
Ensuring authenticity is verifiable for those who need to know
Apple recently introduced a feature designed to prove that a photo was genuinely taken on an iPhone. Further details regarding “Apple Reference Image” were revealed this week.
When the owner of, say, an iPhone 18 Pro activates “Reference” mode and takes a picture, the main camera sensor immediately digitally signs every pixel it captures and prevents the data from being altered. Signed timestamps (marking the moments before and after the shot) are also generated during the process.
All this data is packaged into a “digital negative” and sent to Apple’s cloud. There, no one—not even Apple itself—can view the raw data. The system verifies the signatures, confirms that the sensor and processor belong to the same device, and checks whether the image resembles a genuine camera shot.
If everything checks out, the raw data is processed into a standard photo: noise is removed, colors are adjusted, and the image is compressed into JPEG format. Finally, the photo receives a definitive signature. This signature combines the RSA-3072 system with the ML-DSA-87 algorithm, offering protection against hacking attempts—”even by quantum computers.”
However, Apple retains the ability to revoke the “trust” status of individual photos or all images from a specific sensor should that sensor be deemed “compromised.”