logoalt Hacker News

Retr0idtoday at 9:38 AM1 replyview on HN

It's also something I've been looking into. I've completely broken Google's implementation and I can sign any file as if it were real, more details will be public in the coming weeks.

Signatures are nice, but the contents of the image still matter. Any signs of manipulation should still be treated with suspicion, even if they're "legitimate" edits. The best way to avoid such signs is to have the bare minimum processing.


Replies

Gigachadtoday at 9:46 AM

The technology is fundamentally flawed. It's essentially DRM that relies on making the signing key hard to access.

show 1 reply