It would be great if they could use the LiDAR scanner to sign a depth map of the scene in front of the camera. It would show if you photographed a flat image.
The sensor already uses phase detection autofocus. You can create a depth map out of it. iPhone X used its dual cameras and that phase data for depth maps.
How? Is this for every image taken, or does one need to take a second photo? Or is it "in theory phase detection hardware would let you make a depth map"
The sensor has special pixels which can detect phase differences in incoming light. Camera uses these pixels (aka embedded detectors on the image sensor) to be able to focus where you want. This is same from phones to professional cameras.
(DSLR cameras have independent phase detection arrays. This is why the mirror has a small mirror behind. To illuminate that section).
Lenses are tuned. They know how distant the thing they are focusing on, also photos' EXIF generally carries the focus point information. Side note: Apple Aperture used to be able to show where you focused with that info. Still no app does this. I'm still mad that we don't have Aperture anymore. Anyway...
So, if you collect this phasing information alongside the photo which you're taking, you are capturing the depth map of the photo. Its resolution will be lower, but not lower enough to be useless.
For example, Sony (and most probably all other big camera manufacturers) cameras use this phasing data throughout sensor in real-time for following moving subjects to keep the focus on them by predicting where they are going.
So, there's no "in theory". The phasing data is the depth map. Otherwise your camera can't focus on anything. It's there to focus, and it's done by reading the phasing data and knowing where to go by how much.
All fast AF systems are PDAF. When light is too low, then it's CDAF, which does way slower, without using any phase/depth data.
Images that are meant to be 2d (E.g. a photo of something on paper) isn't going to look 3d. I guess this approach will just have to let anything flat through?
"I took a real photo of this image printed on paper" seems possible to falsify, yeah, but that doesn't seem too surprising to me, given that anyone with a printer can print literally any possible image.
How would that work? I thought the premise here is that you can fool the apple camera by taking a (very carefully aligned) picture of a still image (printed out).
A depth map from the apple camera (again, signed) would show that the entire image had the same distance from the camera.
The photos are cryptographically signed in the apple image pipeline so it's not as simple as just AI generating something. That said, I can't see how this is any different to all the other times we have embedded crypto keys in consumer hardware where eventually someone finds a way to extract the key and the whole thing is busted open.
I think there's a chain of trust. The sensor signs raws, and the private cloud takes signed raws, does minimal processing so they're at least coherent, and re signs that output (maybe even including the original signed raw as well in the image file).
How would the server know that the request is coming from a real iPhone?
This is a pretty standard application of trusted computing and can be done entirely on the iPhone. A server would only possibly be needed for anonymization (while retaining key revocation capabilities if a key does end up leaking), but there are serverless ways to do even that (TPMs have supported these for a while now).
It wouldn't, but you could validate that a particular picture was created at a particular time, and had not changed, for example, especially with metadata that you may not want to share but that establishes certain parameters like gps coordinates. A lock, rather than an end-to-end pixel signature, which shows what was contemporaneous rather than exact provenance. If an event happened on day 0000-00-00 00:00:00am, but your photo was taken at some other time, it casts doubt.
I think a big part of validation for things like these are just "could it have been modified since Z event happened", because Z was not something people paid attention to before.
That's just a timestamping service then, not a content provenance/authentication scheme. Timestamping has been a solved problem for years; certificate authorities offer this, or you could just throw a hash onto any sufficiently trusted blockchain.
Nothing prevents anyone from opportunistically pre-generating and timestamping millions of permutations of fake kompromat and then selectively revealing the one that turns out to be useful after the fact.
You could charge per attestation, but the economics of that don't look great; you could demand publication of the image itself before attestation, but that would obviously not fly for most use cases out of privacy concerns.
That's a good point, You might still be able to trick the cloud to sign your photos, but that's something they could patch in updates without losing control of the key. They could have the server only sign photos taken on the latest ios version.
And honestly you could have a similar antitampering oracle that was at least obscured, in terms of "we've detected tampering but won't tell you how or why", which is frustrating but I have to imagine that 99.9%+ of images are clean.
