Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Introducing System One Models and Jev(typesafe.ai ↗)
    336comments
  2. Apple Reference Image: A New Approach for Verified Photography(security.apple.com ↗)
    83comments
  3. Show HN: An e-ink frame that hears birds and draws them as 1800s illustrations(github.com/arnegiacomo ↗)
    193comments
  4. Show HN: I made a flight simulator, except you're just a passenger(inflightsimulator.com ↗)
    50comments
  5. Negativland, Culture Jamming, and the Art of Making Something New(blog.archive.org ↗)
    17comments
  6. Datamimic – don't let your coding agent invent its own test world(github.com/rapiddweller ↗)
    2comments
  7. An update on Wayback Machine access(blog.archive.org ↗)
    250comments
  8. Gemini 3.8 Live and 3.8 Live Extended Thinking(blog.google ↗)
    242comments
  9. Recreating Voodoo Graphics and a Late-1990s Gaming PC on an FPGA(nand2mario.github.io ↗)
    20comments
  10. German Rheinmetall open-sources its Battlesuite connected weapon system protcol(rheinmetall.github.io ↗)
    60comments
  11. Doing Everyone Else's Job(yosefk.com ↗)
    14comments
  12. Building a Linux GPU Driver for the M4 Mac Mini in One Month(codyho.dev ↗)
    152comments
  13. An interactive world map of the stories cultures have told(sunnyguha.com ↗)
    discuss
  14. Saving Jet Fuel(marksblogg.com ↗)
    33comments
  15. We got admin access to Baseten's production GitHub(strix.ai ↗)
    142comments
  16. Learning to solve hard problems in RL for LLMs by never giving up(mnoukhov.github.io ↗)
    discuss
  17. Jean-Pierre Serre turns 100(st-andrews.ac.uk ↗)
    21comments
  18. Stay discoverable in search while disallowing AI training(cloudflare.com ↗)
    32comments
  19. Chopping up books when they're physically too big(mattkirkland.com ↗)
    146comments
  20. Show HN: Capsule – Single-file web apps that save their data into SQLite(withcapsule.app ↗)
    127comments
  21. A single firm is behind OpenAI, Anthropic, and Meta hacking scandals(effort.news ↗)
    197comments
  22. Let's make quality the norm again(forbrukerradet.no ↗)
    374comments
  23. WangNet – 1.8 MB, zero-dependency Numberwang adjudication in 11 languages(github.com/graafhenk ↗)
    48comments
  24. Suspected sabotage causes major Netherlands rail disruption(bbc.com ↗)
    412comments
  25. Piezoelectric effect in polycrystalline diamond membranes(science.org ↗)
    1comments
  26. Most people prefer traditional architecture(worksinprogress.news ↗)
    262comments
  27. Sierra digital cameras on the Apple II(colino.net ↗)
    5comments
  28. Show HN: Pizza Bot – An inbox for AI agents that work in the background(github.com/pizza-bot-app ↗)
    26comments
  29. The Inference Hardware Revolution of 2026(ieee.org ↗)
    13comments
  30. Jiga (YC W21) Is Hiring Product Engineer (Remote/US)(jiga.io ↗)
    discuss

Apple Reference Image: A New Approach for Verified Photography

153 pointsby 4h agosecurity.apple.com
84 comments
3h agoHN ↗

Apple doesn't address the modified photo replay situation, where you take a picture of an already edited image.

Photoshop / AI-gen an image -> display on a high-resolution monitor -> photograph the monitor with iPhone 18 Pro -> valid Apple Reference image.

To get valid reference photos, you can go to the actual physical location, put the iPhone/monitor in a cardboard box to block external light, then photograph the monitor. Paint the inside of the box using Vantablack (stopping reflections) and cover the LiDAR projector with tape.

I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.

3h agoHN ↗

This would work for close up shots taken on iPhone, but not landscape shots. The infrared dots the iPhone LiDAR projects are too weak to appear over long distances.

Also the dots can be trivially blocked by putting your finger over the sensor, sometimes improving photo quality. I do this frequently when I want to take a photo through a window. The absence of the dot matrix tells the iPhone to focus on the background far away instead of the windowpane.

1h agoHN ↗

I do this frequently when I want to take a photo through a window.

I feel really dumb for not having thought of this.

