Hacker Newsnew | past | comments | ask | show | jobs | submit | Gigachad's commentslogin

It’s stored in the exif data on the photos

The timestamp wouldn’t match the event being depicted and the geotag would show the studio. And the depth sensing would show the image as flat.

It looks like the reason for the custom timestamp setup is to assert and upper and lower bound on time. A normal timestamp server can asset it saw the image at a certain time but not that the image wasn’t created much earlier. This setup, the image processing pipeline can immediately attach the last seen timestamp to the photo as a lower bound, and then connect to the network to get the upper bound time.

If there is too much of a gap between the upper and lower bounds then the image becomes suspicious.


The lower bound is specified by the device, you don't need support from the timestamping server for that. Determining if this timestamp is or isn't suspicious can be done at verification time. The timestamping feature itself makes sense from a verification perspective (though the privacy implications are questionable, of course), but I don't think it necessitates an Apple-specific setup.

This approach does have one benefit, which is that Apple gets all the (meta)data to determine if something is or isn't "real", rather than letting the verifier decide beforehand.

I can only imagine the outrage if Google or Microsoft added a "upload all of your photos to us and we will mark them are real or fake" protocol, even with all of the verified compute gaff.


this already happened -> https://news.ycombinator.com/item?id=49421158 -> My passing comment mentioning Apple Reference Image in the same thread was moderated down into oblivion for some reason!

It seems like the two signatures on device are processed on the camera sensor itself, and then post processing is signed by the SEP. Neither of these would be compromised even if you have a full jailbreak.

This has been possible since the beginning of photography and yet I can’t think of a single scenario where people have been tricked by a staged photo. Yet every day hundreds of millions of people are being fooled by AI generated photos.

Nothing stops you not verifying, or simply stripping the verification off.

What you are prevented from doing is adding a verification to a photo outside of the iOS image pipeline, or modifying the photo with the verification still in tact.


Because it’s impossible to implement this feature in open source and out in the open. It relies on a locked down image pipeline and hidden key.

That's also why the approach is fundamentally flawed. The open-ish C2PA protocol has been "defeated" by tricking phones into signing arbitrary data already. The even-more-closed Apple version can be defeated the same way and relies on Apple to be the sole arbiter of truth.

any other similar approach is also dead on arrival, I can't believe so many apple engineers fails to see it? it's like siri 2012 all over again

its impossible in closed source. there is no reason to believe it does what it says it does. only private keys in the chain need to remain secret.

Incorrect. There is nothing here requiring closed source. Only private keys need to be kept private for obvious reasons

I’m fairly sure that the contact tracing feature has been removed now. And it wouldn’t be needed anyway, the iPhone location services are far more useful. I imagine the geotag could be included with the verification.

Location services is quite hard to trick. To the point people have gone to the lengths of putting iPhones inside a microwave for RF shielding and setting up fake phone tower signals inside to trick the phone in to unlocking the hearing aid feature on AirPods for unapproved countries.


Indeed, that may simply be it. You would want to verify time and date. When coming up with the thought I was looking for ways to crowd verify real world events.

I think the “the rich” in this story is just someone who can afford not garbage boots, and not what we would consider rich today.

It’s also possible the situation has changed enough with modern manufacturing that it’s no longer as relevant.


There’s certainly options above temu junk. Maybe it doesn’t meet your bar but I’ve found the 100% cotton stuff from Uniqlo to be massively higher quality than the average. I’ve got tshirts from them I’d guess I’d worn and washed 80+ times.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: