Proof of Capture: Apple Reference Image, but open source and using steganography
Posted by merybenavente 2 days ago
Comments
Comment by Retr0id 1 day ago
Perceptual hashes are non-cryptographic. There are certainly collision attacks, but what about preimages? A preimage would completely break this scheme.
This paper demonstrates second-preimage attacks against PhotoDNA and PDQ: https://eprint.iacr.org/2021/1531.pdf
Comment by theamk 1 day ago
- "Small content edits slip under the threshold. [...] A localised edit covering ~15%x20% of the frame [...] passes as authentic" - this is the worst part. 15%x20% is huge, for example enough to change the face of the person or the book/text on the image.
- "Cropping is not survivable, at any amount" - given the purported reason for perceptual hashing is surviving light editing, it's pretty disappointing that one of the most common light editing operation is not supported.
Oh, and the whole "cryptographic chip" angle is absolutely bogus from the security perspective. OK, attacker can't extract the private key from chip. But they can simply connect the chip to a different device and have it sign anything! Given that the attacker in this model is device owner, this is absolutely trivial.
Comment by phh 1 day ago
Comment by Retr0id 1 day ago
Comment by fitzn 2 days ago
Comment by smalltorch 2 days ago
https://gitlab.com/here_forawhile/edasm
Example:
After wholly implemented our logging layer with dagger, I posit that the real regression was not the aws itself but the rigorously prototyped around authentication. We consequently extraordinarily profiled the config, henceforth simplified every edge case, and the optimization were unmistakably exemplary. alternatively, the aforementioned monitoring is comparable advantageous to an incremental security environment. I endorse this path if your security team has rigorously instrumented a massive rust codebase before.
Comment by gpugreg 1 day ago
Comment by smalltorch 1 day ago
The text decodes to 'hello world'.
Also, this engine won't compile on non arm64 chips without virtualization layers.
Check the 'Prerequisites' section for required packages to compile.
Comment by 1over137 1 day ago
Comment by smalltorch 1 day ago
The project started as a pure python version, but it's pretty slow.
Comment by merybenavente 2 days ago
Comment by nmadden 1 day ago
https://blog.cryptographyengineering.com/2020/11/16/ok-googl...
Comment by mike_hearn 1 day ago
On the other hand, images faked by AI is a real problem.
Comment by zbentley 1 day ago
"Genuine" is doing a lot of work in that sentence. A big part of the threat model for image provenance/signing/similarity diffing is identifying when images aren't genuine--if they're from elsewhere than they're claimed to be from, or have been modified.
You're right that there are privacy/security costs to attributability, and that it's not always the right thing to do. I hope that keeping provenance information either entirely cryptographic in nature (okay, the image has a signature--you can't determine anything about that signature other than "signed with this key y/n" when you present a key) or reducing identifying or fingerprintable information presence in provenance metadata is sufficient to mitigate some of those concerns.
Dr. Neal Krawetz has written and researched a lot about this topic:
https://hackerfactor.com/blog/index.php?/archives/1069-The-B...
https://hackerfactor.com/blog/index.php?/archives/1098-Metas...
https://www.hackerfactor.com/blog/?/archives/529-Kind-of-Lik...
Comment by smalltorch 1 day ago
That could obviously be used for good or bad purposes.
Reminds me of tracking dots in printers. It was implemented to provide a way to track a document to its source.
Comment by postit 1 day ago
Comment by netsharc 1 day ago
This post https://foxfire.blog/explorations/the-typewriter-that-became... claims "specific machine":
> The forensic science behind this was genuinely elegant. No two typewriters print identically. The mechanical tolerances of individual typebars—those metal arms that swing up to strike the ribbon—create unique signatures. Forensic document examiners look at three primary characteristics: alignment (whether a letter strikes slightly above or below the baseline), impression (whether one side of a letter prints darker than the other due to uneven wear), and damage (a chipped serif, a broken bowl on a lowercase “g”, a filled-in counter on an “e”). Taken together, these micro-imperfections form a pattern as distinctive as a human fingerprint—or so the authorities claimed.
> The East German Stasi took this principle to its industrial extreme. They maintained an exhaustive registry of type samples, a vast database of typewriter fingerprints. When a dissident pamphlet surfaced, the Stasi could compare its letterforms against their archive and, in theory, trace the text back to the specific machine that produced it. The countermeasure was ingenious in its simplicity: dissidents sought out pre-communist typewriter models—early Mignon or Ideal D machines manufactured before the registry existed. A typewriter without a file was a typewriter without a name. It could speak and not be traced.
