Rendered at 19:20:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
bawolff 21 hours ago [-]
> C2PA allows for arbitrary "exclusions". These are byte ranges within the file which are excluded from signature calculations
Glad to see we learned from the mistakes of SAML.
hedora 20 hours ago [-]
If not this, then how would you propose updating the signed file to contain the signature?
/s
mugul 11 hours ago [-]
Would have been great to have that sorted out and fixed before passing the EU AI Act and forcing all content generation providers to embed C2PA manifests in their outputs...
dagmx 4 hours ago [-]
The EU AI act doesn’t force C2PA or any particular standard. Yes many people will use C2PA erroneously, but C2PA is not meant for indicating content was virtually generated, but that it was not modified from origination.
C2PA is fallible if your origin is fallible. SynthID is a better standard for designating something was created with GenAI, though is limited in what it covers. For example, 3D content is currently a poor fit for both SynthID and C2PA. Audio is also imho poorly served.
There are a few things in the works for 3D…audio is an area I’ve tracked less.
But crucially , none of the global regulations require C2PA specifically. And with all synthetic data , you’re really relying on honor system for transparency.
It’s not like the sensor to display pipeline that C2PA and Apple’s Reference Image can provide when enforced in hardware.
j16sdiz 7 hours ago [-]
C2PA is never a good standard for AI.
In traditional provence use case, you want to prove the image have never edited after it was created from the source. When signature mismatch, it is considered invalid.
For AI use case, you want to proof the image have never touched with AI. C2PA only (kind of) proof the last touch wasn't from AI..
simoncion 6 hours ago [-]
> C2PA only (kind of) proof the last touch wasn't from AI..
Given how bad Google's implementation is, the only thing Google's implementation proves is that someone somewhere on earth owns a Pixel phone... and we'll probably learn that it doesn't even prove that.
I like to contrast how Google has responded to the failure of their implementation with how Nikon responded to the very same sort of failures. (Search for "Nikon" here [0], but -IMO- the whole post is worth reading.)
Only tangentially related, but knowing that remote attestation and co. will only ever get... "better" fills me with impotent rage like almost nothing else. https://www.lafkon.net/tc/ (2004) was so very prescient.
Glad to see we learned from the mistakes of SAML.
/s
C2PA is fallible if your origin is fallible. SynthID is a better standard for designating something was created with GenAI, though is limited in what it covers. For example, 3D content is currently a poor fit for both SynthID and C2PA. Audio is also imho poorly served.
There are a few things in the works for 3D…audio is an area I’ve tracked less.
Wacom have a synthid like embedding for geometric data https://youtu.be/AEi083BtgvU?si=Lu9EO4b1SPcfXiQU
And Apple just recently merged a authorship setup into USD https://github.com/PixarAnimationStudios/OpenUSD/pull/4188 (I didn’t realize it was merged till looking it up for this response)
But crucially , none of the global regulations require C2PA specifically. And with all synthetic data , you’re really relying on honor system for transparency.
It’s not like the sensor to display pipeline that C2PA and Apple’s Reference Image can provide when enforced in hardware.
In traditional provence use case, you want to prove the image have never edited after it was created from the source. When signature mismatch, it is considered invalid.
For AI use case, you want to proof the image have never touched with AI. C2PA only (kind of) proof the last touch wasn't from AI..
Given how bad Google's implementation is, the only thing Google's implementation proves is that someone somewhere on earth owns a Pixel phone... and we'll probably learn that it doesn't even prove that.
I like to contrast how Google has responded to the failure of their implementation with how Nikon responded to the very same sort of failures. (Search for "Nikon" here [0], but -IMO- the whole post is worth reading.)
[0] <https://www.hackerfactor.com/blog/index.php?/archives/1102-C...>