What a deepfake video of Mark Zuckerberg reveals about how we're manipulated
cbc.ca
cbc.ca
Bugger that.
This is a tech-created problem it can be tech-solved.
1. Photo manipulation leaves traces on the pixels, and this must be worse.
2. cameras can hash / sign every other frame or similar - we can build a chain of hardware to image that can be followed - and of an image or video does not have a CA cert chain it should be as mis-trusted as a web site without TLS
3. Err - there must be other ways.
Sure! Also, by total coincidence, now it's possible to trace every single photograph ever taken to whoever took it. A bunch of photojournalists in Syria, Iran, Mexico, and Missouri go missing, but I'm sure that's a coincidence.
Traceability is not without its drawbacks.
Not perfectly, but watermarking images in ways that survive re-encoding is far from impossible or unknown.
Oh man, you just articulated something nagging at me about deepfakes that I hadn't been able to.
Killer blockchain app: Couldn't we just use blockchain to protect against video deepfakes? Hash every frame as the video is recording, then create an immutable ledger of frames. All "official" videos must be able to be verified with said ledger, and the ledger itself can only be verified with vendor-specific key licensed by a central authority. Perhaps two -- say, Apple has one for iPhone and they must verify as well.
This could certainly be the billion dollar opportunity blockchain fanatics have been looking for.
If the video of politician X making unguarded remarks comes from a camera owned by CNN for the past two years it is a different level of trust than it coming from one bought last week with a credit card in the name of politicians opponents new intern.
This is honestly one of the very few use cases of cryptography signing a video or picture that I can see. But that would mean amateur journalists or the common person might be excluded from being a trusted source with video evidence.
All we are doing is trusting that the video images came from a given piece of hardware that we can trust belongs to me.
Whether I can be trusted is the same age old problem we have always had
But this simply makes it exponentially harder to fake or alter digitally any image (or at least look stupid when someone says "Citation Needed") - if you cannot produce the original raw footage questions will be asked why.
I can imagine this being something wanted on police bodycams quite soon
Why would this not be easily beatable? Hardware hacking aside, why not the naive approach of filming a monitor playing a deepfake?
So basically GPG for cameras, but with a hip startup name? Maybe any camera would ship with its own private key out of the box, and there'd need to be some kind of key rotation as well as a way to push your public keys … somewhere(s). I guess an attack here is somebody could lift a private key from someone else's camera and use that key to sign their fakes, but at least that's a reasonably tangible sort of attack that people know how to protect against.
(And of course we'll never stop people from watching 24/7 news every minute of the day, so we're all doomed anyway).
So, if I want to fake a picture and make it a bit more convincing, I only need to get my hands on a few cameras from pawn shops in Washington. I just can't say "this is a Reuters photo" or "this is a banned commercial" or whatever.
An example would be, some fake video circulates of some politician saying or doing something they never said or did. Maybe someone created it to harm that politician, maybe it was a prank, doesn't matter. A day later, a gazillion experts do the analysis and come out with public evidence that the video was a fake. Great. Then someone like Alex Jones tells his millions of listeners that he knows better, and some world-class expert who he mysteriously won't name told him privately that the video was real, and that somehow all of those experts were in on a conspiracy to debunk it, even though the evidence they provided debunking the video is all out in public (if perhaps too technical for most people). And then, voila. Millions of people now decide that it was real after all, and that all of those scientists and engineers and law enforcement people who said it was fake are all in on some conspiracy to squash the truth.
So you're right, it is a tech-created problem, and presumably tech solutions will always exist, but as long as you have an uneducated segment of the population that will always just believe whatever their tribe tells them, those tech solutions won't even matter. I don't know how to solve that problem, other than people becoming more educated and less geographically isolated, so that they can recognize and trust expert analysis when it's available and trustworthy.
Put another way, the problem isn't that Alex Jones exists, but that there exist people who think he's credible. The very existence of his listeners is a much bigger problem than his own existence. There will always be conspiracy theorists and there will always be faked evidence to support them, but what holds society together is our collective ability to acknowledge well-documented bullshit as bullshit, regardless of what tribe someone thinks they belong to and regardless of what they want to believe.
I don’t think you understand just how problematic it is to verify anything in the analog world.
Say you sit at a bar and someone displays a news clip on the TV? How do you know it’s real? Someone video or voice calls you with a deepfake of a loved one are you going to do forensics on it before acting on what they asked you to do?
