{"id":26745,"date":"2026-09-17T09:40:00","date_gmt":"2026-09-17T07:40:00","guid":{"rendered":"https:\/\/www.wjst.de\/blog\/?p=26745"},"modified":"2026-09-17T09:47:54","modified_gmt":"2026-09-17T07:47:54","slug":"image-authentification","status":"publish","type":"post","link":"https:\/\/www.wjst.de\/blog\/sciencesurf\/2026\/09\/image-authentification\/","title":{"rendered":"Image authentification"},"content":{"rendered":"<p>I have been interested in that topic since taking my first image of a\u00a0 cell culture in 1984.\u00a0 The original film negative was long the practical proof of authenticity. It is a physical record, and every\u00a0 manipulation would leave some traces that can be examined. It has limits of course but would have needed a lot of technical skills from darkroom compositing, retouched internegatives, or re-photographing a staged print (<a href=\"https:\/\/arxiv.org\/abs\/2507.12237\">some that I have examined recently<\/a>).<\/p>\n<p>With the advent of digital photography RAW files became the &#8220;digital negative&#8221; (NEF, CR2\/CR3, DNG). 95% of the 100++K images that I have under my desk have a corresponding RAW file to allow are new processing. They are harder to fake convincingly than JPEGs, because sensor noise, Bayer pattern, and maker notes have to be consistent. But they carry no cryptographic protection, so this is some plausibility argument, not any proof of origin.<\/p>\n<p>With the more widespread use of cryptographic technologies several vendor signing systems appeared but are already broken in 2010. ElcomSoft extracted the private signing key from a Nikon camera, <a href=\"https:\/\/blog.elcomsoft.com\/2011\/04\/nikon-image-authentication-system-compromised\/\">which made it possible to sign any image<\/a>.\u00a0 A similar fate occured by the <a href=\"https:\/\/www.usa.canon.com\/support\/canon-product-advisories\/adv-dvk-e1\">Canon Original Data Security Kit\u00a0<\/a>. In 2019 the Content Authenticity Initiative was founded by Adobe; in 2021 then came <a href=\"https:\/\/en.wikipedia.org\/wiki\/Content_Credentials\">C2PA<\/a>. How does it work? A quick summary can be found at the <a href=\"https:\/\/spec.c2pa.org\/specifications\/specifications\/1.4\/specs\/C2PA_Specification.html\">technical documentation<\/a>: Utilizing some JPEG Universal Metadata Box Format as generic container, the architecture enforces content integrity through byte-range and general box hashes, and some kind of video segment tracking.<\/p>\n<p>The <a href=\"https:\/\/leica-camera.com\/de-DE\/fotografie\/kameras\/m\/m11-p-schwarz\/jetzt-kaufen\">Leica M11-P<\/a> seems to be the first camera using C2PA with hardware key storage. It stores camera serial, lens, date, time, and location in a C2PA manifest and signs it using a secure chipset holding a private key; Sony followed some months later.\u00a0 I did not understand why the manufacturer of major sports and editorial brands like Sony, Nikon and Canon left the\u00a0 initial approach to a small but exclusive German brand.<\/p>\n<p>Then came the Nikon Z6III C2PA failure last year. Although signing worked well, the camera&#8217;s multiple exposure overlay feature let a non-certified image combined with a certified one be accepted as C2PA compliant. In one demonstration, an AI-generated image was signed. Nikon suspended the service and revoked all certificates.<a href=\"https:\/\/petapixel.com\/2025\/09\/22\/nikon-cant-fully-solve-the-z6-iiis-c2pa-problems-alone\/\"> PetaPixel noted<\/a> that a complete fix also requires changes to the C2PA validation tools themselves. As far as I know\u00a0 the service seems still suspended while Canon began rolling out a C2PA Authenticity Imaging System for the<a href=\"https:\/\/global.canon\/en\/news\/2026\/20260511.html\"> EOS R1 and R5 Mark II<\/a> May 2026.<\/p>\n<p>Canon ignores the <a href=\"https:\/\/www.lumethic.com\/en\/articles\/nikon-c2pa-signature-not-proof\">main objection<\/a> that Nikon now understands: a signed a file proves only the bytes have not changed since. It does not tell you whether the bytes were produced by light hitting a sensor or as a graphic loaded through a side door.<\/p>\n<p>Photographing a deepfake with a C2PA camera app still passes verification (<a href=\"https:\/\/arxiv.org\/pdf\/2407.04169\">arXiv 2407.04169<\/a>).\u00a0 So not only every camera maker but also manufacturer of lab documentation system don&#8217;t have any bullet proof of <a href=\"https:\/\/www.frontiersin.org\/news\/2021\/07\/09\/research-integrity-a-closer-look-at-gel-and-western-blot-image-cropping\">gel authenticity<\/a> at hand &#8211; neither Bio-Rad Laboratories nor <!--TgQPHd|||[]--><!--TgQPHd|||[]--><span class=\"iNqyIf\" data-sfc-cp=\"\" data-sfc-root=\"ep\" data-complete=\"true\" data-copy-service-computed-style=\"font-family: &quot;Google Sans&quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);\">Thermo Fisher Scientific (the latter being <a href=\"https:\/\/www.chemistryworld.com\/news\/thermo-fisher-antibody-data-manipulation-is-a-breach-of-trust-say-researchers\/4023854.article\">currently under fire<\/a> ). Audit trails do not give any proof.<\/span><\/p>\n<p>The iPhone 18 Pro announcement last week on September 9 seems to overcome that <a href=\"https:\/\/security.apple.com\/blog\/apple-reference-image\/\">by sensor signing.<\/a> The sensor itself signs the raw data, and processing happens in an environment that can be independently checked. It includes signed timestamp tokens; the digital negative is stored as DNG and can be shared undeveloped; when developed, a private cloud recomputes the digest and verifies the sensor signature back to the sensor CA; it uses hybrid RSA\/ML-DSA signatures, a revocation system for compromised sensors &#8211; a major leap in 2026.<\/p>\n<p><a href=\"https:\/\/fstoppers.com\/gear\/apple-reference-image-how-iphone-18-pro-proves-photo-real-904649\">Limitations still exist<\/a> as it works only on the main sensor and it is opt-in and unfortunately not available right now in the EU. Apple&#8217;s architecture is one day old publicly, and no independent security analysis exists yet. but it will be exciting to watch if major camera brands will finally adopt sensor signing.<\/p>\n\n<p>&nbsp;<\/p>\n<div class=\"bottom-note\">\n  <span class=\"mod1\">CC-BY-NC Science Surf , accessed 17.09.2026<\/span>\n <\/div>","protected":false},"excerpt":{"rendered":"<p>I have been interested in that topic since taking my first image of a\u00a0 cell culture in 1984.\u00a0 The original film negative was long the practical proof of authenticity. It is a physical record, and every\u00a0 manipulation would leave some traces that can be examined. It has limits of course but would have needed a &hellip; <a href=\"https:\/\/www.wjst.de\/blog\/sciencesurf\/2026\/09\/image-authentification\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Image authentification<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[5149,3729,5150,3836],"class_list":["post-26745","post","type-post","status-publish","format-standard","hentry","category-computer-software","tag-c2pa","tag-sensor","tag-authenticity","tag-camera"],"_links":{"self":[{"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/posts\/26745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/comments?post=26745"}],"version-history":[{"count":7,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/posts\/26745\/revisions"}],"predecessor-version":[{"id":26752,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/posts\/26745\/revisions\/26752"}],"wp:attachment":[{"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/media?parent=26745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/categories?post=26745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wjst.de\/blog\/wp-json\/wp\/v2\/tags?post=26745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}