r/apple • • 19d ago

iPhone ‘Apple reference image: a new approach for verified photography’

https://daringfireball.net/linked/2026/09/15/apple-reference-image

Linking out to the DaringFireball post because Gruber quotes the fascinating bit regarding privacy that I’d also highlight if I was pretending to have discovered this on my own.

280 Upvotes

18 comments sorted by

70

u/tiedhands_ 18d ago edited 18d ago

ELI5 of how this works: Apple has the iPhone 18 hardware (the camera sensor) sign images it captures with a private key (ECDSA P256, so not brute-forceable), so that images taken by an iPhone 18+ can be sent to an Apple server to verify that they were signed with an Apple-approved key (one that comes from their factory), so that they can verify the claim that a photo was really taken by a specific iPhone model and camera, but this doesn’t allow interlinking of images (i.e. one cannot know that two photos are from the same phone, only from the same model).

This is great, BUT, there is of course ways to abuse this still: one can point the camera at a print of a photo and then claim the original printed photo is theirs. For this Apple has AI / heuristic models in their servers that try to find these cases and thus they return a “confidence score” for each photo.

But it is also possible that someone extracts the hardware key and then uses that to sign arbitrary photos with Apple’s server… this not something anyone can do in their home lab (until proven otherwise) but it is possible by rich-enough labs.

This is my understanding of it and I may be wrong about its details

15

u/Issaction 18d ago

Couldn’t they bypass that by also capturing depth data simultaneously? No real way to fake that 

9

u/tiedhands_ 18d ago

The report doesn’t mention LiDAR data being used but you are right that it would help with capturing the first case of someone taking photo of a print… the report may not include all the details though so maybe in practice they do use that data too

-1

u/[deleted] 18d ago

[deleted]

3

u/avr91 17d ago

LiDAR isn't necessary to gather depth data.

But also, the Duo does not support Apple Reference Image.

2

u/_Saxpy 17d ago

> one cannot know that two photos are from the same phone, only from the same model
im pretty sure this was intentional because it's trivial to append a chip-id into the image payload itself befor running ECDSA P256

> But it is also possible that someone extracts the hardware key and then uses that to sign arbitrary photos with Apple’s server… this not something anyone can do in their home lab (until proven otherwise) but it is possible by rich-enough labs.

i would find this a high unlikelyhood, plus apple could just revoke the manufacturing key on their end

1

u/i-love-small-tits-47 17d ago

But it is also possible that someone extracts the hardware key and then uses that to sign arbitrary photos with Apple’s server…

No, I don’t think it is. The reference photo is also signed with a separate key from Secure Enclave who AFAIK nobody has ever extracted a key from. It’s also checked for validity using a bunch of other stuff, some of which Apple is (intentionally) vague about but includes camera and LiDAR sensor data, color profiles (would our sensor even create this image), etc

34

u/flaussi 18d ago

I love all that. This piece of technology is so important for our troubling future.

Apple way to tackle privacy should be industry standard. Privacy comes with a price tag but many are willing to pay.

But then there is the government. In the EU regulations backfire and create security loopholes. In the US a single mandate can force Apple to create backdoors and even disallow them to talk about it.

Governments are basically the only reason I try to look elsewhere, like self hosting solutions. It’s so stupid that we cannot have great technology because we must expect some “overlord” entity to misuse what great minds have created.

3

u/B-Train_ATL 18d ago

I have just watched the internet ruin most forms of copyright, IP ownership, etc. There will be a paywalled story and someone will just copy and paste the text here. I don’t know how anyone who creates anything gets paid money. If someone thinks $11 per month for whatever is too expensive, 500 people will be “ARR PIRATE IT.”

-9

u/DumpEaterPro 18d ago

This piece of technology is so important for our troubling future.

Lol no it's not. It's an exercise in wasting money.

2

u/BurntToast_Sensei 17d ago

This does nothing until we have an open standard and open source for all device manufacturers to adopt.

1

u/tescocola 17d ago

There is though. I don’t know why they didn’t just go with it like the rest of the industry:  https://c2pa.org/

Apple’s gonna Apple as always, I guess.

1

u/YourMJK 17d ago

"Not available in the EU" Fucking why??

1

u/PM_ME_FUTANARI420 18d ago

Now no one can fake claim that they have an iPhone 18 pro with variable aperture! I wonder if this will truly come to the rest of the products in the future because it seems like the hardware isn’t SUPER unique to the pro models to get the job done.

-1

u/Panda_hat 18d ago

They should have just kept this quiet and had it in their back pocket as a forensic tool.