3h agoHN ↗

It also doesn't prevent you from staging an image or anything that's existed since photography was invented. But that's not the problem they're trying to solve.

Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago.

Photoshop has existed for decades and so has fake images. This is a low friction way to attest "this image came from an iPhone sensor and Apple approved it". It will still take the usual image forensics to determine if the scene it depicts is legitimate.

3h agoHN ↗

"But that's not the problem they're trying to solve."

It is the problem that they say they're trying to solve, though. They specifically say "where the essential role of a photograph is to prove that something actually happened".

It fails the reasonable person test to say that the "something" in that phrase refers to the act of taking the photo itself.

Likewise in "distinguish between photographs that depict real events and...".

2h agoHN ↗

This is so stupid. This makes it like, a thousand times harder to fake a photo than it would otherwise be. You pedants imagining a way to fake it doesn't change that.

2h agoHN ↗

This makes it like, a thousand times harder to fake a photo than it would otherwise be.

The problem with this thinking is twofold:

1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.

2) It increases the potential value of a forgery because now your forgery is attested by Apple.

So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.

1h agoHN ↗

You worry that a technology that you have never used nor evaluated might not work in practice...

Therefore because of your worry (which is based on remarkably little information), it's a bad technology?

Come the fuck on. That's beyond luddite bullshit.

1h agoHN ↗

because of your worry (which is based on remarkably little information)

You must be new around here. ;-)

2h agoHN ↗

So, in your view, photography has been fatally flawed since the late 1800’s, and mere mitigation of AI image gen are insufficient if they don’t also solve actors impersonating real people?

2h agoHN ↗

So, in your view, photography has been fatally flawed since the late 1800’s

Used in a capacity as evidence? Uh, yes? Duh? Do you seriously believe otherwise? Anyway, that scenario is made worse not better by Apple promising captured veracity.

2h agoHN ↗

Yes, it is proving something actually happened, that is your monitor screen showing something you photographed.

8m agoHN ↗

No security control is perfect. The point is to increase costs to the point its unfeasible.

After all, if money is no object, you could just bribe every single apple employee involved in the project.

3h agoHN ↗

Claim 7 in this patent application describes how depth sensors are used as part of an image authentication process, which would make such a workaround more difficult:

https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...

The Apple Reference Image feature is here launched on iPhone 18 Pro and iPhone 18 Pro Max that both have built-in LiDAR sensors that could be used for this process.

3h agoHN ↗

iPhone lidar only works up to like 16 feet in the easiest lighting conditions (indoors) and may be functionally ineffective outdoors.

3h agoHN ↗

So you need a big enough screen to cover the entire field of view at 16 ft? Sounds expensive

2h agoHN ↗

Well, first, that's only expensive if you're poor. The world is absolutely full of people who can easily piss away your entire annual income throwing a house party.

But I really mean that if the lidar barely works outdoors anyway then actually you don't need to be 16 feet away at all.

Anyway, one may presume that they've thought about this.

2h agoHN ↗

Thought about it and also are bright enough not to fall for the “if a single person dies wearing a seat belt, we should abandon seat belts because they do no good at all” fallacy.

It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect. But maybe it’s better than nothing?

2h agoHN ↗

But maybe it’s better than nothing?

I think this will depend on how it gets used. I can imagine numerous outcomes where it's in fact worse than nothing (significantly more effective blackmail, for instance).

2h agoHN ↗

maybe it’s better than nothing?

While that is not quite my bar of confidence when implementing wide-reaching technologies that have numerous unexplored knock-on effects, I guess the calculus must have been different on Infinite Loop recently.

1h agoHN ↗

I like that seatbelt argument example.

I’ve seen that type of argument a million times, and I’ll certainly reuse that.

1h agoHN ↗

The problem is that if defeating it is trivial, then it _authenticates_ fake images.

The problem is that it makes it easier to fool people and provide "cryptographic" evidence of validity, backed by big tech.

It's purpose is to stop bad actors from passing of fake as real just as much as it is to prevent real images being dismissed as fake.

1h agoHN ↗

It’s almost certainly possible to fool v1 of this system, for some images, in some contexts. It would be shocking if the first implementation was completely perfect.

Knowing Apple, they've been working on and testing Apple Reference Image for years.

It being perfect isn't the issue; it's that random people on the internet who are just learning about this assume Apple's engineers haven't already thought about everything (and more) mentioned in this thread.

3h agoHN ↗

Still, that means that either the fake target scene and your screen presenting it would need to be outside of LiDAR sensor bounds, or you'd need to find a way to make the depth sensor data conform with your fake scene, both increasing the difficulty of producing a forgery.

1h agoHN ↗

https://news.ycombinator.com/item?id=49721878

increasing the difficulty of producing a forgery

The problem with this thinking is twofold:

1) Whether it actually meaningfully increases the difficulty of a forgery remains to be seen. Despite their initial language about discerning real events, we see no details here about what scene information is used.

2) It increases the potential value of a forgery because now your forgery is attested by Apple.

So it either makes it easier to defraud people or more worthwhile to put in the effort to defraud people or both. None of those outcomes are great.

3h agoHN ↗

Apple's current implementation doesn't integrate LiDAR. And LiDAR wouldn't be enough here, it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos.

A better fix is to take photos with all three iPhone cameras simultaneously, ideally as a 2-3s video, and use the parallax/multiple perspectives to extract depth information. The video files (Possibly audio too) could also be included with the verified image as additional verification.

They can also prevent photos if iPhone detects the LiDAR sensor is covered, similar to how Meta does it with their camera glasses.

2h agoHN ↗

I don't think it's an either or - additional data signals that need to correlate to authenticate will increase confidence. You can use multiple other signals to evaluate whether something is truly a landscape photo, and in that case not require a LiDAR capture, but if you are inside and at close range then you could assume that it should be part of scoring the authentication.

Similarly, LiDAR alone will help disqualify cases where someone is just taking a picture of e.g. a landscape target of the Golden Gate, but that it shown on a screen 1 meter away.

2h agoHN ↗

This approach makes me wonder if the future is actually going to move towards visual cryptography.

2h agoHN ↗

Right but I’d argue that realistically this feature is going to be most useful when taking photos of things reasonably close by, people especially, rather than landscape photography.

1h agoHN ↗

it's trivial to block the projector and hide the dot pattern. No dot pattern = iPhone thinks the object is far away, which is what happens in landscape photos.

I've never looked at the LiDAR hardware, but where is the emitter in relation to the receiver. Why would the LiDAR not reflect off of whatever you're blocking it with and return a very short flight meaning it was very close?

7m agoHN ↗

I knew keeping a pot of vantablack in my jacket pocket would come in handy.

3h agoHN ↗

furthermore, couldnt you do parallax from the multiple cameras as well as flicker the flash?

seems pretty easy to make it sufficiently difficult to trick the system

2h agoHN ↗

Is this really that big of a flaw in this implementation? I don't think it's worth the additional complexity to address it. (Encoding depth information in some way, trying to detect "flat" surfaces, whatever).

Discerning a camera taken image of an image is typically very very easy. The collors/exposure/etc will all be obviously wrong in ways to a human, even without doing any analysis.

2h agoHN ↗

You mean that it is sometimes very easy. But it is also sometimes impossible. You seem to be thinking only of poor quality photos of poor quality prints, but there's no basis for assuming those characteristics.

1h agoHN ↗

To be fair Apple of all companies have the best shot at pulling it off. They've been perfecting their hardware security for years for other reasons and this is just another way to take advantage of that work. But yes, if someone breaks it then the trust is gone and it casts doubt on all of the photos that were ever captured using the broken system.

2h agoHN ↗

It's less about proving a photo's truth than about attesting it.

2h agoHN ↗

Paint the inside of the box using Vantablack

But you're only allowed to do that if your name if Anish Kapoor

1h agoHN ↗

I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.

There’s no such thing as a Golden Gate Bridge.

Prove it.

1h agoHN ↗

This sounds like it could be done, but the costs for doing so are comparably high.

I think the idea is to control the easy, cheap mass production of AI gen picture and not 100% coverage.

That’s a tradeoff I can live with.

48m agoHN ↗

I suspect they have ways to ID at least some things like this somehow in ways that will lead to key revocation.

17m agoHN ↗

I can't wait to see Apple Verified™ photos of UFOs flying over the Golden Gate Bridge.

