logoalt Hacker News

C2PA Cameras Do Not Survive Contact with Reality

60 pointsby Retr0idtoday at 7:38 PM24 commentsview on HN

Comments

randomblock1today at 10:19 PM

Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.

I don't think completely solving this sort of problem is even possible.

show 3 replies
uqerstoday at 10:01 PM

I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?

show 2 replies
ethagknighttoday at 9:21 PM

I got a good laugh out of the "unblur to verify" first image. I dont know what I was expecting to see.

wistytoday at 10:31 PM

I can break it with zero skills. Tripod, camera, clear monitor in a dark room ... just take a real photo of a fake photo.

show 2 replies
jazzyjacksontoday at 9:14 PM

I would be interested in a note on whether Sony / Leica / Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.

show 3 replies
tescrealtoday at 9:44 PM

I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.

hydratermstoday at 11:25 PM

[flagged]

SecuriLayertoday at 10:58 PM

[flagged]

tashiantoday at 9:52 PM

I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.

And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).

show 2 replies