... don't make it so shallow then. Perfectly possible in a consumer-friendly 3D printer for a face or even human body if you have lots of time for the prints.
You’re well on the way to 1:1 replicas at this point. Next you’ll need to match the thermal signature and the exact weather in the sky for the time at that location.
An important distinction but I have taken pics of pics, and sometimes its hard to tell I didn't take it directly. So now, its hard to tell I didn't directly take the photo AND its got the stamp of approval.
People have constructed video walls so high resolution they can film TV series in front of them and to an audience it's indistinguishable from a real set. It's extremely cost-effective for things like space fantasy that needs lots of exotic-looking backdrops, apparently.
It may not be in reach for you and I - but within reach of anyone with the budget to run a 'bot farm'
The high resolution video wall is quite simple. The hard part and why this has not been done earlier is that for filming, they had to synchronize the rendered background with the movement of the camera.
Movement is solved by tracking the camera's position and projecting the background from there.
Proof of captured image with hardware-based-attestation can be increased by adding extra information besides the RGB channels, like depth mapping (which a projected screen wouldn't be able to fake), and eventually light field recording (plenoptic imaging, e.g. Lytro).
also no, even in the high rez video walls its still possible to tell. maybe to an "audience" no but there are lots of fundamental flaws with video walls that make them not the same as filming it for real. all of those flaws show up in the final image and could be detected.
things like color rendering, sharpness, screen door/morie, motion blur, and yup even good ole depth queues in the lens system all show up as artifacts.
case in point, outside of a few specific niche cases like the mandalorian, that virtual production video wall thing is not actually being used all that much because of the amount of post shoot cleanup required to fix all those issues, it wasnt actually that much cheaper and its not really better either. especially when you factor in how hard it is to shoot that way.
> things like color rendering, sharpness, screen door/morie, motion blur, and yup even good ole depth queues in the lens system all show up as artifacts.
Pre-AI fake videos sidestep this sort of issue by lowering the video quality.
Add some motion blur, some camera shake, some poor lighting, the camera being slightly out of focus, and make the video 720p instead of 4k.
The credibility comes from who took the photo. The next logical and easy step is for this metadata to flow to the user agent. I'll know that it was taken by a legit journalist photographer. And id not, I can have my user agent make it fuzzy or replaced with
a kitten photo.
I think this is where we are headed. This feature seems useless on it's own since someone will eventually find a way to extract the key from the iphone and sign any image. But if they could make it so every iphone uses it's own key and the photos show "Taken by xyz" and it's linked to their icloud or identity somehow. That way images shared around will still be able to be linked to a source that you can choose to trust and the viewer can know it wasn't modified from what that person shot.
Then we might move to an age where photos which were not signed by someone will be treated as fake.
You may have forgotten that the world is driven by screenshots, and so a screenshot of a picture with the `(X) Verified by Apple to be Joe Schmoe` tacked on will be just as good as real verification for a lot of people.
What we need is almost something like the classic "press C+A+D to log in" or the idea of "above the browser pane"... something an image cannot show you unless it's legit. Perhaps a personal thumbprint icon that is different for each viewer, so you know its your device telling you that something is real and not just some mock fake thing?
I don't think we'll treat them as fake but they would probably undergo more scrutiny - perhaps in a crowd-sourced manner that provides an overall score of probable legitimacy.
Multiple good things would happen without prop 13:
People would move more instead of being locked in to a low effective property tax.
The tax burden would be much fairer: instead of the police and schools being funded by newcomers, everyone would be contributing their fair share to fund the city, instead of the longest tenure residents mooching off the rest of us.
Unproductive use of land would be discouraged. If a tract became highly desirable, it would be expensive to let it sit in an unproductive form
Cities could raise taxes as high as their residents wanted them to be, instead of being limited by the opinions of non-residents. Some people want to have better funded police and schools, and local government would actually be allowed to deliver that. Citizens who didnt want to live in expensive cities could vote with their feet to cheaper towns.
