I would be interested in a note on whether Sony / Leica / Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.
Retr0id · 2026-08-25 21:18:15 UTC
Unfortunately they're a little outside of my tinkering budget, but if anyone wants to send me some I'll do my best to pwn them. Can't be any harder than a Google flagship, one would imagine.
I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.
kiddico · 2026-08-26 00:34:57 UTC
Could you make use of a Sony a6000?
Legend2440 · 2026-08-25 21:23:39 UTC
My bet is they do considerably worse. Digital cameras are not designed with security in mind. Arbitrary code execution has been achieved on many DSLRs and there's even been open-source firmware projects for some.
EmbarrassedHelp · 2026-08-25 23:06:22 UTC
Why would someone paying for an expensive camera to damage the pixels of their images with "invisible" watermarks?
MadnessASAP · 2026-08-26 03:07:51 UTC
The signature doesn't touch the image data in any way. It's just a piece of metadata attached to the image, like any other metadata tag.
ethagknight · 2026-08-25 21:21:47 UTC
I got a good laugh out of the "unblur to verify" first image. I dont know what I was expecting to see.
andrewflnr · 2026-08-25 23:29:35 UTC
As far as AI-generated images go, that was a good one.
tescreal · 2026-08-25 21:44:51 UTC
I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.
tashian · 2026-08-25 21:52:58 UTC
I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won't be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.
And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
gyomu · 2026-08-25 22:19:02 UTC
Apple isn’t going to touch this with a 10-foot pole.
The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.
Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”
>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.
gyomu · 2026-08-26 05:46:41 UTC
Yeah, it might never ship, or it might not ship as described, or that might be exactly what they do - I love being wrong.
If it does ship like that, it’s hard to not imagine a situation as I described earlier - an “iPhone Reference Image” being used to propagate fake news, at which point the credibility of the feature goes to 0 (and Apple’s takes a severe hit).
Wait & see.
tashian · 2026-08-27 20:48:43 UTC
The proof itself relies on asymmetric crypto, and that part is not tenuous (well, until Q Day, but that's a different story...).
But:
- You cannot prove that no one has ever been able to break a Secure Enclave or a YubiKey or another secure element. That's okay, these companies focus on making it so expensive that it's not worth doing.
- The analog "attack vector" is real, but that was always true with analog cameras as well. Anyone could have taken an analog picture of a screen, or even painted a hyper realistic image of something that never happened.
I think a realistic goal for provenance is to at least get to parity with analog cameras ("this is a picture directly from a sensor"), not to make the perfect system for proving that a photo is of a real world event.
uqers · 2026-08-25 22:01:11 UTC
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
demibabs · 2026-08-25 22:15:23 UTC
Not any rooted device, it must be rooted via an exploit. Still pretty bad, though
12_throw_away · 2026-08-25 23:13:02 UTC
Actually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.
genxy · 2026-08-26 01:46:39 UTC
Wait a minute. I think you might have forgotten a /s, I can spot this kinda thing.
akersten · 2026-08-25 23:46:45 UTC
Well, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape.
Someone better figure out how to make computing devices at home from everyday parts because the only way I see this (shockingly rapid) arms race end is legally mandated, cryptographically locked down hardware and software (or even thin clients) everywhere.
RMS must be having daily nightmares at this point.
P.S.: Fantastic talk you linked there.
hypfer · 2026-08-26 05:56:33 UTC
I think it might tell us something about the culture there by now.
Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying.
I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.
randomblock1 · 2026-08-25 22:19:55 UTC
Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.
I don't think completely solving this sort of problem is even possible.
duskwuff · 2026-08-25 22:24:21 UTC
And I'm not sure it's even useful to solve. The presence/absence of a digital signature will never be the deciding factor in whether people accept/reject an image as authentic.
timcobb · 2026-08-25 23:41:09 UTC
Yeah this is what I don't get why are people even spending time on this.
