‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. tgsovlerkhgsel · · focus · HN ↗
    This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

    There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

    Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

    1. alwillis · · focus · HN ↗
      > This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

      You have it all wrong.

      Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.

      There's no way to link a reference image to a person; it's also not possible to determine if a pair of images came from the same device.

      > And while "a nation state actor can spoof this" is a problem for the journalism use case

      This is incorrect:

          When the image sensor is first initialized in the factory, it creates a
          cryptographic signing identity, sharing only the public key with the
          factory. The SEP similarly creates a separately-attested signing
          identity. These identities are bound together into the device manifest,
          allowing us to later check whether a particular sensor and SEP are from
          the same device.
      
          The final signature on a reference image is a composite post-quantum
          signature combining RSA-3072 and ML-DSA-87. To our knowledge, Apple
          Reference Image is the only image provenance system that provides
          quantum-secure defenses.
      
      So… a nation-state can't really do anything here unless they acquire alien technology. If something crazy happens (solar flare or EMP?), a fraudulent reference image can be revoked.

      > Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

      I would imagine there will be a way to confirm an Apple Reference Image on the web. Pretty soon, 3rd parties will be able to verify the image themselves:

          Reference images can be viewed in the Photos app alongside the main
          image, like a digital negative, to visually compare the two assets and
          determine if any edits were made. APIs are available in iOS, iPadOS, and
          macOS 27 for third-party apps to enable viewing of these reference images.
      1. Retr0id · · focus · HN ↗
        EMPs are not "alien technology", and you don't need to be a nation state either. That said, Apple's hardware security is generally very good.
        1. setopt · · focus · HN ↗
          > EMPs are not "alien technology"

          Yup, you don’t even need nukes: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Explosively_pumped_flux_compression_generator" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Explosively_pumped_flux_compre...

          1. Retr0id · · focus · HN ↗
            or a bic lighter <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Piezo_ignition" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Piezo_ignition
      2. iugtmkbdfil834 · · focus · HN ↗
        &lt;&lt; Apple Reference Image is not an id system;

        I think you have a point. I would only note that just because it is not explicitly designed as one, does not mean it will not be effectively utilized in that manner.

      3. mitxela · · focus · HN ↗
        You&#x27;ll still need an iPhone, the verification is linked to the specific iPhone, and the specific iPhone is linked to you.
        1. throw0101c · · focus · HN ↗
          &gt; You&#x27;ll still need an iPhone, the verification is linked to the specific iPhone, and the specific iPhone is linked to you.

          Unless you use a friend&#x27;s iPhone, or an iPhone you &#x27;rented&#x27; for 5 minutes for $20 from someone on Craigslist or Facebook Marketplace to take a picture on and then Airdrop to you.

          1. mitxela · · focus · HN ↗
            Buying a new overpriced phone every time you want to take a picture is certainly a decision.
          2. autoexec · · focus · HN ↗
            If they airdrop it to you that typically requires you to have an iphone or a mac and airdrop users are able to be identified and tracked so the photo could still be linked to your device. The EU forced apple to use Wi-Fi Aware though, so unless that&#x27;s similarly vulnerable people in the EU might be able to avoid those issues.
            1. propaganja · · focus · HN ↗
              What? Just send the photo using literally any other method. Am I missing something, or did everyone just waste two minutes of their lives reading this?
              1. tmp10423288442 · · focus · HN ↗
                Only wasted two minutes if you read really slowly
            2. lxgr · · focus · HN ↗
              Airdrop has been supported on many Android devices even outside the EU for a while now: <a href="https:&#x2F;&#x2F;www.android.com&#x2F;quick-share&#x2F;with-iphone&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.android.com&#x2F;quick-share&#x2F;with-iphone&#x2F;

              Or you could just email&#x2F;WhatsApp&#x2F;... it.

