Preserving trust in photojournalism through authentication technology
reutersagency.com
reutersagency.com
How exactly do you keep the edit log private without completely losing the chain of authenticity here? One of those edits might be to, say, double the size of a plume of smoke or change a signal flare into a set of missiles[0]. All you have is a promise that at some point, someone opened a real image in some kind of editing software.
The inclusion of a bunch of blockchain nonsense to store the verification also smacks of amateurism. You don't need a public chain with financial costs attached to secure photos you validate yourself. You can just publish a bunch of hashes and a hash of the prior block. Certificate Transparency does this and it works.
[0] https://en.wikipedia.org/wiki/Adnan_Hajj_photographs_controv...
Mostly agree on the blockchain shenanigans, though I suppose using an external blockchain allows you to prove that the image was taken before a certain point in time.
So this scheme can work to ensure that you're seeing the Reuters published version, not that Reuters itself didn't edit it after the camera took it.
Does that help?
>nobody's going to request the huge RAW files for every photo
I don't see this as a big issue as there are several easy ways around it -- the simplest being that the camera could compute and store a second digital signature of a smaller, JPEG-compressed version at photo time. Another possibility is third-party businesses popping up that you (or even high-quality news agencies themselves) pay to do the human verification for you.
Regarding your other comment, sure, such a manual system might be possible, but that relies on either Reuters publishing all of their unedited raw photos (which they probably won't) or a third party photo escrow service with all the rights to the Reuters originals. Neither seems likely.
I don't think this is an easy a problem as you might imagine? Perceptual hashing is a thing but there's no guarantee of forensic accuracy there.
Reuters has a history of doctoring its photos: https://en.wikipedia.org/wiki/Reuters (photo controversy section)
It's not OK when reporters or papers do things like that.
You have the final image (your browser downloaded it to display the page). Their new tech allows you to acquire something that you can be cryptographically certain is the original image. You can then look at the two images, and judge for yourself whether they look similar enough. Where does perceptual hashing come into it?
ETA:
>Regarding your other comment, sure, such a manual system might be possible, but that relies on either Reuters publishing all of their unedited raw photos (which they probably won't) or a third party photo escrow service with all the rights to the Reuters originals. Neither seems likely.
No it doesn't -- they just need to provide those photos on demand. (If they don't, then their system is a hoax -- like giving someone a key that doesn't open any lock.) See my other comments in this thread.
>Reuters has a history of doctoring its photos: https://en.wikipedia.org/wiki/Reuters (photo controversy section)
Didn't read the link but based on another's reply comment, the added smoke is exactly the type of fraud that this new system will detect the first time anyone bothers to check that photo.
It’s trivial to work around this and create inauthentic signed images by staging a fake scene, or doctoring an image and then feeding the doctored image into the camera sensor.
For more details see https://www.hackerfactor.com/blog/index.php?/archives/919-Cl...
Also: Could you, actually? Maybe photos of monitors have "tells" that can be detected with some kind of image processing.
Will that reputational risk actually have any teeth? That's up to us (society at large).
You can already do it now. Somebody even sells premade ones because some people what to screw up Pokemon go players. And it even already caused safety problems. It's the easiest thing of the whole part. Modifying camera require skills. Spoofing gps can be done with a gps spoofer that you may be able to buy somewhere.
A spoofer could obtain signed GPS signals from the time and location where they are claiming to have taken a photo and combine them with a photo taken in a different time and place.
Now, maybe on an interplanetary scale (with various sources playing the role of the GPS satellites, and various locations doing secure timestamping) it could be enough in order to be able to establish (beyond plausible hope of spoofing) a kind of rough region in space-time, but, maybe not very precise.
> It’s trivial to work around this and create inauthentic signed images by staging a fake scene
I'm not sure what the implication of this is. Reuters is attempting a basic technological solution to a technological problems (images can be duplicated, altered and reshared by non-Reuters parties for malicious purposes).
Someone staging a fake scene is not a technological problem that can be solved (though I imagine some amount of depth information and geo-data in the image would help)
I've seen photos of the recent nazi rally in Orlando that were very slightly manipulated to darken the skin of participants to imply they were, in fact, "infiltrated BLM or Antifa".
