Cryptographer Matthew Green questions robustness of Apple's signed 'trusted camera' photo provenance
On September 16, cryptographer Matthew Green posted a series of critiques of Apple's newly launched Reference Image (ARI) "trusted camera" photo provenance mechanism, arguing that this signature-based content credential scheme (similar to C2PA) is too fragile to authenticate high-value photos. He acknowledged that deploying the system at the OS level is a good direction, but said its security model won't hold up at scale, and that forging a "trusted" photo that passes verification is only a matter of time.
What's confirmed
- Green's core objection is fragility: if even a small number of the millions of cameras are compromised, forgers can mass-produce fake photos with trusted signatures and flood the public sphere, collapsing the system's entire foundation of trust.
- He noted that Apple's description of how the system works is vague—likely only Apple itself can trace a photo back to a compromised camera, and the public cannot independently verify its source, so the mechanism offers limited public benefit while introducing new risks.
- He acknowledged the good intentions behind the privacy direction but said this doesn't make up for the verification weaknesses.
- He also outlined a use case he endorses: low-value economic transactions—for example, an insurer that doesn't want to send an adjuster to inspect a car after an accident and only needs photos. ARI fits well here—users could theoretically tamper with their camera to fake photos, but the payoff wouldn't come close to justifying the cost.
Why it matters
ARI represents the industry's "trusted signature" approach to countering AI-generated images, and Green's criticism strikes at the fundamental assumption of its trust model: a signature only proves a photo came from a particular camera, not that the camera wasn't compromised. In high-stakes scenarios (such as journalistic evidence), this gap could be fatal, while in low-value scenarios the cost-benefit calculus is what makes signatures meaningful. This offers an important reference point for assessing the applicability of similar C2PA-style schemes.
2026-09-16 ~ 2026-09-16 · 7 related posts
Primary sources
- Cryptographer Matthew Green: Apple's camera photo provenance system is too fragile — matthew_d_green ·
- Cryptographer Matthew Green questions Apple's photo provenance signing for public trust — matthew_d_green ·
- Matthew Green: photo provenance signing fits low-value transactions like insurance claims — matthew_d_green ·
- Cryptographer Matthew Green: "trustworthy cameras" are too fragile to rely on — matthew_d_green · 2026-09-16
- [source] Cryptographer Matthew Green questions Apple's photo provenance signing for public trust — matthew_d_green · 2026-09-16
- [source] Matthew Green: photo provenance signing fits low-value transactions like insurance claims — matthew_d_green · 2026-09-16
- Cryptographer Matthew Green: camera identity tied to real ID can curb insurance fraud cheaply — matthew_d_green · 2026-09-16
- Cryptographer Matthew Green: Strong Default Privacy Clashes With Large-Scale AI Deployment Security — matthew_d_green · 2026-09-16
2 near-duplicate retellings: matthew_d_green · matthew_d_green