C2PA Cameras Do Not Survive Contact With Reality
58 points by retr0id
58 points by retr0id
i'm extremely uncomfortable with the idea of making Big Techâ„¢ the arbiters of truth (especially if it's the same companies selling the poison and the cure), so i appreciate the effort you have put into this display of the obvious -- impressive work, thank you!
(side note: the banner ad at the end made me genuinely lough out loud, and made me realize ublock crashed on my hacked up browser build)
Especially when "truth" or "security" is coming from their attestation of device and software stack, giving them ability to cut off any player from the market, by making the device untrusted by the companies (Play Integrity) and now by other users (C2PA).
Meta already patched the CVE-2026-43499 LPE on Quest headsets, near the start of the month, to stop people from cheating in VR video games. It's absolutely bonkers to me that Google has not issued a patch for even their flagship Pixel devices yet.
Might it be a revealed preference of megacorps: cheating in VR games is a serious issue, and users' security is not?
Repeating a joke: New lesson for security researchers: when you find a vulnerability, don't use it to steal crypto keys, escalate privilege, or execute shellcode. Just write video game cheats, and the anti-cheat industry will make sure it's patched. DMA attacks were long considered a hypothetical method for FBI/NSA to steal a dissident's laptop disk encryption key in a cafe, yet after a decade of demos, VM and QubesOS users still needed to hunt for motherboards with proper IOMMU. Even after Thunderbolt and USB 4 made these attacks universal, for a long period nobody really cared. It only became the default right now thanks to PCIe cheat hardware. Advancing security and privacy for free software desktops, who cares? Video games losing money? Much better.
Optimists thought that rooting a Pixel is already bad for mobile games! Apparently not bad enough to push Google to do something.
Hackerfactor.com has a long line of blog posts about the myriad of ways that C2PA is broken and misleading. Eg https://hackerfactor.com/blog/index.php?/archives/1080-C2PA-in-a-Court-of-Law.html
The fact I keep hearing about it being pushed is very disheartening. Someone has a business model in mind and doesn't care about the impact on the public.
He's also written about my findings, here https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html - definitely worth a read for the bigger-picture view
Tangentially, I'll probably have some fun with keystork, and dig into my Android TV further. It's very weird under the hood (it doesn't even boot normally, it has a funky custom linux distro that handles a lot of the tv side, and the android parts are just booted in a chroot)
Oh look, more reasons to justify making it impossible to root the devices we own. Good thing none of these reasons are stifling competition or otherwise greedy.
I hate this for a few different reasons. But leaving that aside...
The theory behind the design of the attestation mechanism is that known software LPEs should be patched, and then the Relying Party (the entity verifying the attestation report) can require that users install the updates, and then the updated device can no longer be LPE'd.
Will this even be implemented in practice? Are we going to have "Update your device so that we can check that your media isn't AI generated and then refilm/retake it" prompts start coming in soon? Or are the Relying Parties just going to ignore the software version metadata to avoid user frustration?