Since they had control of commerce, I suppose it was possible to intercept every typewriter and "fingerprint" it before it is sold, or even tweak the typewriter to produce something unique (e.g. chipping a typebar so it prints a particular letter distinctly). Hah, needing to register your name/address to buy a typewriter feels spooky too. And if it gets stolen, you'd have to tell the authorities that it's no longer in your possession.
Comment by treyd 2 days ago
Comment by whywhywhywhy 2 days ago
you don't need to do that just photograph a screen.
This seems close to worthless in "identifying real photos vs AI" for someone actually wanting to do something bad with an AI image, although probably very useful at identifying which phone took a photo when ("the root of trust stays inside Apple's Private Cloud Compute") seen as it's not an entirely local solution a bad actor government could use their powers to completely abuse this.
Comment by DoctorOetker 1 day ago
a continuous stream of video from factory to customer to observation should prevent screen attacks, if there is a trustworthy framework for processing and checking the absence of screen slide-ins etc.
Comment by ares623 1 day ago
Comment by brainwad 1 day ago
Comment by 15155 1 day ago
"Overpowering" (as to jam) inherently means detectable, these signals are arriving below the noise floor anyway. And if you aren't overpowering, the original signals will leak through. Also, depending on the sophistication of the receiver, your ability to present an implausibly different location may not exist at all (AGPS.)
Comment by brainwad 17 hours ago
Comment by 15155 9 hours ago
Comment by ares623 1 day ago
Comment by altairprime 1 day ago
Also, remember how Touch ID sensors are cryptographically paired, and consider whether Apple could bake that into a camera sensor rather than a fingerprint sensor. If they can, then you can run wires all you want; the attestation chain will not be valid. I’d be shocked if they were willing to launch the product without that, and there’s a new hardware dependency or else they’d have released it for earlier phones.
Comment by Retr0id 2 days ago
Comment by hex4def6 1 day ago
I imagine on apple silicon this is buried deep in silicon / ISP IP block, and isn't a discrete IC.
Comment by figmert 2 days ago
Comment by petu 2 days ago
So only on devices with LiDAR / that can capture depth map.
Comment by theamk 1 day ago
Comment by koinedad 2 days ago
Comment by TedDoesntTalk 2 days ago
Comment by Wendell58 1 day ago
Comment by khalic 1 day ago
Comment by ale42 1 day ago
Maybe it should include depth info in the image instead.
Comment by Lammy 2 days ago
Comment by jamesnorden 1 day ago
Comment by vzaliva 2 days ago
However, this will certify only the original image. I think the missing part of this is additional layers of certification which allow some image editing (e.g., rotating, contrast, etc.) yet clearly document that the image was modified and link to the original image ID. Kind of like a signed git log.
Comment by zvr 2 days ago
Comment by throwaway356565 2 days ago
is a post about Google Pixel C2PA cameras experiencing contact with reality
Comment by Retr0id 2 days ago
I'll write more about this in the future.
Comment by xg15 2 days ago
Comment by stvltvs 2 days ago
Comment by cortesoft 2 days ago
Even if you didn't know who owned the camera, you could identify other pictures taken by that same camera, and information in those photos might let you figure out who owns the camera.
Comment by anhner 1 day ago
Comment by cortesoft 1 day ago
If you sign two images with that private key, people will know for certain that you created both of them. This is the whole point of signing something. No one else can fake it because they don't have the private key, but EVERYONE can verify it because they DO have the public key. In fact, they don't even need the public key because they can extract it from the signature and the signed image.
Comment by smalltorch 2 days ago
Comment by lokar 2 days ago
If authenticity later becomes an issue you can produce the original.
Comment by ale42 1 day ago
Comment by DoctorOetker 1 day ago
Comment by lokar 1 day ago
Comment by doc_ick 2 days ago
Comment by xg15 2 days ago
You could use this data to prove that image B is an edit of image A if you already have both A and B.
I still think this is a bad idea, because this all requires the images to have some sort of ID - and that seems like a prime target for tracking.
Comment by lokar 2 days ago
Comment by hamdingers 2 days ago
Nobody cares if your social media photos are edited, they probably are, it's fine.
Comment by xg15 1 day ago
Comment by theamk 1 day ago
This has been the case for many years, and so far social media sites never care - they strip that info instead. Why would this change with one more extra piece of metadata?
