‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. tgsovlerkhgsel · · focus · HN ↗
    This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

    There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

    Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

    1. itake · · focus · HN ↗
      I don’t understand what this brings to the table beyond what we’re currently doing.

      Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.

      1. ben_w · · focus · HN ↗
        As per opening paragraph of link, AI fakes are a thing.

        It&#x27;s been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9224">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9224 and <a href="https:&#x2F;&#x2F;en.wikiquote.org&#x2F;wiki&#x2F;Rob_Malda" rel="nofollow">https:&#x2F;&#x2F;en.wikiquote.org&#x2F;wiki&#x2F;Rob_Malda

        NVIDIA suggested AI fakes controlled with face tracking input as a compression technique just for reducing video call bandwidth requirements (to ~117 bytes per frame). They did that six years ago: <a href="https:&#x2F;&#x2F;www.dpreview.com&#x2F;news&#x2F;5756257699&#x2F;nvidia-research-develops-a-neural-network-to-replace-traditional-video-compression&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.dpreview.com&#x2F;news&#x2F;5756257699&#x2F;nvidia-research-dev...

        As we&#x27;re now in an AI race, even NVIDIA&#x27;s specific technique has flaws which all the current tools can detect, there&#x27;s never any guarantee of this continuing to be the case.

        That said, in the case of Apple, they&#x27;re historically followers not leaders despite the public image they like to present about innovation, and I&#x27;d expect this method to be flawed from day one even if we weren&#x27;t reading a corporate blog post written in a self-congratulatory tone I find almost as off-putting as when AI write.

        1. itake · · focus · HN ↗
          You don’t even need an AI deepfake to edit a video.

          AI deepfake or edit video doesn’t pass liveliness checks without all the c2pa or reference image song and pony show.

          Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive.

          They could also just update their app to stop accepting photos from the album.

          1. lxgr · · focus · HN ↗
            &gt; Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive.

            All of this data can be spoofed if it&#x27;s not somehow authenticated.

            &gt; They could also just update their app to stop accepting photos from the album.

            Doesn&#x27;t help at all if the spoofed data is arriving via spoofed hardware.

        2. alwillis · · focus · HN ↗
          &gt; That said, in the case of Apple, they&#x27;re historically followers not leaders despite the public image they like to present about innovation

          While its true Apple usually isn&#x27;t the first in a product category--not the first mp3 player, not the first smartphone, not the first tablet) but once they get there, they&#x27;re quite innovative.

          When the iPhone 5s was released in 2013, it was the first smartphone with a 64-bit processor, which caught Qualcomm off guard. Even when Qualcomm released a 64-bit processor the following year, it kinda didn’t matter because Android was still 32-bit.

          1. mitxela · · focus · HN ↗
            nobody actually needed that though
        3. mitxela · · focus · HN ↗
          Twitter now flashes your screen different colors while watching the camera pointed at your face when you sign up, you know, to &quot;make sure you&#x27;re a real person&quot;
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.