6 ms·
I don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and prete
by treyd 7d ago
I don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and pretend that the photosensor is capturing whatever image you want. I imagine it's not exactly trivial to do this, but a grad student with an FPGA could probably figure it out.
- figmert 7d agoOr, as the author said, you can just photograph an AI generated picture, and that will work too.
- koinedad 7d agoAdding depth sensor info to the this could help
- petu 7d agoThis feature is Pro phones only, not Duo: https://www.apple.com/iphone/compare/ https://www.apple.com/iphone/compare/ ("Apple Reference Image (Fusion Main)") So only on devices with LiDAR / that can capture depth map.
- theamk 7d agoIf there is signed metadata too, then it's pretty hard. You will need to match focus distance (it will be very small if photographing picture), GPS location, exposure and other settings. If there is a depth map, you'll need to match it too.
- TedDoesntTalk 7d agoEven easier is to just take a picture of an AI-generated picture.
- Retr0id 7d agoSimpler than that, you can just talk to the cryptography IC yourself and ask it to sign stuff. No need for an FPGA, just an arduino. Given the datasheet I imagine any LLM from the last year should be able to oneshot it.
- hex4def6 7d agoif I imagine on apple silicon this is buried deep in silicon / ISP IP block, and isn't a discrete IC.
- whywhywhywhy 7d ago>a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake you don't need to do that just photograph a screen. This seems close to worthless in "identifying real photos vs AI" for someone actually wanting to do something bad with an AI image, although probably very useful at identifying which phone took a photo when ("the root of trust stays inside Apple's Private Cloud Compute") seen as it's not an entirely local solution a bad actor government could use their powers to completely abuse this.
- ares623 7d agoif geolocation data can be captured in the same signature, that would be a good enough approximation for most relevant cases I think.
- brainwad 6d agoGNSS signals can be relatively easily faked because the original signals are very weak so overpowering them doesn't require much broadcast power.
- ares623 6d agoah, damn.
- 15155 6d agoJamming them is easy, replaying them so as to trick unacquainted receivers is easy, but "faking" a network of signals so as to precisely control present a specific location is not easy or feasible. "Overpowering" (as to jam) inherently means detectable, these signals are arriving below the noise floor anyway. And if you aren't overpowering, the original signals will leak through. Also, depending on the sophistication of the receiver, your ability to present an implausibly different location may not exist at all (AGPS.)
- brainwad 5d agoIt seems feasible for state actors, at least: https://en.wikipedia.org/wiki/GNSS_spoofing#Ocurrences https://en.wikipedia.org/wiki/GNSS_spoofing#Ocurrences
- altairprime 6d agoBecause doing so does not materially devalue Apple’s product. Sure, a dedicated attacker could try to overcome it, but few will, and only people of such serious consequence that they can afford the effort of modification. By and large this puts Apple into direct competition with Nikon and it’s long overdue that someone ship this capability to a wider market than authorities. Also, remember how Touch ID sensors are cryptographically paired, and consider whether Apple could bake that into a camera sensor rather than a fingerprint sensor. If they can, then you can run wires all you want; the attestation chain will not be valid. I’d be shocked if they were willing to launch the product without that, and there’s a new hardware dependency or else they’d have released it for earlier phones.