Comment by panarky
4 days ago
C2PA cryptographically guarantees that the bytes came from a hardware/software signer and that the signed payload has not been modified since that signature was applied.
So no, C2PA is not as easy to spoof as EXIF.
And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.
And what happens when someone tells the hardware signer to sign the bytes of a fake image?
What happens when someone extracts the signing key?
The presence of cryptography doesn't magically make something trustworthy.
Just because you can imagine how a thing could theoretically be broken does not make it broken.
It's like saying a prisoner has the same freedoms as everyone else because he could theoretically escape.
It's not a theory, I've done it.
Here's a cryptographically signed + timestamped photo of me winning the lottery: https://verify.contentauthenticity.org/?source=https%3A%2F%2...
Would you like to buy my winning ticket from me?
(Compare against winning numbers and draw timestamp at https://www.euro-millions.com/results/28-08-2026 )
5 replies →
We've been here before: https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...
It's not an apt analogy. The prisoner's every move is guarded; the camera is free in your hands to be disassembled.
This is not the case with current systems, but could future systems be designed to be tamper-evident in a way that makes it impractical to sign fake images or extract the signing key without leaving evidence on the device?
If that were the case, I can imagine a subscription service in which you get a camera for some specified period of time, and then return it to the company that sold it for them to verify the camera hasn't been tampered with. Then the company could publish a list of which keys (unique per camera) have been verified to not be tampered with. Maybe this wouldn't stop everyone, but now the person trying to fake images has to re-do the process every so often and I imagine it's more expensive to avoid leaving evidence.
This might be too impractical to work, and it would be bad for privacy, but maybe for some people the tradeoffs actually would be worth it, someday. For now, I assume there are much cheaper and easier ways to detect faked images, at least for expert humans.
I assume the signing key is different from each camera unit(not only model), so if a picture of you winning lottery in US capture by a camera sold to someone in Thailand, it would be extreme unlikely to be real.
Why would I use a camera from Thailand for my forgery?
[dead]