Comment by tristanj
8 hours ago
Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image.
Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.
To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.
I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
Claim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult:
https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...
The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.
Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos.
A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information. The video files (Possibly audio too) could also be included with the verified image as additional verification.
They can also prevent photos if iPhone detects the LiDAR sensor is covered, similar to how Meta does it with their camera glasses.
> it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos.
I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?
3 replies →
> all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information.
I think optics could be used to make each camera see a different image.
A video could show shake, which could be verified against readings from the phone's accelerometer -- but you could just hold it still and claim that it was on a tripod.
I don't think it's an either or - additional data signals that need to correlate to authenticate will increase confidence. You can use multiple other signals to evaluate whether something is truly a landscape photo, and in that case not require a LiDAR capture, but if you are inside and at close range then you could assume that it should be part of scoring the authentication.
Similarly, LiDAR alone will help disqualify cases where someone is just taking a picture of e.g. a landscape target of the Golden Gate, but that it shown on a screen 1 meter away.
Right but I’d argue that realistically this feature is going to be most useful when taking photos of things reasonably close by, people especially, rather than landscape photography.
This approach makes me wonder if the future is actually going to move towards visual cryptography.
1 reply →
iPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.
Still, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.
1 reply →
So you need a big enough screen to cover the entire field of view at 16 ft? Sounds expensive
13 replies →
furthermore, couldnt you do parallax from the multiple cameras as well as flicker the flash?
seems pretty easy to make it sufficiently difficult to trick the system
It also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve.
> Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago.
Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.
> "But that's not the problem they're trying to solve."
It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened".
It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself.
Likewise in "distinguish between photographs that depict real events and...".
Yes, it is proving something actually happened, that is your monitor screen showing something you photographed.
1 reply →
No security control is perfect. The point is to increase costs to the point its unfeasible.
After all, if money is no object, you could just bribe every single apple employee involved in the project.
So, in your view, photography has been fatally flawed since the late 1800’s, and mere mitigation of AI image gen are insufficient if they don’t also solve actors impersonating real people?
1 reply →
This is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.
5 replies →
> This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it".
Which surely will be useful in ID verification on the Internet; Android devices most likely will follow with same or similar solution
This has been possible since the beginning of photography and yet I can’t think of a single scenario where people have been tricked by a staged photo. Yet every day hundreds of millions of people are being fooled by AI generated photos.
Sony's analogous solution (https://authenticity.sony.net/camera/en-us/) claims 3d depth information is built in, I'm sure Apple could do the same given at least some iPhone models have LiDAR on the back
This would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances.
Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.
> I do this frequently when I want to take a photo through a window.
I feel really dumb for not having thought of this.
It's even easier than that. You just wait for someone else to figure out, some photography professional with fancy equipment and a hacker-y mindset, and you pay them to sign your photos for you.
Once a defeat device (a camera pointed at a screen) is functional, whoever has it, can simply automate a "receive API request, display image on screen, photograph it, return signed image" pipeline. A cheap internet service. I'd WAG a hundred thousand signatures per day per phone, limited by the sensor speed.
Since there's no way for anyone, Apple included, to correlate photo signatures with the device that signed them, it's also true there's no way to stop one device from signing millions in bulk. ("...an outside observer cannot determine whether any pair of reference images were taken by the same device..."; "...avoid even implicit public association between different photos taken by the same sensor...")
It's the same economic asymmetry as DRM vs. movie piracy (as soon as one group defeats a technical challenge, millions instantly benefit, at zero marginal cost). Apple has no chance of winning.
This sounds like it could be done, but the costs for doing so are comparably high.
I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage.
That’s a tradeoff I can live with.
> but the costs for doing so are comparably high
You will find pre made kits to do that exact thing in a few weeks/months on alibaba and similar
> I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified.
It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.
> Paint the inside of the box using Vantablack
But you're only allowed to do that if your name if Anish Kapoor
> take a picture of an already edited image
I think the "reference image" means a photo is taking by a real iPhone 18 device at a certain time, what the content actually means is another matter.
The "digital negative" in DNG format can be used to analyze the authenticity of the content.
>I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.
There’s no such thing as a Golden Gate Bridge.
Prove it.
It's less about proving a photo's truth than about attesting it.
[dead]
Yeah, such systems have been tried (and been hacked) for decades now.
https://www.elcomsoft.com/news/428.html
https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...
You don't even have to travel to the location, you can just spoof GPS. And of course that will only be needed until some eastern european kid gets bored one weekend and the signing keys magically appear on pastebin.
It's funny to see Apple fall into this same trap.
To be fair Apple of all companies have the best shot at pulling it off. They've been perfecting their hardware security for years for other reasons and this is just another way to take advantage of that work. But yes, if someone breaks it then the trust is gone and it casts doubt on all of the photos that were ever captured using the broken system.
I suspect they have ways to ID at least some things like this somehow in ways that will lead to key revocation.
Won't the focus length of the camera be wrong?
Is this really that big of a flaw in this implementation? I don't think it's worth the additional complexity to address it. (Encoding depth information in some way, trying to detect "flat" surfaces, whatever).
Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.
You mean that it is sometimes very easy. But it is also sometimes impossible. You seem to be thinking only of poor quality photos of poor quality prints, but there's no basis for assuming those characteristics.
Exactly, a wave of “verified” fake images are coming.