The company says existing standards like Content Credentials aren’t good enough, so it made its own.
Alongside the addition of a variable aperture and manual controls, Apple introduced an interesting feature to the iPhone 18 Pro: it’s called Reference Image, and is designed to prove that a photo wasn’t altered at any point after the photons hit the sensor.
This system, which currently only works on the iPhone 18 Pro and Pro Max’s main camera, is a distinct mode in the camera app and is aimed primarily at journalists. It tries to overcome several technical hurdles to ensure that both the data as captured by the sensor and the processed result of that data, can be tied back to a specific device within a narrow period of time. In other words, it tries to authenticate both the Raw and the processing that turns it into a viewable image.
Apple isn’t the first company to try to solve this problem. A coalition of companies, including Adobe and several major camera manufacturers, has thrown its weight behind Content Credentials, another system designed to be able to prove that an image is what it claims to be in the age of wholesale AI image generation and assisted editing.
While we’ve written extensively about Content Credentials, Apple has characteristically taken a completely new approach with its own system. So why has it invented its own tech, rather than using the existing standard that some of its competitors have adopted, and how does it work?
What problems is Apple trying to solve?
Apple says it designed the Reference Image system to meet three requirements:
- The resulting image “must faithfully show what the sensor captured,” and you can verify both the Raw capture and the process that turned the raw data captured into a viewable photo
- A false image created via tampering with the sensor, cryptographic software or phone’s OS will fail the verification process. If it’s later discovered that the system verified an image it shouldn’t have, the certificate marking it as authentic must be able to be revoked.
- The images can’t reveal who took them, or whether the same device took any two images. Apple shouldn’t be able to tell what’s in the image when it’s signing it.
The company argues that existing systems like Content Credentials don’t meet these standards. Part of that is because they have different goals; one of the explicit appeals of Content Credentials is that it lets you bake image attribution into the file in a way that’s hard to remove. But Apple also argues that adding a credential after the image is created, as Content Credentials does, leaves space for bad actors to create false images and then sign them as authentic (something that one of our forum members was able to demonstrate with the implementation in the Nikon Z6III).
The system looks to be incredibly robust, which is unsurprising given the level of attacks Apple’s devices have to defend against. (It basically has to assume its systems will be tested by the full capabilities of a hostile government.) It’s built to protect against verifying images made by feeding fake data to the sensor itself through its electrical contacts or by removing it from the phone, and from quantum computers being used to break its encryption, something Apple says no other image provenance systems do. The company says this is to make sure the images are verifiable far into the future; traditional encryption algorithms can withstand most kind of attacks, but because quantum computers work fundamentally differently from the computers they were designed for, they can easily crack them.
What does taking a reference image look like?
The high-level overview is that the phone isn’t always taking Reference Images. You have to purposefully switch to taking them in the camera app, which will reboot the sensor into a special mode. So far, this is only available on the iPhone 18 Pro or Pro Max’s main camera – either in 1x or 2x mode, though not night mode since it appears to only use a single exposure – as it’s a hardware-based feature. Even then, it isn’t available in the EU or China (likely due to its reliance on Apple’s Private Cloud Compute service, which we’ll cover shortly).
After you take a reference image, you then have to choose to “develop” it before you’re able to view or share it. You can share the developed HEIC file as a normal photo, viewable by anyone, or as a special reference image that, currently, can only be viewed using an Apple device running its latest software. The person receiving it will be able to see a version with any edits you’ve made, as well as what the camera originally captured, and the interface can even highlight the differences. It will also show verified metadata, such as when the photo was captured. This does, however, rely on them using Apple software on Apple hardware: otherwise, it’ll just render like a normal HEIC.
How does a Reference Image work?
Apple’s document on the technical details of the Reference Image system is, unsurprisingly, pretty complex, so I’ll try to explain it in a way that will make sense to most people.
The process for creating a reference image starts at the factory, when the phone’s sensor and security chip are tied together in a way that Apple can check later, to confirm that the two actually worked together to create and secure the data that it’s interpreting as a photo.
When you switch to the camera’s Reference Image mode, it reboots the sensor into a secure mode that basically ignores what the operating system is doing, except for receiving a “digest” that contains a securely computed timestamp range and some identifying information for the device and its security chip. The sensor then collects light and digitizes it into data (as cameras tend to do). It then cryptographically signs it before sending it off the chip. This basically means that the raw data the camera captured can’t be changed by the sensor firmware, phone’s processor, operating system or anything else. Otherwise, the signature created by the sensor won’t match the signature produced by the data, and the system could tell something was wrong. The secure metadata, including what time the photo was taken, is also included in that package, before it’s handed back to the OS for storage
This leaves you with what Apple calls a “secure digital negative,” stored as a DNG Raw file, which you can edit and share like normal if need be. However, to make it a Reference Image, you need to then be able to trust the process that turns that “negative” into a viewable file, as the raw data from the image sensor isn’t actually an image. Even when opening a Raw file on your computer, what you’re actually seeing is that data processed in several ways, like demosaicing to interpret color, lens corrections and the application of a tone curve. You are seeing your program’s interpretation of the Raw, not the data itself (which is why it may look different from program to program).
After you’ve taken the picture, you can choose to “develop” it
This is where the second part of the system comes in. After you’ve taken the picture, you can choose to “develop” it into a Reference Image (something that doesn’t happen automatically, and which requires an internet connection). When you do, that “digital negative” is sent to Apple’s Private Cloud Compute servers, which will then recompute the “digest” containing the timestamp and data from the phone and its security chip, ensure the certificate matches the raw data and that it was actually issued by the sensor. It checks a few other things too, making sure that the sensor and the security chip haven’t been altered since they left the factory.
