You’ve seen the AI-generated slop flooding your feeds. The deepfakes, the fabricated receipts, the politicians who never said those words. It feels like reality is slipping through our fingers. So, the tech giants offered us a lifeboat: cryptographic signatures. “Proof of Capture.” They want you to believe that if a photo is digitally signed by the camera, it’s real.
But it’s a lie.
Every cryptographic lock we build to protect reality just creates a new door for the perfect lie.
The open-source community is currently trying to replicate Apple’s “Reference Image” framework using steganography—hiding proof data invisibly inside the pixels of an image. It sounds brilliant. It sounds secure. But it completely misses the point. The vulnerability isn’t in the file format, and it isn’t in the AI model. It’s in the wires.
As one commenter pointed out, a grad student can simply intercept the physical connection between the camera’s light sensor and its image processor. You feed the camera a fake signal, and the camera will happily sign it as an “authentic” capture. The cryptography works perfectly; it’s just signing a lie.
Even without soldering skills, the “screen attack” still works flawlessly. Just take your AI-generated image, display it on a high-end monitor, and take a picture of it with a modern smartphone. The camera captures the fake, stamps it with a cryptographic signature, and sends it out into the world as verified truth. The entire premise of “Proof of Capture” collapses on contact with basic physical reality.
You don’t prove a photo is real by encrypting the file; you prove it by owning the wires.
So, how do the tech giants actually plan to fix this? If the attack surface is the physical boundary between light and silicon, the only way to guarantee a photo is real is to guarantee the physical integrity of the camera itself. That means sealed devices. No third-party repairs. Mandatory, always-on hardware attestation.
And it gets darker. In a world where video evidence is indistinguishable from AI generation, the only way to prove you didn’t commit a crime will be to prove where you were and what you were doing at every second of the day. People will willingly surveil themselves 24/7 with cryptographic proof, because it will be the only way to prove what they didn’t do.
The ultimate price of proving our innocence is recording our every breath.
We are rushing to build a total surveillance state just to win an arms race against AI image generators. The choice is stark: accept a world where visual proof is dead, or surrender physical control of every device we own to a cryptographic authority. The fix isn’t just broken. It’s a trap.
FAQ
Q: What's wrong with using steganography to sign images?
A: It only secures the digital file *after* it's been created. If the data feeding into the sensor is fake, or if you just photograph a high-res screen, you're just cryptographically signing a lie. The math is perfect, but the reality is compromised.
Q: What's the practical implication of this vulnerability?
A: 'Authenticated' photos will become meaningless for high-stakes evidence. Anyone with basic hardware skills can bypass the signature, meaning we cannot rely on cryptographic watermarks to distinguish truth from AI fiction.
Q: What's the contrarian take?
A: We shouldn't try to fix this with cryptography at all. We need to accept that visual proof is dead and adapt our legal and social systems to a world where seeing is no longer believing, rather than surrendering our hardware privacy.