗
<a href="https://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/20260268025" rel="nofollow">https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...
The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.
BugsJustFindMe · · focus · HN ↗
gruez · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all.
Anyway, one may presume that they've thought about this.
brookst · · focus · HN ↗
It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?
BugsJustFindMe · · focus · HN ↗
I think this will depend on how it gets used. I can imagine numerous outcomes where it's in fact worse than nothing (significantly more effective blackmail, for instance).
brookst · · focus · HN ↗
akersten · · focus · HN ↗
While that is not quite my bar of confidence when implementing wide-reaching technologies that have numerous unexplored knock-on effects, I guess the calculus must have been different on Infinite Loop recently.
dd8601fn · · focus · HN ↗
I’ve seen that type of argument a million times, and I’ll certainly reuse that.
MisterKent · · focus · HN ↗
The problem is that it makes it easier to fool people and provide "cryptographic" evidence of validity, backed by big tech.
It's purpose is to stop bad actors from passing of fake as real just as much as it is to prevent real images being dismissed as fake.
alwillis · · focus · HN ↗
Knowing Apple, they've been working on and testing Apple Reference Image for years.
It being perfect isn't the issue; it's that random people on the internet who are just learning about this assume Apple's engineers haven't already thought about everything (and more) mentioned in this thread.
archagon · · focus · HN ↗
ben_w · · focus · HN ↗
Given how many bugs there are in macOS and how long they have remained there, I (who have been writing iOS apps from the release of the first retina iPod touch until AI got good) functionally agree with such people; at best, I think Apple's engineers haven't actually solved everything (and more) mentioned in this thread, even if every one of these things may have come up in discussions and even reached an official backlog or task list or similar.
mitxela · · focus · HN ↗
croon · · focus · HN ↗
somethinsfishy · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
nomel · · focus · HN ↗
[1] <a href="https://commonlands.com/products/ir-cut-filters-csp650?srsltid=AU7gw4X-pCzrQspQzH18g1_O281WPxL3N-zhy48Usxf-IMb8Ctbs45Bk" rel="nofollow">https://commonlands.com/products/ir-cut-filters-csp650?srslt...
pveierland · · focus · HN ↗
BugsJustFindMe · · focus · HN ↗
> increasing the difficulty of producing a forgery
The problem with this thinking is twofold:
1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.
2) It increases the potential value of a forgery because now your forgery is attested by Apple.
So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.
moffkalast · · focus · HN ↗
tristanj · · focus · HN ↗
A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information. The video files (Possibly audio too) could also be included with the verified image as additional verification.
They can also prevent photos if iPhone detects the LiDAR sensor is covered, similar to how Meta does it with their camera glasses.
pveierland · · focus · HN ↗
Similarly, LiDAR alone will help disqualify cases where someone is just taking a picture of e.g. a landscape target of the Golden Gate, but that it shown on a screen 1 meter away.
halestock · · focus · HN ↗
alwillis · · focus · HN ↗
halestock · · focus · HN ↗
sandcat_ · · focus · HN ↗
dylan604 · · focus · HN ↗
I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?
jojobas · · focus · HN ↗
testdelacc1 · · focus · HN ↗
mitxela · · focus · HN ↗
Findecanor · · focus · HN ↗
I think optics could be used to make each camera see a different image.
A video could show shake, which could be verified against readings from the phone's accelerometer -- but you could just hold it still and claim that it was on a tripod.
avianlyric · · focus · HN ↗
I think iPhones already do this (although without taking multiple seconds of video). iOS is capable of generating pretty accurate depth data even on devices with no LiDAR unit.
astafrig · · focus · HN ↗
geokon · · focus · HN ↗
seems pretty easy to make it sufficiently difficult to trick the system
dinobones · · focus · HN ↗
Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.
BugsJustFindMe · · focus · HN ↗
nvme0n1p1 · · focus · HN ↗
<a href="https://www.elcomsoft.com/news/428.html" rel="nofollow">https://www.elcomsoft.com/news/428.html
<a href="https://blog.elcomsoft.com/2011/04/nikon-image-authentication-system-compromised/" rel="nofollow">https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...
You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin.
It's funny to see Apple fall into this same trap.
Rohansi · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
srik · · focus · HN ↗
scorpiosdayoff · · focus · HN ↗
[dead]
walrus01 · · focus · HN ↗
But you're only allowed to do that if your name if Anish Kapoor
zimpenfish · · focus · HN ↗
ricksunny · · focus · HN ↗
There’s no such thing as a Golden Gate Bridge.
Prove it.
baxtr · · focus · HN ↗
I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage.
That’s a tradeoff I can live with.
dgellow · · focus · HN ↗
You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar
Glyptodon · · focus · HN ↗
mw888 · · focus · HN ↗
While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified.
It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.
nalekberov · · focus · HN ↗
Gupie · · focus · HN ↗
est · · focus · HN ↗
I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter.
The "digital negative" in DNG format can be used to analyze the authenticity of the content.
peri-cl · · focus · HN ↗
Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed.
Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...")
It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.
[deleted] · · focus · HN ↗
[deleted]
eutropia · · focus · HN ↗
So if you're the proud owner of "literally the only photo of a ridiculously unusual event in a highly public area" which is bounded to either a plausible 15-30 minute window or a sketchy March2026->Now window, people can do something like "hey, gee, did anyone else see that UFO over the golden gate bridge at 3pm?"
plus, you know, the confidence score from their secret neural network, which has an unknown scoring function.
rlt · · focus · HN ↗
I wouldn't be surprised if it's also possible to detect the differences between a photo of a real scene and a photo of a monitor or printout displaying a photo of a real scene, given they have the raw sensor output.
Not sure if they're doing anything like that.
furyofantares · · focus · HN ↗
However much effort is required to fake it - it's proof that the image is either legit or that much effort went in. There's TONS of cases where it's plausible for someone to have put in the effort to fake a photo with AI (nearly zero effort required) but not remotely plausible that they set up some elaborate high quality photo of a fake.
It's also much more damning if you get caught faking it. Think of the examples where police have been caught posting altered images on social media. The lame excuse that some intern didn't realize it would do more than just upscale the image won't fly if some elaborate setup was required.
HALtheWise · · focus · HN ↗
This sort of concern is presumably why Apple says "Using a neural network with hidden weights, PCC computes a confidence score for the photograph." I'm assuming that things like moire-patterns from pointing the camera at a screen would be caught by that check.
It's of course physically possible to fool the sensor, but at some point it becomes cheaper to just build a UFO and fly it over the actual Golden Gate Bridge.