logoalt Hacker News

fwipsytoday at 6:37 AM2 repliesview on HN

It's funny how people always say something is "a tragedy at the individual level" when they mean "it's not my problem." It's even crazier to dismiss the value of a security feature, just because it might make people feel more secure. That's true of every security feature! Very little of the technology that the web is built on is proof against state actors.

I like being contrarian as much as the next guy, but "Actually, having security is worse for security" is taking it a little too far.


Replies

Melatonictoday at 8:31 AM

Yeah I think any additional security is good. At worst this could help in a lot of court cases. Someone presents photo evidence - it could be manipulated - it could be not. This happens already. Then someone produces an original higher quality version (like a raw photo - which I take even on my phone at all times now) and experts can verify that as the original.

And I agree on state actors. If a major one is invested in something like this they might have well compromised the signing project itself, the verification process, or even the court system or media. That seems like a rare and extremely high bar to guard against.

hypfertoday at 6:41 AM

I am repeating myself, but this is about systems, and not about people.

It is however in the interest of the people to keep the systems running in an untainted way.

As said, on the individual level it's a tragedy, but one that can be absorbed somewhat. Democracy itself failing otoh is kinda hard to absorb.

C2PA is not "having security". It is "having an illusion of security for compliance and CYA reasons, that can be fairly trivially exploited by nation state actors". Banality of evil. Again.

___

Actually, come to think of it, "security" is the wrong term there. Signatures don't secure anything. They attest.

Those are different things. Argh and I ran with your term aah