>The iPhone Pro starts at $1199
The camcorder used to record the Rodney King beating also probably cost at least $1199. LiDAR will spread to cheaper smartphones if enough consumers start to value it, and many (maybe most) consumers will do if it becomes necessary for the consumer to retain the ability to make recordings that can be used as evidence.
>it could be fooled by pointing it at a screen that emits at the same wavelength
LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.
>substitute its electrical output as the input to the signing hardware
The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.
How do I know so much about iPhone hardware? I don't, except I know that Apple is widely believed to be the world's leader in hardware security, so I strongly suspect that every single data path in a recent iPhone is encrypted before it leaves any IC.
>Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.
The web server behind the site would have to be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable that iPhone Pro. Specifically, they will be able to determine its ID number (term?) from the attestation, and I'm pretty sure they already have the ability to disable an iPhone by ID number.
>Moreover, isn't "most people can't do this but some people still can" actually worse?
If Apple cares and is willing to expend the necessary engineering resources, then anyone (other the Apple itself) who makes any sort of notable or economically important or culturally important use of their ability to create a false attestation will retain the ability for only a brief time.
The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days. I expect Apple could exert a level of control over "camera remote attestation" similar to the level of control it has already achieved over which OSes (and which apps) can run on its iPhones. In general, these "technical regimes" are designed to make it easy for the engineering organization to recover from exploits as soon as the organization becomes aware of the exploit.
Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)? If not, then what is your alternative to "technical regimes" reliant on remote attestation similar to the regime I just described?
> I know that Apple is widely believed to be the world's leader in hardware security
That's a pretty rich qualification. "I know" suggests you can prove it, but you have to qualify it with "believed" because you can't. You can't cite anyone that audited Apple's source code, or ask a knowledgeable stakeholder for a credible architectural understanding. You haven't written an exploit, or reverse-engineered one.
It's purely faith. You're making an argument "you know" based on the loyal assumption that Apple's marketing is correct. You could be citing security theater muppets for all you know, but apparently your argument isn't contingent on veracity or transparency.
> Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)?
Yes? Do you really want a purity spiral where people that get abused, subjected to police brutality or sexually assaulted are discredited because they're too poor for a LIDAR camera? I would lobby day and night for this two-tiered evidence system to be reversed because it would force the miscarriage of justice as a marketing gimmeck for iPhone technology. It's not a scalable, holistic, trustworthy, accessible, or safe option for anyone, let alone Americans. There is not a single company in the United States that can implement a system like this protected from domestic or foreign adversaries.
Truly, go fuck yourself if you genuinely think this false dichotomy is the only worthy perspective.
> LiDAR might spread to all smartphones if its starts to become important to society.
You expect $50 phones to have LiDAR hardware?
> LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.
That's assuming you're trying to detect the pulse rather than sending back photons with particular timing from when you expect it to come. Notice that you can also try more than once and only publish the image where you got the timing right.
You also have the advantage because you can have something which is directly in front of the sensor but is sending back photons later than that because you're pretending to be something which is further away.
> The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.
With the right equipment you can affect electrical signals within an IC without disassembling it.
Or you can disassemble it. It doesn't have to be easy when only one person has to do it.
> The web server behind the site would be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable the iPhone. Specifically, they will be able to determine ID number (term?) of the iPhone from the attestation data, and I'm pretty sure they already have the ability to disable an iPhone by ID number.
So they set up an apparatus where they can put any such a phone, buy them in bulk and resell them immediately after use for the same price they paid. Then most are never detected and even if a few of them are, Apple is only disabling the phone of the innocent third party buyer, likely outside of the return window, and thereby negatively impacting the resale value of their own brand.
Also, your premise was that this would be in every phone and then they're not buying late model iPhones, they're getting e-waste phones with dead batteries or cracked screens by the pallet for ~free to use once on their way to the scrapper.
> The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days.
You're assuming they publish their methods for Apple to patch instead of setting up the service to sign images without documenting exactly how they do it.
And also that every phone OEM cares to that extent, which they obviously don't.