That's also why the approach is fundamentally flawed. The open-ish C2PA protocol has been "defeated" by tricking phones into signing arbitrary data already. The even-more-closed Apple version can be defeated the same way and relies on Apple to be the sole arbiter of truth.
any other similar approach is also dead on arrival, I can't believe so many apple engineers fails to see it? it's like siri 2012 all over again
Incorrect. There is nothing here requiring closed source. Only private keys need to be kept private for obvious reasons
its impossible in closed source. there is no reason to believe it does what it says it does. only private keys in the chain need to remain secret.