25 signals
HOlO V1 IS LIVEone ranked AI digest a day, scored in publicREAD HOW IT WORKS →HOlO V2 STARTSyour X account, your signals, every day
signalLobsters2026-10-04

How to Hack Time, With C2PA

David Buchanan demonstrates a C2PA flaw where the entire file can be excluded from signature calculations, allowing tampering after a valid signed timestamp. He shows a photoshopped lottery ticket with valid C2PA metadata and timestamp, verified via the standard tool. The attack exploits the spec's exclusion feature, not the TSA.

for who
Digital content authenticators and C2PA implementers
why now
C2PA's exclusion flaw lets anyone fake timestamps before verification tools catch on.
what changes
Signed files with C2PA metadata can be altered without invalidating signatures or timestamps, undermining trust in content authenticity.
to do
Audit C2PA implementations to prevent unrestricted exclusion ranges and consider restricting exclusion sizes.
key points
  • C2PA allows arbitrary byte-range exclusions from signatures
  • Excluding the whole file yields valid signature over empty string
  • Photoshopped lottery image retains valid timestamp and claim
#C2PA#security vulnerability#timestamp#content authentication
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source