Apple’s Verified Photography System

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone.

Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are concerned this puts some photographers, such as those operating in conflict zones, in a difficult position; it should not be necessary to forgo anonymity in order to prove image authenticity. We built Apple Reference Image to avoid using an explicit, public credential for photographers, and to avoid even implicit public association between different photos taken by the same sensor. The final reference image is instead signed by Apple’s signing service, after validation by PCC. That signature is backed by Apple’s strongest technical guarantees.

Our implementation also protects the confidentiality of the image itself, including from Apple. Merely capturing a reference image should never expose the actual pixels to Apple or anyone else. We achieve this through the exceptional privacy properties of PCC ­ the nodes themselves are architected so that not even Apple can access image data, just as Apple cannot see the information processed for Apple Intelligence in PCC. While the revocation service must maintain a private record of photo GUIDs and associated sensors to allow for revocation, it never has access to the image data, and does not allow for public access to this record. And as final revocation checks occur using on-device lists, a device never reveals to anyone which photo it’s looking at in order to find out whether it’s still valid.

The report makes for good reading; the details are interesting.

Posted on October 7, 2026 at 7:07 AM • 2 Comments

Comments

alnm • October 7, 2026 8:24 AM

So instead of “photographer or institution to vouch[ing] for an image using their own credentials”, Apple will vouch for the image after you upload it to their servers. Ok then.

Chris Boyle • October 7, 2026 9:00 AM

“It can also verify that multiple images came from the same iPhone.”

The report seems to state the opposite: “Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device”. And later “If a device is later found to be compromised, its images can be revoked and flagged retroactively, without revealing which images came from the same sensor.”

(It also mentions checks that a sensor and an SEP are from the same device.)

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.