{
  "id": 11678015,
  "title": "How to Hack Time, With C2PA",
  "url": "https://urgent.news/2026/10/03/how-to-hack-time-with-c2pa",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T11:58:14.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://www.da.vidbuchanan.co.uk/blog/hacking-time.html"
  },
  "original_language": "en",
  "account": "The story of hacking time through C2PA metadata originated from the 2015 film Kung Fury, where the protagonist, Hackerman, uses the power to manipulate time to rectify historic wrongdoings. The concept of hacking time to one's advantage has been explored, with the author themselves attempting to use the lottery numbers from a photo they created. The photo, identified as being photoshopped due to C2PA metadata, can be verified at specific links provided. The C2PA metadata includes a claim signature and a timestamp signature, the latter provided by a Time Stamp Authority (TSA). The TSA serves as an independent witness to confirm the existence of data at a certain timestamp. In the case of Google Pixel 10, devices are assumed to be trustworthy in their timekeeping. The author focuses on exploiting a bug known as the spec footgun, which allows for arbitrary exclusions in the file, enabling changes to be made post-signature without invalidating the C2PA metadata. This allows for the tampering of files, like photoshopping a lottery ticket, without detection. The author suggests that the exclusion feature should be explicitly specified for each file format to avoid potential issues.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}