Why do you need to hide evidence of tampering? You're not supposed to need the camera to later verify its signatures.
> good 99.99% of the time
That's a bigger disaster than not having this technology at all, because now the 0.01% of forgers will be able to say "look, my photo can't be a forgery, it's digitally signed!" and convince a lot of people who would otherwise disbelieve it.
If I know my camera was tampered with, I can invalidate the signing key.
This is the kind of technology that's useless if it's not good 100% of the time.
Parachutes can be useful even if they open 99.999% of the time.
But this is either 100% cryptograhical proven forgery-proof or it isn't. There's no "good enough" middle ground. You care for forgery-proof when important things are hanging on that being the case.
Nothing is ever 100%
On other side this Sony Camera-DRM is not just useless, but dangerous especially since Sony have well established track record with backdoors and cryptography:
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
https://www.engadget.com/2010-12-29-hackers-obtain-ps3-priva...
https://www.pcworld.com/article/411221/backdoor-accounts-fou...
Which it’s still likely better than the current situation, which is photoshops ahoy everywhere.
They do. But we're ok with some losses now and then, if it means parachutes still saves tons of lives...
The thing is a parachute failing doesn't affect other deployments. Whereas the forgery-proof tech being able to fail means no photo with "forgery proof data" can be trusted.
Digital photos are already used extensively without any digital signing at all in court - for very high profile cases, including murder, high stakes civil suits (Depp vs Heard), insurrection against the US, you name it.
How is this going to make it worse exactly?
The systems involved already have to deal with uncertainty, doubt, potential fraud, etc.
If there is a potential signal to help out with that, which this is, it just makes it easier to discover fraud, not bulletproof or impossible, regardless of the tech.
If it's easily broken? By providing fake assurances.
>The systems involved already have to deal with uncertainty, doubt, potential fraud, etc.
Yes, and false assurances has already been an issue with all kinds of forensic processes, and led to numerous bad convictions (numerous that we know of, there are obviously more).
I'd rather have dgital photos "without any digital signing at all" in court, and the court treating them with uncertainty, doubt, potential fraud, etc, than a easy to beat signing system that gives even 10% extra unwarranted assurances to juries and judges....
It’s like with bank cards where everyone in the judicial system for years agreed that they were safe and only when it couldn’t denied anymore suddenly it took another 3 years for the system to reflect that.
A) cryptography is hard. Chances of Sony getting it right are not good. Chances of critical flaws being found later are basically infinite.
B) 99.9% doesn’t exist with technology. Once it’s broken the exploit can be scaled.
And there is a lot more stuff they can do to prevent such naive attacks.
By your simple reasoning, all iphones would be cracked, yet even the USA govt hasn't been able to crack into them.
And what they propose is vastly better than doing nothing.
I don’t think this is quite the right takeaway. What the threat model is for this is not that you’d be able to crack any iPhone you like in whatever circumstances, but rather more like jail breaking one. Jailbreaks definitely exist, and depending on your need, you’d only need to jailbreak one, once. Even with a per-device token, if what you need is to generate a validly signed photo that has been manipulated (say for a passport photo or forensics), you’d be able to do that.
It would be profoundly stupid (and unlikely) that Sony would send data from the sensor to software, then sign using keys simply read into software.
So no, jailbreaks very likely would have zero ability to sign an image.
They do need to push other images from where the sensor would be :).
And is it better than nothing? I think having having which people may treat ad evidence which is trivial to fake is worse than something which people won't treat as evidence
Yes, taking a new photo. However, a photo of a photo is going to show artifacts in the frequency spectrum that should not be difficult to detect.
So they cannot edit a picture, even trying to feed it back into the sensor. And. if the signing is built into the die of the sensor, it would take incredible resources to even attempt to feed new data into the sensor grid itself, tech vastly beyond anyone but a nation state.
>I think having having which people may treat ad evidence which is trivial to fake is worse than something which people won't treat as evidence
So you're against police body cams, because everyday people might be faking all the bad police interactions? Because all cameras I've looked into would be easier to tamper with than one designed with signed images that's done well.