‹ BackHN Continuity

Thread

Apple Reference Image: A New Approach for Verified Photography

539 points · 352 comments · imwally

  1. tgsovlerkhgsel · · focus · HN ↗
    This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

    There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

    Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

    1. alwillis · · focus · HN ↗
      > This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

      You have it all wrong.

      Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.

      There's no way to link a reference image to a person; it's also not possible to determine if a pair of images came from the same device.

      > And while "a nation state actor can spoof this" is a problem for the journalism use case

      This is incorrect:

          When the image sensor is first initialized in the factory, it creates a
          cryptographic signing identity, sharing only the public key with the
          factory. The SEP similarly creates a separately-attested signing
          identity. These identities are bound together into the device manifest,
          allowing us to later check whether a particular sensor and SEP are from
          the same device.
      
          The final signature on a reference image is a composite post-quantum
          signature combining RSA-3072 and ML-DSA-87. To our knowledge, Apple
          Reference Image is the only image provenance system that provides
          quantum-secure defenses.
      
      So… a nation-state can't really do anything here unless they acquire alien technology. If something crazy happens (solar flare or EMP?), a fraudulent reference image can be revoked.

      > Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

      I would imagine there will be a way to confirm an Apple Reference Image on the web. Pretty soon, 3rd parties will be able to verify the image themselves:

          Reference images can be viewed in the Photos app alongside the main
          image, like a digital negative, to visually compare the two assets and
          determine if any edits were made. APIs are available in iOS, iPadOS, and
          macOS 27 for third-party apps to enable viewing of these reference images.
      1. monocasa · · focus · HN ↗
        Nation states almost certainly have the ability to extract the private keys out of an image sensor and SEP. Outside of superpowers even if you're willing to do it destructively.

        They can then sign their own fraudulent images.

        1. autoexec · · focus · HN ↗
          The NSA has probably already forced Apple to hand the keys over to them.
          1. propaganja · · focus · HN ↗
            Apple would be legally restricted from disclosing any government compromises, while still claiming their systems are secure and operating as intended in general.

            We already know it's happening right now, and they know we know, but we can't do shit about it.

            1. alwillis · · focus · HN ↗
              Here&#x27;s a flow chart; tell us at what point there&#x27;s something Apple can be compelled by a 3-letter organization to produce: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49735284
              1. microtonal · · focus · HN ↗
                I think the chart exactly shows the weakness that some people have pointed out. Apple&#x27;s PCC servers at some point in time know the signing identity for a photo and Apple&#x27;s generated replacement signature. The relevant steps from your chart:

                - verifies each link and its certificate chain, sensor signature over pixels, SEP signature, device manifest signature

                - PCC Submits the commitment (the JPEG hash) to Apple&#x27;s signing service.

                So, at some point in time, Apple&#x27;s servers have both the original certificate chain and the new replacement signature. If this is recorded, Apple can deanonimize photos and check whether two photos were from the same device&#x2F;sensor.

                Apple&#x27;s system protects against most state actors, except Apple and the US, unless you fully trust that their PCC is watertight.

                (Remember that Apple was part of PRISM and probably also its successor.)

                I don&#x27;t think law enforcement needs it, because when sending&#x2F;posting a picture, people leak so much metadata anyway.

                But people outside the US should certainly distrust these systems.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.