5 ms·
I think it's practically impossible for such a system to be globally trustworthy due to the practical inevitability of "but improper storage of private keys lea
by PeterisP 2y ago
I think it's practically impossible for such a system to be globally trustworthy due to the practical inevitability of "but improper storage of private keys lead to vulnerabilities" scenarios.
People will expect or require that chain of custody only if all or at least the vast majority of the content they want would have that chain of custody.
Photo/video content will have that chain of custody only if all or almost all of devices recording that content will support it - including all the cheapest mass-produced devices in reasonably widespread use anywhere in the world.
And that chain of custody provides the benefit only if literally 100% of these manufacturers have their private keys secure 100% of the time, which is simply not happening; at least one such key will leak, if not unintentionally then intentionally for some intelligence agency who wants to fake content.
And what do you do once you see a leak of the private keys used for signing the certificates for the private keys securely embedded in (for example) all of 2029 Huawei smartphones, which could be like 200 million phones? The users won't replace their phones just because of that, and you'll have all these users making content - so everyone will have to choose to either auto-block and discard everything from all those 200 million users, or permit content with a potentially fake chain of custody; and I'm totally certain that most people will prefer the latter.
- macrolime 2y agoMultisig by the user and camera manufacturer can help to some extent.
- PeterisP 2y agoMultisig requires user cooperation, many users will not care to cooperate, and chain of custody verification really starts working only if you can get (force) ~100% of legitimate users globally to adopt the system. Also, for the potential creators of political fakes, such a multisig won't change things - getting a manufacturer's key may take some effort, but getting (and 'burning') keys of a dozen random people is relatively trivial in many ways - e.g. buying off of poor people, stealing from compromised random machines, or simply issuing fake identities for state-backed actors.