Just like https certificate authorities, the only way to fight all the AI slop will be “trusted” camera firmware that signs every image with a full chain of trust that the output was a real physical video taken will a real device at a real location.
Just like https certificate authorities, the only way to fight all the AI slop will be “trusted” camera firmware that signs every image with a full chain of trust that the output was a real physical video taken will a real device at a real location.
This is a terrible idea. So of course it already exists https://c2pa.org/
It’s already being exploited https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html
We need a solution but that’s not it.
I assume that scheme is part of a long-term effort from Google to reinforce the idea that nobody but them should be allowed to have root on their phones, and is therefore working as intended.
That would be my guess as well.
The article criticizes software Attestation which is valid criticism but if the Attestation happened in the camera chip itself and not at OS level then even a rooted system would not be able to cheat a certificate
A rooted phone could not, but anyone with a bottle of acid and a microscope could. Or as I’ve said, a nice optics setup and a high quality projector.
My point being that trusting the camera chip does not help much. But, of course, it would block the easiest software attacks like we have seen so far.
Oh neat, i had no idea it was a thing already. What is a better idea?
Neat - so maybe point and click devices get to make a comeback, or the CCD itself could sign.
I’m not a researcher in this field, so I don’t have anything substantial to suggest. My opinion is that it is unsolvable.
No matter what you try, sufficiently powerful entities will be able to modify the sensor to sign images of anything they want to pass as real (or just use a very high quality projector)
It might be better that we are all always weary of an image being AI at this point.
It’s the same thing as with “watermarking” music files - it’s a bunch of hot air, anybody anywhere can just play them back and recapture the analog, and if the watermark survives that then it’s absolutely going to be audible.