And equally faked by bots.
And the value of the signature is also going to vary by who claims it. Improbable photos signed by a random camera body sold to an anonymous consumer should be treated with more suspicion than one a newswire agency publicly claims, for instance.
We should be able to move certificates on and off it because they would most likely expire anyway. So, you can get the keys from the camera, what then? You use openssl to sign an image that shouldn't be signed... what then? You do this enough and get caught, you lose your cert and can never pass the kyc to get another one.
Then every picture you used it for in the past would start showing a big red exclamation point with a note, "This is a scumbag user known for forging images".
You do whatever you want with your provably genuine fake image.
> You do this enough and get caught
How are you going to get caught? By the signature owner repudiating some of the images "he" signed? I can see that working out for him.
Besides wasn't your argument "hacking" a minute ago? So you concede that then? You seem to have moved on.
Public would know the pics were fake let alone know who to report.
> They and/or independent firms investigate.
What's to investigate? You have a fake pic that is indistinguishable from genuine and "proved" by a sig.
If your argument is that images can't be verified, you are going to need to provide some kind of backing to that. We know well that there are watermarks and tell tale signs to go off. Regardless, if they are depicting real world events, outside confirmation can be used.
You also don't seem to understand the point of the signature. It's not to prevent fake images, it's to tie an identity to images so that that trust can be established and permanently lost in the case of a malicious actor. Your arguments repeatedly have failed to engage with the actual system proposed.
It was proposed as a solution to: how is any future viewer going to tell your images from "AI" fakes?
You seem to be saying it is not a solution. I agree.
Let's also list the points you have conceded by quietly giving them up:
1. Hacking the camera is irrelevant.
2. Images can be verified.
Do you want to actually engage with the conversation? The funny thing is that there are engineering challenges in this space, but you don't seem to understand the basics well enough to even get to that point.
You've said it, but you've not credibly substantiated it.
Imagine a famous photo journalist dies and there emerge "AI" fake pics signed with creds stolen from his hacked camera. Trust isn't part of a solution. It is part of the problem.
Besides, after a famous journalist dies, their work is already famous, people already know it or don't. This is a contrived and irrelevant example.
Again, this is not hypothetical, we already know how this works. Next one please.
Next one please.
Let's see if you can even explain what I am telling you.
What would be the first step to resolve this issue in the system I am proposing?
I've seen no credible verification method.
If you have, then you are the one that needs to provide backing.
The idea is that a centralized source of trust would revoke certificates belonging to bad actors or those that were stolen.