Apple Reference Image: A New Approach for Verified Photography
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Apple Reference Image: A New Approach for Verified Photography
Unofficial Hacker News client; not affiliated with Y Combinator.
tgsovlerkhgsel · · focus · HN ↗
There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).
Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.
rickdeckard · · focus · HN ↗
An insurance would either assign #1 an insurance agent or mechanic to initially assess the damage (trusted) or #2 ask the customer to send pictures (untrusted).
Tendency is #2 for cost-saving of the insurance, and 3rd party apps are used to execute this.
Now the idea is that the insurance company discontinues the App and the (untrusted) customer must have an iPhone 18 Pro to make an insurance claim?
Or is the insurance agent / mechanic an untrusted entity who will now be required to have an iPhone 18 Pro?
What is the fraud vector here, and how can the insurance service provider continue cost-saving on damage-assessment by offloading to the customer, if the customer is required to own a specific device?
bayindirh · · focus · HN ↗
This will allow banks to trust these cameras more on the long run, allowing higher security ID checks.
lxgr · · focus · HN ↗
Without it, anyone with a stolen document can pass it. (I don't think there's a generally available database of stolen documents, so I suspect these usually remain valid until their regular date of epxiry.)
bayindirh · · focus · HN ↗
Before deepfakes were dime a dozen, I remember my bank starting a video-call with me and required me to show my ID to them via camera. This was after a multi-factor check that I passed.
Making any of these factors more trustworthy is a win in my perspective, so having a trusted sensor is always better even if you do multi-factor authentication.
Our ID cards have a private-public key pair inside them, and it allows us to sign things amongst other things. Renewing your ID card for any reason revokes the digital signature of the previous one, so scanning it via NFC probably enough to check whether it's revoked. Same with photo (since machine readable part contains serial and check digits and such).