Remix.run Logo
quinncom 5 hours ago

I love that it has a feature to prove images came from the real world:

> Users can now prove the authenticity of a photo taken on iPhone 18 Pro models with Apple Reference Image, powered by the new sensor in the Main camera that can sign every pixel it sees. When a photo is taken in the new Reference mode, the camera captures signed sensor data that Private Cloud Compute develops into an unalterable reference image.5 Reference images can be viewed in the Photos app alongside the main image, like a digital negative, to visually compare the two assets and determine if any edits were made. APIs are available in iOS, iPadOS, and macOS 27 for third-party apps to enable viewing of these reference images.

andrewmutz 4 hours ago | parent | next [-]

Can't I just point my camera at an AI generated image? And it will get the stamp of authenticity?

dabinat 3 hours ago | parent | next [-]

It would be great if they could use the LiDAR scanner to sign a depth map of the scene in front of the camera. It would show if you photographed a flat image.

dwattttt 3 minutes ago | parent | next [-]

The 'ol "analog hole". Never been able to patch that gap.

bayindirh 2 hours ago | parent | prev | next [-]

The sensor already uses phase detection autofocus. You can create a depth map out of it. iPhone X used its dual cameras and that phase data for depth maps.

ks2048 2 hours ago | parent | prev | next [-]

If that became popular, the AIs would learn how to generate a realistic depth map along with any generated image.

Gigachad an hour ago | parent | next [-]

The photos are cryptographically signed in the apple image pipeline so it's not as simple as just AI generating something. That said, I can't see how this is any different to all the other times we have embedded crypto keys in consumer hardware where eventually someone finds a way to extract the key and the whole thing is busted open.

jaggederest 23 minutes ago | parent [-]

Given the whole private cloud bit, I am assuming they keep the private keys server side and never let them out.

Gigachad 16 minutes ago | parent [-]

That's a good point, You might still be able to trick the cloud to sign your photos, but that's something they could patch in updates without losing control of the key. They could have the server only sign photos taken on the latest ios version.

jaggederest 9 minutes ago | parent [-]

And honestly you could have a similar antitampering oracle that was at least obscured, in terms of "we've detected tampering but won't tell you how or why", which is frustrating but I have to imagine that 99.9%+ of images are clean.

lokar 2 hours ago | parent | prev | next [-]

How would that work? I thought the premise here is that you can fool the apple camera by taking a (very carefully aligned) picture of a still image (printed out).

A depth map from the apple camera (again, signed) would show that the entire image had the same distance from the camera.

embedding-shape an hour ago | parent | prev [-]

Even simpler, a 3D printed relief with an image "stamped" on it, now you effectively have a 3D image.

bayindirh an hour ago | parent [-]

…and the PDAF data will show how shallow it is.

embedding-shape 43 minutes ago | parent [-]

... don't make it so shallow then. Perfectly possible in a consumer-friendly 3D printer for a face or even human body if you have lots of time for the prints.

dylan604 36 minutes ago | parent [-]

but what are we really trying to solve here. you're suggesting a helluvalota work for what purpose?

koolala 2 hours ago | parent | prev | next [-]

They could use the camera aperture to take a second photo and calculate blur.

w4der 3 hours ago | parent | prev | next [-]

And what if you take a picture across a IR-filtered window?

apetresc 2 hours ago | parent [-]

Then you won’t be able to prove it was a genuine photograph? That sounds like the right failure mode.

mikeaskew4 2 hours ago | parent | prev | next [-]

Pretty sure it does that already.

selcuka 44 minutes ago | parent | prev [-]

One can 3d-print the AI generated image and photograph that. /s

dymk 2 hours ago | parent | prev | next [-]

It will look like you took a picture of a screen or print out

michaelt an hour ago | parent [-]

People have constructed video walls so high resolution they can film TV series in front of them and to an audience it's indistinguishable from a real set. It's extremely cost-effective for things like space fantasy that needs lots of exotic-looking backdrops, apparently.

It may not be in reach for you and I - but within reach of anyone with the budget to run a 'bot farm'

llukas 3 hours ago | parent | prev | next [-]

Stamp only proves you did the photo and probably some metadata like when where etc.

It helps but doesn't solve credibility issue.

intrasight 2 hours ago | parent | next [-]

The credibility comes from who took the photo. The next logical and easy step is for this metadata to flow to the user agent. I'll know that it was taken by a legit journalist photographer. And id not, I can have my user agent make it fuzzy or replaced with a kitten photo.

