C2PA from the Attacker's Perspective
hackerfactor.com
hackerfactor.com
BTW I guess 'watermarks' can be easily scrambled; add noise, filters, &/or recompress into another image format (eg JPEG -> AVIF).
wtf? It looks like either the date itself isn't signed, or that the validation service doesn't bother validating the date is signed? Later on it says
>This isn't a code problem, this is a standards definition issue.
But it's not clear why the timestamp can't be validated. The timestamping infrastructure used for Windows authenticode signatures seem to work fine. Why can't the C2PA get their timestamping scheme to work?