| |
David Buchanan demonstrates a critical vulnerability in C2PA (Content Authenticity and Provenance) metadata by creating a fake lottery prediction image with a backdated timestamp. The exploit leverages C2PA's allowance of arbitrary "exclusions"—byte ranges excluded from signature calculations—which permits modification of files after they've been cryptographically signed by a Time Stamp Authority. This reveals a fundamental flaw in C2PA's design that undermines its purpose as a tool for verifying media authenticity and provenance.
Read Full Article →
← More Tech news