We already know it's happening right now, and they know we know, but we can't do shit about it.
We already know it's happening right now, and they know we know, but we can't do shit about it.
I'm aware. The point is they can't give the NSA something they don't have. The photo sensor generates its own ECDSA P-256 signing key pair and never releases the private half.
Every device has a unique key pair and the private key is unavailable… there's not a way to give the NSA that would help them. The system is setup so that the image data, meta data, etc can't be accessed by anyone including Apple.
(Similar to how many PGP hardware keys allow generating a private key on-device or writing your own provided key.)
- verifies each link and its certificate chain, sensor signature over pixels, SEP signature, device manifest signature
- PCC Submits the commitment (the JPEG hash) to Apple's signing service.
So, at some point in time, Apple's servers have both the original certificate chain and the new replacement signature. If this is recorded, Apple can deanonimize photos and check whether two photos were from the same device/sensor.
Apple's system protects against most state actors, except Apple and the US, unless you fully trust that their PCC is watertight.
(Remember that Apple was part of PRISM and probably also its successor.)
I don't think law enforcement needs it, because when sending/posting a picture, people leak so much metadata anyway.
But people outside the US should certainly distrust these systems.