4 ms·
I too wonder whether cryptographic signatures will be the long run solution to deepfakes. Can you outline why you don't think that will be the case? Here's an
by sigil 5y ago
I too wonder whether cryptographic signatures will be the long run solution to deepfakes. Can you outline why you don't think that will be the case?
Here's an alt solution to argue against:
1. The necessary PKI gets bootstrapped by social media companies, where deepfakes begin to seriously threaten their "all-in-on-video" strategy, and simultaneously look like an opportunity to layer on some extra blue-check-style verification.
2. Example: you upload your first video to twitter, it sees the AV streams are unsigned, generates a keypair for you, does the signing, and adds the pubkey half to your twitter account. (All of this could be done with no user input.)
3. The AV streams have signatures on short sequences of frames. Say every 24th video frame has a signature over the previous 24 frames embedded into the picture. Similarly, every second of audio has a signature baked in.
4. The signatures aren't metadata that can be easily thrown away. They're watermarked into the picture and audio themselves in a way that's ~invisible & ~inaudible, but also robust to downsampling & compression. This is already technically possible.
5. Since we're signing every past second of the AV streams, this works for live video.
6. Viewers on the platform see a green check on videos with valid signatures; maybe they even see the creator's twitter handle if this is a reshare.
7. Like all social media innovations, the other major platforms copy it within the next 6 - 12 months. POTUS uses it. People come to expect it.
8. Long run: the public comes to regard any unverified video footage with suspicion.
Why won't this deepfake solution come to pass in the long run?
- davidweatherall 5y ago(Not OP) This would work for videos that people want to acknowledge as their own, but they could just tweet out they own it for the same affect. The issue this tackles is videos that people don't want to claim ownership of, e.g. if a video emerged of <insert politician here> kicking a child, the politician can't say "I haven't signed it therefore it's not mine", instead we need tools like the above to be able to say, "this is faked, do not trust it".
- sigil 5y agoMaybe in the interim we need deepfake detection tools, but I'm asking about the long run. Suppose signed AV takes off as described above. The public has been trained: "If the video doesn't have The King's Seal, it's not from The King."
- ChefboyOG 5y agoI think the point is that yes, that seems like a good solution for verifying content that purports to be released by a certain creator, but it doesn't solve the problem of deep fakes for captured footage i.e. you can prove it isn't a video that you created, but you can't prove it isn't a video someone else took of you.
- sigil 5y agoThat makes sense. But if signed AV takes off, the video someone else took of you and shared likely bears their seal. And audiences decide how much they trust that source – just like they look for a CNN / BBC / etc logo in the corner currently.
- asail77 5y agoGreat discussion. Many have asked the same questions. We hope a standard will be created and used by all digital content creation tools. But this will take time. And even then, bad actors will not be deterred. They will always find ways to create fake content and pass it as authentic. We want to be there to fight them every step of the way!
- rockemsockem 5y agoThere is a standard for this actually. Hot(ish) off the press: https://c2pa.org/ https://c2pa.org/
- rockemsockem 5y agoNot OP, but personally I'd love to see this sort of tech baked directly into smartphones and cameras. Your camera could have tamper-proof hardware that embeds signatures like you describe into the metadata of your video/photos while you take them. Sure, the user can separate it, but like you said over time people just won't trust photos/videos without this assurance. Apps like snapchat that let you apply filters could also add additional metadata, going through more hardware verified operations provided by things like Apple's secure enclaves, saying something like "X filter applied over frames N-M" and you can have an edit chain to go with the original video/photo. With this infrastructure in place our phones could really serve as ways to certify reality itself.
- _0ffh 5y agoNo, absolutely not. This will only serve to prop up a false confidence in correctly signed videos. So in the end you're giving all the power to black hat groups and three letter services that can procure the secret keys from the camera vendors. Face it: Video proof is as good as dead, to delude yourself into thinking anything else is extremely dangerous.