Top
Best
New

Posted by Retr0id 11 hours ago

C2PA Cameras Do Not Survive Contact with Reality(www.da.vidbuchanan.co.uk)
112 points | 64 commentspage 2
jazzyjackson 9 hours ago|
I would be interested in a note on whether Sony / Leica / Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.
Legend2440 9 hours ago||
My bet is they do considerably worse. Digital cameras are not designed with security in mind. Arbitrary code execution has been achieved on many DSLRs and there's even been open-source firmware projects for some.
Retr0id 9 hours ago|||
Unfortunately they're a little outside of my tinkering budget, but if anyone wants to send me some I'll do my best to pwn them. Can't be any harder than a Google flagship, one would imagine.

I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.

kiddico 6 hours ago||
Could you make use of a Sony a6000?
EmbarrassedHelp 7 hours ago||
Why would someone paying for an expensive camera to damage the pixels of their images with "invisible" watermarks?
MadnessASAP 3 hours ago||
The signature doesn't touch the image data in any way. It's just a piece of metadata attached to the image, like any other metadata tag.
xyzsparetimexyz 6 hours ago||
Surely the easiest thing to target is photos taken by journalists and modifications, down sampling etc when shared to twitter?
tashian 8 hours ago||
I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.

And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).

gyomu 8 hours ago||
Apple isn’t going to touch this with a 10-foot pole.

The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.

Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”

Legend2440 5 hours ago|||
Apple is working on their own system, which is expected to launch with IOS 27: https://www.macrumors.com/2026/08/10/ios-27-apple-reference-...

>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.

gyomu 55 minutes ago||
Yeah, it might never ship, or it might not ship as described, or that might be exactly what they do - I love being wrong.

If it does ship like that, it’s hard to not imagine a situation as I described earlier - an “iPhone Reference Image” being used to propagate fake news, at which point the credibility of the feature goes to 0 (and Apple’s takes a severe hit).

Wait & see.

tescreal 8 hours ago||
I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.
hydraterms 7 hours ago||
[flagged]
SecuriLayer 7 hours ago||
[flagged]
fenestella 5 hours ago||
[flagged]
Ozzie-D 5 hours ago|
[flagged]