Anyone could use this system or a similar one - if the sensor signs the image with its private key anyone can trace a raw image to a specific sensor and, therefore, to a specific camera. If that image (or enough hash bits it becomes impractical to fake the data via collisions and still have a recognizable image) is placed on a public ledger, you can prove those pixels are yours and were taken at or before the moment in time they were added to the ledger. If the camera is part of a larger system, such as a phone, the software can add your own credentials to the raw image data, proving it was you who took the picture (unlocking the phone with, say, your face).
I would not, however, want my personal family photos to be trackable like that. EU restrictions on images already took away a lot of my joy of photographing people.
1. How will the signing key in the camera be protected? Are camera manufacturers a SPOF?
2. Based on the following quote:
>Editors then work with the pictures, and each successive modification or edit creates a new record in a private database (ProvenDB) that is indexed to the original registration.
How do you ensure that one of the modifications was not "replace all pixels with the one generated by AI", or even "Replace Russian flag with Ukrainian flag"
I only see this possibly working if the new organization releases the raw signed photos to the public. Otherwise, the edit step can do anything.
0: https://en.wikipedia.org/wiki/Digital_Signature#Non-repudiat...
The technical magic is in a (pretty old, pretty basic) crypto primitive called a digital signature, which doesn't actually require storing the originals publicly at all times -- all that's needed for you to verify Canon/Reuters's claim of photo authenticity is for them to supply the original raw pixels when someone "sufficiently important" (maybe you, or maybe a court judge, etc.) demands it. You can then check whether what they give you is in fact the true original by verifying it algorithmically with the JPEG's signature and their public key.
Storing the original in a publicly accessible place is good but kind of secondary -- it's just the most straightforward and convenient way for them to "produce it on demand".
EDIT: Clarified "their signature and public key"
OTOH, yes, privacy and upsetting content are reasons why they might hold some (or all) back from Joe Public and only provide the bits to someone more authoritative.
[1]: https://iacr.org/submit/files/slides/2023/rwc/rwc2023/13/sli...
(Also, I'm really cool for predicting ~5 years ago that this specific tech would happen -- bringing my count of successful tech predictions to 1.)
https://www.washingtonian.com/2017/01/20/searching-metaphor-...
To preserve something, you have to have it first.
[1] https://medium.com/@boneh/using-zk-proofs-to-fight-disinform...
The reason is that this trust was misplaced in the first instance.
I don't follow. Sure, existing images can't be retroactively made verifiable, but tech like this can stem the tide from this point on, and that is useful.
>The reason is that this trust was misplaced in the first instance.
I don't follow this either. Trust in photos? It has always been appropriate to trust a photo in proportion to the difficulty of faking it. Are you commenting on the fact that it has recently become much easier to fake a variety of photos (deepfakes, etc.) but a large fraction of society isn't yet wise to this?
For an example, consider a side on closeup of a trump campaign speech vs a top down view zoomed out of the whole park.
Photojournalists can choose which pictures to use to make an argument, and people are too trusting that there aren't alternatives that more strongly support a different argument
The photo doesn't have to be untrue to be misleading
This is a genuine concern, but one that's shared by all forms of inductive reasoning. The same concern could be raised about everything our senses tell us about the world.
Gpg is well established and eminently applicable here. Both the camera hardware as well as the photo journalist could sign the image data payload, and embed the signature in metadata, especially if the camera hardware accepted new keys. Trust chains could be established both via their publisher and the camera manufacturer.
But let's be real: no one will bother to validate anything.
* I'm being diplomatic
I think there are significant issues with establishing the “authenticity” of digital artifacts in any scheme, but GPG would probably make things worse rather than better here.
But modern alternatives would be SSH signing, signify/minisign or cosign.
Modern cryptographic protocol design has moved away from “Swiss Army knife” designs: protocols and formats are now designed to do one thing well, rather than a whole bunch of things poorly and with an unintuitive user interface.
In other words: use TLS to communicate securely with services. Use Signal or another modern E2EE IM protocol to communicate securely with humans. For file encryption, use age. For digital signatures, use minisign or Sigstore.
[1]: https://blog.cryptographyengineering.com/2014/08/13/whats-ma...