‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. tgsovlerkhgsel · · focus · HN ↗
    This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

    There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

    Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

    1. Topfi · · focus · HN ↗
      > […] the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

      Why do you believe Android manufacturers and SOC makers like Qualcomm won’t be able to offer a similar solution?

      1. rickdeckard · · focus · HN ↗
        Not the OP, but yes, other vendors will be able to support that as well. But a camera sensor that has

        1. a public/private key exchanged during device-production (production-cost),

        2. the capability to reboot in a cryptographic mode (R&D / component cost) and

        3. a cloud-service which then processes the raw data to create a JPG (operational cost)

        comes at a premium. Why should this premium be applied on a 99 USD Smartphone?

        Which is my whole puzzle on this vector: If the big benefit is for insurance/ID-verification, which apply cost-saving by offloading their process to the untrusted customer, how much they can offload this by requiring their customer to own a 1000+ USD smartphone to provide THEIR service...?

        The most I can imagine is insurances offloading their work to OTHER companies, NOT trusting them and therefore requiring them to own a 1000+ USD Smartphone. But even then, why not use a third party app that also runs on a 3y old iPhone and a 99 USD Android device...?

        1. PunchyHamster · · focus · HN ↗
          > comes at a premium. Why should this premium be applied on a 99 USD Smartphone?

          It's entirely software. It's R&D cost, with basically none of it in hardware (you technically just need the private key store which even very cheap devices have)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.