The camera that was supposed to prove photos are real will happily swear an AI image is a photograph

“We built a camera that testifies under oath. It will testify to anything.”

The Story

C2PA was sold as cryptographic proof that a photo came from a real camera. A researcher showed that the Android version of that promise does not survive contact with rooted or glitched phones: a Pixel can be made to sign AI slop as an unedited camera original, and a YouTube clip can be labeled “captured with a camera.” Google paid a bounty and declined to rearchitect the stack. Independent work this week also argues the C2PA spec fails its own security goals.

Why It Matters

The authenticity seal is becoming a costume. Courts, newsrooms, and Oscars-adjacent “prove you’re human” culture just lost their favorite object. Do not make a how-to. Make the cultural funeral for “the camera doesn’t lie.

Evidence

David Buchanan / retr0id, 25 Aug blog; HN (~169 pts). Pixel Camera is C2PA Assurance Level 2 — the “strongest” mobile implementation — and still signs forgeries. Google closed the report as won’t-fix / infeasible.

Sources

Daily scan: 2026-08-26