Apple says it takes great pains to ensure that the timestamp attached to the image is accurate. Rather than using on the device’s clock, your phone routinely gets cryptographically-signed timestamps from Apple’s servers, which it uses to create a window of time that the image must’ve been taken in, based on the timestamp it received before it was taken, and the next one it received, after. (Apple says this happens on average every 15 minutes, though it’ll depend on network connectivity; it can also account for phones that are offline for long periods of time).
After the Private Cloud Compute service has checked over all the certificates, it creates what’s called a confidence score for the image, which decides how likely it is that it is a real photograph based on how well the data matches “physical characteristics expected of raw output from our sensors.” It then turns the Raw into a JPEG before “hashing” it, creating a signature that ensures that the rest of the development process won’t change it, and to identify any subsequent changes that occur after the image is returned to the user.
Apple keeps a running tally of the confidence scores attached to the images submitted by each sensor
The JPEG’s unique identifier, the hash for its Raw, the confidence score and the sensor’s ID, though not the JPEG itself, are sent to a separate service, which checks a few things. Most importantly, it makes sure the image wasn’t created by a sensor that’s been added to a revocation list for having uploaded fake or suspect data. Apple keeps a running tally of the confidence scores attached to the images submitted by each sensor; if that number gets low enough, indicating that something suspicious is happening with that device’s reference images, the Private Cloud Compute service will never sign pictures from it again.
If everything checks out, though, the service signs the JPEG with Apple’s signature, letting everyone know that it passes the company’s technical checks. Importantly, this replaces the photographer in the chain of trust: the company says the system intentionally doesn’t provide a way to identify who took a reference image, to the point where you can’t even use it to tell if two photos were taken by the same phone. It only tells you that Apple can attest to it being unaltered from the point of capture. The Private Cloud Compute server then sends the JPEG, packaged as a HEIC, back to the phone, and moves the “digital negative” to the trash, for deletion after 30 days (though you can tell it not to delete it within that timespan if you want).
Whenever you go to view that image on a supported device, using supported software, it’ll check to make sure it still has the signature, and that Apple’s system hasn’t retroactively revoked it. From there, you’re able to make edits to it, though the end user will be able to see the original, provided you share the Reference Image HEIC, rather than an exported JPEG.
In Apple we trust?
As with most security standards, whether or not you believe an Apple Reference Image is a source of truth*will require putting some amount of faith in the company. The company has a relatively solid track record when it comes to security and cryptography, so it’s not implausible that it could implement a system like this, and Apple says the Private Cloud Compute software that turns those into viewable photos is publicly auditable. Of course, if you’re not a security and cryptography expert, you will have to trust researchers to actually do that work and communicate that it is, in fact, safe.
To me, the real act of faith won’t be in deciding whether the pictures Apple certifies are genuine. It’s trusting the company to never revoke a certificate of a legitimately-captured image for any reason, something that it appears to have the power to do. I also have to assume the system will occasionally get it wrong, either signing an image that shouldn’t have been signed, or not signing one that should, and the test will be how Apple reacts in such situations. Or, indeed, whether it bothers to continue operating the service indefinitely, irrespective of profitability and take-up.
The company has a history of standing up to governments – even powerful ones in the US and UK – when ordered to compromise user privacy and security, and offers some of the most comprehensive protection modes you can get on a phone. However, its track record isn’t spotless. It famously handed off control of the iCloud data for its users in China to comply with the country’s laws, a move that Reuters reports will give that government “far easier access to text messages, email and other data.”
Notably, the Reference Image feature isn’t available in China. It’s also not immediately launching in the EU – Apple is currently in a spat with the bloc over how much privilege it gives its own services on iOS – but the company has at least promised that it’ll bring the feature to the EU at some point in the future.
The chicken and the apple
I’d like to leave you with a few parting thoughts. While there is undoubtedly use for pictures that are in some ways verifiable – especially as journalistic institutions change, and as news is increasingly captured on phones, both by professionals and everyday people – it’s also worth considering how much that can actually move the needle.
We live in a relatively low-trust environment, where large groups of people can’t agree on even relatively basic facts. (Calling topics “debated” would be giving too much credit; debate implies people are willing to change their minds based on evidence presented.) While people not being able to trust images is certainly a problem, especially at scale, there are a lot of examples of hard evidence being ignored because it’s inconvenient.
This is, frankly, not really a problem that Apple can even solve, no matter what technical expertise it brings to bear. I also shudder to think of us handing over that responsibility to a private company, more than we already have. But I also think that it’ll be hard to get back to a place where images are trustworthy again, because it’s a chicken and egg problem: you can’t rely on things like Reference Image or Content Credentials as an indicator of whether an image is fake or not until most or all of the real images you see have them attached. Sure, they can “prove” an image is authentic, but with their limited market penetration, they’re currently not very useful in spotting fakes.
Even if you could flip a switch today and have every picture taken on an iPhone be easily verifiable on any platform where they’re displayed (something that’s currently absolutely not true of the much more widely-adopted Content Credentials), it would probably still require sweeping social changes for that to actually matter. Again, though, that’s not really within Apple’s control. But as things stand, there’s at least one more tool that journalists and citizens can use to try to prove that their images are authentic… assuming the viewing public trusts the system, and that those trying to verify the image own enough new Apple products to do so.
* As much as any photograph can be. Pictures can depict what happened in a moment, but you still have to trust that the photographer or person or organization sharing the image are being honest about the context surrounding it.
Want to stay up to date on the latest product news and releases? Add DPReview as a preferred source to ensure our independent journalism makes it to the top of your Google search results.