EA-3167 · 2026-08-25 23:42:46 UTC
A desperate attempt to preempt regulation.
akersten · 2026-08-25 23:45:11 UTC
A desperate attempt to establish their version of regulatory capture and not have to pay licensing fees to the other guy
timcobb · 2026-08-26 19:41:20 UTC
This is a clear explanation, thank you
HWR_14 · 2026-08-25 23:59:04 UTC
Is this picture real or AI is a real problem it is worth money to solve.
SoftTalker · 2026-08-26 00:48:44 UTC
Why? An image should never be proof of anything, by itself.
HWR_14 · 2026-08-26 15:20:40 UTC
What should be sufficient proof for you that AI wont fake trivially?
duskwuff · 2026-08-26 03:44:47 UTC
What I'm getting at is that metadata that claims that a photo is "real" won't necessarily convince people that it is, and the lack of that metadata doesn't mean anything at all. About the only real use I've seen for C2PA is to confirm that an image bearing that metadata is AI-generated - and that marker is easily lost through editing or retransmission.
timcobb · 2026-08-26 13:24:25 UTC
Yeah we live in the era of alternative facts and this is just more, at best, "fact checking"
HWR_14 · 2026-08-26 15:44:15 UTC
I'm not saying it's an easy problem or that this is the right solution. I'm saying it's a valuable problem and so they are trying this solution.
silon42 · 2026-08-26 07:34:51 UTC
And it's very real problem to workaround (aka, hack the device into faking the signature).
timcobb · 2026-08-26 13:23:12 UTC
It is (not sure I agree, but I can see how one would think this) but you're not going to solve it like this
jasonjayr · 2026-08-25 22:39:12 UTC
And in 2026, I don't think it's too big of a stretch to imagine that there are going to be people in power that can add + remove the metadata to whatever image they want, at will, to tell whatever story they want to create. Sadly.
gruez · 2026-08-25 23:46:46 UTC
There were similar fears about the webtrust CA system, but AFAIK there's no known incidents where a government strongarmed a CA into misissuing a MITM certificate, and then it was used in MITM attacks. The closest is some misissued certificates seemingly due to incompetence but weren't used in attacks.
SoftTalker · 2026-08-26 00:46:32 UTC
And there are unicorns living at the end of the rainbow.
yjftsjthsd-h · 2026-08-25 23:06:31 UTC
> Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.
The analog hole is alive and well:)
taneq · 2026-08-26 00:47:33 UTC
And at that level, it’s a matter of definition anyway. What is “AI generated”? A photo of a screen showing an AI picture is still a photo. If that’s “AI” then what about a photo of an AI generated billboard? Or a photo of a bus with an AI graphic on the side?
wisty · 2026-08-25 22:31:01 UTC
I can break it with zero skills. Tripod, camera, clear monitor in a dark room ... just take a real photo of a fake photo.
That might be detectable if they signed content contains focal-length metadata... but even then, some foresight and a collection of lenses would hide it.
ipython · 2026-08-26 00:01:57 UTC
Wouldn’t the introduction of the lidar signals embedded in the photo (say used with apple’s faceid system) help here?
xyzsparetimexyz · 2026-08-25 23:55:26 UTC
Surely the easiest thing to target is photos taken by journalists and modifications, down sampling etc when shared to twitter?
mistercow · 2026-08-26 01:15:29 UTC
Aside from the fact that this was obviously never viable and the entire problem is clearly unsolvable if you sit down and really probe it for fifteen minutes, what I find most frustrating about this is that the false promise of preserving photos as reliable evidence is actively harmful.
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
qurren · 2026-08-26 01:27:39 UTC
Are we entering a world where if I took a picture with a film camera and scanned it, it would be rejected as not real?
This is ridiculous.
