← Back to context

Comment by hollerith

10 hours ago

Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.

For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.

For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.

How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.

Don't worry, photographs were being faked before Lee Harvey Oswald.

  • The optical data will be cryptographically bound to the state of the autofocus mechanism and to the output of a LiDAR scanner.

    We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner.

    The technology need not be 100% tamper-proof to have a large effect on society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and some prompts and the claim that anyone with years of training and experience in cutting-edge microelectronics could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create false attestations of recordings -- particularly because in a high profile instance such as a repeat of the Rodney King beating, Apple engineering would tend to be very interested in examining the device used to make the recording.

    • > We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner alongside the optical lenses.

      The iPhone Pro starts at $1199.

      Moreover, LiDAR is essentially a laser that emits at a particular wavelength and a camera that detects that wavelength, so it could be fooled by pointing it at a screen that emits at the same wavelength, which in turn could be an ordinary screen with something in front of it that converts light at a wavelength it emits to the one the LiDAR sensor is expecting.

      And that's if you insist on using light. The LiDAR sensor itself is an analog piece of hardware that converts the light into an electrical signal, so if you substitute its electrical output as the input to the signing hardware then it signs whatever you want and never knows the difference.

      The hardest part about this is probably creating a credible depth map of a generated 2D image, which is the part that doesn't require signatures or attestation.

      > The technology need not be 100% tamper-proof to affect society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that Apple's engineers have not detected yet that can be used to create falsely attested recordings.

      Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.

      Moreover, isn't "most people can't do this but some people still can" actually worse? It's a system for providing undue credibility to the forgeries from the people who can do it.

      Without even making most legitimate images more credible, since most phone cameras don't have fancy LiDAR hardware.

      3 replies →