While I'm on board with you about the inabsolute security of this (relative to what's typically expected of cryptographic systems), the fact that their 'verified' state requires a live certification and can be revoked means that the sensor responsible for obviously faked images will see those images and that device no longer certified.

It all relies a lot on trust in Apple, and integration with Apple, and relatively unmotivated attackers.

3h agoHN ↗

terrible idea...

but im sure it will popular with 60 year olds watermarking their pictures of sunsets.

3h agoHN ↗

Waiting for "Apple verified" photo of some important politician doing something wildly inappropriate.

Scrapped in 3..2..1..

3h agoHN ↗

What if someone take the photo of the forged photo displayed on another device, doesn’t the forged photo become an authentic one?

2h agoHN ↗

Sure, if it’s believable that the shot was perfectly flat at, what, 2 feet away?

2h agoHN ↗

A photograph by itself should never be considered proof of anything.

1h agoHN ↗

Don’t know why this was downvoted but this is the right take. A photograph is evidence, but isn’t a proof in and of itself.

2h agoHN ↗

so what happens if you display an extremely high res image of a 100% AI generated fake-something on an 8K display in a photo studio room and take a picture of it with the camera? it gets tagged as authentic.

1h agoHN ↗

That’s a lot of money and effort for a fake photo

2h agoHN ↗

The fundamental issue isn't technical. It's that people will see the "certified real" tag and just take the image for face value of whatever narrative someone wants to convey. They'll see the "Real Photo, Verified by Apple" and their brain will short circuit [0]

I don't think we should have this, for that reason alone (but many others too).

[0]: https://imgur.com/fVPkpuQ

1h agoHN ↗

I’m pretty sure “certified real” aren’t the words Apple will use, nor do they use it in this document. The words to describe the technology were chosen with care: semantic verification, attestation, tamper evident, etc.

2h agoHN ↗

Seems kind of concerning that using this at all means you send your image to Apple’s PCC machines.

1h agoHN ↗

Presumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated.

PCC is quite good, about as close to private remote compute we can get without doing HME.

1h agoHN ↗

Edit^2: On triple reread it sounds like the first pass ("Image Capture") sends the image metadata hash to be timestamped, whereas the second pass (Reference Image Development) sends the image itself but is not what actually creates the timestamp attestation. According to Apple[0][1] it sounds like the second pass (development) only happens when the reference image is actually viewed, which means that your image isn't sent if you never view the reference image?

[0] https://support.apple.com/guide/iphone/view-reference-images...

[1] https://www.apple.com/legal/privacy/data/en/reference-image/

When you take a photo in Reference mode after tapping Reference Mode, your device will include reference image information in the photo’s metadata. If you then view that photo and tap the Reference badge on your iOS device or click it on your Mac, the device will send the raw photograph, metadata about the photograph like the sensor’s signatures and the time frame in which the photo was captured, as well as the sensor’s unique hardware identifiers to Private Cloud Compute.

Edit: On reread it seems they do in fact send the actual photographic data to PCC, which I presume has some reason over signing metadata on-device? Original mistaken post is below for transparency.

You can always not use the reference image mode, and according to the article you send a hash of the signature of the photograph, so all they would know is you took a photograph in reference image mode at some point in time before the request.

51m agoHN ↗

some reason over signing metadata on-device

After my brief read, one of the main reasons they’re using PCC to produce the signed JPEGs, instead of doing everything on device, is that it maintains your privacy.

If you were signing with the iPhone, an attacker could then correlate photos taken with the same device.

Apple certainly has the data that “this sensor, in this device, took this exact photo” in PCC at the time of signing, but they discard that data.

1h agoHN ↗

The timestamp system seems like it provides more benefit than signing the image data itself, at least in terms of difficulty to fake. As long as rolling back the stored timestamp token is prevented, I would have to find a phone that never updated its timestamp after the time I want to fake. Of course you could potentially find a phone that last connected to Apple's servers with a plausible timestamp. Even then the upper bound of when it signs the photo after reconnecting to the internet will raise eyebrows if you take too long to find the phone and fake the photo, so it effectively raises the bar to having to take the fake photo roughly simultaneously with the time the event purportedly took place anyway.

