Cryptographer Matthew Green questions robustness of Apple's signed 'trusted camera' photo provenance

On September 16, cryptographer Matthew Green posted a series of critiques of Apple's newly launched Reference Image (ARI) "trusted camera" photo provenance mechanism, arguing that this signature-based content credential scheme (similar to C2PA) is too fragile to authenticate high-value photos. He acknowledged that deploying the system at the OS level is a good direction, but said its security model won't hold up at scale, and that forging a "trusted" photo that passes verification is only a matter of time.

What's confirmed

Why it matters

ARI represents the industry's "trusted signature" approach to countering AI-generated images, and Green's criticism strikes at the fundamental assumption of its trust model: a signature only proves a photo came from a particular camera, not that the camera wasn't compromised. In high-stakes scenarios (such as journalistic evidence), this gap could be fatal, while in low-value scenarios the cost-benefit calculus is what makes signatures meaningful. This offers an important reference point for assessing the applicability of similar C2PA-style schemes.

2026-09-16 ~ 2026-09-16 · 7 related posts

Primary sources

2 near-duplicate retellings: matthew_d_green · matthew_d_green