3 ms·
> Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data. Is the whole point here that Ap
by avianlyric 17d ago
> Like with C2PA, the entire thing hinges on nobody being able to dump keys or trick the TPM into signing arbitrary image data.
Is the whole point here that Apple have baked the TPM and keys directly into the sensor. So extracting the keys or injecting arbitrary data, will likely involve the destructive delidding of the image sensor itself.
That’s a significantly higher bar you need to jump, than any approach where the sensor and TPM are separate modules with no cryptographic capabilities in the sensor itself.
From the article
> The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data.