The iPhone 18 Pro Has One Big Security Feature That No Android Phone Has

Add BGR on Google:
Google Discover

In the age where we need to constantly ask ourselves if content we find online is real or made by AI, Apple has created an exclusive feature for the new iPhone 18 Pro to make this task easier. Apple Reference Image, as it's called, is a technology that creates a digital negative of a photo or a video to ensure its originality. Furthermore, Apple protects the integrity of the reference image by using Private Cloud Compute, which, according to Apple, can revoke a fraudulent image without exposing who took the photo. Such a tool would be beneficial when fact checking a photo or video posted online, which would not only help social media users but also, say, journalists reporting on a scandal.

This feature is kind of a response to Google using the C2PA (standard for Pixel 10 and Pixel 11 devices), which is a technology that ensures an image is real and hasn't been AI retouched. However, a security researcher showed that the current protocol isn't tamper-proof, and an article from Android Authority showed that C2PA can be tricked using a metadata tool called ExifTool. This article says it's "surprisingly easy" to strip the C2PA metadata from a photo entirely, erasing all trace of its origin or edit history without leaving obvious evidence of tampering. Apple says C2PA creates a compromise that "at any point during the editing chain" the metadata can be altered, which doesn't happen with Apple Reference Image.

Inside Apple Reference Image protocol

Introduced during the iPhone 18 Pro event, it's interesting that Apple is only adding this opt-in technology to the latest Pro phones. Still, it's a response to current AI tools that "allows users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago." While the company itself is also part of the problem as its improved Image Playground feature can now generate realistic images, Apple is also offering a way for customers, governments, and media to verify important information.

Apple says that Apple Reference Image creates a "securely timestamped reference image that accurately reflects what was captured by the iPhone's camera sensor. Dedicated secure hardware on the device protects the integrity of this reference image, and Private Cloud Compute protects the privacy of the image data during processing. The system is built to be resilient to compromise, no matter how unlikely: any fraudulent images can be revoked without exposing the photographer's identity."

The company also reiterates that Apple Reference Image meets three important criteria: Semantic authenticity, resilience to compromise, and privacy preservation. In other words, if someone turns that feature on, each photo can be publicly verifiable, they can't be undermined by tricking the camera sensor or virtual attacks, and an outside observer can't tell which device took the photo, as the images are not exposed to Apple or others.

Other security features that make the iPhone more secure

Apple Reference Image is just a layer in a security architecture Apple keeps building for its iPhones. For example, this wouldn't be possible without the Private Cloud Compute, which was introduced in 2024, and it's how Apple runs AI workloads in the cloud without compromising users' information by offering end-to-end encryption. The company also offers the Secure Enclave, which is a dedicated co-processor that's been available since the iPhone 5s and handles all the biometric data of the phone in addition to cryptographic keys, so even if the iOS system becomes compromised, attackers can't access sensitive credentials.

Other big features introduced by Apple in the previous years have been Lockdown Mode, which can prevent cyberattacks, and Advanced Data Protection, offering end-to-end encryption for iCloud backups, photos, and notes to ensuring that everything you save in your cloud is completely out of reach from other people. All of these technologies also join Stolen Device Protection (adding biometric-only authentication and time delays for critical actions like changing passwords) and App Tracking Transparency (a privacy layer that force apps to ask permission before tracking users across other apps and websites).

Recommended