"People would move more instead of being locked in to a low effective property tax." - this just means that older and retired people would get kicked out of stable living situations, driven by property tax assessments which are often driven by real estate market boom/bust cycles. And housing prices would be just as high as with prop 13.
The bad part about prop 13, is that it never should have applied to anything other than primary residences of people. Having it apply to rental & commercial properties is what warps the market.
Cities should be cutting their police budgets - most small towns have nearly 50% of the budgets tied up in police. All while there has been a multi-decade decrease in crime.
I don't understand why you think old people would have to move. They have the ability to access the equity in their home at any time through HELOCs or mortgages. If they own a house that shoots up 1M in value, they have just had a massive windfall that they can access through financing to pay the taxes associated with that windfall.
Old people seem to be surviving just fine in areas where property tax is based on current market value? It sucks to move, but luckily they have an extremely valuable property to sell
Young people seem to be surviving just fine in areas where the market value is lower. Sucks to not live in the heart of the city but luckily they have their entire lives ahead of them to accumulate the wealth required.
Do you think cities would make the taxes fairer (e.g. spread them out over more residents) or just raise taxes on the these previously protected properties?
My money is on the latter. Nobody is getting a tax cut if Prop 13 is repealed. Everybody's taxes will just continue to go up.
... which is why it was, and still is, common economic knowledge that the government must control marketplaces. Meaning the physical areas where trading is taking place.
We've been through this rodeo before you know. Private ownership of markets, with the obvious result monopoly abuses. Hell we've had private money and that was a total disaster too. And now we have VISA as opposed to government controlled payments.
But then people stopped caring about that. With abuse upon abuse the result. Because it's not like this result, that only by buying a prominent position on a marketplace you can have success as a seller is only the case online. This is very much true in meatspace as well.
And now almost everything you can buy is effectively through a privately owned (semi-)monopoly rather than a marketplace. From supermarkets to app stores.
Addendum: and then governments must NOT let anyone, not even other governments, force "whoever pays most" rules (like the EU is forcing through in Europe)
100% not. To equate fun to play to people buying the game is 100% not how you should say making more money is more people buying the game. Money is money. If the game is mediocre but it is fun enough, it can get more money than a game that is more fun but doesn't have as many opportunities to spend.
This is why things like dark patterns exist that try to get you to spend money through FOMO and other mechanisms like loot boxes.
You can argue that all of these things are people having "fun," but I wouldn't define that as fun to play.
Finally, none of these necessitate people buying the game, but rather spending money in the game. Usually, it's free games where people buy a secondary currency to spend on virtual items. Mobile apps, for example, are huge with this.
So the real answer to your question on multiple grounds is no.
Edit: Now, I will give you that people do have to make a choice, but that's like saying that gambling addiction is not real and it's a choice, or drug addiction is real and it's a choice. The reason for alcoholism and Alcoholics Anonymous is bogus because it's just a choice, but it would be dangerous to classify it as just a choice.
Not necessarily. Some of the most profitable games out there are not very fun to play, but they have their monetization strategy nailed down.
People laughed at Blizzard when it came out with the mobile game Diablo Immortal, and I've never heard it listed among Blizzard's best games, but Diablo Immortal was one of, if not the, best earners the company ever made.
Anyone know the specifics of how this works under the hood? I assumed the people over at Twitter/X would aggressively block systems like this from working. Are they doing something creative to get around that?
Burner accounts are dirt, dirt cheap. I have several hundred I rotate out. I’m afraid to mention the library I’m using in case it’s not in their cross hairs, but it makes scraping trivial. At least at the scale I’m scraping I don’t even need a proxy. My residential up is enough to keep the blocks away.
On most of these sites you can just copy the requests the browser makes. There's a walls and ladders game going on, but all the easy to implement walls aren't very high so most sites don't bother building the tallest one possible.
You can start by making a burner account and viewing some pages in a browser and watching the developer network tab. Either you'll see some dynamic JSON request that fetches the main page content, or it'll be in the initial page request. In either case you can copy that request and parse it. If it's in the initial page then it's in HTML so parse it with BeautifulSoup or similar. A minority of sites are using TLS fingerprinting, so try curl-impersonate if plain curl doesn't work.
At least in Firefox I suggest right click "copy as cURL [command]" and then delete parts of the command to see what's actually needed to get the data, or copy the whole exact thing if you're worried about getting fingerprinted based on the parts you deleted.
There's certainly some kind of auth cookie or token. How long does it last? Maybe 15 minutes, an hour, a day, forever? If it's not forever there's a way to refresh it so look through the network requests again, or maybe the network requests when you log in.
If you get rate limited it's probably by IP address and you can try a few things. Rebooting your router to change IP? If you have IPv6 you can change your address arbitrarily within a /64 and if the site is really dumb it will consider that a new IP, but most know about that. If your ISP gives you a /48 or /56 you can change subnet. You can try running on cloudflare workers or Amazon lambda, which have big IP pools that continually churn. Some sites that use cloudflare may exempt all of cloudflare from rate limiting and you may greatly benefit from running on a cloudflare worker. You can try a mobile connection that may use CGNAT, forcing the site to choose between unblocking you or blocking your carrier. If all else fails, residential proxy access is either very cheap or very expensive to buy, depending on how much data you need to move.
I've found that working in a style similar to this is very useful for managing multiple threads of work at the same time.
I use virtual desktops, where each desktop contains a single thing that I am working on, and everything related to it. Then any good window manager can switch between them quickly and even give you a spatial sense of where you are. I organize them as a priority stack, so the topmost priority is in top position and then it goes downward from there
There's a lot that this "campus" product does that isn't present in such a set up (multi user, zooming, etc...) but virtual desktops give you a lot of the benefit and come built in to most of our operating systems
> On the other hand we don't give technology the same pass we give to humans, meaning that we don't tolerate machine incidents the same way we tolerate human ones.
I completely disagree with this. I don't "give a pass" to humans killing other humans with a car.
Every year that skeptics delay adoption of autonomous driving is another year where tens of thousands of deaths could be prevented.
Tesla, in particular, has given those skeptics so much ammunition to be mad at. The delay isn't purely due to luddites but also somewhat driven by prior obvious bad actions by self-driving car companies.
It's also likely that if a switchover is aggressively pursued it'll cause a massive social backlash and likely evolve into a culture war issue.
I'm still waiting to see independent analysis of the data. Autonomous driving has the potential to be better, but without data I have no idea if it is really better, or even worse.
I've seen lots of people talking, but when I dig in I quickly discover they either don't have access to the full data; or they have reason to be biased and so cannot be trusted. There are many ways to "lie with statistics". You don't even have to be that smart to make some educated guesses. (for starters all drivers include drunk drivers who are a tiny minority and yet make up for an outsized share of issues. As someone who doesn't drink at all their statistics should not compare to me personally)
The folly is thinking that getting hiring right is the solution at all.
As has been pointed out a) leaders matter, b) the difference in impact between great and mediocre/poor leadership is massive, c) even if you hire a great leader you can get poor results.
It follows then that spending more effort to find just the right person is not enough. You must also examine your overall organizational culture, your investors culture, your unspoken assumptions about the goals of your organization, etc etc.
And yes great leaders do all of this - of course - it becomes obvious upon reading my comment. But the point is great leaders doing this is not enough. The organization must be on the same page. You can lead a horse to water etc etc. And yes the leader can "Re-organize" but at that point you may find yourself faced with throwing the baby out with the bathwater unavoidably.
Leaders are necessary. And hiring is hard. But there is no one golden calf like "hire the perfect leader" that will solve a problem.
As with most things worth doing: you have to do it. Doing it is hard. And you might still not get the results you want.
They spend 18 rounds over six months vetting a developer with silly puzzles that must be solved from memory, with an audience. It's about as far from the job as possible.
