‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. tgsovlerkhgsel · · focus · HN ↗
    This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

    There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

    Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

    1. rickdeckard · · focus · HN ↗
      I don't understand the vector of this:

      An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted).

      Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this.

      Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim?

      Or is the insurance agent / mechanic an untrusted entity who will now be required to have an iPhone 18 Pro?

      What is the fraud vector here, and how can the insurance service provider continue cost-saving on damage-assessment by offloading to the customer, if the customer is required to own a specific device?

      1. yreg · · focus · HN ↗
        > Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim?

        In a couple of years it will be almost any iPhone instead of 18 Pro. And if it catches on, other phone vendors will provide a similar service.

        1. rickdeckard · · focus · HN ↗
          So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung?

          And then stop the 3rd party app which is vendor-agnostic and works on all devices?

          I'd say that's unlikely.

          IF that's an industry this Apple-feature will disrupt, it seems it will barely have an impact on the process of insurance companies themselves, but will actually disrupt the service-provider industry FOR insurances:

          The insurance won't be able to stop their existing 3rd party cost-saving, as it provides the largest device-coverage for offloading to the customer.

          Instead, either the insurance or the 3rd party service-provider will have to pay Apple in addition to make use of this feature, with the hopes that the provided data will reduce fraud.

          Which brings me back to my actual question: What is the fraud-vector here?

          1. Topfi · · focus · HN ↗
            > So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung?

            The industry has some extensive experience in independently verifying signatures, I don't see how the manufacturers factor in here. And for app features, just ask banks how integrating biometrics, payment services, etc. goes. Tends to be preferred, once Apple and Google Pay became fully available here in Austria, banks dropped their own NFC payment solutions in rapid succession.

            1. rickdeckard · · focus · HN ↗
              Me neither, so your reply should be on the parent, because it states "And if it catches on, other phone vendors will provide a similar service."
          2. PunchyHamster · · focus · HN ↗
            >So the insurance would then, instead of contracting the current service-provider for the 3rd party app, contract also with Apple and, let's say Samsung?

            There would be no contract, you just upload image from your phone and they verify signature in the file

      2. bayindirh · · focus · HN ↗
        Some banks needs photos of machine readable IDs to verify user details to fight fraud. These IDs can be passports or NFC enabled EU (and compatible) ID cards.

        This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.

        1. rickdeckard · · focus · HN ↗
          Okay, this doesn't answer the question on the vector but is another interesting example. Let's expand on that one then:

          Banks are offloading the trusted process of ID verification to an untrusted entity (end-user, merchant,...) and compensate for the loss of security by using a trusted service-provider (now Apple AND an iPhone 18 Pro).

          This is already happening today in two scenarios:

          1. lower-risk scenarios (remotely) with trusted 3rd party service-providers and very low Hardware-requirements ("use this app on your phone to take a picture/video") and

          2. higher-risk scenarios (on-site) with trusted 3rd party service-providers ("use THIS expensive device to take a picture/video of the customer/citizen")

          Apple now potentially disrupts the service-provider industry of #2 (higher-risk scenarios) by

          #a grabbing a part of this hardware/service market that MAY allow the end-user to be in control of the device and

          #b replacing the on-site hardware/service with an iPhone "in a box".

          They can't disrupt #1 because their cost-saving can't mandate the end-user to buy a 1000+ USD device just for THEM to provide the contracted service. (They can add convenience if you have it, but they can't reject their service if you don't)

          Which means they disrupt mainly #2: The industry providing trusted imaging solutions for higher-risk scenarios.

          --> So it's the Watch Ultra game all over again.

          On Watch Ultra they disrupted the diving-watch market by the sheer scale of selling their development to everyone buying a Watch Ultra, driving down the cost so much that they can undercut every diving-watch company on the market.

          Now they use the sheer scale of iPhone 18 Pro sales to enter the trusted-imaging market-segment, undercutting every player there and take that market.

          1. bayindirh · · focus · HN ↗
            Don't forget law enforcement, customs or any high(ish) stakes sector which needs to be able to trust the images they show as evidence as well.

            Back in the day Canon and Nikon tried this with embedded private keys on their cameras, and with Sandisk's WORM SD cards. Then, somebody extracted the keys and it was game over.

            While my iPhone 17 can't match a full frame mirrorless camera, it can take pretty impressive photos, so they are already more than adequate in detail and clarity department. So making these images trusted is a huge win for them.

        2. lxgr · · focus · HN ↗
          ID document verification via NFC can't by itself replace also biometrically verifying the person purporting to be the one that the document belongs to.

          Without it, anyone with a stolen document can pass it. (I don't think there's a generally available database of stolen documents, so I suspect these usually remain valid until their regular date of epxiry.)

          1. bayindirh · · focus · HN ↗
            Generally, the information in our country is checked via multiple ways: NFC + Biometric data (checked against the data inside the ID card) (+ photo of the ID in some cases), or any combination of those.

            Before deepfakes were dime a dozen, I remember my bank starting a video-call with me and required me to show my ID to them via camera. This was after a multi-factor check that I passed.

            Making any of these factors more trustworthy is a win in my perspective, so having a trusted sensor is always better even if you do multi-factor authentication.

            Our ID cards have a private-public key pair inside them, and it allows us to sign things amongst other things. Renewing your ID card for any reason revokes the digital signature of the previous one, so scanning it via NFC probably enough to check whether it's revoked. Same with photo (since machine readable part contains serial and check digits and such).

      3. tgsovlerkhgsel · · focus · HN ↗
        Nowadays they do #3, demand that the customer takes pictures with a special app that claims to make the process nearly as trusted as #1 while being nearly as cheap as #2.

        The idea is indeed that instead or in addition to requiring an app, the insurance company would require the app to run on a phone that supports Reference Image to make sure the image wasn't tampered with. Not right now, when the phones are new, but in a while when 50% of Americans have a sufficiently new iPhone. The rest of the people gets told to either borrow one if they want to make a claim, or go through some other alternative process designed to be so annoying that most people give up.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.