Skip to content

Comment on A scientist who spots fake videosparent

Comments

I'm not sure in-camera signatures are the way to go.

In the very simplest case, someone could just point a camera at a very high quality screen and record that, generating a signed video.

A more complex attack would be to effectively emulate the image sensor and pipe image data straight into the camera.

If you want to prove that a video was filmed on or before a certain time, one way would be to hash it and put that hash on a blockchain, but that doesn't really solve the problem of authenticity.

Try it. Record something off the screen (including the audio), and see what happens. I'm yet to see one example of that that looks like reality.

Emulating a sensor sounds like it immediately reduces the number of perpetrators by orders of magnitude.

I agree though, what I'm suggesting is not 100% bulletproof, but it's using a proven technology, and it's relatively simple, assuming hardware manufacturers are willing to add one small chip to their cameras.

If you're pretending it's footage of a film, TV show or video game, then recording from the screen will fool a lot of people. And while in a lot of cases that would make the 'metadata' aspect useless anyway, there's always the possibility of a hoaxer either saying:

1. This was recorded from a TV broadcast

2. Or a CCTV camera

Etc.

I've seen a number of YouTube and liveleak videos that were obviously made by recording a security monitor with a phone. Seems to be an acceptable practice for certain genres, and is usually credible.

Which only makes things worse, because if you are trying to create fake security camera footage, you just need to make it real enough to play back on a "security monitor" and record that with a phone camera.

That's not his point. He is claiming he can record a fake video that plays on a screen, and the resulting recording will look like a recording of reality, not of the screen (and the camera will sign it as such).

What if the camera also included gps and time stamp information? That might make it harder to fake, because you would have to be roughly in the location that you were claiming that the footage occurred.

Are the signals from the gps satellites cryptographically signed?

Of course, the cameras would need to have very good physical security so that a person can't either extract the private key from it, or do things like replacing the camera part with something that just feeds in the data you want, and still getting it signed with the key.

I think the design that went into the ORWL pc might be good for this (which would quickly delete the private key if it detected tampering).

In order for one of these to be trusted though, there would have to be a trusted source demonstrating that it was constructed and configured correctly (rather than in a way that would allow faking). Maybe by having the construction and setup be recorded with other cameras of the same type which are already trusted, in a web of trust sort of thing? If one had enough of these cameras I don't think that the bootstrapping of the chain of trust would be too difficult.

It's pretty easy to fake GPS signal with the proper equipment. I remember seeing a video of a guy faking the GPS signal in order to cheat Pokemon Go.

Aw dang, ok.

But if the gps satellites cryptographically signed their messages, would that help this much? And would it be all that much of a cost for future gps satellites to sign their messages?

maybe 3d-cameras can help? anyway, this forgery stuff is getting scary...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.