There are ways around that. Apple & Google can embed a private key into the Secure Enclave, sign every image with this key, and at the same time write the hash onto a fast public ledger (e.g. Solana). This validates that this specific image was taken at that specific point in time. Doing it that way would validate the image. That would lead to a world where only these "vetted" images can be trusted and untrusted devices (e.g. Nikon cameras) can take nice pictures but no "truthy" pictures. But it would be an escape hatch.
What if I held up a display in front of that "verified sensor" that shows the manipulated image? Then you'd end up with a "100%, absolutely verified image" of a manipulated image.
This would be counterproductive, it would make "in-camera" fakes more convincing. For instance, political provocateurs could use actors/makeup/etc to stage a scene then take "vetted" photographs of that.
Indeed, this concept has a concrete standard in progress (originating from Adobe, Microsoft, and the BBC) with the Coalition for Content Provenance and Authenticity (C2PA):
C2PA as far as I remember doesn't require a transparency log, but as you mention it could be a good fit as well. Besides Solana, https://transparency.dev/ could be a good option (used as part of Certificate Transparency and Sigstore).
Comments
There are ways around that. Apple & Google can embed a private key into the Secure Enclave, sign every image with this key, and at the same time write the hash onto a fast public ledger (e.g. Solana). This validates that this specific image was taken at that specific point in time. Doing it that way would validate the image. That would lead to a world where only these "vetted" images can be trusted and untrusted devices (e.g. Nikon cameras) can take nice pictures but no "truthy" pictures. But it would be an escape hatch.
What if I held up a display in front of that "verified sensor" that shows the manipulated image? Then you'd end up with a "100%, absolutely verified image" of a manipulated image.
This would be counterproductive, it would make "in-camera" fakes more convincing. For instance, political provocateurs could use actors/makeup/etc to stage a scene then take "vetted" photographs of that.
Indeed, this concept has a concrete standard in progress (originating from Adobe, Microsoft, and the BBC) with the Coalition for Content Provenance and Authenticity (C2PA):
https://c2pa.org/
C2PA as far as I remember doesn't require a transparency log, but as you mention it could be a good fit as well. Besides Solana, https://transparency.dev/ could be a good option (used as part of Certificate Transparency and Sigstore).
That assumes a high level of tech literacy and a high level of trust in the tech companies implementing the system.
All you need is one demagogue saying “it’s fake, you can’t trust them, big tech is lying to you” etc. And people will believe that.