Remix.run Logo
Retr0id 10 hours ago

It's also something I've been looking into. I've completely broken Google's implementation and I can sign any file as if it were real, more details will be public in the coming weeks.

Signatures are nice, but the contents of the image still matter. Any signs of manipulation should still be treated with suspicion, even if they're "legitimate" edits. The best way to avoid such signs is to have the bare minimum processing.

Gigachad 10 hours ago | parent [-]

The technology is fundamentally flawed. It's essentially DRM that relies on making the signing key hard to access.

Retr0id 10 hours ago | parent [-]

This is also my opinion. However, I still think it's worth raising the bar for plausible fakes. Minimising processing is another way to raise that bar (or at least, lower the floor). It's also not something you can do by default, because consumers demand image processing.