Comment by arjie

7 hours ago

Presumably the OP is proposing something like a TPM attached to the image sensor that signs the sensor output or something like that. You can’t sign it because you can’t get the key out. The key could be per-camera and be a published list.

I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.

Please note: A well-funded organization, like a government, can derive the keys from the TPM hardware using an electron microscope.

  • Also note that there are plenty of viable attack methods that don't even require key extraction, such as asking the TPM to sign arbitrary data.

  • That's assuming they don't just have a backdoor inserted expressly for this purpose. Now only the rich or powerful can produce an "authentic" recording of an event and the same system can be used to hunt down whistleblowers and political enemies by looking up who bought the camera.