This seems like an obvious solve. Produce cameras with HSM (hardware security modules) that cryptographically sign the image using the existing certificate infrastructure. Get browser vendors to visually indicate signed images. Now you have a "class" of images that are known to be produced by taking a photo with a verified device.