I realize this would still allow fakes to be presented by governments in all likelihood, but not everyone.
I realize this would still allow fakes to be presented by governments in all likelihood, but not everyone.
You'd also need close to 100% adoption for this to be effective, otherwise people will just assume the fakes were recorded with one of the cameras that doesn't have that feature, or that they didn't bother to upload the raw footage anywhere.
I'm not aware of any secure digital signature schemes that don't require the thing they signed to be bit-for-bit identical to pass verification. There are perceptual hashing algorithms that could theoretically be used to build such a scheme, but such hashes are not second preimage resistant, so someone could create a modified video that still passes signature verification.
I suppose the validator could do a fuzzy match and just output a similarity score that compares the result to the original image. IE - This image is 75% similar to the original with something like a perceptual hash. Then it's the users problem to decide if 75% is close enough for their trust.
You want it visually identical but not necessarily bit-for-bit identical. Compression and transcoding should not cause validation to fail unless the compression artifacts are particularly severe, but even a tiny, one-pixel change that substantially alters the appearance of the photo should cause validation to fail.
And yes I agree this is hard to quantify and impossible with existing algorithms, that was my point.
As someone with a passing interest in infosec and cryptography, I'm sceptical of the long-term viability of this kind of product; it only takes one person successfully extracting a signing key to undermine the entire project.
[0] https://leica-camera.com/en-int/news/partnership-greater-trust-digital-photography-leica-and-content-authenticity-initiativeI just think there is a world of difference between "certainty" and "plausibility" when it comes to videos on the internet. Yes, state actors might circumvent it, and skepticism should remain, but there is a world of difference between North Korea trying to convince me of some political scandal, and Pepsi Co trying to convince me that someone I trust loves Pepsi.
There might be a specialised line of cameras for forensics that signs the output and has lidar to detect when the camera is pointed at a screen, but the average person won’t have a camera with this kind of crypto. It would just be too easy for hackers to extract the keys from.
they're already locked down as-is.