Apple debuts Reference Image, an opt-in verified photography mode on iPhone 18 Pro
- Apple Reference Image ships as an opt-in camera mode on the main sensor of iPhone 18 Pro and iPhone 18 Pro Max, producing a securely timestamped reference image that reflects what the sensor actually captured, with dedicated secure hardware protecting its integrity.
- The process splits into two phases: a secure digital negative created when the sensor boots into a specialized reference capture mode, then development of that negative into a viewable reference image, so the raw pixels and the final image each get separate protection.
- Apple argues against C2PA-style provenance, which attaches metadata after capture and certifies later edits, because that chain can be compromised at any point with no way for a viewer to detect it, and it can tie an image to a device or a public identity, which is a privacy risk for photographers in dangerous conditions.
- Private Cloud Compute handles the processing so Apple cannot see the image data, any fraudulent reference images can be revoked without revealing the photographer's identity, and an observer cannot tell whether two reference images came from the same device.
Hacker News opinions
Nobody's talking about the replay problem. AI-generate an image, throw it on a high-res monitor, photograph the monitor with the iPhone 18 Pro, and you get a valid Apple Reference image. Put the monitor in a cardboard box painted with Vantablack and tape over the LiDAR and it's done.
Sony's version of this claims it bakes 3D depth data into the attestation. Apple has LiDAR on the back of at least some iPhone models, so they could do the same thing.
This doesn't stop staged photos either, but that's not what they're solving. Photoshop has been around for decades. This just attests that the image came off an iPhone sensor.
Is the screen-replay thing even worth fixing? You're proposing extra complexity to catch something a human notices instantly, since the color and exposure on a photo of a screen are obviously wrong.
Systems like this have been tried and broken for years. Nikon image authentication got defeated, GPS is trivially spoofed, and you only need one bored kid to dump the signing keys on pastebin.
It's less about proving a photo is true than about attesting where it came from. Those are different claims and people keep conflating them.
Cost matters here. Photographing a screen is way more expensive and awkward than generating an image, so this raises the floor on cheap mass-produced fakes. I can live with that tradeoff.
The technical side isn't the real issue. People will see the certified badge and take whatever narrative is attached at face value. That alone is a reason not to ship this.
Apple never uses the words certified real. They wrote semantic verification, attestation, tamper evident. The wording was picked carefully and it shows.
An NFT by another name, honestly.
A photograph should never be treated as proof of anything by itself. It's evidence, not proof.
What bothers me is that using this sends your image to Apple's PCC at all. Presumably you'd only do it for photos you're posting publicly anyway, and PCC is close to the best private remote compute we have.
On the third reread: the first pass just hashes metadata to be timestamped, and development only happens when you actually view the reference image. So if you never view it, the raw photo never leaves the device.
The timestamp part looks harder to fake than the signing. Unless you can roll back the stored timestamp token, you'd need a phone that never updated its clock after the time you want to fake, and the reconnect gap would raise eyebrows.
I've been pitching almost exactly this design for years and getting laughed at. Good to see a serious player actually build it, especially once it extends to video.
Lots of criticism in here, but I think this is genuinely promising. Extended to video and other media, this could put a real dent in slop.