Apple Reference Image: A New Approach for Verified Photography

(security.apple.com)

51 points | by imwally 2 hours ago

7 comments

  • tristanj 1 hour ago
    Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image.

    Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.

    To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.

    I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.

    • nvme0n1p1 17 minutes ago
      Yeah, such systems have been tried (and been hacked) for decades now.

      https://www.elcomsoft.com/news/428.html

      https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...

      You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin.

      It's funny to see Apple fall into this same trap.

    • pveierland 1 hour ago
      Claim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult:

      https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...

      The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.

      • tristanj 47 minutes ago
        LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos.

        A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information. The video files (Possibly audio too) could also be included with the verified image as additional verification.

        They can also prevent photos if iPhone detects the LiDAR sensor is covered, similar to how Meta does it with their camera glasses.

        • pveierland 41 minutes ago
          I don't think it's an either or - additional data signals that need to correlate to authenticate will increase confidence. You can use multiple other signals to evaluate whether something is truly a landscape photo, and in that case not require a LiDAR capture, but if you are inside and at close range then you could assume that it should be part of scoring the authentication.

          Similarly, LiDAR alone will help disqualify cases where someone is just taking a picture of e.g. a landscape target of the Golden Gate, but that it shown on a screen 1 meter away.

        • halestock 35 minutes ago
          This approach makes me wonder if the future is actually going to move towards visual cryptography.
      • BugsJustFindMe 56 minutes ago
        iPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.
        • pveierland 47 minutes ago
          Still, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.
        • gruez 47 minutes ago
          So you need a big enough screen to cover the entire field of view at 16 ft? Sounds expensive
          • nomel 28 minutes ago
            Or, probably just some optics, like a slanted $9 IR mirror [1] in front of it, to direct the lidar to the sky/absorption box. Then you can point at the high res HDR TV that's probably already in your living room.

            [1] https://commonlands.com/products/ir-cut-filters-csp650?srslt...

          • BugsJustFindMe 39 minutes ago
            Well, first, that's only expensive if you're poor. The world is absolutely full of people who can easily piss away your entire annual income throwing a house party.

            But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all.

            Anyway, one may presume that they've thought about this.

            • brookst 16 minutes ago
              Thought about it and also are bright enough not to fall for the “if a single person dies wearing a seat belt, we should abandon seat belts because they do no good at all” fallacy.

              It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?

              • BugsJustFindMe 12 minutes ago
                > But maybe it’s better than nothing?

                I think this will depend on how it gets used. I can imagine numerous outcomes where it's in fact worse than nothing (significantly more effective blackmail, for instance).

      • geokon 46 minutes ago
        furthermore, couldnt you do parallax from the multiple cameras as well as flicker the flash?

        seems pretty easy to make it sufficiently difficult to trick the system

    • osy 1 hour ago
      It also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve.

      > Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago.

      Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.

      • BugsJustFindMe 48 minutes ago
        > "But that's not the problem they're trying to solve."

        It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened".

        It fails the reasonable person test to say that in the phrase "something actually happened" the "something" refers to the act of taking the photo.

        Likewise, in "photographs that depict real events", no reasonable person could say that "real events" includes fabrications or that the "event" in question is the taking of the photo itself.

        • brookst 13 minutes ago
          So, in your view, photography has been fatally flawed since the late 1800’s, and mere mitigation of AI image gen are insufficient if they don’t also solve actors impersonating real people?
          • BugsJustFindMe 8 minutes ago
            > So, in your view, photography has been fatally flawed since the late 1800’s

            Used in a capacity as evidence? Yes. The scenario is made worse not better by the second largest company in the world promising captured veracity.

        • spiderice 14 minutes ago
          This is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.
          • BugsJustFindMe 3 minutes ago
            > This makes it like, a thousand times harder to fake a photo than it would otherwise be.

            Whether it does remains to be seen. Do you have inside knowledge about how it works? Despite their initial language about discerning real events, none of their technical explanation says anything at all about anything outside of the camera itself.

    • srik 10 minutes ago
      It's less about proving a photo's truth than about attesting it.
    • amanj41 1 hour ago
      Sony's analogous solution (https://authenticity.sony.net/camera/en-us/) claims 3d depth information is built in, I'm sure Apple could do the same given at least some iPhone models have LiDAR on the back
      • tristanj 58 minutes ago
        This would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances.

        Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.

    • dinobones 41 minutes ago
      Is this really that big of a flaw in this implementation? I don't think it's worth the additional complexity to address it. (Encoding depth information in some way, trying to detect "flat" surfaces, whatever).

      Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.

      • BugsJustFindMe 16 minutes ago
        You mean that it is sometimes very easy. But it is also sometimes impossible. You seem to be thinking only of poor quality photos of poor quality prints, but there's no basis for assuming those characteristics.
  • jithinsankar 50 minutes ago
    What if someone take the photo of the forged photo displayed on another device, doesn’t the forged photo become an authentic one?
    • brookst 11 minutes ago
      Sure, if it’s believable that the shot was perfectly flat at, what, 2 feet away?
  • WalterGR 1 hour ago
  • SoftTalker 19 minutes ago
    A photograph by itself should never be considered proof of anything.
  • SXX 53 minutes ago
    Waiting for "Apple verified" photo of some important politician doing something wildly inappropriate.

    Scrapped in 3..2..1..

  • xeonmc 36 minutes ago
    NFTs by another name...
  • puppycodes 1 hour ago
    terrible idea...

    but im sure it will popular with 60 year olds watermarking their pictures of sunsets.