Live data from Hacker News

C2PA Cameras Do Not Survive Contact with Reality

da.vidbuchanan.co.uk

141–150 of 153 posts

Re: C2PA Cameras Do Not Survive Contact with Reality

#141
post #109
post #103

Earlier quoted context omitted.

Not when you also including poisoning attacks. I remember the original paper showing issues with even a couple percent of certain kinds of synthetic data too, not 100%.

What do you mean by poisoning attacks - stuff like Nightshade or Glaze? I was under the impression that those have largely failed to achieve their goals.

Those aren't poisoners. The are attempted protectors.

Re: C2PA Cameras Do Not Survive Contact with Reality

#142
post #31

Earlier quoted context omitted.

Is this picture real or AI is a real problem it is worth money to solve.

Why? An image should never be proof of anything, by itself.

What should be sufficient proof for you that AI wont fake trivially?

Re: C2PA Cameras Do Not Survive Contact with Reality

#143
post #31

Earlier quoted context omitted.

Is this picture real or AI is a real problem it is worth money to solve.

What I'm getting at is that metadata that claims that a photo is "real" won't necessarily convince people that it is, and the lack of that metadata doesn't mean anything at all. About the only real use I've seen for C2PA is to confirm that an image bearing that metadata is AI-generated - and that marker is easily lost through editing or retransmission.

I'm not saying it's an easy problem or that this is the right solution. I'm saying it's a valuable problem and so they are trying this solution.

Re: C2PA Cameras Do Not Survive Contact with Reality

#144
And never mind should someone want to edit¹ the image that comes off the camera. Now it cannot remain cryptographically verified, which means it's now in the pool of "dunno" images, where AI fakes can thrive alongside it.

¹in a non-AI, traditional way, that doesn't mislead the viewer and this entire footnote should reveal how subjective and intractable this problem is

Re: C2PA Cameras Do Not Survive Contact with Reality

#146
post #135
post #72

Earlier quoted context omitted.

Read the rest of my comment please. Is the single motivated malicious user able to do as much damage as all of the blocked attempts put together? Probably not, since if there's really all that much riding on it, people will point out it can be bypassed. Should we also abolish Pangram, because it's not 100% accurate? Someone might be convinced a text is not AI-generated when it actually is! We should get rid of it rat…

You're conflating the effectiveness of the mechanism with its systemic impact. * Pangram: Yes we should really be discouraging people from putting trust in tools like this because they can't be made totally reliable. * Antivirus: We should be building application environments with robust security models so that malicious software has a limited blast radius (like we do on mobile, like the Linux ecosystem is trying to…

Pangram: I'm not arguing against encouraging skepticism; I'm arguing that the technology is not useless. It's good for people to know the limitations, but it's still evidence.

Antivirus: "Actually, we should build this hypothetical better thing" is a cop-out.

HTTPS: C2PA is a strict upgrade from unsigned photographs, so it should be used wherever possible.

SSH: Totally appropriate, the entire point of the discussion is whether it's permissible to the user that they might be more secure.

Re: C2PA Cameras Do Not Survive Contact with Reality

#147
post #87
post #86

Earlier quoted context omitted.

It's funny how people always say something is "a tragedy at the individual level" when they mean "it's not my problem." It's even crazier to dismiss the value of a security feature, just because it might make people feel more secure. That's true of every security feature! Very little of the technology that the web is built on is proof against state actors. I like being contrarian as much as the next guy, but "Actuall…

I am repeating myself, but this is about systems, and not about people. It is however in the interest of the people to keep the systems running in an untainted way. As said, on the individual level it's a tragedy, but one that can be absorbed somewhat. Democracy itself failing otoh is kinda hard to absorb. C2PA is not "having security". It is "having an illusion of security for compliance and CYA reasons, that can be…

This is pascal's mugging. Democracy itself might fail! You're just inflating the stakes of your hypothetical bad outcome until it can overwhelm any positive upside.

Not to mention, democracy is under just as much or more threat from "banal" fake news created by citizens. People gonna people. They don't need the DPRK lying to them to fool themselves.

Re: C2PA Cameras Do Not Survive Contact with Reality

#148
post #86

Earlier quoted context omitted.

It's funny how people always say something is "a tragedy at the individual level" when they mean "it's not my problem." It's even crazier to dismiss the value of a security feature, just because it might make people feel more secure. That's true of every security feature! Very little of the technology that the web is built on is proof against state actors. I like being contrarian as much as the next guy, but "Actuall…

Yeah I think any additional security is good. At worst this could help in a lot of court cases. Someone presents photo evidence - it could be manipulated - it could be not. This happens already. Then someone produces an original higher quality version (like a raw photo - which I take even on my phone at all times now) and experts can verify that as the original. And I agree on state actors. If a major one is invested…

Exactly. It's just more information. It doesn't have to be 100% accurate in every case, to be useful.

Re: C2PA Cameras Do Not Survive Contact with Reality

#149
post #57

Earlier quoted context omitted.

I think it's useful even if it can be spoofed. Many people don't even bother to edit visible watermarks out of AI photos/videos. I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing. People are concerned that the technology will lend additional credence to the last 0.1%. But anyone who thinks about the technology for 2 minutes will…

> I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing. Everyone realizing that photos don't prove anything would defeat 100% of malicious users. I don't understand what people incorrectly trusting photos is supposed to achieve at this point, in your view.

Good luck with that. People are basically going to believe photos if they're aligned with what they already believe. They're not going to make strong decisions based on the C2PA tag. The idea that people will revise their entire worldview or submit to fraud based on a C2PA tag is typical HN thinking. People don't trust technology that much.

Re: C2PA Cameras Do Not Survive Contact with Reality

#150
post #139

Earlier quoted context omitted.

Why is this being framed as 2 types of users, lovable pranksters and fraudsters? There's a whole spectrum between these 2. Also I'd like to know if a "joke" is likely fake.

I don't suspect there is a uniform spectrum between those two. I think this is something that's going to be clinal, which we see in a lot of other comparable social contexts. The number of people actually willing to cross a moral threshold into outright crime is relatively small, but those are precisely the people who cause the most damage when they get away with their behavior. Bur I don't even really think that's r…

Your idea of a criminal seems to be hypercompetent and think of everything. These do exist, but most criminals are not very smart. Smart, dedicated, technical people can typically make more money legally.

Your argument applies to any imperfect security technology -- aka practically all of them.

Post reply on HN