signed photos and content provenance: what broke in 2025â2026, and what to research
(authored by agents unless marked đ§)
read this first
- this extends your photo crypto auth notes and the c2pa folder, both from Dec 2024
- short version of what happened since
- C2PA shipped on phones and cameras, then got broken in public
- Pixel 10 signs every photo in hardware (Sep 2025); a rooted Pixel can still make the chip sign any file (Aug 2026); Google: âWonât Fix (Infeasible)â
- Nikon Z6 III shipped C2PA (Aug 2025), a hobbyist signed an AI image with it, Nikon revoked every certificate and suspended the service
- a university team did the first formal analysis and says âit should not yet be relied upon for high-stakes usesâ
- the âphoto of a photoâ question you marked â now has a real literature, and it is an arms race
- attack (Chimera, USENIX Sec 2025) â depth defense (Scoop, USENIX Sec 2025) â $210 optical attack (WOOT 2026) â dual-pixel defense (lab only)
- almost nothing on the web carries C2PA: 27 of 6,580 news images in Oct 2026, none from a camera; platforms strip it
- proving edits in zero knowledge went from a server with 120 GB RAM to a laptop in 6.6 min; still trusts the camera
- C2PA shipped on phones and cameras, then got broken in public
- my top three research ideas, details under âresearch ideasâ below
- a differential tester for C2PA validators: feed the same crafted files to every validator, reproduce known disagreements, then test for new failures under matched specification and trust settings
- an evidence package that keeps a signed photo verifiable for 10 years: trusted timestamps already permit validation after certificate expiry; measure missing archival evidence and policy changes
- a repeatable platform and CDN audit of what survives upload; the only numbers are one-off tests by journalists and a 59-upload preprint
- fact vs opinion
- cards quote the sources verbatim; âwhat it showsâ lines are my plain reading
- the ideas and rankings are my opinion
- papers from 2025â2026 are the ones you most likely have not seen; your notes already cover most of 2023â2024
what changed since your notes
- phones and cameras
- Google Pixel 10 (Sep 2025): keys in the Titan M2 chip, one certificate per photo, âPixel maintains a trusted clock in a secure environment ⊠to generate its own cryptographically-signed time-stampsâ (Google security blog)
- the only product at C2PA âAssurance Level 2â for a phone app, per Krawetz
- Samsung Galaxy S25 and S26 Ultra: C2PA on Galaxy AI edits only (c2paviewer device list, secondary)
- Apple: announced âApple Reference Imageâ with iPhone 18 Pro and iOS 27 (Sep 2026), proprietary, not C2PA; signs âraw pixel data at the camera sensorâ, opt-in per shot (MacRumors, news)
- Nikon Z6 III: C2PA firmware Aug 2025, suspended Sep 2025, all certificates revoked; still suspended early 2026 (PetaPixel, news)
- Sony, Leica, Canon: Leica M11-P and SL3-S, several Sony bodies, Canon âstill developingâ (secondary sources, not verified by me)
- Google Pixel 10 (Sep 2025): keys in the Titan M2 chip, one certificate per photo, âPixel maintains a trusted clock in a secure environment ⊠to generate its own cryptographically-signed time-stampsâ (Google security blog)
- governance
- C2PA Conformance Program launched 2025; two assurance levels; signing certificates last at most 366 days (level 1) or 90 days (level 2); details in the conformance card under âtrusting a signature for yearsâ
- EU AI Act Article 50 and an EU Code of Practice on AI transparency drive AI-labeling; platform audits below show labeling reaches a minority of fakes
- your platform notes need updates
- X still strips everything: âTwitterâs CDN strips all embedded metadata on uploadâ (Zewde 2026)
- TikTok reads C2PA and writes its own AI label into downloads; YouTube reads C2PA and showed a âcaptured with a cameraâ box that Buchanan forged
- LinkedIn still shows the icon; Meta reads only the âAI generatedâ signal
- Cloudflare Images can keep and extend manifests on resize (opt-in per zone)
answers to your open questions
- âTaking photo of photo ⊠Literatures? ⊠Bad search termâ
- search terms that work: ârecapture attackâ, ârebroadcast attackâ, âscreen recaptureâ, âmoirĂ©â
- state: image-only detectors reach 97â99% on fixed datasets but a trained attacker drops them to near zero (Farid 2018, Chimera 2025); phone depth sensors catch TV recaptures (Scoop, 94.81% on iPhone) but a hot mirror plus a cardboard cutout beats that 100% (WOOT 2026); next defense (dual-pixel sensors) is lab-only
- Apple and Samsung âresponded that recapture detection via Scoop is not a security feature of their productsâ
- your RGBD idea: already built (Scoop) and already broken; the open gap is a defense that works inside a signing pipeline and a benchmark that counts false alarms on honest flat scenes (murals, documents)
- âPKI: long term verification support? Literatures? Trusting signed document long termâ
- mechanisms exist and are old: RFC 3161 timestamps, RFC 4998 evidence records with renewal, RFC 9921 (Feb 2026) for putting a timestamp on a COSE signature, OpenTimestamps and transparency logs for an independent witness
- C2PA practice: a timestamp lets a 90-day certificate stay valid, but the timestamp covers only the signature bytes, exclusion ranges can empty the hash, and validators need not check revocation
- measured problem: âsome C2PA-signed media have already become unverifiableâsometimes within monthsâ (Golaszewski et al.); an Arizona pilot image âvalidated in January 2025, but fails to validate a year laterâ
- the archival-measurement gap remains unconfirmed; this is idea 2 under âresearch ideasâ
- âRemoving metadata rids hard binding. Soft binding improvements?â
- C2PAâs plan: watermark carries an ID, a manifest store returns the manifest, a fingerprint checks the match (CAI âDurable Content Credentialsâ, 2024, no evaluation)
- evidence for: one 2026 paper found a Meta watermark survived JPEG, crop and screenshot-like degrading with bit accuracy â„0.902 (Nemecek 2026)
- evidence against: MarkNull (USENIX Sec 2026) pushes watermark bit accuracy to 53.14% and beats SynthID-Image on 20 images; Fairoze et al. prove a robust, unforgeable, publicly checkable watermark needs âa leap in deep learning capabilitiesâ
- Microsoft Research: fingerprinting âis not a viable path to high-confidence validation and faces significant scaling costsâ
- nobody has tested the whole recovery loop (strip â watermark â store â match) end to end on real platform pipelines; part of idea 3 under âresearch ideasâ
- âbuild open-source solution for mobile?â and âPKI: get certificate? scaling? revocation?â
- the design is now public (Google): key in StrongBox, Android Key Attestation at enrollment, a CA issues one certificate per photo, no account, on-device trusted clock
- the cost side you worried about is gone: Googleâs CA charges nothing and ProofMode is GPL; Truepic pricing is irrelevant now
- the hard part is not cost, it is meaning: âan attacker does not need the raw key material! As root, they can ask StrongBox to use these keys to sign whatever data they likeâ (Buchanan); all Android C2PA camera apps he checked are âbroken in the same wayâ
- Microsoft Research agrees in principle: âavailable protections to stop a key being used by an unauthorized application are very limitedâ
- revocation versus privacy is unsolved: one certificate per photo means you cannot revoke a compromised device without revoking every real Pixel photo (Krawetz)
- my take: an open-source phone signer is cheap to build and would be no worse than Pixel Camera, but a paper needs a claim beyond âwe built itâ; the candidate claim is a privacy-preserving revocation handle, or binding the signature to sensor data via the OS camera HAL, which Buchanan says needs âcompletely rearchitecting the software stackâ
- âinfluencer have posted genuine photo but for irrelevant eventâ and Ardi & Madhyastha
- their PDF is a 3-page proposal (created Sep 2024, no venue, nothing evaluated); it assumes âevery photo and videoâ will carry signed time and place
- the vision side has datasets and models (NewsCLIPpings 2021, COSMOS 2021, COVE at NAACL 2025) that use pixels and text only, no signed metadata
- the signed-metadata premise is weaker than in 2024: Pixel 10 puts EXIF and GPS in an exclusion range, âenabling an attacker to insert a false GPS locationâ (Golaszewski et al.); Scoop notes GPS âvulnerable to spoofing through low-cost toolsâ
- still unbuilt; see idea 5 under âresearch ideasâ
- âCamera private key leakâ
- happened in practice without a leak: Nikon multiple-exposure trick, Pixel rooted signing; the key stays in hardware, the signing path is abused
- validators mostly ignore revocation, and a timestamp can âun-revokeâ a certificate, so a stolen key plus backdating is the open attack (Krawetz; SEAL review by UMBC)
research ideas
- differential testing of C2PA validators (strongest, my opinion)
- claim: âthe same file gets different verdicts from different conforming validators, here are N classes of disagreement, and M of them let a forged or edited file passâ
- why it sells: Golaszewski et al. found validator inconsistency by hand and call for âMandate consistency across validation toolsâ; Buchananâs empty-hash file passed âall the C2PA verification tools I can findâ; CVE-2026-34668 is a parser crash in c2pa-rs; the official public test files are an additional baseline; broader automated testing coverage is unconfirmed
- build: a generator of mutated manifests (exclusion ranges, timestamp payloads, revoked and expired certificates, trust-list choice, multiple claims, redactions); run c2pa-rs, c2pa-web, Adobe Inspect, CAI Verify, Truepic, Verifieddit, Google Photos, YouTube; cluster the disagreements
- baseline to beat: UMBCâs manual tests and the public test-file set
- risk: web validators rate-limit or change; mitigate by local libraries plus a small browser harness
- venue: USENIX Security or CCS; also IMC if framed as measurement
- your fit: it is a systems and testing project, no vision, no crypto
- long-lived evidence for signed photos
- claim: âa signed photo verified today fails in T months under policy P, and this package of K bytes keeps it verifiable for 10 years across validatorsâ
- why it sells: 90-day certificates, âunverifiableâsometimes within monthsâ, â16 of 22â TSA certificates without revocation (Krawetz), timestamps that un-expire keys, no validator agreement; archives and courts are a real customer (CITP newsroom guide, Krawetzâs court post)
- build: an archiver that stores bytes, manifest, chain, OCSP responses, RFC 3161 token, an OpenTimestamps or transparency-log receipt, the trust list snapshot; a replay harness that advances the clock and rotates trust lists; RFC 4998 renewal
- measure: which validators change verdicts and when; storage and renewal cost; share of real C2PA files in the wild that already fail
- baseline: ETSI long-term signature profiles (CAdES/PAdES) and RFC 4998, which solve this for documents but are not wired to C2PA
- risk: it may turn out that âjust add an RFC 3161 token and a log receiptâ is enough; then the paper is a measurement of how much of the deployed base lacks it, still publishable
- venue: USENIX Security, or a systems venue if the archive design is the contribution
- a repeatable upload audit: what survives each platform and CDN
- claim: âacross P platforms and C CDNs, hard binding survives in x%, the AI label in y%, soft-binding recovery works in z%, and here is a monthly dashboardâ
- why it sells: the only numbers are the Washington Post test, Indicatorâs 516-post audit (30% labeled), Rijsboschâs 59 uploads (61%), Metawatchâs lead-photo crawl; nobody tests the recovery loop
- build: sign test images with a camera (Pixel 10), an AI tool and your own signer; embed TrustMark or Video Seal; upload to Instagram, TikTok, X, YouTube, LinkedIn, Bluesky, Mastodon, Telegram, WhatsApp; download; check manifest, watermark, fingerprint match against a local manifest store
- risk: terms of service and account bans; use few accounts and public posts
- venue: IMC, WWW, or CSCW if paired with the label-display question
- overlaps with the sibling web measurement group; coordinate
- sensor-bound signing on a phone: what would it take
- claim: âan Android camera HAL extension can bind a signature to sensor frames so a rooted OS cannot sign arbitrary files, at cost X ms and Y mWâ
- why it sells: Google calls the fix infeasible; Microsoft Research says enclaves are âessentialâ; ProvCam shows a full custom module costs 53.8M transistors and under 1 W, but no one has tried the cheaper middle (TEE-side frame hashing in the camera HAL, or a dual-pixel depth check inside the TEE)
- build: on a dev board with an open camera stack (or an AOSP phone with a GKI kernel and a Trusty TA), hash frames in the TEE before the ISP hands them to Android; sign in StrongBox over that hash
- risk: hardware access and vendor blobs; may only work on a dev kit, which reviewers may accept as a feasibility study
- venue: MobiSys, MobiCom, or USENIX Security
- this is the open-source mobile signer you wanted, with a claim attached
- caption-versus-capture contradictions with private predicates (Ardi & Madhyastha, built)
- claim: âsigned capture time and place reject x% of fact-checked wrong-context posts with y% false alarms, while disclosing only interval membershipâ
- build: corpus from fact-checker archives (place, time of the real photo), caption parser (LLM), predicate check on intervals; compare against COVE and NewsCLIPpings-style models; optional zero-knowledge interval proofs later
- risk: the premise needs signed, protected time and place, which Pixel 10 does not give; the honest paper measures the gap and says what metadata must be inside the hash
- venue: WWW, ICWSM, or CSCW
- revocation that keeps per-photo privacy
- claim: âa device can be revoked without linking its photos, using group signatures or a per-device blinded handle in the certificate, at cost Xâ
- why: Krawetz shows the dilemma on Pixel; VerITAS slides list âPrivacy â group signaturesâ as open; ProvCam says DAA âmight not be idealâ
- risk: it is crypto design, outside your stated strengths; reviewers at S&P would want proofs
- ideas I would skip
- a new recapture detector from images alone: Farid 2018 and Chimera show it is a losing loop, and vendors say it is not a security feature
- blockchain-anchored C2PA: covered by BureacÄ 2024, Numbers, Nodle; a log receipt (SCITT, OpenTimestamps) gives the same guarantee without the baggage
- another user study on labels: four already exist (Feng 2023, Trattner 2026, Höltervennhoff 2026, Pawelczyk 2026, Koech 2026), all agree labels help and create over-reliance
literature cards: attacks on deployed C2PA
- Golaszewski, Krawetz, Sherman, Zieglar, Matukumalli, Yus, Kegley, Barthel, Bowman, Barot, Kullman, âVerifying Provenance of Digital Media: Why the C2PA Specifications Fall Shortâ, arXiv 2604.24890, Apr 2026; long version âSecurity Analysis of C2PA and its Implementationâ, IACR ePrint 2026/804, revised Jun 2026
- label: preprint (UMBC with NSA co-authors); no venue found
- âOur study includes the first formal-methods analysis of C2PAâs core protocols. We find that the current C2PA specifications fail to achieve their claimed security goals.â
- âConforming validators are not required to check for revoked certificates, allowing adversaries to use compromised keys without detectionâ
- âNothing in the signed data references the timestamp, allowing removal and replacement without detection.â
- âGoogleâs conforming Pixel 10 Pro camera places GPS information in an exclusion range, enabling an attacker to insert a false GPS location.â
- Nikon test: after revocation, âAdobe Inspect (pictured here) reports the signature as valid, while Verifieddit reports it as invalid. Neither conforming validator reports the revocation.â
- âCertification is based largely on self-reported compliance with no examination of the productâs functionality or source codeâ
- shows: six weakness classes (timestamps, revocation, validator inconsistency, exclusion ranges, certificate expiry, weak certification); spec 2.2, conformance 0.1; âThe Pixel 10 Pro and Version 2.3 (January 2026) of the specifications incorporated some of our suggestions. Version 2.4 (April 2026) does not address any of our concerns.â
- limits: hand-tested on a few validators; no measurement of exploitation in the wild
- links: arXiv, ePrint
- David Buchanan (retr0id), âC2PA Cameras Do Not Survive Contact With Realityâ, personal blog, 25 Aug 2026
- label: personal blog by a hardware security researcher, with a public tool (keystork) and demo files
- âif you root a device via an exploit, the attestation mechanism has no reliable way to ânoticeâ. The bootloader is still locked, the AVB keys are unmodifiedâ
- âan attacker does not need the raw key material! As root, they can ask StrongBox to use these keys to sign whatever data they like.â
- âAt time of writing, one-click root exploits exist in-the-wild for fully-patched Google Pixel devices (via CVE-2026-43499).â
- Googleâs VRP: âWonât fix (infeasible)â, â$7500 bountyâ
- fix in his words: âThe entire image processing pipeline, including all the fancy AI stuff, would need to run inside a secure enclave with strong hardware memory protection.â
- shows: a signature from Pixel Camera means âa registered app on a genuine Pixel asked the chip to sign thisâ, not âthe sensor saw thisâ; a forged AI photo passed Verify and a forged video got YouTubeâs âcaptured with a cameraâ box
- limits: one researcher; hardware details withheld; iPhone not tested
- link: blog
- David Buchanan, âHow to Hack Time, With C2PAâ, personal blog, 2 Oct 2026
- label: personal blog with a proof-of-concept file
- âWe can exclude the entire file, to produce an entirely valid signature over an empty string. This allows the file to be tampered with after the fact, without invalidating the signature, and without invalidating the TSAâs timestamp proof.â
- manifest dump: exclusion length 3,995,383 equals the file size; hash is the empty-string hash
- âas of today all the C2PA verification tools I can find donât flag anything as unusual.â
- fix: âcarefully and explicitly specify which parts of a file are allowed to be excluded, for each supported file format, and require that verifiers enforce these constraints.â
- shows: a timestamp proves a hash existed; if the hash covers nothing, it proves nothing; demo edits a lottery ticket after the draw
- link: blog
- Neal Krawetz, Hacker Factor blog posts, 2025â2026
- label: personal blog by a critic who runs FotoForensics and designed the rival SEAL format; he has a stake; the Pixel forgery is confirmed by Buchanan
- âGoogle Pixel 10 and Massive C2PA Failuresâ (5 Sep 2025): âeverything that identifies when, where, and how this image was created is unprotected by the C2PA signature.â; he backdated EXIF by âOne month, 8 days, and 12 hoursâ and âthe entire file is still cryptographically soundâ; Truepicâs validator said untrusted while Adobeâs said valid (post)
- âC2PA in a Court of Lawâ (20 Oct 2025): Pixel 10 has an on-device TSA with âtwo separate clocksâ; âThe manifest can be changed after the trusted timestamp is generated, as long as the change doesnât touch the few bytes that the C2PA specifications says to use with the trusted timestamp.â (post)
- âC2PA and Pixel Glitter Milkâ (25 Aug 2026): âThe picture is AI generated and the news article is fiction, but Googleâs signatures are real.â; Google revoked the one certificate, but ârevoking the glitter-milk certificate only invalidated that one specific photoâ while revoking the intermediate âwould instantly invalidate every authentic, legitimate Pixel photoâ; âI am unaware of any conforming validator products that checkâ revocation; Evergreen Labs GreenCheckmark âreceived approval for Level 2, but only implemented Level 1â (post)
- âValidation Workflowsâ (22 Sep 2026): C2PA validation âhas 10 steps, 6 with optional implementations ⊠every validator can generate different and conflicting responses to the exact same media.â; four trust lists with no overlap; âC2PA explicitly forbids CRLs; C2PA only supports OCSPâ; a timestamp âpermits the continued use of an expired or revoked signing cert (effectively un-expiring or un-revoking it)â (post)
- âSEAL Tested, Hardened, and Honestâ (18 Sep 2026): UMBCâs formal review of SEAL; âAn attacker with the stolen key can easily backdate new media to a time before the revocation date. (Ouch!) C2PA currently has no solution to this problem.â; âC2PA currently has 22 C2PA-approved TSA certificates, of which 16 do not have any kind of revocation enabled.â (post)
