← Back to context

Comment by Retr0id

4 days ago

And what happens when someone tells the hardware signer to sign the bytes of a fake image?

What happens when someone extracts the signing key?

The presence of cryptography doesn't magically make something trustworthy.

Just because you can imagine how a thing could theoretically be broken does not make it broken.

It's like saying a prisoner has the same freedoms as everyone else because he could theoretically escape.

This is not the case with current systems, but could future systems be designed to be tamper-evident in a way that makes it impractical to sign fake images or extract the signing key without leaving evidence on the device?

If that were the case, I can imagine a subscription service in which you get a camera for some specified period of time, and then return it to the company that sold it for them to verify the camera hasn't been tampered with. Then the company could publish a list of which keys (unique per camera) have been verified to not be tampered with. Maybe this wouldn't stop everyone, but now the person trying to fake images has to re-do the process every so often and I imagine it's more expensive to avoid leaving evidence.

This might be too impractical to work, and it would be bad for privacy, but maybe for some people the tradeoffs actually would be worth it, someday. For now, I assume there are much cheaper and easier ways to detect faked images, at least for expert humans.

I assume the signing key is different from each camera unit(not only model), so if a picture of you winning lottery in US capture by a camera sold to someone in Thailand, it would be extreme unlikely to be real.