hn.today

Apple Reference Image: A New Approach for Verified Photography

security.apple.com237 points152 comments
Screenshot of Apple Reference Image: A New Approach for Verified Photography

Apple Reference Image is a verifiable-photography system built into an opt-in camera mode on iPhone 18 Pro and iPhone 18 Pro Max that guarantees an image represents sensor-captured reality, resists compromise, and preserves photographer privacy. It produces a secure digital negative by booting the sensor into a protected capture mode that cryptographically signs raw pixel data and sensor-originated metadata at the moment of capture; off-sensor metadata is signed by the Secure Enclave Processor. Capture time is bounded with cryptographic timestamps (a lower-bound heartbeat token held on-device and an upper-bound token requested after capture). The digital negative contains pixels, essential metadata, and timestamp bounds, and is uploaded to Private Cloud Compute (PCC) to be developed into a viewable reference image using publicly auditable processing builds recorded in an append-only transparency log.

The pipeline defends against OS compromises, sensor-bus injection, hardware tampering and future cryptographic attacks. Sensors and SEPs are issued factory keys and bound in device manifests so PCC can validate genuine sensor-device pairings. Final reference images carry a composite post-quantum signature (RSA-3072 + ML-DSA-87) and are subject to a confidence score and revocation system that can revoke specific photos or sensors without exposing photographer identity. PCC’s private-compute guarantees prevent Apple or others from seeing image contents, while devices regularly fetch revocation lists so viewers can detect known fraudulent images.

Read on security.apple.com152 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.