1. Internet mobs will be de-clawed and any random person on the street that may have had their private information used against them now has instant plausible deniability. This is a big step towards valuing due process and personal privacy as digging into people's personal histories will become far less valuable than before if it can simple be handwaved away.
2. This could be a step back from the balkanization of the media. If anything can be faked than personal reputation and organizational reputation will be become far more valuable when it comes to the spread of stories.
1) High profile low volume content that trends (article)
2) Low profile high volume content spam (your point)
The second one seems like a much harder problem than the first (but both matter). Everyone already gets dozens of spam/phishing emails and links a day and not much has been done about it. I have no idea what the impact of deepfakes on the latter even looks like.
A thing which works to some degree is some more subtle editing (see the recent case of the slow Pelossi video) making people appear drunk or sick can be powerful.
Did your friend on Skype really tell you to meet them on Main and Broadway at 4PM?
We've seen the impact of that politically, but I worry what will come during an actual large-scale military conflict when the battlefield very much becomes digital and attempting to subvert civilians to the cause.
That would be a nice change! I think that's also the most optimist view. A pessimist would say that the end is no one trusts anything and we get more fractured and partisan.
The treatment of emails, however, does not inspire much hope. That is, in most courts, a printout of an email is treated -- as a practical matter -- similarly to a document signed by the author. Very frustrating. There is nothing magical about a piece of paper with an email header... you can create same in two minutes with a word processor. And don't even Get me started with text messages... try to introduce an unsigned typed scrap of paper and you'll get laughed out of court; but, put the text into something that looks like a screenshot of a phone and, voila, instantly admissible as an authentic text message.
- We've already had sophisticated image editing capabilities for a long time, and it hasn't substantially changed how newspapers, blogs, and social media accounts share photos. In particular, I see screencaps of Twitter threads all the time, even though they're trivial to fake. For whatever reason, people already seem to be OK with this. Maybe image editing did upset everything and I'm just too young to remember, but in either case, it doesn't look to me like the world fell apart.
- We've had (relatively) sophisticated audio editing capabilities for a somewhat lesser period of time, and that hasn't changed the landscape of how I see audio reported on. Reporters still use audio as evidence in articles, we haven't seen a wide spread of proprietary chains of trust, anything like that.
- We've seen decent evidence that deepfakes aren't required to currently fake video content to the point that you can deceive people. Deceptive cutting, slowdown, etc... seems to be enough. For people who want reasons to distrust a video, those methods also seem to be adequate. I regularly encounter people who'll look at body-cam footage and say, "well, you don't know, it doesn't show the full context." I'm skeptical deepfakes will make this situation worse -- at most I suspect they'll just further divide us into groups who research sources and groups who don't.
- Deepfakes are getting better, and I keep on getting told that they're eventually going to be perfect, but again, in practice I can't help but compare it to Photoshop. It turned out that with Photoshop, people's ability to spot fakes improved at roughly the same rate as the technology, to the point where I don't think it would be trivial for me today to make a fake photo of a politician that wouldn't get quickly identified as such on Reddit or Twitter. I've seen some really impressive AI generated content that blows me away, but right now I can still tell that it's all fake. I haven't seen anything that can consistently produce results that fool me beyond the most straightforward, boring use-cases. And I'm not an expert on this stuff, if it's good it should be able to fool me.
In theory, deepfakes are concerning, and I get why people are concerned about them. The technology will get better, it will be easier and easier for anyone to make a video saying anything they want. In theory, I agree with all of that. I just don't see a lot of practical evidence that it's going to be any better or worse than what we have right now.
If I hadn't grown up in an era where people were making what to me sounded like similar claims about Photoshop, I would be more worried.
Imagine you're a VIP and someone shows you footage of yourself doing something unacceptable from 30 years ago. There's a good chance that you might believe that footage and accept that as a true memory, even though it is entirely fake.
I'm not necessarily being theoretical about that. Growing up, I used to Photoshop family Christmas photos when not all of us could get together at the same time. Near the end of their lives, I vaguely remember it causing my grandparents to occasionally get confused about who was or wasn't actually at a gathering.
And it's not like I did a particularly great job of it -- they just didn't have experience with what the technology was capable of.
I guess what I'm trying to say is, yes, it seems obvious that there will be a generation of people who are not equipped to deal with the current state of image/audio/video manipulation, but is that actually a new thing? Hasn't that kind of always been the case?
any trust left in institutions will erode. we cant even believe our eyes or ears.
Photographic evidence hasn't stopped Trump from believing his inauguration was larger than Obama's. And it has always been easy to get people en-mass to believe hoaxes using doctored evidence.[0][1]