1h agoHN ↗

Hot damn. I've described this concept before, obviously not to this level of detail, but leaving this comment in here in case I can find my old comments. A bunch of people have poo-poo'd my proposals, but glad to see a serious actor really executing it. Probably no one at Apple ever read my posts, but it sure does feel good to see something executed. Hopefully it sticks.

1h agoHN ↗

Lots of criticism here but I think this is extremely promising. When this tech is extended to videos and perhaps even other forms of media, I think it has the potential of stopping all slop!

1h agoHN ↗

All slop? I'm sure that some "Shrimp Jesus" or "Talking Strawberry" was never considered to be authentic by anybody. There is a lot of useless AI generated content of which everybody knows it's AI generated littering the web. Having it marked as AI will not stop that.

1h agoHN ↗

This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification).

Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

48m agoHN ↗

People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

True.

raises the bar but could be bypassed with enough effort.

Anyone can spoof this.

Apple cannot stop spam iMessages. They can't stop someone from rendering their privileged UI inside a browser viewport. People copy and paste remote script executions from convincing captchas.

This whole provenance thing is a red herring. You agree with me, but there's truly not a single application for this that won't be exploited.

44m agoHN ↗

I don’t understand what this brings to the table beyond what we’re currently doing.

Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.

1h agoHN ↗

I‘ve been wondering whether the contact tracking features introduced for Covid 19 could be used to verify that pictures of an event where taken by people who were actually around the scene. That way you‘d have some reassurance that a given picture was actually from the event. Combined with pictures from different angles from different people and some kind of verified photography should make alterations harder.

38m agoHN ↗

Seems to lead us down the slippery slope of requiring an Apple device, or a Google device (e.g., https://cybernews.com/privacy/google-qr-code-recaptcha-requi...), or the device of some other entity (that may be mostly non-aligned with democratic values) in order to participate in society.

The unfortunate result of AI slop is reduced trust, which in turn is responded to with surveillance, which ultimately leads to the loss of liberty. Is it possible to do these sorts of verifications in an open way? I kinda doubt it, since someone has to control the hardware manufacturing process.

35m agoHN ↗

This is so insanely complex and requires placing trust in the correctness of so many pieces, many of them closed-source. And uploading every verified "developed" image to Apple's servers. And giving up full control of the software and hardware you "own". All to achieve a goal of "verifying" photons, which is only a part of the real problem of verifying the truth of an event that was photographed.

I hope that companies and governments don't start forcing us to use this stuff by requiring it for their services.

27m agoHN ↗

Am wondering why no one is talking about traceability of Photos. Ex: CSAM which Apple was fighting for a long time. I thought this feature was the answer to provide proof of who shot the picture.

26m agoHN ↗

Or have I understood the feature's capability completely wrong?

2m agoHN ↗

I dont think this is relavent to that use case. It seems like this proposal would be an optional off by default feature. They also seem to be going to lengths to make it privacy first so the verified photos cannot be linked to a specific photographer.

23m agoHN ↗

I skimmed the whole article and I didn’t see a single image so I’m confused. Is there some watermark of some kind or where is this metadata integrated? Because if it’s just metadata then I need to parse each photo I come across manually, and if it’s a watermark it can be faked because I won’t manually validate every single image I come across to prove the watermark isn’t fake.

4m agoHN ↗

presumably the metadata reader app would be integrated into the photo viewer app which would verify the digital sigs.

I have my doubts about this scheme but this is not one of them. If the point is that someone in principle could verify, that is enough for it to be useful, even if not everyone does.

23m agoHN ↗

Apple has to allownpost-manufacruring exchanges of camera due ton right of repair legislation. This requires them to publish pairing tools that are to be used during the repair process to update all the cryptographic vérification chains in the device.

Now the camera module is supposed to generate a key pair internationally and send the public key over the bus. This looks like it is interceptable at repair time and a man in the middle can insert a different public key that they generated externally. Is there a way to stop this?

1m agoHN ↗

I think this is really good and kudos to Apple for implementing it. The first question that popped into my mind was "what new scenarios of government X forcing Apple to do 'terrible thing' to 'individual' this enables?", but I can't think of anything. It seems that all government attack vectors this feature enables are of the type "government X forces Apple to do 'terrible thing' to 'Apple'", i.e. a government can try to force Apple into certifying a narrative, and of course Apple is going to fight tooth and nail the lack of credibility that would result from that.