‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. RandomGerm4n · · focus · HN ↗
    This approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification system for a company that the manufacturer claimed was absolutely secure. All it took was rooting the smartphone and bypassing the root detection. After that, you could play any pre recorded video, which would then be recognized as camera input. Under those conditions, it was easy to manipulate a video so that a company employee would consider it real enough to verify the test subject.

    It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.

    1. avianlyric · · focus · HN ↗
      The approach assumes that most people don’t have the ability to directly attack the image sensor itself. It’s a little buried in the article, but creating reference images involves having the actual image sensor sign the raw data it captures using a key unique to that sensor. The rest of the device can’t tamper with data anymore.

      I don’t think there any many people out there with the right equipment to carefully ablate the top of a sensor off, so they can directly inject their own data into the start of signing process. It’s not impossible, but it’s also not the kind of thing most people and organisations are going to be capable of doing.

      > The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.