Trust in a photograph usually rests on the chain of edits that follows capture. Apple wants it to rest on the sensor instead. Apple has released the design for Reference Image, a camera mode buyers must switch on. On the iPhone 18 Pro and Pro Max it produces a timestamped picture that can be verified as untouched sensor output.
The target is C2PA, the editing-chain standard backed by Adobe, Microsoft and the BBC. Apple’s objection is that signing happens after capture, leaving the window before it open to tampering, and that credentials can tie an image to a public identity.
In Reference mode the sensor boots into a dedicated state and signs pixel data the moment it is recorded, while the Secure Enclave handles metadata that comes from elsewhere, such as zoom. Two signed RFC 3161 timestamps bound the capture, one gathered over the push notification heartbeat beforehand and one requested after, routed through Oblivious HTTP. The output is kept as a secure digital negative in DNG format.
Processing runs in Private Cloud Compute, which checks the signature chain back to factory certificate authorities, confirms sensor and enclave share one handset, then demosaics, tone maps and compresses. Signatures on the finished file pair ML-DSA-87 with RSA-3072. Apple describes that combination as the only quantum-secure provenance scheme in use.
Sceptics found holes. One asked whether photographing an AI-generated image on a high-resolution display could yield a valid file, though a 48MP sensor would likely leave visible moire. Others noted that nodes briefly hold both the device’s original certificate chain and Apple’s replacement signature, so the anonymity guarantee rests on the cloud.