Aside from the fact that this was obviously never viable and the entire problem is clearly unsolvable if you sit down and really probe it for fifteen minutes, what I find most frustrating about this is that the false promise of preserving photos as reliable evidence is actively harmful.
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
indutny 41 minutes ago [-]
In my opinion, the benefits for end users are rather minimal since I doubt an average person would ever be checking C2PA provenance data, but there is a commercial incentive for Google and others to promote C2PA, since it makes preparing training material for Machine Learning significantly easier, and perhaps as a smaller benefit justifies hardware attestation that locks users down into proprietary OSes.
qurren 1 hours ago [-]
Are we entering a world where if I took a picture with a film camera and scanned it, it would be rejected as not real?
This is ridiculous.
CapitalistCartr 55 minutes ago [-]
It's not a matter of "rejected as not real", it's "There's no way to know if this is real or not".
lelandfe 20 minutes ago [-]
The defendant submitted a remarkably high quality video of you saying you generated it with Nano Banana.
LiamPowell 18 minutes ago [-]
I always got the impression that C2PA is a way to say "this photo came from the BBC (for example) and they've only signed it because they've verified the supplied edit chain". It's always been obvious that one could point a camera at a screen, I don't think anyone involved with C2PA has claimed otherwise.
It seems like there's a big disconnect between what C2PA says it's for and what certain journalists think it's for.
trentor 1 hours ago [-]
It's compliance for advertising. Your client doesn't want AI in their project you show them the audit trail and if it turns out to be faked you point to the supplier who faked it. Our agency signed a insurance not only because of clients who don't want to use AI in their artwork but also because of the EU AI act. They c2pa to get their money back from a cheating supplier if they are not compliant with the AI act.
uqers 5 hours ago [-]
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
12_throw_away 4 hours ago [-]
Actually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.
genxy 1 hours ago [-]
Wait a minute. I think you might have forgotten a /s, I can spot this kinda thing.
akersten 3 hours ago [-]
Well, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape.
Not any rooted device, it must be rooted via an exploit. Still pretty bad, though
randomblock1 5 hours ago [-]
Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.
I don't think completely solving this sort of problem is even possible.
duskwuff 5 hours ago [-]
And I'm not sure it's even useful to solve. The presence/absence of a digital signature will never be the deciding factor in whether people accept/reject an image as authentic.
timcobb 3 hours ago [-]
Yeah this is what I don't get why are people even spending time on this.
HWR_14 3 hours ago [-]
Is this picture real or AI is a real problem it is worth money to solve.
SoftTalker 2 hours ago [-]
Why? An image should never be proof of anything, by itself.
EA-3167 3 hours ago [-]
A desperate attempt to preempt regulation.
akersten 3 hours ago [-]
A desperate attempt to establish their version of regulatory capture and not have to pay licensing fees to the other guy
rackp 2 hours ago [-]
[dead]
jasonjayr 4 hours ago [-]
And in 2026, I don't think it's too big of a stretch to imagine that there are going to be people in power that can add + remove the metadata to whatever image they want, at will, to tell whatever story they want to create. Sadly.
gruez 3 hours ago [-]
There were similar fears about the webtrust CA system, but AFAIK there's no known incidents where a government strongarmed a CA into misissuing a MITM certificate, and then it was used in MITM attacks. The closest is some misissued certificates seemingly due to incompetence but weren't used in attacks.
SoftTalker 2 hours ago [-]
And there are unicorns living at the end of the rainbow.
yjftsjthsd-h 4 hours ago [-]
> Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.
The analog hole is alive and well:)
taneq 2 hours ago [-]
And at that level, it’s a matter of definition anyway. What is “AI generated”? A photo of a screen showing an AI picture is still a photo. If that’s “AI” then what about a photo of an AI generated billboard? Or a photo of a bus with an AI graphic on the side?
wisty 4 hours ago [-]
I can break it with zero skills. Tripod, camera, clear monitor in a dark room ... just take a real photo of a fake photo.
Terr_ 4 hours ago [-]
That might be detectable if they signed content contains focal-length metadata... but even then, some foresight and a collection of lenses would hide it.
ipython 3 hours ago [-]
Wouldn’t the introduction of the lidar signals embedded in the photo (say used with apple’s faceid system) help here?
I got a good laugh out of the "unblur to verify" first image. I dont know what I was expecting to see.
andrewflnr 3 hours ago [-]
As far as AI-generated images go, that was a good one.
jazzyjackson 6 hours ago [-]
I would be interested in a note on whether Sony / Leica / Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.
Legend2440 6 hours ago [-]
My bet is they do considerably worse. Digital cameras are not designed with security in mind. Arbitrary code execution has been achieved on many DSLRs and there's even been open-source firmware projects for some.
Retr0id 6 hours ago [-]
Unfortunately they're a little outside of my tinkering budget, but if anyone wants to send me some I'll do my best to pwn them. Can't be any harder than a Google flagship, one would imagine.
I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.
kiddico 2 hours ago [-]
Could you make use of a Sony a6000?
EmbarrassedHelp 4 hours ago [-]
Why would someone paying for an expensive camera to damage the pixels of their images with "invisible" watermarks?
xyzsparetimexyz 3 hours ago [-]
Surely the easiest thing to target is photos taken by journalists and modifications, down sampling etc when shared to twitter?
tescreal 5 hours ago [-]
I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.
fenestella 2 hours ago [-]
[flagged]
hydraterms 3 hours ago [-]
[flagged]
SecuriLayer 4 hours ago [-]
[flagged]
Ozzie-D 1 hours ago [-]
[flagged]
tashian 5 hours ago [-]
I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.
And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
gyomu 5 hours ago [-]
Apple isn’t going to touch this with a 10-foot pole.
The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.
Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”
>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.
3 hours ago [-]
5 hours ago [-]
Rendered at 02:54:29 GMT+0000 (Coordinated Universal Time) with Vercel.
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
This is ridiculous.
It seems like there's a big disconnect between what C2PA says it's for and what certain journalists think it's for.
At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg
I don't think completely solving this sort of problem is even possible.
The analog hole is alive and well:)
I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.
And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.
Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”
>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.