hackerfactor.com/blog/index.p...
I'm often asked if I have a list of C2PA problems. Yes, yes I do. Here's the current 27-page bulleted list. Any one of these issues should make companies reconsider any C2PA adoption plans and run away.
hackerfactor.com/blog/index.p...
I'm often asked if I have a list of C2PA problems. Yes, yes I do. Here's the current 27-page bulleted list. Any one of these issues should make companies reconsider any C2PA adoption plans and run away.
hackerfactor.com/blog/index.p...
C2PA won't stop fake IDs, BBC made their bad example worse, Microsoft's validation service is offline, and Truepic's gives bad results. But good news: UMBC is formally evaluating C2PA, SEAL, and related tech.
hackerfactor.com/blog/index.p...
C2PA won't stop fake IDs, BBC made their bad example worse, Microsoft's validation service is offline, and Truepic's gives bad results. But good news: UMBC is formally evaluating C2PA, SEAL, and related tech.
hackerfactor.com/blog/index.p...
Simple tips to stay safe online when attending a protest.
hackerfactor.com/blog/index.p...
Simple tips to stay safe online when attending a protest.
hackerfactor.com/blog/index.p...
Don't trust signatures in PDF files. They are too easy to forge and alter.
hackerfactor.com/blog/index.p...
Don't trust signatures in PDF files. They are too easy to forge and alter.
hackerfactor.com/blog/index.p...
The Arizona Secretary of State released a pilot program that demonstrates C2PA signing. Every example demonstrates how C2PA does NOT work.
hackerfactor.com/blog/index.p...
The Arizona Secretary of State released a pilot program that demonstrates C2PA signing. Every example demonstrates how C2PA does NOT work.
www.hackerfactor.com/blog/index.p...
At ShmooCon, Microsoft presented on C2PA but didn't address any of the problems. To demonstrate the ineffectiveness of C2PA, I walk through step-by-step how to create an authenticated forgery.
www.hackerfactor.com/blog/index.p...
At ShmooCon, Microsoft presented on C2PA but didn't address any of the problems. To demonstrate the ineffectiveness of C2PA, I walk through step-by-step how to create an authenticated forgery.
"The Garamond brothers are back and they're going after the Courier," declared Arielle.
"Don't worry," Roman replied. "The New Times reported that there's a new Serif in town."
"The Garamond brothers are back and they're going after the Courier," declared Arielle.
"Don't worry," Roman replied. "The New Times reported that there's a new Serif in town."
hackerfactor.com/blog/index.p...
SEAL can now digitally sign over two dozen different common file formats, including images, audio, video, and documents.
hackerfactor.com/blog/index.p...
SEAL can now digitally sign over two dozen different common file formats, including images, audio, video, and documents.
news.adobe.com/news/news-de...
It's written by Adobe's Head of Responsible Innovative Communications, who is working on Adobe's C2PA and CAI.
Yup, no bias in these findings! (sarcasm emoji: 💩)
news.adobe.com/news/news-de...
It's written by Adobe's Head of Responsible Innovative Communications, who is working on Adobe's C2PA and CAI.
Yup, no bias in these findings! (sarcasm emoji: 💩)
www.hackerfactor.com/blog/index.p...
I recently participated in a panel discussion about C2PA. As part of the attacker's perspective, I demonstrated how to trivially alter C2PA's cryptographically signed time stamp.
www.hackerfactor.com/blog/index.p...
I recently participated in a panel discussion about C2PA. As part of the attacker's perspective, I demonstrated how to trivially alter C2PA's cryptographically signed time stamp.
www.hackerfactor.com/blog/index.p...
www.hackerfactor.com/blog/index.p...
www.hackerfactor.com/blog/index.p...
Finally figured out how to stop the random CPU crashes! (At least, I really think so this time.)
www.hackerfactor.com/blog/index.p...
Finally figured out how to stop the random CPU crashes! (At least, I really think so this time.)
A simple, free, and decentralized solution for media authentication. (A better solution than C2PA.)
A simple, free, and decentralized solution for media authentication. (A better solution than C2PA.)