CapitalistCartr · 2026-08-26 01:59:36 UTC
It's not a matter of "rejected as not real", it's "There's no way to know if this is real or not".
account42 · 2026-08-26 13:08:13 UTC
When 99% of people are posting pics from their big tech approved smartphones with the "200% real no way to fake this" badge it doesn't matter that absence of the badge technically doesn't mean fake, that's what it will be interpreted as.
lelandfe · 2026-08-26 02:34:54 UTC
The defendant submitted a remarkably high quality video of you saying you generated it with Nano Banana.
ted_dunning · 2026-08-26 03:14:45 UTC
And their video was C2PA signed.
spaqin · 2026-08-26 10:09:26 UTC
You can even do it wholly in an analogue process, do a darkroom print, and it could be seen as fake as well - darkroom techniques are quite flexible as well. And a negative itself? That could be a copy of a prepared printed slide.
indutny · 2026-08-26 02:13:54 UTC
In my opinion, the benefits for end users are rather minimal since I doubt an average person would ever be checking C2PA provenance data, but there is a commercial incentive for Google and others to promote C2PA, since it makes preparing training material for Machine Learning significantly easier, and perhaps as a smaller benefit justifies hardware attestation that locks users down into proprietary OSes.
chrisjj · 2026-08-26 08:15:07 UTC
> it makes preparing training material for Machine Learning significantly easier
How?
lazide · 2026-08-26 08:40:04 UTC
A huge problem with ML training is the ‘ouroboros issue’ - training ML with input from other MLs breaks things in very deep (but difficult to stop/detect when it’s happening) ways due to the way the internal math works (model collapse).
Right now, the Internet training set is becoming more and more contaminated with better and better generative AI images and video.
It makes the models more screwed up, and makes it very difficult for humans to figure out what is original and not too.
If there was some signal that could at least make it easier to identify ‘original’/real images…
The original model collapse paper assumes you train networks on 100% synthetic data produced by the previous generation. But if you maintain some portion of real data then the problem is mitigated.
lazide · 2026-08-26 08:56:11 UTC
Not when you also including poisoning attacks.
I remember the original paper showing issues with even a couple percent of certain kinds of synthetic data too, not 100%.
ainch · 2026-08-26 09:44:43 UTC
What do you mean by poisoning attacks - stuff like Nightshade or Glaze? I was under the impression that those have largely failed to achieve their goals.
chrisjj · 2026-08-26 15:06:58 UTC
Those aren't poisoners. The are attempted protectors.
kawogi · 2026-08-26 10:40:30 UTC
I think the term "AI incest" would sum this up :)
chrisjj · 2026-08-26 11:27:30 UTC
OK, but any reliance on a fakable signal such as this seems guarateed to invite poisoning.
fwipsy · 2026-08-26 03:20:52 UTC
I think it's useful even if it can be spoofed. Many people don't even bother to edit visible watermarks out of AI photos/videos. I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing.
People are concerned that the technology will lend additional credence to the last 0.1%. But anyone who thinks about the technology for 2 minutes will see you can just point the camera at the screen. In cases where it really matters (a court of law, internet arguments between nerds) people will know it's not 100% reliable. Locks can be picked, and signatures can be forged, but that doesn't make them useless.
"C2PA Cameras Do Not Survive Contact With Reality" does not survive contact with reality where very, very few users would even think of rooting their phone so they can create signed fake images.
Retr0id · 2026-08-26 03:32:47 UTC
When I search for "C2PA" on the google play store, there are more AI-watermark-removal apps than there are signing apps. Certain types will jump through ridiculous hoops if they think it will affect their algorithmic reach on social media.
Malicious users don't need to root their own phones. They just need to go to fakemyimage dot com, and someone else's rooted phone in a clickfarm-type setup signs it for them. I am not operating such a service myself because I thought it was unnecessary in making my point, but perhaps I will have to reconsider.
fwipsy · 2026-08-26 05:16:29 UTC
You're arguing that lots of people can spoof this, the other guy is arguing that nobody will know it can be spoofed so it will do more damage. But these are contradictory -- if fakes become common, then they will also become common knowledge. The impact of any given fake is reduced if there are more of them. The technology doesn't need to provide 100% assurance. If it adds even a little friction to the slop mills then that's increasing the signal to noise ratio.
treyd · 2026-08-26 03:37:31 UTC
It's actually worse if it is plausibly trustworthy for "99.9%", since that's enough that naive users will get accustomed to believing the verification badge is authentic.