            3. throw0101c · · focus · HN ↗
              &gt; If they airdrop it to you that typically requires you to have an iphone or a mac […]

              Perhaps do not be so literal: Airdrop, SMS&#x2F;MMS&#x2F;RCS, WhatsApp, Signal, etc:

              * <a href="https:&#x2F;&#x2F;github.com&#x2F;localsend&#x2F;localsend" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;localsend&#x2F;localsend

              1. autoexec · · focus · HN ↗
                I agree, lots of alternatives to the specific one you suggested exist and would probably be better.
        2. alwillis · · focus · HN ↗
          The reference image isn&#x27;t linked to any particular iPhone or person:

              We built Apple Reference Image to avoid using an explicit, public
              credential for photographers, and to avoid even implicit public
              association between different photos taken by the same sensor. The
              final reference image is instead signed by Apple’s signing service,
              after validation by PCC. That signature is backed by Apple’s
              strongest technical guarantees.
          
              Our implementation also protects the
              confidentiality of the image itself, including from Apple. Merely
              capturing a reference image should never expose the actual pixels to
              Apple or anyone else. We achieve this through the exceptional privacy
              properties of PCC — the nodes themselves are architected so that not
              even Apple can access image data, just as Apple cannot see the
              information processed for Apple Intelligence in PCC.
          1. microtonal · · focus · HN ↗
            The reference image isn&#x27;t linked to any particular iPhone or person

            It is for Apple, to the extend that if there are backdoors and weaknesses in their PCC, they could register a device signing identity to Apple signature mapping.

            I think the line of reasoning is that you have to trust Apple anyway, since they could also roll out a malicious image to your particular phone, but I still feel like PCC is much harder to verify&#x2F;audit than an iPhone already is.

      4. layer8 · · focus · HN ↗
        &gt; it&#x27;s also not possible to determine if a pair of images came from the same device.

        It’s possible for Apple, as stated in the blog post (e.g. “which lets the device later produce signatures that Apple can attribute to that specific phone”).

        1. sandy_ilands · · focus · HN ↗

          [dead]

          1. meindnoch · · focus · HN ↗

            [dead]

      5. RobotToaster · · focus · HN ↗
        &gt; So… a nation-state can&#x27;t really do anything here unless they acquire alien technology.

        At least for the image itself, using direct projection onto the sensor (in a way similar to a retinal projector or film recorder) would be difficult to detect I imagine?

        1. wildzzz · · focus · HN ↗
          They mention something about image heuristics typical of an iPhone image, that may mean that this reference mode takes a spatial image using dual sensors that help convince the PCC that it&#x27;s an image of something real. Or perhaps it uses a lidar sensor, both lidar and reference mode are only offered on the Pro models. The whole camera system is one module so it could be using all of it. Regardless, you&#x27;d need a pretty complex setup and a deep understanding of the image sensors to project something that looks real. We really don&#x27;t know what is in that first lump of signed sensor data.

          But at the end of the day, even if you manage to get a fake reference image, it&#x27;s still on the person making the claim to show that the content of the image is real. A reference image of a document is useless, the physical document could be a forgery. A photo of people could be refuted with alibis during the timestamp window (max 15 minutes it sounds like?). A photo of property damage doesn&#x27;t prove how or when it happened.

      6. coldtea · · focus · HN ↗
        &gt;There&#x27;s no way to link a reference image to a person; it&#x27;s also not possible to determine if a pair of images came from the same device.

        Apple knows the iphone the reference image was uploaded from, so, yes, there is.

        1. jclardy · · focus · HN ↗
          It doesn&#x27;t, as it is run through an Oblivious HTTP relay run by a third party before getting to Apple&#x27;s servers. So it has no IP information, and the requests use anonymous access tokens.

          It is probably possible for an entity to break it, but it would require live access to both Apple and the third party (Likely Cloudflare) servers. And that is assuming there is only one third party routing OHTTP requests, otherwise you would need to monitor all of them, in real time, since the requests are transient.

          1. cobbzilla · · focus · HN ↗
            Apple gets the device-signed image and replaces with a PCC signature to preserve anonymity.