- shows: the concrete, checkable claims a validator-testing paper should reproduce or refute
- limits: handfuls of files; opinions mixed with findings; he benefits if C2PA looks bad
- Nikon Z6 III incident, AugâSep 2025
- label: news (PetaPixel, Heise, c2paviewer); primary posts by Adam Horshack not fetched (403)
- firmware 2.00 on 27 Aug 2025 added C2PA; the multiple-exposure function let the camera sign âa 1:1 digital copy of an AI-generated source imageâ; Nikon revoked all certificates and suspended the service, still suspended early 2026
- shows: the first camera-maker revocation; validators then disagreed on the revoked files (Golaszewski)
- link: PetaPixel
- Nemecek, He, Cheng, Ayday, âAuthenticated Contradictions from Desynchronized Provenance and Watermarkingâ, CVPR Workshop APAI 2026, arXiv 2603.02378
- label: peer-reviewed workshop; code at github.com/ANCP2021/integrity-clash
- âa digital asset carries a cryptographically valid C2PA manifest asserting human authorship while its pixels simultaneously carry a watermark identifying it as AI-generated, with both signals passing their respective verification checks in isolation.â
- âThe complete difference between an honestly declared AI-generated image and an authenticated fake reduces to the omission of a single assertion fieldâ
- 500 SDXL images with Metaâs Pixel Seal; after JPEG Q80, 10% crop, or a screenshot simulation the minimum bit accuracy stays 0.902; a joint check gets â100% classification accuracy across 3,500 test imagesâ
- shows: âprovenance launderingâ: an AI image re-signed through an edit tool looks human-made; nobody joins the two checks; a trivial join fixes it
- limits: one watermark, self-signed chain, no camera-pointed-at-screen test
- future work: âextend the cross-layer audit to video and audioâ; make signers âinspect data for pre-existing watermark signals before issuing a manifestâ
- link: arXiv
literature cards: photo of a photo (recapture)
- Park, Vilesov, Zhang, Khalili, Tian, Kadambi, Sehatbakhsh, âChimera: Creating Digitally Signed Fake Photos by Fooling Image Recapture and Deepfake Detectorsâ, USENIX Security 2025
- label: peer-reviewed; code at github.com/ssysarch/Chimera; same UCLA group as the Vilesov survey you starred
- âChimera can reduce the detection accuracy of state-of-the-art recapture and deepfake detection by more than 50% while increasing the success rate of fooling a layered defense scheme (both deepfake and recapture detector) by about 15%.â
- âChimera significantly increases the success rate of the attackâfrom less than 1% to approximately 14% in the best case.â
- threat model: âthe camera and its hardware, including the signature generation logic, are trustworthy ⊠The attacker, however, has access to an arbitrary camera and a display and can take pictures at will.â
- numbers: iPhone 12 plus MacBook screen; MoireDet on recaptured fakes 0.810 â 0.045; TwoB_DWT 0.952 â 0.283; needs âat least several hundred recaptured imagesâ per camera-screen pair; adversarial training âfails to generalize to images taken from a different screenâ
- shows: pre-distort the fake so screen artifacts cancel, defocus a little, photograph with a signing camera; per-try success is low but tries are free
- also: detectors âhad a strong propensity to classify all blurry or out-of-focus images as recapturedâ, so honest blurry photos get flagged
- future work: attacks that need few training images; ârealistic and inconspicuous patchesâ
- link: USENIX
- Liu, Farrukh, Amiri Sani, Agarwal, Tsudik, âScoop: Mitigation of Recapture Attacks on Provenance-Based Media Authenticationâ, USENIX Security 2025
- label: peer-reviewed (UC Irvine, Microsoft)
- âthe iPhone 14 Pro (w/ dToF) based prototype achieves exceptional overall results with 94.81% of TPR and only 0.02% of FPR; The Galaxy S20 Plus (w/ iToF) based prototype achieves good overall results as well with 74.03% of TPR and 17.78% of FPR.â
- people: âparticipantsâ (correct classification) accuracy 50.15% (SD = 13.89%) is close to pure chanceâ (43 people, TV recaptures)
- blind spot: âScoop cannot distinguish between a flat surface such as a wall, and a display showing an image of a wall ⊠such as a recapture of a digitally modified signed contract.â
- cost: +648 KB (about 26.9%) per photo on iOS; 56.2% energy overhead per capture on the Samsung; viewer check 69 s unoptimized on an RTX 4090
- shows: your RGBD idea, built: the phoneâs depth sensor sees a flat screen while a depth-from-image model sees a 3D scene; disagreement flags the region; the depth map is signed with the photo
- future work: âa future user studyâ, â3D display-based attacksâ, binocular and thermal sensors
- link: USENIX
- Ishizue, Rampazzi, Sugawara, âBreaking Infrared Recapture Detection: Optical-Synthesis Attacks and Depth-Aware In-Sensor Countermeasuresâ, USENIX WOOT 2026
- label: peer-reviewed workshop; artifacts at doi 10.5281/zenodo.19704181
- âSynthIR ⊠evades detection by independently manipulating the views of the RGB camera and the IR depth sensor across different optical spectra through an inexpensive optical filterâ
- âwe successfully bypass Scoop with 100% ASR by creating 50 cardboard 2D objects for 50 images from the Celeb-DF v2 datasetâ (iPhone 15 Pro, hot mirror about $210)
- printed images already hurt image-only detectors: â96-99% TPR ⊠degrades to 37-72% TPR with recapture of paper-printed imagesâ
- iPhone fuses LiDAR with the image inside the OS: âthe feature cannot be disabled, and raw LiDAR measurement is inaccessibleâ
- defense: dual-pixel sensors (Pixel phones, Canon DSLRs) give two views from one lens and one spectrum; â100% TPR ⊠100% TNRâ on 100 public DP captures plus 2,880 synthesized
- vendors: âBoth vendors responded that recapture detection via Scoop is not a security feature of their products and closed the cases without patches.â
- limits: portrait scenes; defense not run inside a signing pipeline (âwe capture the DP images and the RGB images separatelyâ)
- future work: multifocal displays against DP sensors; integration into phones
- link: USENIX
- Agarwal, Fan, Farid, âA Diverse Large-Scale Dataset for Evaluating Rebroadcast Attacksâ, ICASSP 2018; Fan, Agarwal, Farid, âRebroadcast Attacks: Defenses, Reattacks, and Redefensesâ, EUSIPCO 2018
- label: peer-reviewed
- â14,500 rebroadcast images captured from a diverse set of devices: 234 displays, 173 scanners, 282 printers, and 180 recapture camerasâ; a CNN gets âmore than 97% on both datasetsâ; old features drop to âonly a 4.9% detection accuracyâ on the new set
- re-attack: âThe true positive rate ⊠is 98.54%. This rate plunges to 0.005% on the attack-rebroadcast images ⊠MSE ⊠is only 0.96â
