Inserting fake sensor readings is plausible but complicated enough I doubt any but state actors would or could bother.
Even this standard only raises the cost to create fake images to 100K would be fantastic for journalism and democracy. Much better than the cost being $0.
What DoF/focal length metadata?
Then why not replace the sensor entirely and send fake sensor data? It would be difficult to fake depth of field changes in response to camera's focus motor moving. If I were a security researcher, I would really try to see if the camera is smart enough to tell if the sensor data is fake.
> take a photo of a sufficiently high-resolution display
A 60 MP display? (10000x6000 resolution? I want one!!!) That would still make pixels visible. I suspect a display at least 4x larger would be needed. And it needs to be curved, or the out-of-focus corners will ruin the illusion.
The signature just says who took the picture, not that the image is not ai generated.