            &gt; The final reference image is instead signed by Apple’s signing service, after validation by PCC.

            So, if compelled, Apple could theoretically tell someone if two images came from the same camera.

            1. lxgr · · focus · HN ↗
              I wonder why they&#x27;re not doing something like DAA [1], which achieves the same privacy properties without a centralized server.

              [1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Direct_Anonymous_Attestation" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Direct_Anonymous_Attestation

            2. colejohnson66 · · focus · HN ↗
              Still, &quot;the same camera&quot; isn&#x27;t &quot;this person&quot; without more information.
              1. cobbzilla · · focus · HN ↗
                sure but if you can tie “this person” to “this one photo”, then for any photo, Apple can (again, theoretically) identify all photos by that person.

                it’s one step removed from identity.

                fwiw i think this is an unambiguous improvement over current post-sensor attestations, it’s just good to explore the edges

            3. alwillis · · focus · HN ↗
              &gt; So, if compelled, Apple could theoretically tell someone if two images came from the same camera.

              No they couldn&#x27;t.

              If you generate two SSH key pairs on your laptop, there&#x27;s no way to confirm they were created on the same machine.

              There&#x27;s no device identifying data in a reference image, which is the point. The factory signature, the image sensor key, the Secure Enclave Processor key and all of the signing that takes place on PCC are all device-agnostic.

              The reference image is processed and eventually signed by Private Cloud Compute&#x27;s post-quantum signature using a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme.

              So… it&#x27;s not possible for Apple to know if two images came from the same iPhone.

              1. cobbzilla · · focus · HN ↗
                I stand corrected. If it’s truly only the signatures and zero other identifying info, then yes you’re as secure as the underlying algorithm. I think they implied there are multiple device-originated signatures for different parts of the data, this may open some possibilities for cryptanalysis
              2. microtonal · · focus · HN ↗
                I am not sure I follow. The private keys in the image sensor and the SEP are static, so you can see that two images are signed with the same private key. Apple &#x27;decorrelates&#x27; this by letting PCC verify the signature and then replacing it by their own signature:

                When the user initiates developing a reference image, the device uploads the secure digital negative to Private Cloud Compute. PCC recomputes the digest embedded in the frame and verifies the sensor&#x27;s signature over the pixels and that digest, verifying the certificate chain back to the sensor CA. PCC also verifies the SEP signature and chains it to the BAA CA, and it verifies the signature on the device manifest and chains it to the CA that signs device manifests at the factory. It then confirms that the sensor and SEP named in those chains belong to the same device. [...] If these checks pass, PCC then submits the commitment to our signing service, which signs it with a composite post-quantum signature using a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme. The signature is embedded in the JPEG, and the reference image is returned to the device, which associates it with the main photo from the original capture.

                After the secure digital negative is successfully developed, it&#x27;s automatically moved to the deleted photos folder.&quot;

                So in the end it all depends on how much you trust Apple&#x27;s cloud and PCC nodes. If there is a weakness in their services, Apple could record both the original signatures and their signature, and could prove whether two photos were made using the same lens&#x2F;device and they could even trace it back to a specific device (by looking up the original signature + signing identity given their signature).

      7. monocasa · · focus · HN ↗
        Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you&#x27;re willing to do it destructively.

        They can then sign their own fraudulent images.

        1. autoexec · · focus · HN ↗
          The NSA has probably already forced Apple to hand the keys over to them.
          1. propaganja · · focus · HN ↗
            Apple would be legally restricted from disclosing any government compromises, while still claiming their systems are secure and operating as intended in general.

            We already know it&#x27;s happening right now, and they know we know, but we can&#x27;t do shit about it.

            1. alwillis · · focus · HN ↗
              &gt; Apple would be legally restricted from disclosing any government compromises, while still claiming their systems are secure and operating as intended in general.

              I&#x27;m aware. The point is they can&#x27;t give the NSA something they don&#x27;t have. The photo sensor generates its own ECDSA P-256 signing key pair and never releases the private half.

