Earlier quoted context omitted.
Camera C2PA can never meaningfully confirm that a photo is authentic, it bears about as much credence as EXIF metadata. It's like saying the existence of DRM confirms that a movie hasn't been pirated.
C2PA cryptographically guarantees that the bytes came from a hardware/software signer and that the signed payload has not been modified since that signature was applied. So no, C2PA is not as easy to spoof as EXIF. And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.
What happens when someone extracts the signing key?
The presence of cryptography doesn't magically make something trustworthy.