signalLobsters2026-10-04
How to Hack Time, With C2PA
David Buchanan demonstrates a C2PA flaw where the entire file can be excluded from signature calculations, allowing tampering after a valid signed timestamp. He shows a photoshopped lottery ticket with valid C2PA metadata and timestamp, verified via the standard tool. The attack exploits the spec's exclusion feature, not the TSA.
- for who
- Digital content authenticators and C2PA implementers
- why now
- C2PA's exclusion flaw lets anyone fake timestamps before verification tools catch on.
- what changes
- Signed files with C2PA metadata can be altered without invalidating signatures or timestamps, undermining trust in content authenticity.
- to do
- Audit C2PA implementations to prevent unrestricted exclusion ranges and consider restricting exclusion sizes.
key points
- C2PA allows arbitrary byte-range exclusions from signatures
- Excluding the whole file yields valid signature over empty string
- Photoshopped lottery image retains valid timestamp and claim
#C2PA#security vulnerability#timestamp#content authentication
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source