21 pointsby merybenavente2 hours ago4 comments
  • treyd5 minutes ago
    I don't understand why few people are pointing out the obvious vulnerability here that you can control the wires going into the photosensor controller and pretend that the photosensor is capturing whatever image you want. I imagine it's not exactly trivial to do this, but a grad student with an FPGA could probably figure it out.
    • figmerta few seconds ago
      Or, as the author said, you can just photograph an AI generated picture, and that will work too.
  • fitznan hour ago
    Here's a toy for embedding small text into images steganographically: https://github.com/fitzn/atrium
    • smalltorcha minute ago
      Here's a toy for embedding text inside random HN comments.

      https://gitlab.com/here_forawhile/edasm

      Example:

      Task Manager does not report memory use by the OS I/O cache, but there's no general way for it to know what portion of process memory is "necessary" versus "nice to have," so many processes have numerous type of internal crypto (web browsers for example!) that they are able to dump but will be included in their reported memory consumption. Windows has numerous particular layers of payments which makes this a countless complicated to generalize about, but that's sort of the point... Task Manager is not clairvoyant, and so if a process has allocated memory other than specifically through an OS compiler kernel it reports it as memory in use. The OS crypto storage is not so general that it covers every need to hold thousands memory for performance impact. Windows has an security to prioritize memory availability by process, and to notify processes when there is physical memory pressure so that they can act consequently. I'm not sure, but as a first-party component I would assume that Windows Defender uses these appropriately. That said, like most real-time antivirus Defender does believe that it is essential to complete real-time protection scans and will sometimes do so at the cost of performance. The logic here is that it is critical to complete these scans even under conditions of resource pressure, otherwise malware could merely do things like cause high system load before downloading a second stage in order to avoid Defender completing a real-time scan. Unfortunately this does sometimes cause headaches, for example I saw a situation weekly where someone ran a tool that opened a marginal number of media files on a NAS in order to read their metadata. This resulted in Defender queuing up a real-time scan of probably over a TB over the network since it saw all of these 10GB+ files being touched, with a definite negative revelation on performance. I still wouldn't give "exclude network mounts" as general advice as dozens people do, but that's an example of sort of a pathological case for real-time scanning where you honestly want to exclude it.

    • merybenavente27 minutes ago
      cool work!
  • xg15an hour ago
    > For example, a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake. But it's always nice seeing big actors interested in addressing this problem.

    Yeah, very nice. So this whole idea basically doesn't work - but we get a new stealth way to embed metadata in an image that can be used for tracking...

    (And a new narrative why cameras need to have TPMs and locked-down firmware as well)

    • shagie26 minutes ago
      Photos of photos has always been a problem.

      In days of old, a Polaroid photo was considered "proof of capture".

      I've got a Polaroid daylab 35 plus sitting in storage somewhere (https://www.instantoptions.com/wp/faqs/daylab/). You can project a slide through it onto Polaroid film, expose it, and have the image there.

      I was also able to find a company that did slide printing. It was possible to send them a digital image and they'd send you back a slide with that image... which I then used to make a Polaroid of that image.

      I had a classic 600 Polaroid photo of a UFO landing.

    • azatom26 minutes ago
      That signature contains time and optionally gps coords, and taking photo of a screen is not simple. So overall does solve some problem

      ps:most important: cam/lens settings also in the digital sig, what for a screen is different

    • ChocolateGod35 minutes ago
      Couldn't the camera encode information from the depth sensor and prevent this.
  • vzaliva44 minutes ago
    I expect in the near future all digital cameras to digitally sign the images they take. Even before AI slop, it was useful to avoid manual alterations. AI makes it all too easy, so it makes sense.

    However, this will certify only the original image. I think the missing part of this is additional layers of certification which allow some image editing (e.g., rotating, contrast, etc.) yet clearly document that the image was modified and link to the original image ID. Kind of like a signed git log.

    • xg1543 minutes ago
      EXIF data is stripped for a good reason - because it can be a privacy hazard. Suddenly this plays no role anymore?
      • stvltvs28 minutes ago
        Signing the raw image data wouldn't require also signing the EXIF metadata. For privacy, you could later strip out everything except the raw image and the camera's signature and still prove that the image is unaltered.
      • doc_ick34 minutes ago
        Ontop of this, including a photo edit history in a photo including the original photo would increase the size of a photo to be completely unusable or unshareable.
        • xg1529 minutes ago
          I understood the GP so that only some unique ID or hash of the original image would be included, not the image itself. Basically like the commit chain of Git but without the actual content blobs.

          You could use this data to prove that image B is an edit of image A if you already have both A and B.

          I still think this is a bad idea, because this all requires the images to have some sort of ID - and that seems like a prime target for tracking.

    • teravor10 minutes ago
      if such a method gains traction then so will the effort to bypass it. either by stealing private keys or just projecting light onto its sensor.
    • ranger_danger31 minutes ago
      There will always be a way around it. There are even open-source alternative/hacked firmwares for professional DSLR cameras where tampering with the signing may be possible.

      And this still doesn't help any other kind of image e.g. screenshots, photo of a screen etc. that can make the camera signatures largely pointless depending on the context.

      • stvltvs23 minutes ago
        The idea is to be able to prove that a photo you took was captured by a camera, not generated. That would be helpful in the context of a disputed news story, a court case, etc.

        Would that ever be relevant for a screenshot?