We built Apple Reference Image to avoid using an explicit, public
credential for photographers, and to avoid even implicit public
association between different photos taken by the same sensor. The
final reference image is instead signed by Apple’s signing service,
after validation by PCC. That signature is backed by Apple’s
strongest technical guarantees.
Our implementation also protects the
confidentiality of the image itself, including from Apple. Merely
capturing a reference image should never expose the actual pixels to
Apple or anyone else. We achieve this through the exceptional privacy
properties of PCC — the nodes themselves are architected so that not
even Apple can access image data, just as Apple cannot see the
information processed for Apple Intelligence in PCC.It is for Apple, to the extend that if there are backdoors and weaknesses in their PCC, they could register a device signing identity to Apple signature mapping.
I think the line of reasoning is that you have to trust Apple anyway, since they could also roll out a malicious image to your particular phone, but I still feel like PCC is much harder to verify/audit than an iPhone already is.
Unless you use a friend's iPhone, or an iPhone you 'rented' for 5 minutes for $20 from someone on Craigslist or Facebook Marketplace to take a picture on and then Airdrop to you.
Or you could just email/WhatsApp/... it.
Perhaps do not be so literal: Airdrop, SMS/MMS/RCS, WhatsApp, Signal, etc: