6 ms·
I wouldn't be that pessimistic just yet. It's yet possible that new advances in authentication technology might counteract some of these trends.
by Chaebixi 9y ago
I wouldn't be that pessimistic just yet. It's yet possible that new advances in authentication technology might counteract some of these trends.
- unethical_ban 9y agoWhat do you mean "authentication technology"? Tamper detection? The ability to see that a tool was used? It may slow things down, but this is an arms race.
- BoiledCabbage 9y ago> What do you mean "authentication technology"? Cryptographic signatures. Ie every frame in a video is signed with a 512-bit key that states authoritatively what camera was the source of the video and when it was taken. In order to change any pixels in the video you'd break this key and need to resign it. An attacker would be unable to do this unless they had physical access to the original camera. But it'll be at least 3 decades before this technology is commercialized, people see the demand for it, and the majority of all cameras in the world are replaced by it. Even if this new tech is on the market in a decade (simple tech, no demand / ecosystem yet), but 90% of existing / installed cameras don't have the feature then fake videos still get created with them. Only once ~80% of videos are authenticated, and a significant portion of the remaining 20% are fakes will people be able to dismiss non authenticated video. Up until then it's fakes non-stop. We've got some ugly decades coming up.
- bduerst 9y agoWhat's to keep you from adding the key to a camera after falsely generating the media? Or using the key of a known camera to generate false footage?
- andrewstuart2 9y agoRequire that videos submitted as evidence use keypairs which were provably registered or published prior to the event. Don't have a registered key? Great, but that's no longer admissible. Still, problems would exist with letting the camera read the private key for signing, but not allowing an attacker (forger) to access the private key and thus sign their modified footage. Just a thought.
- PeterisP 9y agoCourts will use the best evidence available for a particular case, including all kinds of things that obviously can be less than perfectly reliable. Physical photographs have been doctored (or staged) for more than a century, and that doesn't mean that photos as such are inadmissible as evidence; so the fact that the process for taking video wasn't especially tamper-proof won't by itself be sufficient to disqualify it. If a video is available and doesn't contain a pre-published key then the courts will still want to use it as useful evidence instead of simply ignoring it - sure, the opponent might have a slightly easier time attempting to contest that evidence as possibly doctored (just as they can do now), but courts will still make a judgement for each individual case.
- smallnamespace 9y agoAtoms are harder to move around then bits, and the rapid development in our ability to generate convincing video means that it will be hard to predict what sort of evidence we can generate now that will be convincing in the future.
- swsieber 9y agoTimestamped signatures + publishing the public key w/a timestamp (blockchain?).
- Y_Y 9y agoI think this is the answer. But then who's going to maintain a worldwide database of all the hashes of all the photos and videos made, and who would we trust to do it?
- kaybe 9y agoI suspect the recent Kodak blockchain adoption might be connected with this use case. Not specifically, but with respect to getting into the technology and acquiring IP and expertise.
- BoiledCabbage 9y agoSo spitballing, my assumption is that it'd end up looking something like SSL certificate chains today. In the situation you mentioned: 1. The attacker wouldn't have access to the original cameras private key. 2. The attacker creates a fake video, creates a private key and signs the video with the key 3. The attacker tries to install the key into a camera Step 3 has to be made impossible. Meaning that a camera becomes a trusted entity and only allowed parties (ex the camera manufacturer) has the authority to insert a private key into a camera. This would be that after installing a camera with a new private key, the key would then need to be signed with the manufacturer's private key and also stored in the camera. This shows the manufacturer is responsible for the contents of the video. If someone tries to change the camera's private key it would no longer match what the manufacturer signed. Which yes then means we need to have authorized camera manufactures and a process for certificate revocation and all of that. The exact opposite of "free and open" for recording devices - and the only way we aren't flooded with fake videos flooding and seriously impacting society. We have to want this if we want to still have a concept of video evidence in either the justice or social spheres.
- Chaebixi 9y agoThis isn't a completely technical problem, there's not going to be an air-tight technical solution. I think, at this point, anything more than the camera having a secure device-generated key that it uses to sign its output and produce watermarks is overthinking it. That will add a nearly insurmountable barrier many classes of forgery, namely one were a forger claims to have a photo taken with your camera. You also have to remember a significant class of photo-forgery would involve images that are claimed to originate from a camera the attacker controls. For instance, forged video of a robbery from a security camera. That could, in some cases, be defeated by observing that the images have authentication information they shouldn't have (such as traces of watermarks from other cameras). At the end of the day, forgeries will be spotted by observing that they have subtle errors that don't add up. That's how it's always been done.
- deleted 9y ago[deleted]
- robocat 9y agoHow easy is it to put a different key into an iPhone? How easy is it to get a private key within an iPhone?
- bdeorus 9y agoWouldn't this limit video post-processing (e.g. color correction, etc.) ?
- kaybe 9y agoAs long as you keep the original this should be fine. If anyone needs proof just show them.
- dingaling 9y agoCanon had a cryptographic add-on module for image verification for their 1D series way back in the 2000s but it was cracked. I don't know if they subsequently updated it ( was called OSK ) but the idea has been around for some time. It was considered important for submission of evidence and several news agencies also insisted on it.
- noobermin 9y agoI think in general, as creating fakes becomes more and more prevalent, society is going to have to view crypto as more and more a necessity instead of as a niche thing.
- jdoliner 9y agoWhat if after I'm done creating my fake picture I carefully take a picture of it with an authenticated camera?
- sigstoat 9y agowith a bit of setup you could remove the lens (while keeping it electrically connected for EXIG purposes) and then project whatever image you want on to the sensor.
- PeterisP 9y agoRequiring proof of authenticity is a niche use case, it doesn't seem realistic that this alone will be sufficient to ensure that most cameras in the world gain extreme security to prevent tampering by users, rogue employees in manufacturing companies, etc, etc. Also, we haven't ever been able to make perfectly secure software - an exploit that allows a key to be extracted from the camera is likely, and camera buyers won't care. A key is just data. Even if the key can't be extracted from common cameras, there's no magic that can prevent from someone making a device with a known key (or falsely register to the magic worldwide-trustworthy central registry that USA, China and Russia trusts but aren't able to influence to get keys for manufacturing fake news) that a particular camera has been made), one that can be used to sign data outside the camera context to make it appear that it was "securely" seen by a legitimate camera.
- icc97 9y agoYou just have to make it hard enough that the likelihood of it being tampered with is small enough to be acceptable for a court. If you're up against the NSA then pretty much any tech evidence would be invalid. But if you're having a small claim court case, then it seems reasonable that authentication technology can keep up with faking technology.
- blattimwind 9y agoDSLRs already do this, but it's been cracked in the past (Canon and Nikon at least).
- Chaebixi 9y agoBoth. It is an arms race, but it isn't hopeless. Think of it this way: we have fantastic technology for forging paper documents, but we still trust them. For instance, someone forged a memo to make a former president look bad close to an election, and they were tripped up because they weren't thinking about fonts [1]. Getting a forgery right is hard, and requires a lot of attention to detail. Technology will improve to add even more details that require careful attention, and maybe some cryptographic assurances. Maybe it won't be a world where anyone can spot a forgery, but there will still be experts who can. [1] https://en.wikipedia.org/wiki/Killian_documents_controversy https://en.wikipedia.org/wiki/Killian_documents_controversy
- ioquatix 9y agoPeople still use ink signatures for things. :/
- fishcolorbrick 9y agoHere's another one: https://www.engadget.com/2017/07/12/microsoft-calibri-pakistan-fontgate/ https://www.engadget.com/2017/07/12/microsoft-calibri-pakist...
- icc97 9y agoFascinating story, although it wasn't just the font, it was trying to pass off default output from 2004 Word as a 1973 typewriter. It seems all they did was run it through a copier a few times. So it was font, paragraph style, and superscript. If you're gonna frame a presidential candidate you should try harder.
- rlpb 9y agoHow about this: Every recording device sends a stream of hashes to be cryptographically timestamped in realtime as they record. Now the time window to create fake evidence becomes incredibly small. You have to arrange the fake to be created at the same time or earlier than you will claim that the event happened. You have to know what you need to fake in advance, too, which isn't the case for all fraud. Evidence will be corroborated from multiple places. If I'm in a public place, I can bet the scene is being recorded from multiple places, and I will not be able to predict who will be in that place in advance. Fake evidence can be caught out by finding discrepancies. If the majority of recording device owners whose evidence corroborates can be trusted, then the identification of the fake one can be made with reasonable certainty.
- BoiledCabbage 9y ago[Edit] - Moved to sibling comment
- ABetterTomorrow 9y agoIn the meantime, perhaps privacy-conscious individuals can wear smart burkas with vocal modulation when in public.
- quotemstr 9y ago> new advances in authentication technology I'm not so optimistic. Other people here are focusing on breaking the authentication, and that's something to worry about. I'm worried about the effect that even _known_ false content will have on people. Seeing a perfectly realistic video of $POLITICIAN doing something repulsive will affect your emotional perception of $POLITICIAN even if your rational mind reads and understands some kind of "unauthenticated" label attached to the video.
- Chaebixi 9y agoI think the solution to that is a social one: generate so many authentic-looking but obviously false videos that no one will believe them without authentication. I think these immunization-fakes could reach even the most information-poor voter: just make them funny memes, etc. Plus, if there are enough of them, I'd think the emotional balance between rivals could even out.