              Every device has a unique key pair and the private key is unavailable… there&#x27;s not a way to give the NSA that would help them. The system is setup so that the image data, meta data, etc can&#x27;t be accessed by anyone including Apple.

              1. microtonal · · focus · HN ↗
                I believe them, but the process is hard to check. How do we verify that they don’t have the sensor burn in a private key generated by them?

                (Similar to how many PGP hardware keys allow generating a private key on-device or writing your own provided key.)

            2. alwillis · · focus · HN ↗
              Here&#x27;s a flow chart; tell us at what point there&#x27;s something Apple can be compelled by a 3-letter organization to produce: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284
              1. microtonal · · focus · HN ↗
                I think the chart exactly shows the weakness that some people have pointed out. Apple&#x27;s PCC servers at some point in time know the signing identity for a photo and Apple&#x27;s generated replacement signature. The relevant steps from your chart:

                - verifies each link and its certificate chain, sensor signature over pixels, SEP signature, device manifest signature

                - PCC Submits the commitment (the JPEG hash) to Apple&#x27;s signing service.

                So, at some point in time, Apple&#x27;s servers have both the original certificate chain and the new replacement signature. If this is recorded, Apple can deanonimize photos and check whether two photos were from the same device&#x2F;sensor.

                Apple&#x27;s system protects against most state actors, except Apple and the US, unless you fully trust that their PCC is watertight.

                (Remember that Apple was part of PRISM and probably also its successor.)

                I don&#x27;t think law enforcement needs it, because when sending&#x2F;posting a picture, people leak so much metadata anyway.

                But people outside the US should certainly distrust these systems.

          2. alwillis · · focus · HN ↗
            &gt; The NSA has probably already forced Apple to hand the keys over to them.

            Again, that&#x27;s not how it works.

            There&#x27;s no set of keys and certificates they could give to the NSA. Every iPhone 18 Pro and Pro Max has a unique set of cryptographic keys, most of which can&#x27;t be accessed by Apple.

            The first thing that happens is when photo sensor is initialized at the factory, it creates its own ECDSA P-256 signing key pair; the private key is never disclosed. The public key is signed by the factory&#x27;s certificate authority.

            This ain&#x27;t X.509 where VeriSign&#x27;s key pair is sitting in a HSM at their HQ and in theory could be forced to sign a fraudulent certificate or revoke someone&#x27;s valid website certificate.

            1. microtonal · · focus · HN ↗
              They don’t need the signing keys though. Apple could roll out a separate version of sepOS to assist law enforcement that signs at they will.

              Also, while the unique device ID is supposed to be burned into fuses by the SE during production, it is kinda hard to prove for anyone that is not Apple that this indeed happens in the way they state.

              Personally I’m not a strong believer in such theories though. I think it’s more mundane and Apple helps law enforcement by having some weak defaults. Like how iMessage is end-to-end encrypted, but most chats are available to law enforcement because most people turn on iCloud Backups&#x2F;Messages in iCloud and not ADP, resulting in chats only being encrypted at-rest in iCloud. This is only stated somewhere in a footnote in one of their security documents.

              There are more weak defaults like that in various crucial apps (e.g. WhatsApp) that makes most important stuff available to law enforcement when needed.

        2. alwillis · · focus · HN ↗
          &gt; Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you&#x27;re willing to do it destructively. They can then sign their own fraudulent images.

          That&#x27;s not how this works.

          Let&#x27;s pretend they&#x27;re able to extract the sensor key and the SEP key. Then what?

          An attacker won&#x27;t have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service.

          When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device&#x27;s secure boot manifest.

          More encryption and checking happens until the secure digital negative is sent to Private Cloud Compute:

              PCC recomputes the digest embedded in the frame and verifies the
              sensor&#x27;s signature over the pixels and that digest, verifying the
              certificate chain back to the sensor CA. PCC also verifies the SEP
              signature and chains it to the BAA CA, and it verifies the signature
              on the device manifest and chains it to the CA that signs device
              manifests at the factory. It then confirms that the sensor and SEP
              named in those chains belong to the same device. Only if all these
              checks pass does processing continue.
          
