10 ms·
I would imagine that in the future video encoders will start to automatically include a cryptographic signature every X frames, which then players will become a
by _red 7y ago
I would imagine that in the future video encoders will start to automatically include a cryptographic signature every X frames, which then players will become aware of and show an indicator for "original / modified" content.
- kittiepryde 7y agoI'm thinking that we'd need an Originality Authority (like a CA), to act as the anchor. I assume anyone could just strip the cryptographic signature and then re-sign it with their own signature, and we'd need an authority to prevent that. Upload your content, request a key you can sign with, the OA checks against previously registered content in it's database for originality (I can only assume this would be as buggy as Youtube's algorithm is today).
- SkyBelow 7y agoIf everyday people are allowed to possess hardware that can sign images, it would only require someone feeding the fake images into the sensor that would be recording. Then, they would have a verified yet still fake image, which if anything would lead to more people falling for it. You could require that information about the recording also be included (gps, timestamp, etc.) but not only does that harm privacy, it means that when someone fakes it then people will trust the fake even more.
- cr0sh 7y agoI wonder if it'd be possible to "deepfake" the crypto sigs...?
- vokep 7y agoIt should be entirely unfeasible if its good crypto In order to deepfake it, a neural net would have to understand the crypto algo in such a way it could modify its deepfake input to collide with the original input's hash. Basically it would need to reverse the crypto to generate all frames that evaluate to a certain hash, and then find one that is mostly similar to the intended input. I don't think it will be realistic at all, if even theoretically possible.
- buildzr 7y agoIt'd be too easy to fake, just replace the sensor in an approved camera with your own data feed. And that's assuming it wouldn't be somewhat trivial to dump keys from one or more cameras on the market to create a an easy tool or resignvideo.com... which is a massive assumption. As the movie industry has already seen, cryptography doesn't help you when you push out the keys to everyone. It'd be about as effective as DRM is at stopping video piracy.
- tylerhou 7y agoYou could go on the level of Apple - hardware security chip with presigned bootloader + a chain of trust to boot the OS, and the private key stored in a secure enclave. Then generate a cert for every second of video or so and embed it into the media format. Don’t sign the video if you detect any foreign hardware.
- buildzr 7y agoYou could try but it'd still be possible to just fake it at the sensor level, essentially so the IC would see your video as the analog signal coming in and encode it as if it were any other image. It's basically the "analog hole" of the video world. If you wanted to do the cheap version of this you could probably set up a screen with proper lighting such that it'd line up well enough that screen and sensor pixels matched closely making it near if not completely impossible to tell a screen was involved. Worse, such a signature on a fake video may give people false confidence in it being real, when really it still needs scrutiny especially if a possible state level or dedicated attacker is involved.
- floatingatoll 7y agoNikon’s been offering chip-based video crypto for years, it’s just not popular in consumer-grade hardware yet. If it was, we’d all be up in arms about our devices having a unique fingerprint in every photo (or video) that could be used to track us.
- anbop 7y agoYou could have onboard acceleration and depth sensors on the camera to make the fake costlier to produce.
- bufferoverflow 7y agoThat wouldn't stop from someone filming a fake video.
- duxup 7y agoIt wouldn't, but it is a pretty big hurdle to stage a whole thing for an actual camera. What you describe has always been possible, but it seems rare.
- mises 7y agoThat works great if I'm looking for an official video from the Wall Street Journal, but not if I'm watching Fred's Blog Channel. Also, what if I want to edit something? What if I want to tweak the color profile? Add an effect? Oh, so now adobe software can re-sign something, but not the open-source option? And as pointed out by another comment, you'd get a modified camera and feed it into the sensor, or modify the firmware. And some guy in China will do a clean-room RE and make little video signers. The bottom line is it's a cool idea, but I don't think it will work, and I don't think it will stop fake anything.
- mises 7y agoThat works great if I'm looking for an official video from the Wall Street Journal, but not if I'm watching Fred's Blog Channel. Also, what if I want to edit something? What if I want to tweak the color profile? Add an effect? And as pointed out by another comment, you'd get a modified camera and feed it into the sensor, or modify the firmware. And some guy in China will do a clean-room RE and make little video signers. The bottom line is it's a cool idea, but I don't think it will work, and I don't think it will stop fake anything. Also, most of us complain about code signing when it affects us; why would this be different? Fred the Blogger can't get an "official video signing certificate", which is probably what we would end up with. Or better yet, get the government involved and create a Bureau of Trustworthy Video Sources!
- BlueTemplar 7y agoYep, this might make Intel-style rootkit+DRM legally mandatory... welcome to 1984 ! :(
- SmellyGeekBoy 7y agoWe've been through this whole argument before when HDCP was first proposed. I'd imagine this following exactly the same path.
- BlueTemplar 7y agoWell, the stakes are much higher now. See how Facebook got roped into having to do moderation !
- HeWhoLurksLate 7y agoSee how it's much harder for anyone else to replace Facebook now, because they need more staff to start out with?
- BlueTemplar 7y agoI don't follow ?
- jerf 7y agoI believe it's a reference to a general effect of regulation, which is by making the business being regulated more expensive due to following regulations, it prevents smaller businesses from popping up to potentially displace the larger business. For a generally positive example of this, see a good chunk of the history of Silicon Valley with smaller tech companies displacing larger companies like IBM, because there was no regulation stopping it. For an example generally less loved around here, consider Uber making a good pass at eating the entire Taxi industry by virtue of dodging regulations.
- 7y ago
- euparkeria 7y agoA blockchain could be used to solve this problem.