This kind of "verification" doesn't work. You're trying to have the device authenticate the image. That implies a root of trust that goes through the device manufacturer, which state actors will immediately compromise, making the signatures untrustworthy regardless. Then people will find vulnerabilities in the devices themselves, or convincing ways to have the device take a picture of a doctored photograph instead of a picture of the world, extending the ability to forge signatures to the general public.
The resources needed to forge a signature aren't going to be much different than the resources needed to create a deepfake to begin with. The creator gets to choose which device to use and can choose based on which device they find a vulnerability in. So it's more likely to be a liability than a benefit because it lends false credence to the authenticity of fakes.
For it to work you would need all devices to be secure against all attackers. It's not realistic.
How? If you have a public/private key pair and then do some kind of multisig process wherein the manufacturer can sign the photo, the OS can sign the photo, and then a user supplied signature could also sign the photo. You're not going to be able to fake 3 cryptographic signatures without 3 private keys. It would be extremely difficult to fake all of that. It would take a concerted, concentrated effort and would be extremely rare in practice. It would certainly improve the situation.
This image can now be injected into the news cycle and be taken seriously.
Keeping a secret on the camera is more or less the "jailbreak problem", aka being able to make a dvd player or console that only does the things that the manufacturer wants.
I will be pretty sad if this problem is actually "solved" effectively because it portends a future where manufacturers can completely curtail user freedom. But...
If the key on the device is compromised by reverse engineering or because the manufacturer is compromised then the whole root of trust is gone.
Attackers can choose the weakest brand of camera.
You now have some doubt about any image that has been "verified" because it could have come from a compromised camera secret.
All the rest of the stuff, the blockchain, etc depends on the root of trust in the camera.
You also now have debates around camera country of origin because there is no near future world where governments can't lean on local manufacturers. Finally, doubt can be thrown on images retro-actively if we later learn that a camera we thought was secure, has vulnerabilities.
All of this would be optional, of course. People can always edit out metadata. But it would lend credence and authority to a photograph or video. Which would carry more weight in a court of law, for example, where this stuff really matters.
I think the disconnect might be that you are working from a threat model where someone else is trying to tamper with an image from your camera. I agree you could make that arbitrarily difficult. But I am primarily concerned with the threat where someone is tampering with their own camera to fake evidence. This possibility makes it harder for you to prove that your own image is legitimate.
Your reasoning implies that one or two hacked cameras are not a problem. To my way of thinking, the possibility that "at least 1 hacked camera exists" or "any camera could possibly be hacked" are enough to throw doubt on any "verified" images that someone tries to present in a high stakes context such as national security or the courtroom. We're back to debating provenance.
It would require a larger degree of premeditation and effort to convincingly pull off a deep fake in that world.
It's not a technicality if the video can't be distinguished from perfect nonsense. Just as you don't let someone with a documented history of hallucinations testify on their own.
Or, you'd adapt a hardware wallet to do the same. Either way, there'd be two devices from two manufacturers, communicating over a transparent protocol.
I imagine deepfakes will become way easier in the near future because there are legitimate commercial reasons to make them easy and accessible (for example digital art assets). I don't see the same happening for cracking devices, which is more a standard security cat and mouse game between hackers and device manufacturers.
If someone presents altered footage, you can show that the checksum of the original was uploaded earlier.
This of course only covers certain cases. If the deepfake is crafted from scratch or from a camera that doesn't upload its checksums, and the incentive for the creation of the deepfake arises before the supposed time the deepfake takes place, then this method won't be of use.
And subject to attack. Don't want to be recorded? Jam wireless so they can't have anyone sign their videos, then claim they're fake.
Also doesn't work for state actors. A country can compromise three separate signing authorities.
And you can just upload it to ten different authorities in ten different jurisdictions, or even a hundred if you're paranoid. States are powerful but they're not _that_ powerful. It's the same principle that makes Tor work.
I agree jamming wireless could be an issue, but only for prosecution. In the case of proving innocence it's a moot point because this checksum system only covers after-the-fact fabrication anyway.
They'd also have logged the IP, which combined with a time will probably significantly narrow down the individual in question if you can also access telco records. Especially if inadvertently more information is also documented (such as a user agent).
> It's the same principle that makes Tor work.
Tor doesn't work for this kind of problem, unless you are significantly more technically savvy (and even then...) then the average smartphone user.
Yes, if a state actor wants to create evidence to frame you, and they didn't care about cost or returns, they could do so. But they could always do so. The fact is most of us are never going to get framed by a nation state.
The notion that you're either secure against all possible attacks or nothing is absurd.
> Yes, if a state actor wants to create evidence to frame you, and they didn't care about cost or returns, they could do so. But they could always do so. The fact is most of us are never going to get framed by a nation state.
This is a major problem for elections. Nation states absolutely will doctor video of adversarial political candidates and for other propaganda purposes.
> The notion that you're either secure against all possible attacks or nothing is absurd.
But that's how signatures work. You're trusting every device in the world to sign the output of its camera. If the attacker can compromise any device, they can produce signed forgeries.
Again, nation states have always been able to doctor video of adversarial political candidates. Lookup pictures where the KGB made someone disappear.
Yes, if an attacker can compromise any device they can produce a signed forgery. But that's a really big if. There are a lot of potential attackers who can't compromise any and all devices, and signatures protect against them.
Scaling the image down seems like one of the best tricks if you can get away with it. Another cheap one would be shifting the image 4 pixels over to break up the DCT artifact grid.
With a good forgery it will be. Even then, the fact that it's noise means that you won't ever be sure about this.
Are you saying that by law devices should cryptographically sign pictures?
Just saying "we need to sign photos" isn't enough and simply naïve.