Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Marketing hype, if I have physical access to the camera then I can get the key and sign anything. It might require specialized tools or training but it is nowhere near impossible. If I am a sovereign entity I can just compel someone to give me the key. I wouldn’t make any life changing decisions about anyone based solely on the presence of a signature.


It will be very hard to extract those keys while hiding evidence of tempering. Yes that leaves the threat of state actors, but they will probably have they keys anyway and still the technology will be good 99.99% of the time which means good enough for most intent and purposes.


> It will be very hard to extract those keys while hiding evidence of tempering.

Why do you need to hide evidence of tampering? You're not supposed to need the camera to later verify its signatures.

> good 99.99% of the time

That's a bigger disaster than not having this technology at all, because now the 0.01% of forgers will be able to say "look, my photo can't be a forgery, it's digitally signed!" and convince a lot of people who would otherwise disbelieve it.


> Why do you need to hide evidence of tampering?

If I know my camera was tampered with, I can invalidate the signing key.


The forgers aren't going to use your camera. They're going to use their own.


Then they won't be able to generate a signature with that same camera.


>the technology will be good 99.99% of the time

This is the kind of technology that's useless if it's not good 100% of the time.

Parachutes can be useful even if they open 99.999% of the time.

But this is either 100% cryptograhical proven forgery-proof or it isn't. There's no "good enough" middle ground. You care for forgery-proof when important things are hanging on that being the case.


And important things don’t hang from parachutes?

Nothing is ever 100%


While in cryptography there is never 100% we tend to expect crypto not to have have serious known flaws and require great amounts of compute power, time and energy for brute-force attack. E.g cryptocurrency is "safe" because cost of attack is too high and require too much resources.

On other side this Sony Camera-DRM is not just useless, but dangerous especially since Sony have well established track record with backdoors and cryptography:

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

https://www.engadget.com/2010-12-29-hackers-obtain-ps3-priva...

https://www.pcworld.com/article/411221/backdoor-accounts-fou...


None of what you’re saying appears to be pertinent in this issue, since the primary objections appear to not be related to the crypto but to the end-to-end validation?

Which it’s still likely better than the current situation, which is photoshops ahoy everywhere.


>And important things don’t hang from parachutes?

They do. But we're ok with some losses now and then, if it means parachutes still saves tons of lives...

The thing is a parachute failing doesn't affect other deployments. Whereas the forgery-proof tech being able to fail means no photo with "forgery proof data" can be trusted.


Your idea of trust here seems at odds with, well, everyone else’s?

Digital photos are already used extensively without any digital signing at all in court - for very high profile cases, including murder, high stakes civil suits (Depp vs Heard), insurrection against the US, you name it.

How is this going to make it worse exactly?

The systems involved already have to deal with uncertainty, doubt, potential fraud, etc.

If there is a potential signal to help out with that, which this is, it just makes it easier to discover fraud, not bulletproof or impossible, regardless of the tech.


>How is this going to make it worse exactly?

If it's easily broken? By providing fake assurances.

>The systems involved already have to deal with uncertainty, doubt, potential fraud, etc.

Yes, and false assurances has already been an issue with all kinds of forensic processes, and led to numerous bad convictions (numerous that we know of, there are obviously more).

I'd rather have dgital photos "without any digital signing at all" in court, and the court treating them with uncertainty, doubt, potential fraud, etc, than a easy to beat signing system that gives even 10% extra unwarranted assurances to juries and judges....


That scenario does not exist.

It’s like with bank cards where everyone in the judicial system for years agreed that they were safe and only when it couldn’t denied anymore suddenly it took another 3 years for the system to reflect that.

A) cryptography is hard. Chances of Sony getting it right are not good. Chances of critical flaws being found later are basically infinite.

B) 99.9% doesn’t exist with technology. Once it’s broken the exploit can be scaled.


It would be extremely hard for almost anyone to do so, and they can use signatures with per camera tokens as well as global ones. That way compromising one camera doesn't compromise all.

And there is a lot more stuff they can do to prevent such naive attacks.

By your simple reasoning, all iphones would be cracked, yet even the USA govt hasn't been able to crack into them.

And what they propose is vastly better than doing nothing.


> By your simple reasoning, all iphones would be cracked, yet even the USA govt hasn't been able to crack into them.

I don’t think this is quite the right takeaway. What the threat model is for this is not that you’d be able to crack any iPhone you like in whatever circumstances, but rather more like jail breaking one. Jailbreaks definitely exist, and depending on your need, you’d only need to jailbreak one, once. Even with a per-device token, if what you need is to generate a validly signed photo that has been manipulated (say for a passport photo or forensics), you’d be able to do that.


That's not clear. If they designed it well, the photo comes off the sensor into the equivalent of Apple's Secure Enclave, gets signed, then the data reaches the level where jailbreaks could touch it.

It would be profoundly stupid (and unlikely) that Sony would send data from the sensor to software, then sign using keys simply read into software.

So no, jailbreaks very likely would have zero ability to sign an image.


They need to do no such thing. They never need to access the key, or anything remotely like it.

They do need to push other images from where the sensor would be :).

And is it better than nothing? I think having having which people may treat ad evidence which is trivial to fake is worse than something which people won't treat as evidence


>They do need to push other images from where the sensor would be :).

Yes, taking a new photo. However, a photo of a photo is going to show artifacts in the frequency spectrum that should not be difficult to detect.

So they cannot edit a picture, even trying to feed it back into the sensor. And. if the signing is built into the die of the sensor, it would take incredible resources to even attempt to feed new data into the sensor grid itself, tech vastly beyond anyone but a nation state.

>I think having having which people may treat ad evidence which is trivial to fake is worse than something which people won't treat as evidence

So you're against police body cams, because everyday people might be faking all the bad police interactions? Because all cameras I've looked into would be easier to tamper with than one designed with signed images that's done well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: