C2PA Cameras Do Not Survive Contact With Reality

David Buchanan demonstrates that C2PA's content authenticity system on Android is fundamentally broken. By combining known root exploits and low-cost hardware fault injection, he forges C2PA-signed images and videos that pass verification as genuine camera captures. He explains how Key Attestation and Play Integrity fail against these attacks, and why hardware vulnerabilities can't be patched. Google acknowledged the issue but marked it as 'Won't fix (infeasible)', awarding a $7,500 bounty. The article includes a proof-of-concept tool and highlights that all C2PA camera apps on Android are similarly vulnerable.
C2PA on the Android platform is broken, in a way that cannot be realistically patched.
- mistercow
Aside from the fact that this was obviously never viable and the entire problem is clearly unsolvable if you sit down and really probe it for fifteen minutes, what I find most frustrating about this is that the false promise of preserving photos as reliable evidence is actively harmful.
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
- trentor
It's compliance for advertising. Your client doesn't want AI in their project you show them the audit trail and if it turns out to be faked you point to the supplier who faked it. Our agency signed a insurance not only because of clients who don't want to use AI in their artwork but also because of the EU AI act. They c2pa to get their money back from a cheating supplier if they are not compliant with the AI act.
- yaro330
All these funny jabs at Android's security meanwhile Pixels are literally one of the most secure devices in the industry and Google invest tons into security.
Hardware attestation stands unbroken to my knowledge, only software attestation can be faked, and even then it's a constant cat and mouse game which Google continues playing until they are done with Pixel 3 generation.
C2PA is not immune to the analogue hole, sure, but dark room + photo of a photo approach falls apart the moment you bake in depth data into the image, which is already done.
- uqers
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
- LiamPowell
I always got the impression that C2PA is a way to say "this photo came from the BBC (for example) and they've only signed it because they've verified the supplied edit chain". It's always been obvious that one could point a camera at a screen, I don't think anyone involved with C2PA has claimed otherwise.
It seems like there's a big disconnect between what C2PA says it's for and what certain journalists think it's for.
- randomblock1
Even at the hardware level, if it was a separate chip that the camera data passed through or something, that's not really good enough either, people have broken TPMs before. It'd have to be baked into the camera sensor. Even then, you could attack it from the next level up, with some fancy optics and a display, or something like that.
I don't think completely solving this sort of problem is even possible.
- vanyle
This reads a bit like "Door locks do not survive contact with reality."
The point is not to prevent state-sponsored actors to produce fake media, but to add friction and avoid shady marketing agency and photographs from claiming their pictures are genuine.
- CrzyLngPwd
C2PA was never going to work to prevent abuse, but what it will do it give false confidence.
Most people don't read HN, or understand tech, and so if the device says "captured with camera" then they will believe it since Google says it's true.
Accusing someone of a crime, with fake but verified photographic or video evidence will be trivial, and claiming it's fake just makes someone tap the "Google says it's true" sign.