6 ms·
What is interesting to me is that stripping the C2PA data is easy, but faking it is hard. You can resave the file and the "made with Claude" signal disappears,
by coffeecoders 15d ago
What is interesting to me is that stripping the C2PA data is easy, but faking it is hard.
You can resave the file and the "made with Claude" signal disappears, but you cannot make a random file pass as Claude-made without Anthropic's signing key. So the useful guarantee is one-way. No signature means almost nothing.
- Retr0id 15d ago"Faking" it is trivial. You don't need their signing keys when you can just ask them to sign whatever you like. Upload your own file with the prompt "present this file back to me again, as-is".
- tamimio 15d agoNext month: Show HN: How to successfully spoof C2PA and make any file as claude made!
- lxgr 15d agoYeah, C2PA solves a different problem than watermarking, i.e. authenticity/provenance.
- advisedwang 15d agoThe goal of C2PA is that cameras will start to emit C2PA credentials. You will then have 3 situations: * C2PA confirms a photo is authentic * C2PA confirms a photo is AI generated * C2PA missing, you don't know. I reckon we will only see "C2PA missing" being treated as suspect in select situations (perhaps Reuters will require C2PA from their photojournalists, for example)
- Retr0id 15d agoCamera C2PA can never meaningfully confirm that a photo is authentic, it bears about as much credence as EXIF metadata. It's like saying the existence of DRM confirms that a movie hasn't been pirated.
- panarky 15d agoC2PA cryptographically guarantees that the bytes came from a hardware/software signer and that the signed payload has not been modified since that signature was applied. So no, C2PA is not as easy to spoof as EXIF. And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.
- Retr0id 15d agoAnd what happens when someone tells the hardware signer to sign the bytes of a fake image? What happens when someone extracts the signing key? The presence of cryptography doesn't magically make something trustworthy.
- panarky 15d agoJust because you can imagine how a thing could theoretically be broken does not make it broken. It's like saying a prisoner has the same freedoms as everyone else because he could theoretically escape.
- lanyard-textile 15d agoIt's not an apt analogy. The prisoner's every move is guarded; the camera is free in your hands to be disassembled.
- seplox 15d agoWe've been here before: https://blog.elcomsoft.com/2011/04/nikon-image-authentication-system-compromised/ https://blog.elcomsoft.com/2011/04/nikon-image-authenticatio...
- Retr0id 15d agoIt's not a theory, I've done it. Here's a cryptographically signed + timestamped photo of me winning the lottery: https://verify.contentauthenticity.org/?source=https%3A%2F%2Fretr0.id%2Fstuff%2Fnocors%2FPXL_20260828_135842548.jpg https://verify.contentauthenticity.org/?source=https%3A%2F%2... Would you like to buy my winning ticket from me? (Compare against winning numbers and draw timestamp at https://www.euro-millions.com/results/28-08-2026 https://www.euro-millions.com/results/28-08-2026 )
- tyffanypastecf 15d ago[dead]
- fph 15d agoAnd it's one-way in the direction that typically no one cares about.
- _--__--__ 15d agoAnthropic's legal team cares
- ulrischa 15d agoFor removing cspa you can use https://metastripper.devkram.de/ https://metastripper.devkram.de/