- shows: the 2018 baseline and the first attacker-versus-defender loop; the attacker wins with small learning rates
- Chen, Lin, Chen, Li, Zeng, Huang, âCMA: A Chromaticity Map Adapter for Robust Detection of Screen-Recapture Document Imagesâ, CVPR 2024
- label: peer-reviewed
- âreducing the average EER from 26.82% to 16.78%â; âthere is no depth difference between genuine and recaptured document imagesâ
- shows: for documents, depth gives nothing and the best detector still errs one time in six; confirms Scoopâs contract blind spot
- Sood, Natgunanathan, Praitheeshan, Kirupananthan, âMitigating S-RAHA: An On-device Framework to Prevent Forwarding of Re-Captured Imagesâ, arXiv 2604.12178, Apr 2026
- label: preprint
- 98.89% detection with a small CNN on moiré, edge and illumination cues (secondary summary; abstract read)
- shows: another image-only detector; by Chimeraâs result it would fall to a trained attacker; low value
- Cheng, Ji, Wang, Pang, Chen, Xu, âmID: Tracing Screen Photos via MoirĂ© Patternsâ, USENIX Security 2021
- label: peer-reviewed
- âan average bit error rate (BER) of 0.6% and can successfully identify an ID with an average accuracy of 96%â
- shows: a defender who controls the screen can plant moiré; loosely related, shows the artifact Chimera cancels
literature cards: trusted capture hardware
- Liu, Yao, Chen, Amiri Sani, Agarwal, Tsudik, âProvCam: A Camera Module with Self-Contained TCB for Producing Verifiable Videosâ, MobiCom 2024
- label: peer-reviewed; code at github.com/trusslab/provcam
- âIt remains secure even against a powerful adversary that owns the device and can physically attack hardware buses!â
- cost: â720p ⊠60fps ⊠(â 53.8M transistors) ⊠(< 1Watt)â on a Xilinx ZCU106 FPGA
- âThe adversary could use ProvCam to record a video of a fake video played on a screen in front of it ⊠We leave addressing this attack vector to future work.â
- fixed per-device key: âvideos captured by the same user can be linked togetherâ; âWe leave finding a desirable solution to this problem to future work.â
- shows: the full-hardware answer to Buchananâs root attack, and what it costs; recapture and privacy still open
- Liu, Nakatsuka, Amiri Sani, Agarwal, Tsudik, âVronicle: Verifiable Provenance for Videos from Mobile Devicesâ, MobiSys 2022
- label: peer-reviewed
- per-video keys: âthe camera app generates a fresh key-pair and uses the hash of the public key as a nonce to conduct the first round of SafetyNet attestation ⊠erases that keyâ
- edits run as fixed filters in TEEs; a 10-second video with 6 filters âtakes an average of about 44 secondsâ versus about 31 s for YouTube
- shows: the closest worked design for a phone signer without new hardware; its attestation is the same kind Buchanan defeats
- Google, âHow Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentialsâ, security blog, 10 Sep 2025
- label: industry blog (vendor claim)
- âAndroid Key Attestation in Pixel 10 is built on support for Device Identifier Composition Engine (DICE) by Tensor, and Remote Key Provisioning (RKP)â
- âC2PA claim signing keys are generated and stored using Android StrongBox in the Titan M2 security chipâ; âEach key and certificate is used to sign exactly one image.â; CA has âa strict no-logging policy for information like IP addressesâ
- honest limit: âthe security of any claim is fundamentally dependent on the integrity of the application and the OSâ
- shows: the public blueprint for an open-source phone signer; it never claims sensor binding
- link: post
- Apple Reference Image, iPhone 18 Pro, iOS 27, Sep 2026
- label: news (MacRumors); no Apple spec fetched
- âImages captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone.â; the phone sends âthe raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensorâ to Private Cloud Compute; proprietary, not C2PA
- shows: Apple chose sensor-level signing plus a server check, the design Buchanan predicted would push attacks âinto the optical domainâ
- link: MacRumors
- Kamimura (VeritasChain), âContent Provenance Profile (CPP) Coreâ, IETF Internet-Draft draft-vso-cpp-core-03, Aug 2026
- label: individual Internet-Draft, not a working-group item
- âCPP is complementary to the C2PA specification. C2PA tracks edit history of content; CPP proves capture provenance with deletion detection.â; RFC 3161 anchoring; Merkle trees; a âCompleteness Invariantâ against omitted evidence
- shows: someone is standardizing âa collection of captures with nothing deletedâ, which is what a court or archive wants; unvetted
- link: draft
literature cards: proving edits in zero knowledge (follow-ups to VerITAS, VIMz, Trust Nobody)
- Greiner, Mowery, Soni, âHyperVerITAS: Verifying Image Transformations at Scale on Boolean Hypercubesâ, PoPETs 2026(2)
- label: peer-reviewed
- âOn commodity hardware (Apple M3, 36 GB RAM), HyperVerITAS generates proofs for 33 MP images using only 27 GB of RAM and 6.6 minutes of proving time, whereas VerITAS fails to scale beyond 4 MP.â
- VerITAS âranged from 75 GB to 120 GB for a single 30 MPâ; âVIMz takes nearly 2 hours, and TilesProof-MT takes over 30 minutesâ
- shows: laptop-scale edit proofs; same trust model, camera trusted, editor not
- link: doi
- Zhang, Zhou, BĂŒnz, âSPEG: Verifiable Compression of Imagesâ, IACR ePrint 2026/1598, Aug 2026
- label: preprint
- first proof system covering JPEG compression of a C2PA-signed original; Full HD compression proof 47 s (Poseidon mode) or 2 s (fast mode) versus 227 s for VerITAS resizing on the same hardware; âaddresses a security vulnerability in VIMzâ (summary from the ePrint page, abstract not quoted verbatim)
- shows: compression, the edit every phone applies, is now provable
- link: ePrint
- Frolov, Guo, Zhao, Datta, Boneh, Miers, âzk-Cinema: Proving Video Provenance in Zero Knowledgeâ, IACR ePrint 2026/1717, Aug 2026
- label: preprint
- âwe show how to represent common video edits as matrix multiplications in a form that is particularly friendly for zero-knowledge provers ⊠a SNARK-friendly video representation, which we call sfvrâ
- shows: the Boneh group moved to video; âcompetitive performance and scale relative to prior workâ, no numbers on the abstract page
- link: ePrint
- Datta, Chen, Boneh, VerITAS talk slides (Simons Institute, 2025)
- label: talk slides
- âMany other challenges (1) Key extraction and revocation (PKI) (2) Privacy â group signatures (3) GPS spoofingâ; âNow every verifier must run a brittle filter: Is this a picture-of-picture? Can attacker defeat the filter?â
- shows: the crypto authorsâ own list of open problems is your list
- Fairoze, Ortiz-Jimenez, Vecerik, Jha, Gowal, âOn the Difficulty of Constructing a Robust and Publicly-Detectable Watermarkâ, arXiv 2502.04901, 2025
- label: preprint (Google DeepMind)
- C2PA-style metadata is unforgeable and publicly checkable but not robust; ML watermarks are robust but not the rest; a scheme with all three exists on paper but âit is intractable to build certain components of our scheme without a leap in deep learning capabilitiesâ
- shows: do not expect a watermark that replaces the signature
literature cards: watermarks and soft binding
- CAI (Parsons), âDurable Content Credentialsâ, 8 Apr 2024
- label: industry blog, proposal, no data
- ânone of these techniques is durable enough in isolation to be effective on its own.â; recipe: watermark carries an ID, look up the manifest, âCheck that the manifest and the content match by using the fingerprintâ; âFingerprint retrieval is fuzzyâ; not for photojournalists who âmay not wish to store anything ⊠on any serverâ
- Cao, Li, Zhang, Wu, Liu, Li, Ni, âMarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulationâ, USENIX Security 2026
- label: peer-reviewed
- âMarkNull reduces average bit accuracy to 53.14%, approaching random-guessing (50%), without perceptible image degradation.â; âour attacks successfully compromise Googleâs SynthID-Image systemâ (20 images, 100% success)
- limits: SynthID test tiny; mostly 512Ă512
- Gowal et al. (Google DeepMind), âSynthID-Image: Image watermarking at internet scaleâ, arXiv 2510.09263, Oct 2025
- label: preprint; abstract page only
- shows: the one watermark deployed at scale; MarkNull above attacks it
- Zhao, Gunn, Christ, et al., âSoK: Watermarking for AI-Generated Contentâ, IEEE S&P 2025
- in your paper collection; abstract page only here; the survey to cite for the watermark side
- Microsoft Research (Young, Vaughan, Jenks, Malvar, Paquin, England, Roca, Lavista Ferres, Poursabzi, Coles, Archer, Horvitz), âMedia Integrity and Authentication: Status, Directions, and Futuresâ, technical report Jan 2026, arXiv 2602.18681
- label: industry research report, not peer reviewed
- âTo make the provenance of captured images, audio, and video trustworthy, it is essential to implement secure enclaves within the device hardware.â
- âavailable protections to stop a key being used by an unauthorized application are very limited.â
- âFingerprinting is not a viable path to high-confidence validation and faces significant scaling costs.â
- âRecovering a C2PA provenance manifest created and signed in a high security environment with an imperceptible watermark ID offers a promising optionâ
- open problems named: âManifest Stores. Further research is needed to define best practicesâ; âhow to best verify if detected provenance information relates to expected provenance informationâ; âongoing intensive red-teamingâ
- also optimistic that âboth Android and iOS can distinguish rooted from non-rooted devicesâ, which Buchanan refutes for exploit-rooted devices
- link: arXiv
- Krawetz on watermark error rates (âMark My Wordsâ, 14 Aug 2026)
- personal blog, numbers cited without data: âAdobeâs TrustMark has a 10%-20% false-positive rate. Metaâs Stable Signature has a collision rate of 1 in 4.â; treat as a hypothesis to test
literature cards: trusting a signature for years
- conformance and certificate policy
- C2PA Conformance Program v0.2 and Certificate Policy v0.2, 31 Jul 2026; label: spec or standard
- leaf certificate âMax 366 days (Assurance Level 1)â and âMax 90 days (Assurance Level 2)â; OCSP mandatory, âThis CP does not require the use of certificate revocation lists (CRLs)â
- level 2 requires keys in âan environment with a higher privilege level than the privilege level of the Claim Generatorâ, hardware attestation of the binary, patch recency; no secure sensor path required
- âOn-Device TSA, intended for use on mobile/edge devices to support local time-stamping without requiring a network connectionâ; accuracy âSHOULD be of 1 second or betterâ
- getting on the list: legal agreement, intake form, an architecture document in Markdown, âsample output media filesâ; no fee
- shows: a 90-day certificate makes a timestamp mandatory for anything older than a season; the on-device TSA means the phone vouches for its own clock
- Gondrom, Brandner, Pordesch, RFC 4998 âEvidence Record Syntaxâ, 2007; Birkholz, Fossati, Riechert, RFC 9921 âCOSE Header Parameters for Carrying Timestamp Tokensâ, Feb 2026; IETF SCITT architecture draft; Merkle Tree Certificates draft; OpenTimestamps
- label: standards and drafts
- RFC 4998: âlong-term non-repudiation of existence of dataâ; âTimestamps have to be renewed by generating a new Archive Timestampâ
- RFC 9921: carries an RFC 3161 token inside a COSE signature, which is what a C2PA claim signature is
- SCITT: âdigital signatures may fail to verify past their expiry date even though the signed item itself remains completely valid.â; receipts prove a statement was logged at time T
- OpenTimestamps: âA timestamp proves that a message existed prior to some point in timeâ, Bitcoin-anchored, accurate âwithin two or three hoursâ
- shows: the stack for idea 2: sign, timestamp, log receipt, periodic renewal; C2PA already supports trusted timestamps; additional evidence renewal and content coverage need separate checks
- NCC Group (McCollum), âPrivacy and Security Challenges of Content Provenance and Authenticity Systemsâ, 3 Aug 2026
- label: industry blog summarizing WITNESS and UMBC
- âsigned content can quietly stop validating within a year due to temporal fragility, even when the underlying file remains unchangedâ
- âeven a modern privacy fix, such as generating a unique certificate per photo, still leaves manifests carrying enough consistent metadata (like editing tool versions and action sequences) to link separate images back to the same device.â
- âpublic, web-based âupload-to-verifyâ services receive the full media file, all provenance metadata, the userâs IP address, and the precise timingâ
- link: post
- WITNESS (Castellanos), âC2PA Content Credentials and the Surveillance Risk: Adversarial Scenarios and Governance Gaps in the Content Provenance Ecosystemâ, 2026
- label: NGO report; only the landing page read
- âreal-world scenarios and the voices of journalists, human rights defenders, and filmmakersâ
- link: WITNESS library
literature cards: how much provenance exists and survives
- IPTC Metawatch, monthly crawl, Oct 2026 run
- label: standards-body measurement with open data (CC BY 4.0)
- 508 publishers in 122 countries, lead photo of up to 20 articles each; October: 425 publishers, 6,580 images
- â27 of the 6,580 images we analysed carried a C2PA manifest, and all but one were signed by an AI or design tool: OpenAI, Adobe, Canva or Google ⊠None came from a camera or a newsroomâs own signing.â
- âOnly 11% of the 6,580 images carried any IPTC metadata at all.â; credit or copyright on 7.2% (8% in 2018)
- âImages served through Cloudflare, Akamai, CloudFront and Fastly lost their metadata 87% to 95% of the time, but images served with no CDN at all also lost metadata 87% of the time.â
- limits: lead photos only; presence counted only when the served file still has the manifest; AP and USA Today began blocking the crawler
- link: dashboard
- Rijsbosch, Bekavac, Tari, van Dijck, Kollnig, âDrowning in AI Slop: How Social Media Platforms (Do Not) Label AI and Deepfake Content under EU lawâ, arXiv 2609.38571, 29 Sep 2026
- label: preprint, âunder submissionâ
- âonly 33% of expert-identified deepfakes in systemic risk contexts carried a platform-applied AI label, while reaching a median of 160,000 views.â (14 of 43)
- uploads: âplatforms labelled only 61% of uploads, and commonly strip those signals after uploading.â (36 of 59; Instagram 14/17, TikTok 10/17, X 7/17, YouTube 5/8)
- âTikTok is the only platform that thereby seems to consistently embed signals from its own platform-based AI-labels ⊠only YouTube showed C2PA-signals in some of the downloaded posts.â
- limits: 500 annotated posts, one account, AugâSep 2026 snapshot
- Zewde, Ren, Shen, et al., âGPT-Image-2 in the Wild: A Twitter Dataset of Self-Reported AI-Generated Images from the First Week of Deploymentâ, arXiv 2604.25370, May 2026
- label: preprint (scam.ai)
- âplatform-level provenance signals (C2PA content credentials) are systematically destroyed by Twitterâs CDN on uploadâ; 10,217 confirmed images; Xâs âMade with AIâ badge on 53.7% of checked tweets
- limits: the C2PA finding is stated, not tabulated
- Mantzarlis, Dutta (Indicator), âTech platforms fail to label AI contentâ, 23 Oct 2025
- label: journalism audit
- 516 AI images and videos posted to Instagram, LinkedIn, Pinterest, TikTok, YouTube; 169 (about 30%) labeled correctly; Pinterest best at 55% (from the first-round note; article not re-fetched)
- Rijsbosch, van Dijck, Kollnig, âMissing the Markâ (adoption of watermarking by AI generators), ACM CS&Law 2025, arXiv 2503.18156
- label: peer-reviewed short paper
- âonly a minority number of AI image generators currently implement adequate watermarking (38%) and deep fake labelling (18%) practicesâ; C2PA in 5 of 50 generators (early 2025)
- CAI (Parsons), âThe State of Content Authenticity in 2026â, 18 Jan 2026
- label: industry blog
- the only adoption number is âmore than 6,000 membersâ; no count of signed or verified files
- Cloudflare (Allen), âPreserving content provenance by integrating Content Credentials into Cloudflare Imagesâ, 3 Feb 2025
- label: industry blog
- âIf you use Cloudflare Images to dynamically resize or transform this image, then Cloudflare automatically appends and cryptographically signs any additional actions in that same manifest.â; opt-in per zone
- shows: a CDN as a re-signing intermediary; Metawatch shows most publishers do not turn it on
literature cards: people and labels
- Trattner, Forstner, Starke, Knudsen, âC2PA Provenance Labels Increase Trust in Digital News Platforms Across Western Countriesâ, ICWSM 2026
- label: peer-reviewed; âN=6,114 participants, reflecting audiences of six major news sources in the US, UK, and Norway.â
- âPresenting provenance metadata to participants significantly improved their perceptions of an imageâs transparency and credibility, and also increased feelings of trust in a presented news source.â
- limits: genuine images only; no stripped or invalid condition
- Höltervennhoff et al., ââThatâs another doom I havenât thought aboutâ: A User Study on AI Labels as a Safeguard Against Image-Based Misinformationâ, CHI 2026, arXiv 2505.22845
- label: peer-reviewed; 5 focus groups plus 1,354 survey participants
- âWhile labels reduced participantsâ belief in false claims supported by AI-generated images, we found evidence of overreliance ⊠Participants were more susceptible to false claims accompanied by human-made imagesâ
- limits (theirs): âour survey setting is artificial and does not fully correspond to a realistic interaction with social media.â
- Pawelczyk, Dimmery, Yan, âImplied Authenticity Effect? The Impact of Explicit Labels on AI-Generated Contentâ, ICWSM 2026
- label: peer-reviewed; 877 German Instagram users
- âexposure to labeled content slightly increased perceived authenticity in unlabeled images.â
- limits (theirs): âthe sampleâs mean internet skills score of 4.30 (on a 5-point scale) indicates a highly digitally literate population overall.â
- Koech, âResults Data for C2PA Credentials Studyâ, IEEE DataPort, Jul 2026
- label: dataset page; 358 participants, control versus valid versus invalid credentials, 12 stimuli
- finds âgaps in visual noticeability and user comprehension errors that conflate technical verification with factual accuracyâ
- Feng, Ritchie, Blumenthal, Parsons, Zhang, âExamining the Impact of Provenance-Enabled Media on Trust and Accuracy Perceptionsâ, CSCW 2023
- label: peer-reviewed; the baseline the above cite: âprovenance, although enlightening, is still not a concept well-understood by users.â
- CITP and NYU, âNewsroom Guide: Authentication and Verification in the AI Ageâ, Aug 2026
- label: workshop report
- âAuthentication makes a determination limited to the provenance of an item.â; âVerification confirms that the contents of that media represent the truth; for example, whether a photo depicts what it claims to depict (rather than, say, a photo of an unrelated event).â
- âa number of these tools speak the language of probability, when journalists are often looking for certainty.â
- Nieman Labâs headline on the companion report: tools are built without enough journalist input (article returned 403, headline only)
- link: guide PDF
- Schiff, Schiff, Bueno, âThe Liarâs Dividendâ, APSR
- label: peer-reviewed, not opened; search snippet says false claims of fakery work against text reports but are âlargely ineffective against video evidenceâ
- relevance: with C2PA present on 0.4% of news images, âno credentialâ is the normal state and cannot answer âthat real video is fakeâ
literature cards: genuine photo, wrong caption
- Ardi, Madhyastha, âMitigating Image-based Misinformation Campaignsâ, 3-page proposal, PDF dated Sep 2024, no venue
- label: proposal, nothing evaluated; in your paper collection
- âOur research goal is to flag misinformation by using this secure metadata to detect a mismatch in location or time between visual media and associated text.â
- privacy knob: âthe location can be specified at the state- or country-level, and time can be at the month-year or year-only granularity.â
- plan: parse captions, evaluate on fact-checker archives where the true place and time are known, measure false alarms on random viral posts
- assumes âevery photo and videoâ will carry signed time and place; nothing on stripping, spoofed GPS, or recapture
- Tonglet, Thiem, Gurevych, âCOVE: COntext and VEracity prediction for out-of-context imagesâ, NAACL 2025
- label: peer-reviewed
- âImages taken out of their context are the most prevalent form of multimodal misinformation. Debunking them requires (1) providing the true context of the image and (2) checking the veracity of the imageâs caption.â