When a motivated malicious user (who doesn't actually need that much resources) will be able to convince people something is authentic because the verification passes when it shouldn't since naive users are primed to believe it by default.
fwipsy · 2026-08-26 05:11:01 UTC
Read the rest of my comment please. Is the single motivated malicious user able to do as much damage as all of the blocked attempts put together? Probably not, since if there's really all that much riding on it, people will point out it can be bypassed.
Should we also abolish Pangram, because it's not 100% accurate? Someone might be convinced a text is not AI-generated when it actually is! We should get rid of it rather than fool people into thinking it can be determined accurately. What about antivirus? We should abolish it as well rather than fool people into thinking that their software is ever 100% safe. What about HTTPS? We shouldn't call it "secure" shell because the computer you're connecting to could be compromised! I could go on and on and on.
The median instance of AI image generation isn't evidence in a court case. It's cyberbullying, or deepfakes, or fake news. It's called "slop" because there's a lot of it being churned out at low effort.
hypfer · 2026-08-26 05:33:10 UTC
You're missing all of the points that there could be by focussing on random people.
While it is always an individual tragedy when people treat each other badly (e.g. through deepfakes and all), the real threat does not exist on that level.
This is about misinformation and disinformation, so we're talking state actors. And with that, the 99.9% hypothesis does not hold true.
fwipsy · 2026-08-26 06:37:44 UTC
It's funny how people always say something is "a tragedy at the individual level" when they mean "it's not my problem." It's even crazier to dismiss the value of a security feature, just because it might make people feel more secure. That's true of every security feature! Very little of the technology that the web is built on is proof against state actors.
I like being contrarian as much as the next guy, but "Actually, having security is worse for security" is taking it a little too far.
hypfer · 2026-08-26 06:41:48 UTC
I am repeating myself, but this is about systems, and not about people.
It is however in the interest of the people to keep the systems running in an untainted way.
As said, on the individual level it's a tragedy, but one that can be absorbed somewhat. Democracy itself failing otoh is kinda hard to absorb.
C2PA is not "having security". It is "having an illusion of security for compliance and CYA reasons, that can be fairly trivially exploited by nation state actors".
Banality of evil. Again.
___
Actually, come to think of it, "security" is the wrong term there. Signatures don't secure anything. They attest.
Those are different things.
Argh and I ran with your term aah
fwipsy · 2026-08-27 02:26:55 UTC
This is pascal's mugging. Democracy itself might fail! You're just inflating the stakes of your hypothetical bad outcome until it can overwhelm any positive upside.
Not to mention, democracy is under just as much or more threat from "banal" fake news created by citizens. People gonna people. They don't need the DPRK lying to them to fool themselves.
Melatonic · 2026-08-26 08:31:27 UTC
Yeah I think any additional security is good. At worst this could help in a lot of court cases. Someone presents photo evidence - it could be manipulated - it could be not. This happens already. Then someone produces an original higher quality version (like a raw photo - which I take even on my phone at all times now) and experts can verify that as the original.
And I agree on state actors. If a major one is invested in something like this they might have well compromised the signing project itself, the verification process, or even the court system or media. That seems like a rare and extremely high bar to guard against.
fwipsy · 2026-08-27 02:27:40 UTC
Exactly. It's just more information. It doesn't have to be 100% accurate in every case, to be useful.
Gormo · 2026-08-26 12:23:33 UTC
> Is the single motivated malicious user able to do as much damage as all of the blocked attempts put together?
Yes, absolutely. Probably moreso. The whole point of these proposals is to try to solve for the "motivated malicious user" who is engaging in actual high-stakes fraud. There is no point in applying techniques that suppress inconsequential pranks while making serious crimes easier to get away with.
