I don't see this as any different. We will determine new ways of establishing trust. They'll certainly have flaws, as establishing trust in a society always has, but we'll learn to recognize those flaws and hopefully fix them.
Beyond that, what's the alternative? Banning the technology? That doesn't seem feasible for various reasons, not least of which is it isn't going to stop bad actors. Another pretty good reason is it's just not really possible - anyone with enough compute can build LLMs now.
As a bit of an aside, why hasn't society fallen yet? I mean, ChatGPT has been around for a couple years now, and I've been hearing about how LLMs are the single greatest threat to civilized society we've ever faced... yet they don't seem to have had a major impact.
Now it's utterly simplistic to forge, to libel, to slander, and there is no easy path in many cases to sue.
While you can say "yes, but..." to the above, that's the reality that we've lived with for 150 years, less extremely rare edge cases. All this has changed over the course of a couple of decades, with most of that change in the last 10, and focuses on the last 2 years.
Beyond that, it took significant effort and labour to create fake stories and images. People had to be experts, or be wordsmiths. Now, click click, and fake generated stories abound. In fact, they're literally everywhere. There's absolutely no comparison here.
Now, in the time it used to take one person to generate one fake story, you can generate millions and trillions if you have the cash. Really, it's the same problem with spam phone calls, and with spam email.
You didn't get 1000 spam letters in the mail in the 80s, because that cost money. Email was free, thus spam became plentiful. The same with spam phone calls, it cost hard cash for each call, now it's pennies per hundreds of automated calls, so spam phone calls abound.
The same is happening with all content on the internet. Realistically the web is now dead. It's now gone. Even things such as wikipedia are going to die, as over the next 2 to 3 years LLM output will become utterly and completely indistinguishable in all aspects.
Like I said, people have been saying this exact thing for a couple years now. I'm sure I'll be hearing the same in a couple more.
We should train users to ignore news from unverified sources.
We should observe and track the reputation of journalists, and stop broadcasting testimony that is untrustworthy.
Similarly, Google doesn't let you use face matching in image search to find every photograph of you on the web, even though they could, and quite similar technology is built into Google Photos.
Voice impersonation has been possible forever, actually; and it use for misinformation (as well as less nefarious things like entertainment) is hardly novel. (Same with impersonation that goes beyond voice.)
Yeah, preserving the chain of custody is hard. I was thinking there are a few options: (1) the signature of the original video could be attached even after editing/compression, and then a news org would let you look up the signature. That way if someone copied the signature and stuck it on a fake video, you could see the original video that actually passes with that signature, and determine if something has been doctored. Or (2), you could have editing software add a signature verifying the edits made: eg compression, rescaling etc.
And then a law to make it illegal to remove/tamper/valsify a signature, like we have for DVDs, to allow some form of prosecution. The hardware stack is a little easier to protect; the software stack less so. But if we can do it with things like eg browser DRM or http signatures, maybe we can with media editing software? But I'm not versed enough in Cryptography to really know.
And cool will read up on intel SGX, thanks!
I've thought about this sort of approach many times in the past, and also done a lot of work with SGX and similar tech that implements remote attestation (RA). So I know how to build this sort of system conceptually. RA lets you do provable computations where the CPU can sign data, and the "public key" contains a hash of the program and data along with certificates that let you check the CPU was authentic. And it runs the program in a special CPU mode where the kernel and other things can't access the memory space. That's all you need to do verifiable computation.
So to preserve chain of custody you just have a set of filters or transforms that are SGX enclaves running ffmpeg or whatever, and each one attaches the attestation data to the output video which includes a hash of the input video. Then you gather up a certificate+signature over the original raw video from the camera (the cert is evidence the camera is authentic and the key is protected by the camera - you can get this from iPhone cameras), then an org certificate showing it came from a certain company, and then the attestation evidence for each transform. A set of scripts lets people verify all the evidence.
The problem is, after doing some business case analysis, I concluded it would only really be useful in some very small and specific cases:
1. Citizen journalists who are posting videos online that then get verified by news orgs. So the other way around. In this case the origin camera would use iPhone App Attestation to generate the source certificate, and all the fancy attested transform stuff isn't really important because it's the news org doing the transforms and doing the verifying.