This happened by trying to find capable people that didn't come to you through nepotism and paper mills and such.
The strange thing is that nobody has developed a hiring battery for the naturally hyperconfident employee you met through the grapevine, who costs you millions, and as often as not, irreparably damages the company.
Sure, where would be biological lifeforms today if hadn’t been driven by some visionary leaders. Ooops? But I mean, now that humanity provide great leaders, biosphere is thriving like never before. Reooops?
Speaking of Tor, there is currently a massive and great Bundle for Scalzi books over at Humble by Tor. Just bought it, even if I already own a few of those, because the 4 books I don't yet have would be more expensive to buy separately.
If you’re not redistributing ebooks you bought, it’s hard to imagine what legal claim someone could make against you, and even harder to establish the ethics of that claim.
Breaking any kind of DRM (or writing, distributing, or using software that does so) violates section 1201 of the DMCA[1]. The maximum penalty for a violation is $500k and up to 5 years in prison. There are some token exemptions but none would apply in this case.
Ethically it's all completely bunk, but more people should be aware how insane modern copyright laws are so that we can reform them. And this is not new, folks like the FSF and EFF protested the signing of the 1996 WIPO Treaty too.
What are you suggesting exactly? That the maker of this hardware should do whatever it takes so that there is some official Kindle app like on Android?
I want to access my books on random devices too, which is why I never bought a frikkn Kindle book.
I did buy a bunch of Audible books, starting way back when there was nothing else, and I knew the deal when buying, so I simply went through the grief on my end to strip them (easy these days) and don't care about the legality (or rather, am willing to fight and defend the legality).
But buying something from Amazon and then complaining to anyone but Amazon that you want something Amazon doesn't provide or even allow, I don't get that.
This wish for this thing that you want should be directed at Amazon, and if you recognize that that would be pointless, well, correct, that's why you shouldn't buy a book from Amazon in the first place.
Or you should decide you don't recognize any legal conflict and help write software to uncrappify your property.
This issue isn't specific to the Kindle, you can go and buy books on Apple or Google or Kobo or Barnes and Noble and its the same story.
Many books can only be bought this way. Publishers don't want to sell books through platforms that don't have DRM, because they are scared of piracy.
It would be great if we could have open ebook reader software that could display these books.
eReaders like the Xteink X4 are beautiful but lots of books are impossible to legally read on it. Yes, I know that I can break the DRM, but I think its sad that this is the only path for legitimate purchases.
> It would be great if we could have open ebook reader software that could display these books.
I agree, but it also would be great if DRM wouldn't be use to restrict your device choice. The only reason Kindle DRM "works well" is because Amazon is basically the biggest eBook store in the world and Kindle are the most popular brand. But you can't buy a book in Kindle and use it in a Kobo device, for example.
DRM would be slightly more acceptable if the companies themselves didn't use it to also enforce their device lock-in (e.g., license their DRM to other companies), and so we are in the current situation where there is device lock-in and you are required to buy a eReader from Amazon if you want to read Kindle books, or at minimum buy one of those Android eReader devices since you can install Kindle app on it (but in this case you have all the other issues that you get by running Android in a eReader).
One man's offensive penetration tool is another mans defensive tool. In the recent HuggingFace/OpenAI incident the safety controls stood in the way of the defenders, not the attackers:
Apparently, the attacker in the Hugging Face case was reported to be an internal OpenAI model trying to break into HF and steal the answers to cybersecurity benchmarks: https://openai.com/index/hugging-face-model-evaluation-secur... It really doesn't matter what restrictions are placed on public use of models if the attacking models are internal models at the AI labs themselves.
So if the AI labs are literally running rogue models breaking into other organizations' servers, then yes, I am OK with those organizations self-hosting Chinese models for defensive use.
The issue is that models are not well-controlled and are increasingly powerful.
Offense/defense/Chinese/American/OAI/HuggingFace – none of it matters. What matters is introducing highly capable intelligences that we - quite demonstrably – do not have effective positive control over.
reply