| ▲ | tgsovlerkhgsel an hour ago | |
This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally". There are already plenty of insurances that require you to submit claims through a smartphone app that tries to essentially do this by capturing sensor metadata etc. - those don't need to be nation-state resilient, just Joe the Crackhead Insurance Scammer resilient, so this works. Likewise, more and more things online require identity verification (either officially or disguised as age verification). Edit: And while "a nation state actor can spoof this" is a problem for the journalism use case, the insurance/ID verification use cases are perfectly fine with anything that raises the bar but could be bypassed with enough effort. Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves. | ||
| ▲ | itake 20 minutes ago | parent | next [-] | |
I don’t understand what this brings to the table beyond what we’re currently doing. Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess. | ||
| ▲ | doctorpangloss 24 minutes ago | parent | prev [-] | |
> People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves. True. > raises the bar but could be bypassed with enough effort. Anyone can spoof this. Apple cannot stop spam iMessages. They can't stop someone from rendering their privileged UI inside a browser viewport. People copy and paste remote script executions from convincing captchas. This whole provenance thing is a red herring. You agree with me, but there's truly not a single application for this that won't be exploited. | ||