Remix.run Logo
C2PA Cameras Do Not Survive Contact with Reality(da.vidbuchanan.co.uk)
67 points by Retr0id 5 hours ago | 27 comments
randomblock1 2 hours ago | parent | next [-]

Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.

I don't think completely solving this sort of problem is even possible.

duskwuff 2 hours ago | parent | next [-]

And I'm not sure it's even useful to solve. The presence/absence of a digital signature will never be the deciding factor in whether people accept/reject an image as authentic.

timcobb 33 minutes ago | parent [-]

Yeah this is what I don't get why are people even spending time on this.

HWR_14 15 minutes ago | parent | next [-]

Is this picture real or AI is a real problem it is worth money to solve.

EA-3167 32 minutes ago | parent | prev [-]

A desperate attempt to preempt regulation.

akersten 29 minutes ago | parent [-]

A desperate attempt to establish their version of regulatory capture and not have to pay licensing fees to the other guy

jasonjayr 2 hours ago | parent | prev | next [-]

And in 2026, I don't think it's too big of a stretch to imagine that there are going to be people in power that can add + remove the metadata to whatever image they want, at will, to tell whatever story they want to create. Sadly.

gruez 28 minutes ago | parent [-]

There were similar fears about the webtrust CA system, but AFAIK there's no known incidents where a government strongarmed a CA into misissuing a MITM certificate, and then it was used in MITM attacks. The closest is some misissued certificates seemingly due to incompetence but weren't used in attacks.

yjftsjthsd-h an hour ago | parent | prev [-]

> Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.

The analog hole is alive and well:)

xyzsparetimexyz 19 minutes ago | parent | prev | next [-]

Surely the easiest thing to target is photos taken by journalists and modifications, down sampling etc when shared to twitter?

uqers 2 hours ago | parent | prev | next [-]

I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?

akersten 28 minutes ago | parent | next [-]

Well, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape.

At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg

12_throw_away an hour ago | parent | prev | next [-]

Actually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.

demibabs 2 hours ago | parent | prev [-]

Not any rooted device, it must be rooted via an exploit. Still pretty bad, though

ethagknight 3 hours ago | parent | prev | next [-]

I got a good laugh out of the "unblur to verify" first image. I dont know what I was expecting to see.

andrewflnr an hour ago | parent [-]

As far as AI-generated images go, that was a good one.

wisty 2 hours ago | parent | prev | next [-]

I can break it with zero skills. Tripod, camera, clear monitor in a dark room ... just take a real photo of a fake photo.

ipython 13 minutes ago | parent | next [-]

Wouldn’t the introduction of the lidar signals embedded in the photo (say used with apple’s faceid system) help here?

Terr_ an hour ago | parent | prev | next [-]

That might be detectable if they signed content contains focal-length metadata... but even then, some foresight and a collection of lenses would hide it.

jedbrooke an hour ago | parent | prev [-]

see also https://en.wikipedia.org/wiki/Telecine

jazzyjackson 3 hours ago | parent | prev | next [-]

I would be interested in a note on whether Sony / Leica / Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.

Legend2440 3 hours ago | parent | next [-]

My bet is they do considerably worse. Digital cameras are not designed with security in mind. Arbitrary code execution has been achieved on many DSLRs and there's even been open-source firmware projects for some.

Retr0id 3 hours ago | parent | prev | next [-]

Unfortunately they're a little outside of my tinkering budget, but if anyone wants to send me some I'll do my best to pwn them. Can't be any harder than a Google flagship, one would imagine.

I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.

EmbarrassedHelp an hour ago | parent | prev [-]

Why would someone paying for an expensive camera to damage the pixels of their images with "invisible" watermarks?

tescreal 2 hours ago | parent | prev | next [-]

I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.

tashian 2 hours ago | parent | prev [-]

I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.

And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).

gyomu 2 hours ago | parent [-]

Apple isn’t going to touch this with a 10-foot pole.

The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.

Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”