> This is really clever from Apple. The journalist use case is just the PR story. This will be really useful for identity verification and insurance apps, and has the potential to shift from "you need a smartphone to be able to live normally" to "you need an iPhone to be able to live normally".

You have it all wrong.

Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.

There's no way to link a reference image to a person; it's also not possible to determine if a pair of images came from the same device.

> And while "a nation state actor can spoof this" is a problem for the journalism use case

This is incorrect:

    When the image sensor is first initialized in the factory, it creates a
    cryptographic signing identity, sharing only the public key with the
    factory. The SEP similarly creates a separately-attested signing
    identity. These identities are bound together into the device manifest,
    allowing us to later check whether a particular sensor and SEP are from
    the same device.

    The final signature on a reference image is a composite post-quantum
    signature combining RSA-3072 and ML-DSA-87. To our knowledge, Apple
    Reference Image is the only image provenance system that provides
    quantum-secure defenses.
So… a nation-state can't really do anything here unless they acquire alien technology. If something crazy happens (solar flare or EMP?), a fraudulent reference image can be revoked.

> Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.

I would imagine there will be a way to confirm an Apple Reference Image on the web. Pretty soon, 3rd parties will be able to verify the image themselves:

    Reference images can be viewed in the Photos app alongside the main
    image, like a digital negative, to visually compare the two assets and
    determine if any edits were made. APIs are available in iOS, iPadOS, and
    macOS 27 for third-party apps to enable viewing of these reference images.

> it's also not possible to determine if a pair of images came from the same device.

It’s possible for Apple, as stated in the blog post (e.g. “which lets the device later produce signatures that Apple can attribute to that specific phone”).

> So… a nation-state can't really do anything here unless they acquire alien technology.

At least for the image itself, using direct projection onto the sensor (in a way similar to a retinal projector or film recorder) would be difficult to detect I imagine?

You'll still need an iPhone, the verification is linked to the specific iPhone, and the specific iPhone is linked to you.

<< Apple Reference Image is not an id system;

I think you have a point. I would only note that just because it is not explicitly designed as one, does not mean it will not be effectively utilized in that manner.

EMPs are not "alien technology", and you don't need to be a nation state either. That said, Apple's hardware security is generally very good.

> EMPs are not "alien technology"

Yup, you don’t even need nukes: https://en.wikipedia.org/wiki/Explosively_pumped_flux_compre...