8 ms·
Same way it works for tls and code signing. Public reports bad actors to the signing authority. They and/or independent firms investigate. You self report theft
by jfyi 1mo ago
Same way it works for tls and code signing. Public reports bad actors to the signing authority. They and/or independent firms investigate. You self report theft. It's not like we are inventing pki from scratch here and wondering what an implementation would look like. We have decades of use to look at.
Besides wasn't your argument "hacking" a minute ago? So you concede that then? You seem to have moved on.
- chrisjj 1mo ago> Public reports bad actors to the signing authority. Public would know the pics were fake let alone know who to report. > They and/or independent firms investigate. What's to investigate? You have a fake pic that is indistinguishable from genuine and "proved" by a sig.
- jfyi 1mo agoYes, "the public" includes experts in the subject field and independent witnesses to events. If your argument is that images can't be verified, you are going to need to provide some kind of backing to that. We know well that there are watermarks and tell tale signs to go off. Regardless, if they are depicting real world events, outside confirmation can be used. You also don't seem to understand the point of the signature. It's not to prevent fake images, it's to tie an identity to images so that that trust can be established and permanently lost in the case of a malicious actor. Your arguments repeatedly have failed to engage with the actual system proposed.
- chrisjj 1mo ago> You also don't seem to understand the point of the signature. It's not to prevent fake images, it's to tie an identity to images so that that trust can be established and permanently lost in the case of a malicious actor. It was proposed as a solution to: how is any future viewer going to tell your images from "AI" fakes? You seem to be saying it is not a solution. I agree.
- jfyi 1mo agoI have already said, it's done by establishing trust by tying identity to images. Your assertions aren't a counter to that. You thinking they are shows a lack of understanding of how to verify truth on a fundamental level. Let's also list the points you have conceded by quietly giving them up: 1. Hacking the camera is irrelevant. 2. Images can be verified. Do you want to actually engage with the conversation? The funny thing is that there are engineering challenges in this space, but you don't seem to understand the basics well enough to even get to that point.
- chrisjj 1mo ago> I have already said, it's done by establishing trust by tying identity to images. You've said it, but you've not credibly substantiated it. Imagine a famous photo journalist dies and there emerge "AI" fake pics signed with creds stolen from his hacked camera. Trust isn't part of a solution. It is part of the problem.
- jfyi 1mo agoThen the cert is pulled with a date and the timestamps on the images can be used to verify when they happened. This is generally how you'd handle theft. You can then also resign with a new cert at a later date. Besides, after a famous journalist dies, their work is already famous, people already know it or don't. This is a contrived and irrelevant example. Again, this is not hypothetical, we already know how this works. Next one please.
- chrisjj 1mo ago> If your argument is that images can't be verified, you are going to need to provide some kind of backing to that. I've seen no credible verification method. If you have, then you are the one that needs to provide backing.