Apple details Reference Image: sensor signing, PCC verification and post-quantum signatures for photo provenance
智东西 · wechat · 2026-09-18
Alongside the iPhone 18 Pro lineup, Apple introduced Apple Reference Image, a photo authenticity feature, and published a technical deep-dive on how it works. Available only on the iPhone 18 Pro/Pro Max main camera (not yet in China or the EU), it verifies that a photo was captured by a specific sensor within a time window and that the imaging pipeline wasn't tampered with.
Key points:
- Two-stage flow: the sensor cryptographically signs raw pixels and metadata into a "secure digital negative," then Private Cloud Compute verifies device identity, runs the image processing, and issues a verifiable credential for the final JPEG
- Anti-tampering: hardware identity binding (sensor key + SEP tied to a device manifest), a composite post-quantum signature (RSA-3072 + ML-DSA-87), image confidence scoring, and a revocation system that can invalidate photos from a compromised sensor
- Privacy: photographers stay anonymous, timestamps use Oblivious HTTP, and revocation checks happen locally without revealing which photo is being viewed
Apple claims it's the only image provenance system with quantum-safe defenses.
More from Safety
- Developer slams AI labs' 'slowing down for safety' posts: deliver secure models or don't ship — andrejusb · 2026-09-18
- HEIF Heist: one image parser bug class hits OpenAI, Meta, Slack, GitHub Enterprise — jedisct1 · 2026-09-18
- HEIF image exploit chains into OpenAI internal GitHub via Discourse forum bug — jedisct1 · 2026-09-18
- vishalmisra shares his full takes on various 'AI doom' scenarios — vishalmisra · 2026-09-18
- Networking veteran pushes back on AI doom claims: 'because ASI' excuses bad security takes — vishalmisra · 2026-09-18
- X user defends side-channel air-gap claims: it's one example of many, not the whole case — Mallchad · 2026-09-18