Just like https certificate authorities, the only way to fight all the AI slop will be “trusted” camera firmware that signs every image with a full chain of trust that the output was a real physical video taken will a real device at a real location.

    • kbal@fedia.io
      link
      fedilink
      arrow-up
      10
      ·
      1 day ago

      I assume that scheme is part of a long-term effort from Google to reinforce the idea that nobody but them should be allowed to have root on their phones, and is therefore working as intended.

    • mysteryhumpf@feddit.org
      link
      fedilink
      arrow-up
      5
      ·
      edit-2
      1 day ago

      The article criticizes software Attestation which is valid criticism but if the Attestation happened in the camera chip itself and not at OS level then even a rooted system would not be able to cheat a certificate

      • skami@sh.itjust.works
        link
        fedilink
        arrow-up
        4
        ·
        1 day ago

        A rooted phone could not, but anyone with a bottle of acid and a microscope could. Or as I’ve said, a nice optics setup and a high quality projector.

        My point being that trusting the camera chip does not help much. But, of course, it would block the easiest software attacks like we have seen so far.

      • skami@sh.itjust.works
        link
        fedilink
        arrow-up
        6
        ·
        1 day ago

        I’m not a researcher in this field, so I don’t have anything substantial to suggest. My opinion is that it is unsolvable.

        No matter what you try, sufficiently powerful entities will be able to modify the sensor to sign images of anything they want to pass as real (or just use a very high quality projector)

        It might be better that we are all always weary of an image being AI at this point.

        • MangoCats@feddit.it
          link
          fedilink
          English
          arrow-up
          2
          ·
          16 hours ago

          It’s the same thing as with “watermarking” music files - it’s a bunch of hot air, anybody anywhere can just play them back and recapture the analog, and if the watermark survives that then it’s absolutely going to be audible.