5 comments

  • uqers8 minutes ago
    I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
  • tashian17 minutes ago
    I have a feeling Apple is going to knock it out of the park on this when they get around to it. They have a great foundation for doing image provenance well. The device attestation workflows are already there. And the same attacks that work against Android won&#x27;t be as easy or effective because of Secure Enclave. Apple could run the whole signing process inside SEP.<p>And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
  • ethagknight48 minutes ago
    I got a good laugh out of the &quot;unblur to verify&quot; first image. I dont know what I was expecting to see.
  • jazzyjackson55 minutes ago
    I would be interested in a note on whether Sony &#x2F; Leica &#x2F; Olympus “content credentials” do any better with their hardware to ensure a signature is assigned to data straight off the sensor.
    • Legend244046 minutes ago
      My bet is they do considerably worse. Digital cameras are not designed with security in mind. Arbitrary code execution has been achieved on many DSLRs and there&#x27;s even been open-source firmware projects for some.
    • Retr0id51 minutes ago
      Unfortunately they&#x27;re a little outside of my tinkering budget, but if anyone wants to send me some I&#x27;ll do my best to pwn them. Can&#x27;t be any harder than a Google flagship, one would imagine.<p>I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I&#x27;m not sure how far I&#x27;ll be able to get with it.
  • tescreal25 minutes ago
    I expect the only plausible chance (and it is a stretch) will be at-the-censor marking. Quantum bla bla magic pixie dust or unicorn farts something. The chance of a trustworthy (including from nation-state tampering a la Stalin et al) means of verification of digital anything is as good as dead imho.