4 ms·
> I worked in device attestation at Android. It’s not robust enough to put our understanding of reality in. I don't follow. Isn't software backward compatibili
by dataflow 3y ago
> I worked in device attestation at Android. It’s not robust enough to put our understanding of reality in.
I don't follow. Isn't software backward compatibility a big reason why Android device attestation is so hard? For cameras, why can't the camera sensor output a digital signature of the sensor data along with the actual sensor data?
- teaearlgraycold 3y agoThere's been a slow march to requiring hardware-backed security. I believe all new devices from the last couple of years need a TEE or a dedicated security chip. At least with Android there are too many OEMs and they screw up too often. Bad actors will specifically seek out these devices, even if they're not very technically skilled. The skilled bad actors will 0-day the devices with the weakest security. For political reasons, even if a batch of a million devices are compromised it's hard to quickly ban them because that means those phones can no longer watch Netflix etc.
- dataflow 3y agoBut you don't have to ban them for this use case? You just need something opportunistic, not ironclad. An entity like Google could publish those devices' certificates as "we can't verify the integrity of these devices' cameras", and let the public deal with that information (or not) as they wish. Customers who care about proving integrity (e.g., the media) will seek the verifiable devices. Those who don't, won't. I can't tell if I'm missing something here, but this seems much more straightforward than the software attestation problem Android has been dealing with so far.
- johnny22 3y agoWoudln't that prevent most folks from being able to root their devices without making the camera lesser than everyone else's camera?
- dataflow 3y agoWhat does this have to do with root? The camera chip would be the one signing the data flowing through it, not the Android kernel.
- 8note 3y agoIf you do a jpeg compression, or crop the file, then does that signature matter anymore?
- dataflow 3y agoNot if you do it, only if the chip also gives you a signed JPEG. Cropping and other simple transformations aren't an issue, though, since you could just specify them in unsigned metadata, and people would be able to inspect what they're doing. Either way, just having a signed image from the sensor ought to be adequate for any case where the authenticity is more important than anesthetics. You share both the processed version and the original, as proof that there's no misleading alteration.
- chii 3y ago> You share both the processed version and the original, as proof that there's no misleading alteration so you cannot share the original if you intend to black out something from the original that you don't want revealed (e.g., a face or name or something). The way you specced out how a signed jpeg works means the raw data _must_ remain visible. There's gonna be unintended consequences from such a system. And it aint even that trustworthy - the signing key could potentially be stolen or coerced out, and fakes made. It's not a rock-solid proof - my benchmark for proof needs to be on par with blockchains'.
- dataflow 3y ago> The way you specced out how a signed jpeg works means the raw data _must_ remain visible. There's gonna be unintended consequences from such a system. You can obviously extend this if you want to add bells and whistles like cropping or whatever. Like signing every NxN sub-block separately, or more fancy stuff if you really care. It should be obvious I'm not going to design in every feature you could possibly dream of in an HN comment... And regardless, like I said: this whole thing is intended to be opportunistic. You use it when you can. When you can't, well, you explain why, or you don't. Ultimately it's always up to the beholder to decide whether to believe you, with or without proof. > And it aint even that trustworthy - the signing key could potentially be stolen or coerced out, and fakes made. I already addressed this: once you determine a particular camera model's signature ain't trustworthy, you publish it for the rest of the world to know. > It's not a rock-solid proof - my benchmark for proof needs to be on par with blockchains'. It's rock-solid enough for enough people. I can't guarantee I'll personally satisfy you, but you're going to be sorely disappointed when you realize what benchmarks courts currently use for assessing evidence tampering...
- qbit42 3y agoI am not sure how verifying that a photo was unaltered after capture from a camera if very useful though. You could just take a photo of a high-resolution display when an edited photo on it
- dataflow 3y agoThat wouldn't look nearly realistic. And it would be significantly harder to achieve for most people anyway.
- michaelt 3y agoIt's true that 1990s pirated videos where someone snuck a handheld camera into the cinema were often very low quality. But did you know large portions of The Mandalorian were produced with the actors acting in front of an enormous, high-resolution LED screen [1] instead of building a set, or using greenscreen? It turns out pointing a camera at a screen can actually be pretty realistic, if you know what you're doing. And I suspect the pr agencies interested in flooding the internet with images of Politician A kicking a puppy and Politician B rescuing flood victims do, in fact, know what they're doing. [1] https://techcrunch.com/2020/02/20/how-the-mandalorian-and-ilm-invisibly-reinvented-film-and-tv-production/ https://techcrunch.com/2020/02/20/how-the-mandalorian-and-il...
- dataflow 3y agoThat's a freaking massive LED wall... with professional cinematography on top. If you believed my comment was intended to imply that I believed that's somehow impossible, well... you and I have a very different understanding of what it means to "just take a picture of a high-resolution display"...