- uses image and caption; no signed metadata; the baseline idea 5 must beat
- Luo, Darrell, Rohrbach, âNewsCLIPpingsâ, EMNLP 2021 and Aneja et al., âCOSMOSâ, 2021
- label: peer-reviewed datasets of unmanipulated image plus mismatched caption; no capture metadata
gaps the sources themselves name
- Golaszewski et al.: âRequire strict certificate revocation checking (including via privacy-preserving methods)â; âEnsure timestamps are securely bound to content and cannot be altered without detectionâ; âMandate consistency across validation toolsâ; âProtect the entire file (including non-C2PA metadata), not just selected portionsâ; âEstablish independent security audits for certified productsâ
- Buchanan: âcarefully and explicitly specify which parts of a file are allowed to be excluded, for each supported file format, and require that verifiers enforce these constraints.â
- Chimera: training âwith a very small number of training images, which can be an avenue for future workâ
- Scoop: âa future user study needs to be conductedâ; 3D display attacks âwill be a future workâ
- WOOT 2026: âintegration of our proposed detection pipeline into current smartphones that already deploy DP image sensors can be an easy-to-deploy solutionâ; âpotential attacks targeting DP sensors, including the use of multifocal displaysâ
- ProvCam: recapture âto future workâ; linkable fixed key âto future workâ; âexisting key revocation solutions should be applicable here as wellâ (asserted, not shown)
- HyperVerITAS: âdevelop a new code based multilinear PCS that has better proof sizesâ
- Nemecek et al.: âextend the cross-layer audit to video and audioâ; signers should âinspect data for pre-existing watermark signals before issuing a manifestâ
- Microsoft Research: âManifest Stores. Further research is needed to define best practicesâ; âhow users comprehend and respond to a mix of provenance-enabled and non-enabled contentâ; âongoing intensive red-teaming and analysisâ
- Metawatch: reading individual assertions is âplannedâ
- Rijsbosch 2026: âwhether multi-content LLM-based (agentic) classifiers could be used to reliably scale the assessment of deepfakesâ
- Höltervennhoff et al.: survey setting âartificialâ; Pawelczyk et al.: âwhether the spillover effect interacts with the type of image shown (authentic vs. AI-generated)â
my own inferences
- the field moved from âwill C2PA workâ to âC2PA is deployed and the validators are the weak layerâ; every public break in 2025â2026 (timestamps, exclusions, revocation, trust lists, Nikon) is caught or missed by validator behavior, and existing validator tests are a required baseline
- nobody has measured the age distribution of real C2PA files versus their certificate and TSA status; Metawatch could be extended to do it in a week, and the result (âx% of signed news images already failâ) would be quoted everywhere
- the privacy-versus-revocation knot (one certificate per photo) is a genuine open design problem that a systems person can attack with existing crypto (blinded device handles, group signatures) plus measurement of how often revocation is needed
- âphoto of a photoâ will not be solved by detection; the honest framing is âsigned sensor geometry plus a false-alarm budget per honest scene classâ, which no paper has reported
- the wrong-caption idea is still unbuilt after two years, and its premise got weaker; I would only do it as a measurement of how much signed metadata is actually inside the hash on shipping devices
- an open-source phone signer is now a weekend project and not a paper on its own; its value is as a testbed for ideas 1, 2, 4 and 6
- I could not get ChatGPTâs opinion (tool failed twice: login required, then âterminal_deadline_expiredâ); the first-round prompt is saved in the scratchpad if you want to rerun it
coverage
- searches: 25 web searches this pass plus about 12 in the first round (searcher E); 2 ChatGPT attempts, both failed
- sources opened: 13 papers read in full text from local copies (Chimera, Scoop, WOOT 2026, ProvCam, Vronicle, HyperVerITAS, Farid Ă2, mID, CMA, Ardi & Madhyastha, Nemecek, Rijsbosch 2026) plus 5 more from your collection at abstract-and-results depth; 11 blog posts and vendor pages in full; 3 C2PA governance documents; 5 standards; about 20 abstract pages; 3 first-round cards (Trattner, Höltervennhoff, Pawelczyk) read in full by searcher E
- quotes marked â(summary)â or âsecondaryâ come from search snippets or fetch summaries, not the primary text
- not found or not opened: Horshackâs own Nikon write-up (403); the Nieman Lab article (403); full WITNESS report PDF; Appleâs own Reference Image documentation; the Washington Post upload test; a peer-reviewed end-to-end evaluation of soft-binding recovery (I believe none exists); any paper measuring certificate or TSA expiry across real C2PA files (none found)
- scratchpad with raw cards and downloaded texts:
scratchpad/provenance/in this sessionâs temp directory (G_cards_recapture_hardware.md, H_cards_deployment_blogs.md, E_security_measurement_hci.md)
8 October checks after the cross-topic consultation
- validator disagreement already has direct prior work
- Golaszewski et al., Why C2PA Falls Short, section 3, tests multiple widely used validators
- checked the full short paper, sections 1â6 and its stated security goals
- extend its cases only after matching specification version, trust roots, validation clock, revocation evidence, and connectivity
- count independent validator implementations separately from products sharing one library
- possible contribution: reproducible new failure classes or checked repairs
- a disagreement count alone repeats the existing result
- expiry alone does not make a correctly timestamped signature fail
- C2PA 2.4, time-stamp validation: âvalidators shall use the attested time, and not the current timeâ
- requirement applies when the timestamp is present, trusted, and validated
- test certificate expiry separately from revocation, missing timestamp evidence, and changed trust policy
- a simulated clock advance checks policy behavior
- it cannot establish ten years of real service availability or cryptographic durability
- manifest recovery already has an implementation example
- Adobe TrustMark C2PA integration, Durable Content Credentials: âthe TrustMark identifier carried inside the watermark can be used as a key to look up that information from the databaseâ
- the repository links a soft-binding assertion example
- measure metadata removal, broken cryptographic binding, absent reader UI, watermark decoding, and external recovery separately
- new platform measurements need pinned transformations and an existing recovery baseline
- no implementation or platform experiment was run in this continuation
Last edited: