Comment by advisedwang

4 days ago

The goal of C2PA is that cameras will start to emit C2PA credentials. You will then have 3 situations:

* C2PA confirms a photo is authentic

* C2PA confirms a photo is AI generated

* C2PA missing, you don't know.

I reckon we will only see "C2PA missing" being treated as suspect in select situations (perhaps Reuters will require C2PA from their photojournalists, for example)

Camera C2PA can never meaningfully confirm that a photo is authentic, it bears about as much credence as EXIF metadata. It's like saying the existence of DRM confirms that a movie hasn't been pirated.

  • C2PA cryptographically guarantees that the bytes came from a hardware/software signer and that the signed payload has not been modified since that signature was applied.

    So no, C2PA is not as easy to spoof as EXIF.

    And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.

    • And what happens when someone tells the hardware signer to sign the bytes of a fake image?

      What happens when someone extracts the signing key?

      The presence of cryptography doesn't magically make something trustworthy.

      14 replies →