News: 0184901770

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Slashdot Reader Builds a Photo-Verification App for iPhones (nerds.xyz)

(Saturday August 08, 2026 @11:52PM (EditorDavid) from the phoning-it-in dept.)


Long-time Slashdot reader [1]BrianFagioli is [2]announcing that he's released a new iPhone app that creates a cryptographic witness for photos without uploading the original image.

> The app hashes the file, signs the hash using a dedicated identity stored in Apple Keychain, and publishes the witness to Nostr relays while keeping the photo inside the app unless the user chooses to export it.

>

> Rather than trying to determine whether a scene was genuine, the app — named Veridenz — answers a narrower question, by verifying whether a photo file matches the one that was originally witnessed. Users do not need a Nostr account because the app creates its own signing identity, keeping private documentation separate from a public Nostr profile.

"The developer does not collect any data from this app," says [3]its page in Apple's iPhone store . The app's tagline is "Capture. Prove. Verify."



[1] https://www.slashdot.org/~BrianFagioli

[2] https://nerds.xyz/2026/08/veridenz-verify-photos-nostr/

[3] https://apps.apple.com/us/app/veridenz/id6796029293



"Free" isn't free (Score:2)

by Sebby ( 238625 )

even when the unlock is $1.99.

Re: (Score:2)

by ShanghaiBill ( 739463 )

To be fair, I don't see Brian saying it is free.

The freeness claim appears to have been added by Slashdot editors.

Re: (Score:3)

by EditorDavid ( 4512125 )

Apple listed it as "free" with "in-store purchases". But okay, I've updated the headline...

And the name is terrible. (Score:2)

by Mr. Dollar Ton ( 5495648 )

Weirdenz? WTF?11!! Should have called it "Fair Witness" or "Anne"!11!! .

No other way to sell it profitably to x.com.

But really, good job, it is an application domain with a future.

What kind of hash? (Score:3)

by anomaly256 ( 1243020 )

Is it a hash of the actual file, or a perceptual hashing of the image scene? The former would be quite fragile as so many things can alter an image file without altering the image per se, like compression or metadata stripping when uploading the file. Perceptual hashing would verify the authenticity of the scene itself and should survive file conversion and some amount of compression.

> I did not build Veridenz only for investigators or attorneys. I was thinking about ordinary situations where stronger documentation could become useful later. Contractors could document completed work, while landlords and tenants could record the condition of an apartment. Homeowners might capture insurance damage, delivery workers could document drop-offs, and online sellers could photograph valuable items before shipping them. Photographic& Digital Arts

This sounds like perceptual hashing would be more useful, specially since the use cases mentioned are unlikely to have proper chain of custody processes for evidence handling without accidentally altering image files during upload / exchange

Re: (Score:2)

by ShanghaiBill ( 739463 )

> Is it a hash of the actual file, or a perceptual hashing of the image scene?

It is a hash of the actual file.

Re: (Score:1)

by Narcocide ( 102829 )

This is the type of argument made by someone who has a vested interest in tampering with evidence. Of course it's fragile. That's the point.

Re: (Score:2)

by anomaly256 ( 1243020 )

Wow that's quite the leap you made there. No I have no vested interest in tampering with evidence. I'm just acutely aware that modern cloud platforms and web services do not keep original image files in-tact when you use them to exchange said images.

Your mental gymnastics are truly impressive though!

Re: (Score:1)

by Narcocide ( 102829 )

If the cloud hosting tampers with the metadata, or re-compresses the image, changes formats, "optimizes" it, then it's been tampered with, period.

Re: (Score:2)

by Aighearach ( 97333 )

> Of course it's fragile. That's the point.

No, you're not comprehending.

A fragile hash is almost useless. For example, you hash an image, then upload it somewhere. Somebody else saves the file, and without intentionally modifying it, uploads it to social media. Somebody checks the hash, and it's different, because all the social media sites re-encode the images to save bits.

Whereas, a more sophisticated perceptual hash would identify the plagiarism.

> This is the type of argument made by someone who has a vested interest in tampering with evidence.

If you're gonna be an asshole, it helps not to also be a moron at the same time.

7 digit ID counts as longtime? (Score:2)

by damn_registrars ( 1103043 )

Yes, I know my ID is also 7 digits long. I don't consider myself longtime, even having read and posted for over 20 years here.

The people who need this, don't need a iPhone app (Score:2)

by terraformer ( 617565 )

They need it embedded in their SLRs. This needs to somehow be able to integrate into the cameras people use for business purposes. Also into security cams, etc; But this is a start, I am not knocking it at all. It just needs to spread like wildfire because what's coming as AI/cgi gets better is going to make everyone question all reality.

Re: (Score:3)

by test321 ( 8891681 )

The C2PA (Coalition for Content Provenance and Authenticity) standard is integrated into all high-end cameras already, starting by Sony since 2021; and in smartphones there is the Pixel 10.

Re: (Score:2)

by Powercntrl ( 458442 )

Maybe I'm missing something, but it seems like this is just cloud storage for the md5sums of the images you've captured in the app. The signatures would be broken the moment you upload the images to pretty much everywhere that hosts images, these days.

It's pretty much useless unless you're absolutely sure you're sending the original image file via a method that avoids recompression. I guess there's a few niche use cases where this makes sense, but in most situations where you need to send photographic pro

Re: (Score:2)

by znrt ( 2424692 )

this is the equivalent of mailing your own work to yourself in a sealed envelope: you can eventually prove that at a given date a specific version of that work existed and was in your control. it's a cheap version of copyright registration, only useful to disprove a possible later claim of authorship, provided you're ready to go to court and have got the means to do so by then.

Just spam (Score:1)

by Anonymous Coward

Apparently it's not enough this guy spams his own website in the submissions all the time but now /. is promoting his (paid) app? WTF?

Re: (Score:2)

by Mr. Dollar Ton ( 5495648 )

Better than the incessant torrent of "AI" spam that we're getting "officially" from the "editors".

what is the point of this? (Score:2)

by snowshovelboy ( 242280 )

Its not going to work on screenshotted reshares, so it can't verify the authenticity of a photo that is shared with me. All it can do is help me remember if I edited my own photos, which you can do without a hash and a signing key.

The average Ph.D thesis is nothing but the transference of bones from
one graveyard to another.
-- J. Frank Dobie, "A Texan in England"