3 ms·
On smartphones at least, you could require users to use a specific app to establish the authenticity of the footage. You could have a code hash signature for th
by johnfernow 3y ago
On smartphones at least, you could require users to use a specific app to establish the authenticity of the footage. You could have a code hash signature for the app to compare against the current hash and make sure the compiled code was not altered. The app can be open source so people can trust it and compile it themselves, but if the hash doesn't match the videos would be considered untrusted. You would also have to take measures to ensure that there aren't runtime modifications — a difficult thing to accomplish for sure, but something some companies are getting increasingly good at.
In addition to LIDAR data, throw in gyroscope data (would make recording a screen more obvious) and GPS data (would need the screen where you say you are — would also need to make sure device is not rooted or jailbroken to prevent spoofing of GPS) and it becomes even more challenging to fake a video. I think securing the app against modification or runtime injections is probably the biggest point of focus, but even if you were able to defeat all those measures, you'd still need to have models generate convincing LIDAR, gyroscope and GPS data. Not impossible of course, but at that point you need a rooted phone that is able to successfully hide that it is rooted, several well trained models, and the ability to defeat the video app's own security measures against both binary and runtime modifications.
On a technical level, it may not be possible to develop an app that records videos with LIDAR, gyroscope and GPS data that could not be fooled by recording a screen. In practice, I think it is possible to develop an app that could establish the authenticity of videos that nearly everyone except maybe state actors would be incapable of defeating (maybe the world's richest corporations might also have the funds to do so, though I think the odds of a whistleblower or leaks is a bit higher there — maybe Microsoft could gather a team of highly talented AI developers to generate fake videos passed as real ones without notice, but I think the likelihood of not a single one of the employees revealing that info to journalists, the government or public is low.)
I share many concerns about device attestation, as it has potential to limit a user's freedom to do what they want with the hardware that they bought and software and services that they pay for. That said, if I really was dying to use a rooted phone (I'm not currently, due to it being more hassle than it's worth), I wouldn't mind buying a second, heavily locked down device for proving videos I record are real. The device could even be powered by entirely open source software, but have a hash for the compiled ISO that is used to install the OS.