‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. jeroenhd · · focus · HN ↗
    That's a lot of words to say "we re-invented C2PA but made worse by getting our servers involved somehow".

    Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. The timestamping server is a nice idea (though I don't see why they can't just use a normal timestamping server, I guess to keep control over the protocol) but it doesn't solve the fundamental problem that defeated C2PA.

    1. willy_k · · focus · HN ↗
      Doing that on modern iOS is unlikely. They’ve really locked it down in the past half decade.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.