Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple explains how the iPhone 18 Pro’s new Reference Image camera mode works

A new post on Apple’s Security Research blog details the fascinating tech, architecture, and thinking behind the iPhone 18 Pro’s new Reference Image camera mode . Here are the details more…

Apple explains how the iPhone 18 Pro’s new Reference Image camera mode works

Apple has revealed the inner workings of the iPhone 18 Pro's innovative Reference Image camera mode in a detailed new post on its Security Research blog. The company's new photographic authenticity system, unveiled in a blog post titled "Apple Reference Image: A New Approach for Verified Photography," aims to address the growing threat of synthetic or edited images. While existing industry standards like C2PA offer some protection, Apple believes its system provides a higher level of security and privacy.

Apple's approach relies on a secure digital negative, which stores raw pixel data along with signed metadata, timestamps, and other crucial information. This negative is created within Apple's Private Cloud Compute structure, ensuring that the process remains private and verifiable. The system's three core requirements are semantic authenticity, resilience to compromise, and privacy preservation.

The process begins during the iPhone's manufacturing, when the camera sensor generates a unique signing key pair. The private key remains within the sensor, while the public verification key is shared with the factory recording station, which signs the sensor with a factory certificate and records it in the device's hardware manifest. This signed key is then used to authenticate every photo taken in Reference Image mode, linking the pixel data and sensor metadata to the specific sensor.

To further secure the process, Apple employs cryptographic timestamps. Instead of relying on the device's general operating system, which could be compromised, the iPhone receives a secure timestamp token periodically. After capturing an image, the device requests another timestamp to establish an upper bound. This allows Apple to verify that the image was taken within a specific time window.

The Secure Enclave also contributes by signing metadata outside the camera sensor, which is then verified by Private Cloud Compute. This ensures that the sensor, Secure Enclave, and device belong to the same iPhone, and that the timestamps are accurate before the secure digital negative is processed into the final JPEG Reference Image. The final image is then signed using a combination of traditional and post-quantum cryptography, designed to remain verifiable even against future quantum attacks.

One notable aspect of the system is Apple's commitment to preserving user privacy. The framework is designed so that an outside observer cannot determine the identity of the photographer, the device that took a given photo, or whether the same device captured multiple Reference Images. This is particularly valuable for photographers working in sensitive environments, such as conflict zones, where maintaining anonymity is crucial.

Written by urgent.news from 9to5Mac's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at 9to5mac.com →

More in Tech

Deleting a secret from your Docker image doesn't delete it from your build history

An autonomous hacking agent found a live GitHub admin token in Baseten's infrastructure by pulling a public Docker image and reading its build history.

  • Secret token persisted in Docker image build history despite removal
  • GitHub admin token retained internal repository permissions from March 2023 to July 2026
  • Build history contains plaintext token, posing significant threat to security

Yokhash Meets VPC: Exploring Amazon Virtual Private Cloud ☁️

📝 Introduction What is the AWS service? Amazon VPC (Virtual Private Cloud) is a networking service that lets you create your own logically isolated section of the AWS cloud.

  • Amazon Virtual Private Cloud (VPC) enables isolated AWS cloud sections.
  • VPC launched in 2009 to improve secure, enterprise-grade architectures.
  • VPC provides control over IP range, subnets, route tables, and gateways.

More from Wednesday 16 September →