C2PA Cameras Do Not Survive Contact With Reality
C2PA, a technology designed to prevent AI forgeries by having cameras cryptographically sign images, is flawed on Android platforms. Several factors contribute to this, including reliance on Key Attestation and Google Play Integrity, which both fail when apps are rooted. Android devices can be rooted through low-cost hardware fault injection attacks, and existing hardware vulnerabilities cannot be patched.
This renders C2PA ineffective on Android, as anyone can now generate forged images without hardware attacks. Google's Pixel Camera app achieved the highest security rating within the C2PA Conformance Program, but this is due to software-only exploits being more convenient and easily available. The existing hardware exploits cannot be patched and pose a significant threat, especially to groups with advanced resources.
Additionally, hardware exploits cannot be patched, leaving Android devices vulnerable. Users can now sign any image with C2PA, as demonstrated by provided PoC scripts and tools, such as keystork, which allows arbitrary operations against the KeyStore API.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.