Apple’s Verified Photography System

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone.

Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are concerned this puts some photographers, such as those operating in conflict zones, in a difficult position; it should not be necessary to forgo anonymity in order to prove image authenticity. We built Apple Reference Image to avoid using an explicit, public credential for photographers, and to avoid even implicit public association between different photos taken by the same sensor. The final reference image is instead signed by Apple’s signing service, after validation by PCC. That signature is backed by Apple’s strongest technical guarantees.

Our implementation also protects the confidentiality of the image itself, including from Apple. Merely capturing a reference image should never expose the actual pixels to Apple or anyone else. We achieve this through the exceptional privacy properties of PCC—the nodes themselves are architected so that not even Apple can access image data, just as Apple cannot see the information processed for Apple Intelligence in PCC. While the revocation service must maintain a private record of photo GUIDs and associated sensors to allow for revocation, it never has access to the image data, and does not allow for public access to this record. And as final revocation checks occur using on-device lists, a device never reveals to anyone which photo it’s looking at in order to find out whether it’s still valid.

The report makes for good reading; the details are interesting.

Posted on October 7, 2026 at 7:07 AM • 20 Comments

Comments

alnm • October 7, 2026 8:24 AM

So instead of “photographer or institution to vouch[ing] for an image using their own credentials”, Apple will vouch for the image after you upload it to their servers. Ok then.

Chris Boyle • October 7, 2026 9:00 AM

“It can also verify that multiple images came from the same iPhone.”

The report seems to state the opposite: “Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device”. And later “If a device is later found to be compromised, its images can be revoked and flagged retroactively, without revealing which images came from the same sensor.”

(It also mentions checks that a sensor and an SEP are from the same device.)

TimH • October 7, 2026 9:34 AM

There are two competing use cases:

  1. Whistleblower wants to submit a photograph with no
    evidence linking them to the photograph. Also, hard evidence that the picture is exactly as taken by the camera without editing. Editing includes the photograph “improving” that cameras nowadays are wont to do. Just the sensor capture.
  2. Copyright holder wants to submit a photograph with hard evidence that they own the rights. This is hard evidence that the picture is as taken and stored by a specific camera including merging multiple shots and other on-camera editing.

KC • October 7, 2026 11:09 AM

@ Dave Sanford

At early review, this feature appears to split image provenance into two strictly isolated phases.

  1. Create a secure digital negative on device
  2. Develop it inside Private Cloud Compute

Here’s a guide on how to opt-in as well as develop a reference image:

https://support.apple.com/en-us/128064

KC • October 7, 2026 11:10 AM

From Apple on sharing photos:

“If you share a Reference mode photo before reference image has been developed, it may include sensitive information about your device, such as the serial number, and the full image frame regardless of the zoom setting at capture.”

Also, does anyone know if you can develop the negative more than once?

Grumpy Old Coot • October 7, 2026 11:26 AM

“If a device is later found to be compromised, its images can be revoked and flagged retroactively, without revealing which images came from the same sensor.” And scarily, what prevents this being ‘hijacked’ to cause data to disappear? “This device was compromised” -> “This device belongs to a journalist. Let’s compromise it and invalidate all evidence.’

freedom • October 7, 2026 11:55 AM

What this means is that now the image sensors are backdoored as well.

This is another victory of the GCHQ-NSA-corporate mafia, a child-murdering mafia.

Rontea • October 7, 2026 12:20 PM

Fascinating move by Apple with their Reference Image system. This is a classic example of end-to-end thinking in both security and privacy. They’re not just slapping a signature on an image—they’re building a chain of trust from the sensor silicon, through cryptographic attestation, and into a privacy-preserving compute environment.

From a defensive standpoint, I like the layered approach: hardware-secured pixel capture, Secure Enclave attestation, cryptographic timestamps, and PCC for verifiable image development. The post-quantum signature step is forward-leaning, acknowledging that content authenticity needs to survive decades of adversarial advances.

The revocation concept is also smart; it’s a rare admission that no system is perfect, and gives a way to restore trust if something goes wrong without unmasking the photographer. This is a thoughtful blend of integrity, privacy, and resilience that raises the bar for verifiable media in the age of AI-generated fakes.

freedom • October 7, 2026 12:36 PM

they’re building a chain of trust from the sensor silicon,

Yes, the sensor is backdoored.

It’s quite entertaining to see that no one on this blog is an actual advocate of privacy for actual, real, ordinary people.

