Cryptographic signatures. Ie every frame in a video is signed with a 512-bit key that states authoritatively what camera was the source of the video and when it was taken. In order to change any pixels in the video you'd break this key and need to resign it. An attacker would be unable to do this unless they had physical access to the original camera.
But it'll be at least 3 decades before this technology is commercialized, people see the demand for it, and the majority of all cameras in the world are replaced by it. Even if this new tech is on the market in a decade (simple tech, no demand / ecosystem yet), but 90% of existing / installed cameras don't have the feature then fake videos still get created with them. Only once ~80% of videos are authenticated, and a significant portion of the remaining 20% are fakes will people be able to dismiss non authenticated video. Up until then it's fakes non-stop.
We've got some ugly decades coming up.
A key is just data. Even if the key can't be extracted from common cameras, there's no magic that can prevent from someone making a device with a known key (or falsely register to the magic worldwide-trustworthy central registry that USA, China and Russia trusts but aren't able to influence to get keys for manufacturing fake news) that a particular camera has been made), one that can be used to sign data outside the camera context to make it appear that it was "securely" seen by a legitimate camera.
If you're up against the NSA then pretty much any tech evidence would be invalid. But if you're having a small claim court case, then it seems reasonable that authentication technology can keep up with faking technology.
1. The attacker wouldn't have access to the original cameras private key. 2. The attacker creates a fake video, creates a private key and signs the video with the key 3. The attacker tries to install the key into a camera
Step 3 has to be made impossible. Meaning that a camera becomes a trusted entity and only allowed parties (ex the camera manufacturer) has the authority to insert a private key into a camera. This would be that after installing a camera with a new private key, the key would then need to be signed with the manufacturer's private key and also stored in the camera. This shows the manufacturer is responsible for the contents of the video. If someone tries to change the camera's private key it would no longer match what the manufacturer signed.
Which yes then means we need to have authorized camera manufactures and a process for certificate revocation and all of that.
The exact opposite of "free and open" for recording devices - and the only way we aren't flooded with fake videos flooding and seriously impacting society. We have to want this if we want to still have a concept of video evidence in either the justice or social spheres.
I think, at this point, anything more than the camera having a secure device-generated key that it uses to sign its output and produce watermarks is overthinking it. That will add a nearly insurmountable barrier many classes of forgery, namely one were a forger claims to have a photo taken with your camera.
You also have to remember a significant class of photo-forgery would involve images that are claimed to originate from a camera the attacker controls. For instance, forged video of a robbery from a security camera. That could, in some cases, be defeated by observing that the images have authentication information they shouldn't have (such as traces of watermarks from other cameras).
At the end of the day, forgeries will be spotted by observing that they have subtle errors that don't add up. That's how it's always been done.
Don't have a registered key? Great, but that's no longer admissible.
Still, problems would exist with letting the camera read the private key for signing, but not allowing an attacker (forger) to access the private key and thus sign their modified footage.
Just a thought.
If a video is available and doesn't contain a pre-published key then the courts will still want to use it as useful evidence instead of simply ignoring it - sure, the opponent might have a slightly easier time attempting to contest that evidence as possibly doctored (just as they can do now), but courts will still make a judgement for each individual case.
I don't know if they subsequently updated it ( was called OSK ) but the idea has been around for some time. It was considered important for submission of evidence and several news agencies also insisted on it.
Think of it this way: we have fantastic technology for forging paper documents, but we still trust them. For instance, someone forged a memo to make a former president look bad close to an election, and they were tripped up because they weren't thinking about fonts [1].
Getting a forgery right is hard, and requires a lot of attention to detail. Technology will improve to add even more details that require careful attention, and maybe some cryptographic assurances. Maybe it won't be a world where anyone can spot a forgery, but there will still be experts who can.
[1] https://en.wikipedia.org/wiki/Killian_documents_controversy
If you're gonna frame a presidential candidate you should try harder.
Every recording device sends a stream of hashes to be cryptographically timestamped in realtime as they record. Now the time window to create fake evidence becomes incredibly small. You have to arrange the fake to be created at the same time or earlier than you will claim that the event happened. You have to know what you need to fake in advance, too, which isn't the case for all fraud.
Evidence will be corroborated from multiple places. If I'm in a public place, I can bet the scene is being recorded from multiple places, and I will not be able to predict who will be in that place in advance. Fake evidence can be caught out by finding discrepancies. If the majority of recording device owners whose evidence corroborates can be trusted, then the identification of the fake one can be made with reasonable certainty.