          Only PCC can create an Apple Reference Image; an attacker having the image and sensor private keys doesn&#x27;t enable them to create a reference image.
          1. monocasa · · focus · HN ↗
            &gt; An attacker won&#x27;t have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service.

            Sure they can, they have everything needed to prove to Apple&#x27;s servers that they&#x27;re a real iPhone since pulling the keys means they have the cryptographic root of trust, and Apple&#x27;s servers will happily be a signature oracle for them in that case.

            &gt; When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device&#x27;s secure boot manifest.

            And when you know what is measured into those manifests and the keys at the root of trust you can manufacture those too.

            The entire scheme is dependent on not being able to extract device specific keys. At the end of the day, those are almost certainly efuses burnt based on a on-chip HRNG as a manufacturing step which is intended to never leave the device, but instead only signatures and associated public keys.

            But when you have chip development hardware of the kind you&#x27;d have at a decent fabless semiconductor company, you can very clearly see burnt efuses.

            1. alwillis · · focus · HN ↗
              I made a flow chart of the Apple Reference Image process; hopefully it clears up some misconceptions [1].

              [1]: &quot;How pixels become an Apple Reference Image&quot; - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284

              1. monocasa · · focus · HN ↗
                That matches what I said.
      8. walrus01 · · focus · HN ↗
        &gt; Apple Reference Image is not an id system; it&#x27;s primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way

        You think that this won&#x27;t be used as additional data by the various competing companies who have implemented &quot;take a live still or video selfie of yourself with your phone and show us your ID cards&quot; for identity verification purposes?

      9. JW_00000 · · focus · HN ↗
        &gt; Apple Reference Image is not an id system; it&#x27;s primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.

        &gt; There&#x27;s no way to link a reference image to a person; it&#x27;s also not possible to determine if a pair of images came from the same device.

        Some banking apps nowadays ask you to upload a photo of your ID and then use the webcam&#x2F;selfie camera to confirm that&#x27;s it&#x27;s really you (sometimes asking you to move your head in a particular way). But how trustworthy is that process really? Apple Reference Image could be (part of) a solution, by certifying that both images were taken by the same device around the same time.

        1. CrazyStat · · focus · HN ↗
          &gt; Apple Reference Image could be (part of) a solution, by certifying that both images were taken by the same device

          This is explicitly not possible, as the post you were replying to pointed out.

          1. [deleted] · · focus · HN ↗

            [deleted]

      10. tencentshill · · focus · HN ↗
        I can tell its &#x27;shopped because of the pixels
      11. PunchyHamster · · focus · HN ↗
        The described scheme links the image to the device&#x27;s signing key

        &gt; There&#x27;s no way to link a reference image to a person; it&#x27;s also not possible to determine if a pair of images came from the same device.

        How would they do that ? There is only one signed key of the device

      12. startup_zombie_ · · focus · HN ↗

        [dead]

      13. appletrotter · · focus · HN ↗
        Looks like you saw the word ID and went off. OP never called it an ID system
      14. cvoss · · focus · HN ↗
        &gt; You have it all wrong.

        &gt; Apple Reference Image is not an id system

        GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID.

        That the Apple Reference Image itself is not traceable to the device&#x2F;user is beside the point in this use case.

        1. slester · · focus · HN ↗
          Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
          1. JumpCrisscross · · focus · HN ↗
            &gt; If they can verify an Apple Reference Image they can verify an NFC document

            Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC&#x27;d anything, and that includes my banks, which could easily ask for my debit card&#x27;s NFC but don&#x27;t.

            1. inquirerGeneral · · focus · HN ↗

              [dead]

            2. lxgr · · focus · HN ↗
              ICAO doc 9303 validation is about 10 lines in Python (on top of importing the right packages) last time I did it around 2012. I doubt it has become harder since then.
              1. fweimer · · focus · HN ↗
                Was the public key directory even operational in 2012? What about revocation checking?

                I think processing that information is mandatory now, but probably was optional&#x2F;largely unimplemented in 2012. But maybe I&#x27;m off by five years or so?

                1. lxgr · · focus · HN ↗
                  Revocation checking seems like a big gap, yeah. I’m not aware of any public revocation lists (but I’m also not super familiar with the industry), so I can only assume (hope?) that there are some shadowy but highly accurate databases that KYC providers are tapping into.

                  The CA public key I just got off my country’s website, they were kind enough to just publish it :)

            3. crote · · focus · HN ↗
              Counterpoint: all of the identity-verification flows I have experienced in the last few years used NFC to read the chip in my identity documents - from car rental apps to my bank doing KYC.

              If anything, verifying NFC is easier than images. Asking the chip in my identity card to provide a cryptographically-signed &quot;This document belongs to Jane Doe&quot; request is a handful of lines of code. Doing the same with images? Good luck coming up with an approach which isn&#x27;t fooled by a photocopy!

              1. JumpCrisscross · · focus · HN ↗
                Cool! Where are you geographically? I’m mostly in North America, Europe and South Asia.
            4. microtonal · · focus · HN ↗
              My credit card company’s app (in Europe) reads my ID through NFC when logging in for the first time (besides requiring ID photos).

              Our national app for logging into government sites and confirming things also requires a step where the ID’s NFC is read to reach the highest trust level.

              So it’s definitely becoming more and more common here.

          2. tmp10423288442 · · focus · HN ↗
            There are tons of online services that require you to take pictures of your face, driver’s licenses, passports, etc.
          3. happyopossum · · focus · HN ↗
            How exactly am I expected to upload my nfc chip to my insurance company’s website?
            1. lxgr · · focus · HN ↗
              They just have you tap your identity document against your phone. Works pretty well in my experience.

              The phone is just a relay to a remote server here, as newer ICAO machine readable travel documents intentionally don&#x27;t support signatures&#x2F;non-repudiation anymore, so you have to run the entire exchange against a component you trust (i.e. your server, not so much your app on a rooted&#x2F;manipulated phone).

        2. rickdeckard · · focus · HN ↗
          I agree, but for this to matter, a critical amount of fraud should be based on people uploading modified photos of ID&#x27;s.

          If someone took a picture of a fake ID in the past, this method will bring no benefit, it will just add Apple as a paid service-provider.

          It also doesn&#x27;t change the trust-relationship between the two parties: If I need to prove my identity by uploading a government ID, _I_ am doing the photo attestation that this is the ID matching the data I provided, with or without an Apple Reference image.

        3. alwillis · · focus · HN ↗
          &gt; Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID.

          The image will be authentic, but an authentic image of a fake id isn&#x27;t useful to them.

          Also--only two iPhone models support this technology. It&#x27;ll be years before the DMV or whoever could count on enough adoption before they could support it.

        4. vablings · · focus · HN ↗
          I think this is a good thing. Proof that an image is actually real is a valuable underpinning of society and being able to provide that is incredibly important.
      15. lxgr · · focus · HN ↗
        No, you just didn&#x27;t understand GPs point, i.e. that an image provenance&#x2F;authentication system (such as Apple Reference Image) can eventually become a load-bearing and by extension anticompetitive component in a larger authentication&#x2F;identity verification scheme.

        &gt; a nation-state can&#x27;t really do anything here unless they acquire alien technology.

        Alien technology such as NSLs or supply chain attacks against Apple?

      16. solarkraft · · focus · HN ↗
        You seem to have it wrong. You don’t need an identification system for these use cases, you only need exactly what the tech does.
      17. illiac786 · · focus · HN ↗
        How is stealing&#x2F;extracting a private key alien technology? Or even more simple, subpoena a private key to create fake authentic compromising pictures of pesky political opponents.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.