Gigachad an hour ago | parent [-]

I think this is where we are headed. This feature seems useless on it's own since someone will eventually find a way to extract the key from the iphone and sign any image. But if they could make it so every iphone uses it's own key and the photos show "Taken by xyz" and it's linked to their icloud or identity somehow. That way images shared around will still be able to be linked to a source that you can choose to trust and the viewer can know it wasn't modified from what that person shot.

Then we might move to an age where photos which were not signed by someone will be treated as fake.

intrasight 30 minutes ago | parent [-]

I don't think we'll treat them as fake but they would probably undergo more scrutiny - perhaps in a crowd-sourced manner that provides an overall score of probable legitimacy.

lokar 2 hours ago | parent | prev [-]

what is it missing then?

44 minutes ago | parent | prev [-]
[deleted]
sheepybloke 2 hours ago | parent | prev | next [-]

On the opposite side, this read to me like there was so much image processing going on in the background and off device that they felt like they needed to prove that there was a real image backing the creation, and that it was not all AI. It really begs the question of what the extent is of image processing.

Gigachad an hour ago | parent [-]

The iphone image pipeline is mostly just playing with exposure and color, things that we widely regard as fair game in editing. Where the line was crossed was magic eraser and reframe where the iphone is straight up making objects in the image.

spacebanana7 3 hours ago | parent | prev | next [-]

The weakness of this is that a person can take a picture of a high resolution screen or print.

We really need Apple to open up true depth APIs to make forgery non trivial.

apetresc 2 hours ago | parent | next [-]

I don’t know too much about image processing, but my intuition tells me that distinguishing a photo of a 3d scene from a photo of a photo of a 3d scene is a much easier engineering problem than distinguishing it from an AI-generated diffusion. So even just reducing the problem to the former is still a worthy accomplishment.

awkwardleon 2 hours ago | parent | prev [-]

Agree with the weakness, but the benefit of provenance is still there. You can't tell if the picture that person took is of an AI image, but there's some value in saying "I took this" and being able to prove it.

snypher 3 minutes ago | parent | next [-]

How does this actually work though?

1) I see a photo online and doubt it's provenance

2) I contact the photographer and ask to see their cloud image (???!)

2a) I borrow someone's mac to download the image (.jpg?) and it can be verified on that?

Gigachad an hour ago | parent | prev [-]

I hope future social media presents this metadata so if someone claims a photo is from the BBC, it actually gets checked against the keys the BBC sign their photos with.

siva7 21 minutes ago | parent | prev | next [-]

A mobile phone.. an internet communicator.. a music player.. don't you get it? well, steve, actually 18 years later it's a .. camera

cavoirom 4 hours ago | parent | prev | next [-]

Yes, this is really a "Pro" feature, while C2PA exists, not many consumer products have it, iPhone will be the game changer for reporters.

kllrnohj an hour ago | parent [-]

Reporters who only capture pictures on an iPhone and not a "real" camera, and who also never need to edit the photo to crop off or obscure identifying information, innocent bystanders/victims, gory violence or nudity, etc...

The problem is real, but this solution seems to not really solve it in any practical sense.

reaperducer an hour ago | parent [-]

Reporters who only capture pictures on an iPhone and not a "real" camera, and who also never need to edit the photo to crop off or obscure identifying information, innocent bystanders/victims, gory violence or nudity, etc...

So, 90% of photojournalism outside of the major cities, then.

FireBeyond 3 hours ago | parent | prev | next [-]

Canon's original high end digital models had this as a feature, that your images could be digitally signed in-camera based on raw sensor data. Primarily for law enforcement. Obviously a far broarder use case, now.

lern_too_spel 2 hours ago | parent | prev | next [-]

Finally. Android phones have been shipping with C2PA since last year, so it's great that the final holdout has capitulated, though with its own set of nonstandard tools.

https://c2paviewer.com/articles/samsung-galaxy-s25-c2pa

https://security.googleblog.com/2025/09/pixel-android-truste...

https://c2paviewer.com/supported-devices

nxc18 2 hours ago | parent [-]

The Android version is useless though, TBD if Apple can do better.

https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html

whatever1 3 hours ago | parent | prev | next [-]

I wish next year for videos too.

We really need it for journalism. Otherwise we will not know what is real and what fabricated with ai.

xattt 4 hours ago | parent | prev | next [-]

*Not available in EU or China.

I wonder what the common thread is.

rock_artist 3 hours ago | parent [-]

> I wonder what the common thread is.

Regulation.

For China I would assume like other services, if there's some cloud involved, it should be on Chinese soil and accessible to China.

For EU harder to guess, but again the lock-in with "Private Cloud Computing" feels related.

Frost1x 5 minutes ago | parent | prev [-]

[dead]