← Back to context

Comment by whywhywhywhy

15 hours ago

>a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake

you don't need to do that just photograph a screen.

This seems close to worthless in "identifying real photos vs AI" for someone actually wanting to do something bad with an AI image, although probably very useful at identifying which phone took a photo when ("the root of trust stays inside Apple's Private Cloud Compute") seen as it's not an entirely local solution a bad actor government could use their powers to completely abuse this.

its conflicting desiderata: a videographer doesn't want to constantly power a device to maintain provable continuity, but screen attacks necessitate such a scheme

a continuous stream of video from factory to customer to observation should prevent screen attacks, if there is a trustworthy framework for processing and checking the absence of screen slide-ins etc.

if geolocation data can be captured in the same signature, that would be a good enough approximation for most relevant cases I think.

  • GNSS signals can be relatively easily faked because the original signals are very weak so overpowering them doesn't require much broadcast power.

    • Jamming them is easy, replaying them so as to trick unacquainted receivers is easy, but "faking" a network of signals so as to precisely control present a specific location is not easy or feasible.

      "Overpowering" (as to jam) inherently means detectable, these signals are arriving below the noise floor anyway. And if you aren't overpowering, the original signals will leak through. Also, depending on the sophistication of the receiver, your ability to present an implausibly different location may not exist at all (AGPS.)