Also many of the posts look like plain apple spam, probably machine generated spam.

freedom • October 7, 2026 12:48 PM

they’re building a chain of trust from the sensor silicon,

A “chain of trust” under complete control of the “apple” mafia, a pseudo-private business that is a facade for the NSA-GCHQ mafia.

The objective of the system is of give total control to the real owners, crapple and the US government, and to remove all control from the user who paid for the phone.

The point of this system is to allow the US-UK-Isreal police surveillance state to know where and when any picture is taken.

The “chain of trust” is meant to prevent any kind of defense against total surveillance.

SocraticGadfly • October 7, 2026 5:03 PM

It’s kind of interesting to see “freedom” make blanket claims that aren’t true.

Clive Robinson • October 7, 2026 11:37 PM

@ Bruce, ALL,

If you think about it this is a technology that you would design for “Client Side Scanning” and “use blocking” if you wanted Corporate or State level censorship.

This is at least the second time Apple has been the lead in such technology.

The first being their now aborted anti-CSAM “on host scanning and reporting” on images from a few years back.

I’m sure this technology will make the US DoJ and FBI extremely happy along with all those repressive governments like the UK and Australia. That claim to be democracies but are anything but as they slid into more and more authoritarian tactics/legislation on the way to becoming Guard Labour run “Police States”. All driven by “Think of the children” or “Health and Safety” style “dog whistles” and faux “for societal good” excuses.

Anyone who thinks “age validation” is for protecting children is sadly deluding themselves[1]. It’s purpose is to enforce “OnLine ID” which most Western Governments know is extremely unpopular with voters and generates significant “kick back”. But politicians / legislators stupidly hunger for such “Snooping and Authoritarian Control” powers, you can see this in the way the EU Executive has and is behaving.

I can see them rubbing their hands with glee when the “secret advantage” of such technology is “confidential explained to them”.

But remember Microsoft tried similar on with “Office Files” many years ago and then dropped it because they saw more advantage in “Open Standards” than “Proprietary Standards”.

Which suggest the way to apply leverage is by only supporting Open Standards that stop this sort of “back door censorship” ambitions.

[1] An extension on the proof of why “Guard Rails and Sandboxes” will always be ineffective against “entities with agency” demonstrates why.

But further “children / minors” have already demonstrated beyond doubt that the “gap problem” also can be exploited as with all biometrics abd similar. That is there always exists a “gap” between a “tangible physical object” and an “intangible information object” that tests and records / represents it, this gap always allows for forgery etc.

With Age Verification some enterprising solutions have been thought up and put into practice by “children / minors” including the simplicity of just painting a false moustache on…

lurker • October 8, 2026 12:07 AM

@Clive Robinson, ALL
“Anyone who thinks “age validation” is for protecting children is sadly deluding themselves”

Apple’s version is apparently good enough for a certain “adult” site in one repressive regime. But using it surely must be as private as using your own credit card to subscribe to said site.

https://www.bbc.com/news/articles/cwvgdlzvl9ego

cybershow • October 8, 2026 1:54 AM

I don’t think there is any technological solution to human trust,
because there is no technology beyond question. That makes for
an infinite regress. Whose assertions about technology do you trust?
One has simply moved the problem into a place where, even if compelling
proofs exist, the average person has no intellectual purchase (and that
includes judges and officials).

Trust is emotional and so many will trust Apple’s tech because of their
brand attachment. A great many more will not trust Apple to be arbiters
of truth. So there are two very different issues here.

That has little or nothing to do with the utility of verification/attestation
tech for media in civilian life now. Trust in images is over. Photographers,
journalists, analysts, news reporters and audiences all need to get over that.
The infallible image was brief moment in human history.

That’s not to say sensor authenicity and data signing at the transducer aren’t
useful and important in other areas. I’m interviewing another CNI architect
working on the UK power grid about real-time tampering by foreign actors
to destablilise supplies. The privacy of power generators doesn’t feature in that
equation.

- • October 8, 2026 8:38 AM

Moderator:

1, Never Forget 7-10

Is political, aimed at stirring up conflict for this blog by a person who has their posts removed on a daily basis.

freedom • October 8, 2026 12:21 PM

I’m sure this technology will make the US DoJ and FBI extremely happy along with all those repressive governments like the UK and Australia.

Thanks Clive, that is the heart of the matter.

One can note that governments worldwide are getting more and more totalitarian, but western governments, led by the US-UK, deserve a special mention since

One, they claim to be morally perfect.
Twp, they are actually the worst criminals on the planet.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.