This really seems like a rehash of the perennial DRM argument: DRM restrictions provably do not reduce large-scale motivated copyright infringement, they just annoy legitimate paying users. This is the same class of solution, in that it is effective only where the stakes are low and the impact is minimal.
anonreplier · 2026-08-26 13:18:06 UTC
Why is this being framed as 2 types of users, lovable pranksters and fraudsters? There's a whole spectrum between these 2.
Also I'd like to know if a "joke" is likely fake.
Gormo · 2026-08-26 14:03:54 UTC
I don't suspect there is a uniform spectrum between those two. I think this is something that's going to be clinal, which we see in a lot of other comparable social contexts. The number of people actually willing to cross a moral threshold into outright crime is relatively small, but those are precisely the people who cause the most damage when they get away with their behavior.
Bur I don't even really think that's really relevant anyway, because whatever the density of "malicious" motivations is, the point here is that the fact that it only is an effort/motivation threshold that allows this technique to "block" malicious uses, and the motivation to overcome that threshold correlates directly with the stakes involved in the malicious use.
In other words, the more malicious the abuse is, the less effective this solution will be: the boundary of its usefulness will be wherever the line between pranksters and actual criminals happens to lie.
fwipsy · 2026-08-27 02:39:57 UTC
Your idea of a criminal seems to be hypercompetent and think of everything. These do exist, but most criminals are not very smart. Smart, dedicated, technical people can typically make more money legally.
Your argument applies to any imperfect security technology -- aka practically all of them.
Gormo · 2026-08-27 11:53:48 UTC
> Your idea of a criminal seems to be hypercompetent and think of everything.
No, my idea of a criminal is someone who is motivated to commit crime, and I feel that we've already established in this thread that the approaches we're discussing are motivation gates far more than competence gates.
> Smart, dedicated, technical people can typically make more money legally.
Then who's been running all the botnets, writing cryptolocker malware, and running phishing scams for the past couple of decades?
We've always had script kiddies, and now we have people using AI itself to do malicious things. Technical skill has never been an obstacle for sufficiently motivated scammers.
> Your argument applies to any imperfect security technology -- aka practically all of them.
Ultimately, everything has weaknesses, and with enough effort, most measures can be circumvented. But how much effort is enough varies wildly between solutions.
There's a huge gulf between a "no trespassing" sign, on the one hand, and a concrete wall topped with barbed wire, on the other. The "no trespassing" sign only keeps out people willing to obey it; the concrete wall keeps out anyone who isn't willing and able to accept the time, effort, and risk necessary to climb over it or knock it down.
And the point is that using digital signatures to distinguish AI-generated media from hand-made media is much closer to the "no trespassing" side of things than it is to the wall. Maybe it's analogous to a gate with a latch you can open from the other side if you reach over in just the right spot.
treyd · 2026-08-26 13:21:57 UTC
You're conflating the effectiveness of the mechanism with its systemic impact.
* Pangram: Yes we should really be discouraging people from putting trust in tools like this because they can't be made totally reliable.
* Antivirus: We should be building application environments with robust security models so that malicious software has a limited blast radius (like we do on mobile, like the Linux ecosystem is trying to do with Flatpak, etc).
* HTTPS: HTTPS is a strict upgrade from HTTP so we should be using it everywhere possible. The UI symbols to indicate to users the security expectations they're getting are good practice.
* ssh: This is just an inappropriate comparison.
The HTTPS comparison would make more sense if actually 0.1% of the time when their browser said they were using HTTPS it was just lying.
fwipsy · 2026-08-27 02:23:28 UTC
Pangram: I'm not arguing against encouraging skepticism; I'm arguing that the technology is not useless. It's good for people to know the limitations, but it's still evidence.
Antivirus: "Actually, we should build this hypothetical better thing" is a cop-out.
HTTPS: C2PA is a strict upgrade from unsigned photographs, so it should be used wherever possible.
SSH: Totally appropriate, the entire point of the discussion is whether it's permissible to the user that they might be more secure.
fightfake-ai · 2026-08-26 06:42:35 UTC
I agree with "I'm fairly certain this will defeat 99.9% of malicious users".
