Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Because usually the open standard isn’t good enough.

As an example, being able to authenticate to any random server means that you really can’t trust authentication responses. You see that with TLS; not every CA can be trusted, even though they all are supposed to be trusted.

As a thought experiment, ask yourself if it would be OK if the authentication server was run by the government? I suspect most people would say “no.”
They can implement the spec in their server
 
So what, Apple wants to label their computational highly preprocessed photos as “real” just so no one can say they are not? Can see a lot of influence from 1984!

Kinda ironic of Apple to think their photos are real and something coming from AI isn’t. At this point Apple iPhone takes such overprocessed photos that I can’t tell if it was generated by AI or real, both look like ugly slop

1786429925843.jpeg
 
Last edited:
why don’t they use the open standard then
There are two problems with this:

1. Somebody already explained that it means you have to make the original content available for verification, while Apple’s method allows for a more privacy preserving approach. Most people won’t care but someone using a photo or video as evidence could become a target for retaliation in an oppressive regime for example.

2. Most of the authentication systems now are focused on declaring “this is not true”. This is great, but only works if everyone making the content want people to know said content is fake. It does nothing to stop bad actors with enough resource to locally deploy their own models from generating content that isn’t tagged. You can do this now with as little as a highly specced Mac mini. Once you start to realise how “easy” it could be, you start to realise how much value there is in working with a “this is true” mentality instead.

Both options have their pros and cons and tbh we will likely need both in the fight to know what media is “true” and what isn’t going forward. But this is the correct move for a platform vendor with the unique control over hardware, software, and scale of devices in use that Apple has.
 
Last edited:
How is this presumedly badge of authenticity going to sit with the AI powered ‘extend my photo’ gesture from iOS 27?

I’d like to see a mode where Apple removes all computational photography from the image pipeline.

Let’s - literally - keep it real.
 
  • Like
Reactions: Timpetus
My thoughts exactly.. standards get pushed aside and then to authentication you have to put it against several different methods. We just need one standard—then everyone can use it

Same here. Work with other manufacturers to come up with a common standard so, gee, one tool can verify the authenticity of pictures from all devices. Apple could ensure personal data is not part of the base standard, and yet the standard could allow extending the data with such information if the photographer wanted to; say a pro who wants copyright information embedded.

Apple could still use their servers, I'm guess they figured it would be faster, and they could create a better solution, to roll their own rather than get the industry to agree on a standard.
 
Annnnd your privacy goes right out the window with it.
Not at all. This protects privacy while also authenticating that an image is “real” instead of fully AI generated.

Edit: To make this more clear. As explained in the article, this is likely primarily aimed at photojournalists, photographers, and others who need to be able to prove their images are real. If that's not you, then don't enable the setting.
 
Last edited:
A chain of trust is needed, like we have had with SSL in browsers. As mentioned, someone could point the phone at an AI image, so AI detection is also needed, but the source would still be that person - their reputation is a factor here.

On a general level, what we strive for is verification that an image actually came from the organization or person it is attributed to.
 
  • Like
Reactions: Sergio The One
so what happens if an image taken with an iPhone camera is then edited (heavily) through either AI or traditional editing apps?

its still taken from a camera but the authenticity vanishes?

does the metadata then disappear?
 
Combine this with Claude adding invisible digital watermarks to text and media generated by AI including account level information, you'll be able to know who generated any content anywhere, text, photos, etc... complete attribution to your online activity. Cool with me, but a word of warning to anyone posting dumb sh*t.
 
  • Like
Reactions: Sergio The One
Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.

They need a server to validate metadata?
 
  • Like
Reactions: Terry2023
Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers.
When authenticating a photo, Apple receives sensor data, a hash, and the assessment results, but not the raw photo.

Uh... so which is it? Do they get the raw image/photo, or not?
 
It cannot be used to trace back to the specific device because the info is hashed (which is a mathematically one-way computation) before leaving the device; it’s used to attest that “some genuine device” was used to capture the photo.
Almost all of this is not true.

Hashes are not necessarily "one-way computations" (base64 is also a hash), they are just data represented in a different way, and even those made to be "one-way" like you say, can sometimes be brute forced (md5)

Also a value like this can definitely be used to track back to the device, but that is based on whether the value was generated by being dependant on a device id or something unique like that, which without being an apple engineer working on this, you cannot possibly know right now, so you cannot possibly say "it cannot be traced back to you".
 
I love it.

This doesn’t just address the problem of verifying if a picture is AI or not.

It also enables for the first time without any doubts to be able to prove that a photo hasn’t been tampered with in ANY way.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.