2. Phone cam shots for insurance and other similar use cases. There is some business potential here, but it'd be sales force heavy as nobody knows the tech exists and deepfake fraud may not be a big enough problem for them to care (yet ...). If someone is looking for a startup idea, have this one for free.
3. Very new news companies that don't have any reputation yet and want to stand out from the crowd.
The thing is, for (3) or any place where a news org wants to increase the trust of the viewers, you don't need cryptography. That's just over-complicating things. You can just put a short random four letter code into the chyron that's unique to that particular shot you see on screen. Then on your website you have a page where the original unedited files can be downloaded by supplying the code. If you use cameras that produce cryptographic evidence like timestamps that's gravy, and for browny points you could publish video hashes into an unforgeable replicated log to stop you backdating footage. For most people that will be more than good enough. The sort of thing that causes people to lose trust in media is stuff not CNN broadcasting outright deepfakes, although that will happen eventually, but when they engage in selective editing, drop stories entirely, use archive footage and misrepresent it as something new etc.
The worst kind of fakery I've seen mainstream media engage in was Channel 4 UK's recent broadcast of a fake news segment, in which they "secretly filmed" someone who was pretending to be a racist Reform activist. People on X swiftly discovered that the person on-screen wasn't an activist at all but a professional actor, who had been putting on a fake accent the whole time (that he even advertised on his website). It looks for all the world like C4 broadcast entirely and truly fake news, knew they were doing it, and when they were called on it they just flat out refused to investigate knowing the British establishment was behind them all the way, as Reform is unpopular with the civil servant types who are supposed to police the media.
Unfortunately, for that kind of fakery there is no technological solution. Or, well, there is, but it's called social media + face recognition, and we already have it.
There is no alternative to this idea. It is completely impossible for an individual to possess all of the knowledge of everything that affects their lives. The only option for getting some of this information is going to trusted sources that compile it and present some conclusions.
This applies just as much to scientific knowledge as it does to medicine or to politics.
If you want to avoid trusting any authority, it's hard to even confirm that North Korea exists. Confirming that it is ruled by an authoritarian regime and that it possesses nuclear weapons is impossible. And yet it's a trivial bit of info that everyone agrees on - imagine what avoiding trusted authorities would do to knowledge about other more subtle or more controversial topics.
I said do your thinking for you, not do your information gathering for you.
I would suggest that you do not trust any single source to only ever tell you things that are true. If there’s a topic you want to know something about it’s a much better course of action to look at multiple different sources, and do your own thinking to come to your own conclusions.
There are no authorities who can reliably take on this role for you, and LLMs don’t change this. The same is true with science. Even prior to LLMs, the replication crisis should have shown that a single paper on any topic can’t be relied on to contain any truth (the same would be true even in the absence of a replication crisis for that matter).
I very much agree with your actual point - that no source should be trusted absolutely, and that the only way to get a decent-to-solid idea on a topic is to consume multiple sources on that topic.
However, the problem is that even then people have relatively little time. It's important to have sources that one can rely on to be relatively accurate with a high probability, to get some vague idea about a topic you're not deeply invested in, but do care about somewhat. And I think this is where LLMs can hurt the most.
The difference between economically successful countries like the US and the peripheral countries is we are a high-trust society.
I don't spend 100 hours chemically testing my food because I have faith it is safe to eat. I don't waste money on scam after scam because I have faith most businesses are legitimate. If I'm a business, I can order stuff and more stuff and I trust the spec.
Our outsourcing of that trust to other people is what makes us economically successful.
Other countries which don't have this trust focus on basic tasks. Gathering food, water, shelter, and basic infrastructure. Because ultimately every man is out for himself. They aren't building software and airplanes and whatnot. Because as complexity increases, the more people are involved and therefore the most trust is required. Trust is required because of the fundamental limitations of human meat space - we have limited time and survival needs.
Contracts allow for recompense if there is mistrust. We've been signing contracts forever.
Every automated system needs someone to jail in the event of failure.