Also, note that C2PA should have something like Level 3 as well: "The image is mathematically proven to have come from the physical camera sensor."
It's somehow difficult to achieve this, but it's possible (although the attacks will always be possible of course).
dTal · 2026-08-26 09:13:40 UTC
Difficult and also solves nothing, since you can just point the camera at a screen.
Have you ever tried pointing a camera at a screen?
The screen is doing all kinds of crazy things that are not apparent to your eyes, but that show up clearly on camera.
blincoln · 2026-08-26 12:54:25 UTC
Some screens are like that, but it's not an inherent property of all visual displays.
For example, you'll see a sort of barber-pole effect when pointing a video camera at a raster-scan digital display whose refresh rate isn't synced to the camera's frame rate. To avoid that, sync them, or maybe use a colour e-ink display.
Alternatively, print a high-resolution version with a decent photograph printer and take a picture of the print with the C2PA camera.
rcxdude · 2026-08-26 08:03:47 UTC
What percentage of users are malicious, do you think? To me the issue is precisely what the product is trying to solve: propaganda using faked footage passed off as real, which generally has no real difficulty with resources available to boost their message. Giving that any kind of stamp of authenticity is a bad idea, IMO, and the fact that it'll work on 99% of the cases that don't matter makes it even worse.
Gormo · 2026-08-26 12:17:36 UTC
> I think it's useful even if it can be spoofed. Many people don't even bother to edit visible watermarks out of AI photos/videos. I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing.
Exactly: most people don't bother editing visible watermarks out of AI-generated media, because they have little or no incentive to bother doing so. This will "defeat" the 99.9% of users who are not actually trying to do anything malicious, but will be a minor annoyance to the 0.1% of users who are actively engaging in fraud, fabrication of evidence, etc.
The upshot is that not only us this not useful for its intended purpose, it will lure people into a false sense of security by creating expectations that AI-generated media will always be easily identifiable as such, and reduce the level of scrutiny that gets applied to the stuff that actually is malicious.
mistercow · 2026-08-26 12:36:45 UTC
> I'm fairly certain this will defeat 99.9% of malicious users, many of whom won't even know it exists until someone points out it's missing.
Everyone realizing that photos don't prove anything would defeat 100% of malicious users. I don't understand what people incorrectly trusting photos is supposed to achieve at this point, in your view.
fwipsy · 2026-08-27 02:37:01 UTC
Good luck with that. People are basically going to believe photos if they're aligned with what they already believe. They're not going to make strong decisions based on the C2PA tag. The idea that people will revise their entire worldview or submit to fraud based on a C2PA tag is typical HN thinking. People don't trust technology that much.
fwipsy · 2026-08-27 02:42:07 UTC
Almost everyone seems to be overindexing on this second-order effect. But second-order effects don't typically negate or surpass the original effect, because they depend on the original effect.
Gigachad · 2026-08-26 03:24:26 UTC
I don’t think there is a technical solution to this problem but I think there is a legal one.
Make it a legal requirement to mark AI generated photos and enforce penalties for posting unmarked AI generations. Social media should also mark the country of origin for each post, with the knowledge that posts from your own country are covered by these laws.
Comments
I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.
And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.
Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”
>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.
If it does ship like that, it’s hard to not imagine a situation as I described earlier - an “iPhone Reference Image” being used to propagate fake news, at which point the credibility of the feature goes to 0 (and Apple’s takes a severe hit).
Wait & see.
But:
- You cannot prove that no one has ever been able to break a Secure Enclave or a YubiKey or another secure element. That's okay, these companies focus on making it so expensive that it's not worth doing.
- The analog "attack vector" is real, but that was always true with analog cameras as well. Anyone could have taken an analog picture of a screen, or even painted a hyper realistic image of something that never happened.
I think a realistic goal for provenance is to at least get to parity with analog cameras ("this is a picture directly from a sensor"), not to make the perfect system for proving that a photo is of a real world event.
