10 ms·
I'd always thought the usefulness of C2PA was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure,
by TOMDM 24d ago
I'd always thought the usefulness of C2PA was limited to verified devices in custody by trusted actors.
Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery.
The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?
- hypfer 24d ago> was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery. But that is also not the case, because whatever keys are in those devices may have been duplicated in the factory or somewhere along the supply chain. Or the stuff is cloud connected and an exploit can be executed via that. Or, as written in the blog post you're commenting on, software exploits. The whole idea is that the concept works for no one.
- TOMDM 23d agoWell, you can say the same thing about HSMs, or the CPU in your device. If there's no trust afforded to the device holder, or it's manufacturer, there's no trust in anything. Always to degrees, and never fully, but trust can still be had.