So no, C2PA is not as easy to spoof as EXIF.
And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.
So no, C2PA is not as easy to spoof as EXIF.
And no, the existence of DRM doesn't validate the integrity or the provenance of the bytes.
What happens when someone extracts the signing key?
The presence of cryptography doesn't magically make something trustworthy.
It's like saying a prisoner has the same freedoms as everyone else because he could theoretically escape.
Here's a cryptographically signed + timestamped photo of me winning the lottery: https://verify.contentauthenticity.org/?source=https%3A%2F%2...
Would you like to buy my winning ticket from me?
(Compare against winning numbers and draw timestamp at https://www.euro-millions.com/results/28-08-2026 )
In cryptography, once any SINGLE person in the world has compromised a signing key, EVERY person in the world can use it.
Thus for a prisoner analogy, its equivalent to say once any SINGLE prisoner escapes, EVERY prisoner has the ability to escape.
So yes, in this terrible analogy it means all prisoners are free.
If that were the case, I can imagine a subscription service in which you get a camera for some specified period of time, and then return it to the company that sold it for them to verify the camera hasn't been tampered with. Then the company could publish a list of which keys (unique per camera) have been verified to not be tampered with. Maybe this wouldn't stop everyone, but now the person trying to fake images has to re-do the process every so often and I imagine it's more expensive to avoid leaving evidence.
This might be too impractical to work, and it would be bad for privacy, but maybe for some people the tradeoffs actually would be worth it, someday. For now, I assume there are much cheaper and easier ways to detect faked images, at least for expert humans.