Andy Beach's Engines of Change

Andy Beach's Engines of Change

The Revocation List

Legitimacy, Part I

Andy Beach's avatar
Andy Beach
Sep 27, 2026
∙ Paid

The Inheritance Shift argued that context has to survive the pipeline, because a media system that transports files without carrying what those files mean will keep reconstructing meaning downstream, and invariably it will be done badly and at rising cost. Once context persists, the question changes shape, and in The Human Layer I took it up. If infrastructure can carry meaning forward on its own, the people who used to carry it sit somewhere else in the process. Once the people have moved, control follows the layer where the context now lives, which is what The Control Layer traced. Rights, identity, provenance, governance. Not the model, which commoditizes, but the upper most substrate underneath it, which accumulates. My Persistence series came out of watching those arrangements settle, and found that systems carry decisions forward past the conditions that produced them, so what persists is not always what anyone would choose again.

Four arcs with one progression, and a thing none of them examined. Each assumed a decision point and then described the machinery around it. Whether a provenance claim holds. Whether a credential counts. Whether a record is authoritative enough to act on. The work kept arriving at the moment of determination and kept turning to look at the pipes instead. That was the right order to work in, and it has now gone as far as it can.

The closing piece of The Control Layer put the gap directly. The layer can operate without legitimacy, but it cannot be governed without it, and no institution currently constituted is supplying what is missing. That was where the argument stopped.

So in this arc we take up the deferred question. The premise is that technical systems are beginning to distribute decision-making power. A system that determines whether something counts is exercising power over everyone who has to work with that determination, whether or not anyone involved thinks of it in those terms. Establishing that such a system works, that the engineering is sound, the cryptography current, the privacy properties real, settles a question about the viability of the system. It does not settle whether its determinations should be accepted, by whom, and with what recourse when they are wrong. Those are two questions, and the second one is what this arc will explore.

The hypothesis I want to test is that a system which makes decisions people have to live with, and never says how those decisions can be questioned, uses up their willingness to go along with it. That claim needs evidence this piece does not have, and later installments will either find it or not.

Part I has a narrower job. It shows that the question is now attached to a shipping product rather than to a scenario, and stays exact about what that product does and does not establish.

Which brings us to a camera.

On September 15, Apple published the design of Apple Reference Image, an opt-in camera mode on the main sensor of iPhone 18 Pro and iPhone 18 Pro Max. The system signs pixel data inside the sensor at the moment of capture, develops the resulting negative inside Private Cloud Compute (PCC), and returns an image carrying a post-quantum signature. It is not an implementation of C2PA. Apple’s post argues that attaching provenance after capture leaves a chain that can break at any editing step, and builds a separate path instead, one Apple operates end to end. It is a serious piece of work and I will get to why. The part I want to focus on is a short passage in the middle of Apple’s writeup, describing what happens when the system decides an image is not what it appears to be.

What the system issues, and what it takes back

Apple’s account describes a revocation system that can revoke individual photos as well as all photos from a specific sensor. During development, PCC computes a confidence score assessing whether the image has the physical characteristics expected of raw output from Apple’s sensors. Before the developed image is signed, PCC sends the photo GUID, the raw hash, the confidence score, and the sensor ID to a companion service, which records them, updates a running confidence score associated with that sensor, and confirms the sensor does not appear on a revocation list. If a low-scoring sensor is revoked, PCC stops signing its images. Devices fetch updated revocation lists on a regular cadence, and a client checks the list before it displays any reference image. Apple states that if a device is later found to be compromised, its images can be revoked and flagged retroactively.

Three different things can happen to a photograph here, and they do not mean the same thing.

The first case is an image with no credential at all, which follows from shooting in the ordinary mode. That absence describes how the photograph was taken and reflects nothing the system concluded about it. The second is a capture that goes through Reference mode and comes back without one, which can follow from a verification step or from the sensor already sitting on the revocation list. The third is a credential that was issued and later withdrawn, so the status changes underneath a viewer who may have already relied on the image.

Only the third involves taking back something the system already granted, and that case is the subject here.

User's avatar

Continue reading this post for free, courtesy of Andy Beach.

Or purchase a paid subscription.
© 2026 Andy Beach · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture