Apple knows the iphone the reference image was uploaded from, so, yes, there is.
Apple knows the iphone the reference image was uploaded from, so, yes, there is.
It is probably possible for an entity to break it, but it would require live access to both Apple and the third party (Likely Cloudflare) servers. And that is assuming there is only one third party routing OHTTP requests, otherwise you would need to monitor all of them, in real time, since the requests are transient.
> The final reference image is instead signed by Apple’s signing service, after validation by PCC.
So, if compelled, Apple could theoretically tell someone if two images came from the same camera.
[1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation
it’s one step removed from identity.
fwiw i think this is an unambiguous improvement over current post-sensor attestations, it’s just good to explore the edges
No they couldn't.
If you generate two SSH key pairs on your laptop, there's no way to confirm they were created on the same machine.
There's no device identifying data in a reference image, which is the point. The factory signature, the image sensor key, the Secure Enclave Processor key and all of the signing that takes place on PCC are all device-agnostic.
The reference image is processed and eventually signed by Private Cloud Compute's post-quantum signature using a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme.
So… it's not possible for Apple to know if two images came from the same iPhone.
When the user initiates developing a reference image, the device uploads the secure digital negative to Private Cloud Compute. PCC recomputes the digest embedded in the frame and verifies the sensor's signature over the pixels and that digest, verifying the certificate chain back to the sensor CA. PCC also verifies the SEP signature and chains it to the BAA CA, and it verifies the signature on the device manifest and chains it to the CA that signs device manifests at the factory. It then confirms that the sensor and SEP named in those chains belong to the same device. [...] If these checks pass, PCC then submits the commitment to our signing service, which signs it with a composite post-quantum signature using a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme. The signature is embedded in the JPEG, and the reference image is returned to the device, which associates it with the main photo from the original capture.
After the secure digital negative is successfully developed, it's automatically moved to the deleted photos folder."
So in the end it all depends on how much you trust Apple's cloud and PCC nodes. If there is a weakness in their services, Apple could record both the original signatures and their signature, and could prove whether two photos were made using the same lens/device and they could even trace it back to a specific device (by looking up the original signature + signing identity given their signature).