At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg
RMS must be having daily nightmares at this point.
P.S.: Fantastic talk you linked there.
Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying.
I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.
I don't think completely solving this sort of problem is even possible.
The analog hole is alive and well:)
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
This is ridiculous.
How?
Right now, the Internet training set is becoming more and more contaminated with better and better generative AI images and video.
It makes the models more screwed up, and makes it very difficult for humans to figure out what is original and not too.
If there was some signal that could at least make it easier to identify ‘original’/real images…
The original model collapse paper assumes you train networks on 100% synthetic data produced by the previous generation. But if you maintain some portion of real data then the problem is mitigated.
I remember the original paper showing issues with even a couple percent of certain kinds of synthetic data too, not 100%.
People are concerned that the technology will lend additional credence to the last 0.1%. But anyone who thinks about the technology for 2 minutes will see you can just point the camera at the screen. In cases where it really matters (a court of law, internet arguments between nerds) people will know it's not 100% reliable. Locks can be picked, and signatures can be forged, but that doesn't make them useless.
"C2PA Cameras Do Not Survive Contact With Reality" does not survive contact with reality where very, very few users would even think of rooting their phone so they can create signed fake images.
Malicious users don't need to root their own phones. They just need to go to fakemyimage dot com, and someone else's rooted phone in a clickfarm-type setup signs it for them. I am not operating such a service myself because I thought it was unnecessary in making my point, but perhaps I will have to reconsider.
When a motivated malicious user (who doesn't actually need that much resources) will be able to convince people something is authentic because the verification passes when it shouldn't since naive users are primed to believe it by default.
Should we also abolish Pangram, because it's not 100% accurate? Someone might be convinced a text is not AI-generated when it actually is! We should get rid of it rather than fool people into thinking it can be determined accurately. What about antivirus? We should abolish it as well rather than fool people into thinking that their software is ever 100% safe. What about HTTPS? We shouldn't call it "secure" shell because the computer you're connecting to could be compromised! I could go on and on and on.
The median instance of AI image generation isn't evidence in a court case. It's cyberbullying, or deepfakes, or fake news. It's called "slop" because there's a lot of it being churned out at low effort.
While it is always an individual tragedy when people treat each other badly (e.g. through deepfakes and all), the real threat does not exist on that level.
This is about misinformation and disinformation, so we're talking state actors. And with that, the 99.9% hypothesis does not hold true.
I like being contrarian as much as the next guy, but "Actually, having security is worse for security" is taking it a little too far.
It is however in the interest of the people to keep the systems running in an untainted way.
As said, on the individual level it's a tragedy, but one that can be absorbed somewhat. Democracy itself failing otoh is kinda hard to absorb.
C2PA is not "having security". It is "having an illusion of security for compliance and CYA reasons, that can be fairly trivially exploited by nation state actors". Banality of evil. Again.
___
Actually, come to think of it, "security" is the wrong term there. Signatures don't secure anything. They attest.
Those are different things. Argh and I ran with your term aah
Not to mention, democracy is under just as much or more threat from "banal" fake news created by citizens. People gonna people. They don't need the DPRK lying to them to fool themselves.
And I agree on state actors. If a major one is invested in something like this they might have well compromised the signing project itself, the verification process, or even the court system or media. That seems like a rare and extremely high bar to guard against.
Yes, absolutely. Probably moreso. The whole point of these proposals is to try to solve for the "motivated malicious user" who is engaging in actual high-stakes fraud. There is no point in applying techniques that suppress inconsequential pranks while making serious crimes easier to get away with.
This really seems like a rehash of the perennial DRM argument: DRM restrictions provably do not reduce large-scale motivated copyright infringement, they just annoy legitimate paying users. This is the same class of solution, in that it is effective only where the stakes are low and the impact is minimal.
Also I'd like to know if a "joke" is likely fake.
