I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
C2PA Cameras Do Not Survive Contact with Reality
21–30 of 154 posts
Re: C2PA Cameras Do Not Survive Contact with Reality
#22Re: C2PA Cameras Do Not Survive Contact with Reality
#23I got a good laugh out of the "unblur to verify" first image. I dont know what I was expecting to see.
Re: C2PA Cameras Do Not Survive Contact with Reality
#24Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that. I don't think completely solving this sort of problem is even possible.
And I'm not sure it's even useful to solve. The presence/absence of a digital signature will never be the deciding factor in whether people accept/reject an image as authentic.
Re: C2PA Cameras Do Not Survive Contact with Reality
#25Earlier quoted context omitted.
And I'm not sure it's even useful to solve. The presence/absence of a digital signature will never be the deciding factor in whether people accept/reject an image as authentic.
Yeah this is what I don't get why are people even spending time on this.
Re: C2PA Cameras Do Not Survive Contact with Reality
#26Re: C2PA Cameras Do Not Survive Contact with Reality
#27I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg
Re: C2PA Cameras Do Not Survive Contact with Reality
#28Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that. I don't think completely solving this sort of problem is even possible.
And in 2026, I don't think it's too big of a stretch to imagine that there are going to be people in power that can add + remove the metadata to whatever image they want, at will, to tell whatever story they want to create. Sadly.
Re: C2PA Cameras Do Not Survive Contact with Reality
#29I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP. And, Apple could choose to integrate a LiDAR depth m…
Apple isn’t going to touch this with a 10-foot pole. The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push. Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a re…