It's also something I've been looking into. I've completely broken Google's implementation and I can sign any file as if it were real, more details will be public in the coming weeks.
Signatures are nice, but the contents of the image still matter. Any signs of manipulation should still be treated with suspicion, even if they're "legitimate" edits. The best way to avoid such signs is to have the bare minimum processing.
The technology is fundamentally flawed. It's essentially DRM that relies on making the signing key hard to access.