Bur I don't even really think that's really relevant anyway, because whatever the density of "malicious" motivations is, the point here is that the fact that it only is an effort/motivation threshold that allows this technique to "block" malicious uses, and the motivation to overcome that threshold correlates directly with the stakes involved in the malicious use.
In other words, the more malicious the abuse is, the less effective this solution will be: the boundary of its usefulness will be wherever the line between pranksters and actual criminals happens to lie.
Your argument applies to any imperfect security technology -- aka practically all of them.
No, my idea of a criminal is someone who is motivated to commit crime, and I feel that we've already established in this thread that the approaches we're discussing are motivation gates far more than competence gates.
> Smart, dedicated, technical people can typically make more money legally.
Then who's been running all the botnets, writing cryptolocker malware, and running phishing scams for the past couple of decades?
We've always had script kiddies, and now we have people using AI itself to do malicious things. Technical skill has never been an obstacle for sufficiently motivated scammers.
> Your argument applies to any imperfect security technology -- aka practically all of them.
Ultimately, everything has weaknesses, and with enough effort, most measures can be circumvented. But how much effort is enough varies wildly between solutions.
There's a huge gulf between a "no trespassing" sign, on the one hand, and a concrete wall topped with barbed wire, on the other. The "no trespassing" sign only keeps out people willing to obey it; the concrete wall keeps out anyone who isn't willing and able to accept the time, effort, and risk necessary to climb over it or knock it down.
And the point is that using digital signatures to distinguish AI-generated media from hand-made media is much closer to the "no trespassing" side of things than it is to the wall. Maybe it's analogous to a gate with a latch you can open from the other side if you reach over in just the right spot.
* Pangram: Yes we should really be discouraging people from putting trust in tools like this because they can't be made totally reliable.
* Antivirus: We should be building application environments with robust security models so that malicious software has a limited blast radius (like we do on mobile, like the Linux ecosystem is trying to do with Flatpak, etc).
* HTTPS: HTTPS is a strict upgrade from HTTP so we should be using it everywhere possible. The UI symbols to indicate to users the security expectations they're getting are good practice.
* ssh: This is just an inappropriate comparison.
The HTTPS comparison would make more sense if actually 0.1% of the time when their browser said they were using HTTPS it was just lying.
Antivirus: "Actually, we should build this hypothetical better thing" is a cop-out.
HTTPS: C2PA is a strict upgrade from unsigned photographs, so it should be used wherever possible.
SSH: Totally appropriate, the entire point of the discussion is whether it's permissible to the user that they might be more secure.
Also, note that C2PA should have something like Level 3 as well: "The image is mathematically proven to have come from the physical camera sensor."
It's somehow difficult to achieve this, but it's possible (although the attacks will always be possible of course).
But yeah, difficult too :)
The screen is doing all kinds of crazy things that are not apparent to your eyes, but that show up clearly on camera.
For example, you'll see a sort of barber-pole effect when pointing a video camera at a raster-scan digital display whose refresh rate isn't synced to the camera's frame rate. To avoid that, sync them, or maybe use a colour e-ink display.
Alternatively, print a high-resolution version with a decent photograph printer and take a picture of the print with the C2PA camera.
Exactly: most people don't bother editing visible watermarks out of AI-generated media, because they have little or no incentive to bother doing so. This will "defeat" the 99.9% of users who are not actually trying to do anything malicious, but will be a minor annoyance to the 0.1% of users who are actively engaging in fraud, fabrication of evidence, etc.
The upshot is that not only us this not useful for its intended purpose, it will lure people into a false sense of security by creating expectations that AI-generated media will always be easily identifiable as such, and reduce the level of scrutiny that gets applied to the stuff that actually is malicious.
Everyone realizing that photos don't prove anything would defeat 100% of malicious users. I don't understand what people incorrectly trusting photos is supposed to achieve at this point, in your view.
Make it a legal requirement to mark AI generated photos and enforce penalties for posting unmarked AI generations. Social media should also mark the country of origin for each post, with the knowledge that posts from your own country are covered by these laws.