Comment by xoa 2 days ago
Can you clarify what your actual complaint is here? Putting aside for a second obvious implementation options, it's pretty standard that there can be a tradeoff between privacy and trust. Any of us are still perfectly free to upload images for fun to forums or social media or whatever that are private, or edited or whatever we like. But if there's something we [i]want[/i] to prove, this gives an extra option to do so. And in particular the set of cases where one cares the most about enhancing authenticity appears at first thought to be pretty much a union set with the cases where one will put their name (or at least the location and time of the picture in question) behind the image? Like, can you give examples of specific cases you are imagining where simultaneously the photo itself reveals no information about time and location [i]and[/i] it's something local/national/international-newsworthy where people would fear AI-alteration? Like, say you're photographing at a protest to document it including any violations of law. By definition, the images you take reveal the location and the time. That's the whole point of them. Having the location and timestamp signed wouldn't reveal anything extra as long as the photo was unaltered.
And actual legit journalism always has name(s) standing behind the reporting. Or for that matter, even if we're merely talking something like a review of a product, is it actually wrong to put a name or pseudonym behind that review if you expect readers to give you much credence? I mean, you'd be free in terms of law and tech to not bother. But even long before the current growing AI-slop age a lot of us have been starting to treat anonymous reviews with a lot of skepticism, or discounting them entirely for some product classes, for good reason.
Even in terms of maintaining privacy, remember we already have "tools" for that which this in turn could further help. You could privately report a tip to a reporter at a media organization, and then they could report on that without revealing you but be able to say "we verified the signature of the raw image and sensor data" alongside normal follow up. Then it's their name, but having a stronger chain behind it could still be helpful in places.
Finally getting back to "implementation options", there's no technical reason the image and multiple sets of metadata can't all be signed separately by the sensor stack such that you can pick & choose what to include and still have it all be signed, with readers giving greater or lesser weight to the trust based on your choices.
Comment by xg15 1 day ago
> Any of us are still perfectly free to upload images for fun to forums or social media or whatever that are private, or edited or whatever we like.
First, the paper proposed a method of embedding the metadata inside the actual image pixels in a way that makes it difficult to remove. I think it's still possible, but you're will need a specialized tool to do so and it will alter the image.
Second, that's assuming forums or social media would still be allowing uploading unsigned images. If AI images really become as much of a problem as anticipated here, then sites might decide to block any image they can't verify completely.
> Like, can you give examples of specific cases you are imagining where simultaneously the photo itself reveals no information about time and location [i]and[/i] it's something local/national/international-newsworthy where people would fear AI-alteration?
All kinds of photos from warzones have this property. We wouldn't have an entire science of geolocating photos from landmarks that were accidentally captured if everyone was so easy with putting their GPS coordinates in the file.
Comment by Someone 1 day ago
That’s not necessarily missing. For photography competitions, what matters is that people send original photos; for press photos, you don’t need a digital link between what’s published and the original, either. What matters is that papers, when questioned, can produce the original of a photo they published. Then, humans can determine whether editing changed the story.
Comment by ranger_danger 2 days ago
And this still doesn't help any other kind of image e.g. screenshots, photo of a screen etc. that can make the camera signatures largely pointless depending on the context.
Comment by stvltvs 2 days ago
Would that ever be relevant for a screenshot?
Comment by qingcharles 1 day ago
Comment by ranger_danger 2 days ago
It's relevant that a screenshot doesn't have a signature, in the case that you want to remove any "proof" or tracking info from a real photo when uploading an image. Maybe I don't want people to know what brand/model of camera I use.
And it's relevant if a screenshot did have a signature if you want to "prove" that the screenshot itself hasn't been tampered with after the fact.
Comment by xg15 1 day ago
That's how I understood it at least.
Comment by ranger_danger 1 day ago
Comment by teravor 2 days ago
Comment by mandolingual 2 days ago
Comment by account42 1 day ago
Comment by nulltrace 2 days ago
Comment by amelius 1 day ago
Glad that at least we have that now.
Comment by xg15 2 days ago
Yeah, very nice. So this whole idea basically doesn't work - but we get a new stealth way to embed metadata in an image that can be used for tracking...
(And a new narrative why cameras need to have TPMs and locked-down firmware as well)
Comment by shagie 2 days ago
In days of old, a Polaroid photo was considered "proof of capture".
I've got a Polaroid daylab 35 plus sitting in storage somewhere (https://www.instantoptions.com/wp/faqs/daylab/). You can project a slide through it onto Polaroid film, expose it, and have the image there.
I was also able to find a company that did slide printing. It was possible to send them a digital image and they'd send you back a slide with that image... which I then used to make a Polaroid of that image.
I had a classic 600 Polaroid photo of a UFO landing.
Comment by ChocolateGod 2 days ago
Comment by TedDoesntTalk 2 days ago
Comment by mandolingual 2 days ago
Comment by petu 2 days ago
Comment by petu 2 days ago
Comment by azatom 2 days ago
ps:most important: cam/lens settings also in the digital sig, what for a screen is different