Live data from Hacker News

C2PA Cameras Do Not Survive Contact with Reality

da.vidbuchanan.co.uk

151–152 of 152 posts

Re: C2PA Cameras Do Not Survive Contact with Reality

#151
post #57

Aside from the fact that this was obviously never viable and the entire problem is clearly unsolvable if you sit down and really probe it for fifteen minutes, what I find most frustrating about this is that the false promise of preserving photos as reliable evidence is actively harmful. You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to cas…

I think it's useful even if it can be spoofed. Many people don't even bother to edit visible watermarks out of AI photos/videos. I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing. People are concerned that the technology will lend additional credence to the last 0.1%. But anyone who thinks about the technology for 2 minutes will…

Almost everyone seems to be overindexing on this second-order effect. But second-order effects don't typically negate or surpass the original effect, because they depend on the original effect.

Re: C2PA Cameras Do Not Survive Contact with Reality

#152
post #83
post #81

I'd always thought the usefulness of C2PA was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery. The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?

> was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery. But that is also not the case, because whatever keys are in those devices may have been duplicated in the factory or somewhere along the supply chain. Or the stuff is cloud connected and an exploit can be executed via that. Or,…

Well, you can say the same thing about HSMs, or the CPU in your device.

If there's no trust afforded to the device holder, or it's manufacturer, there's no trust in anything.

Always to degrees, and never fully, but trust can still be had.

Post reply on HN