I'd always thought the usefulness of C2PA was limited to verified devices in custody by trusted actors.
Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery.
The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?
> was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery.
But that is also not the case, because whatever keys are in those devices may have been duplicated in the factory or somewhere along the supply chain.
Or the stuff is cloud connected and an exploit can be executed via that.
Or, as written in the blog post you're commenting on, software exploits.
The whole idea is that the concept works for no one.
The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?