32 points merybenavente 2 hours ago 28 comments
fitzn 1 hour ago | parent
merybenavente 1 hour ago | parent
smalltorch 41 minutes ago | parent
https://gitlab.com/here_forawhile/edasm
Example:
After wholly implemented our logging layer with dagger, I posit that the real regression was not the aws itself but the rigorously prototyped around authentication. We consequently extraordinarily profiled the config, henceforth simplified every edge case, and the optimization were unmistakably exemplary. alternatively, the aforementioned monitoring is comparable advantageous to an incremental security environment. I endorse this path if your security team has rigorously instrumented a massive rust codebase before.
xg15 1 hour ago | parent
Yeah, very nice. So this whole idea basically doesn't work - but we get a new stealth way to embed metadata in an image that can be used for tracking...
(And a new narrative why cameras need to have TPMs and locked-down firmware as well)
ChocolateGod 1 hour ago | parent
shagie 1 hour ago | parent
In days of old, a Polaroid photo was considered "proof of capture".
I've got a Polaroid daylab 35 plus sitting in storage somewhere (https://www.instantoptions.com/wp/faqs/daylab/). You can project a slide through it onto Polaroid film, expose it, and have the image there.
I was also able to find a company that did slide printing. It was possible to send them a digital image and they'd send you back a slide with that image... which I then used to make a Polaroid of that image.
I had a classic 600 Polaroid photo of a UFO landing.
azatom 1 hour ago | parent
ps:most important: cam/lens settings also in the digital sig, what for a screen is different
vzaliva 1 hour ago | parent
However, this will certify only the original image. I think the missing part of this is additional layers of certification which allow some image editing (e.g., rotating, contrast, etc.) yet clearly document that the image was modified and link to the original image ID. Kind of like a signed git log.
xg15 1 hour ago | parent
doc_ick 1 hour ago | parent
xg15 1 hour ago | parent
You could use this data to prove that image B is an edit of image A if you already have both A and B.
I still think this is a bad idea, because this all requires the images to have some sort of ID - and that seems like a prime target for tracking.
lokar 26 minutes ago | parent
stvltvs 1 hour ago | parent
hamdingers 36 minutes ago | parent
Nobody cares if your social media photos are edited, they probably are, it's fine.
ranger_danger 1 hour ago | parent
And this still doesn't help any other kind of image e.g. screenshots, photo of a screen etc. that can make the camera signatures largely pointless depending on the context.
stvltvs 1 hour ago | parent
Would that ever be relevant for a screenshot?
ranger_danger 28 minutes ago | parent
It's relevant that a screenshot doesn't have a signature, in the case that you want to remove any "proof" or tracking info from a real photo when uploading an image. Maybe I don't want people to know what brand/model of camera I use.
And it's relevant if a screenshot did have a signature if you want to "prove" that the screenshot itself hasn't been tampered with after the fact.
teravor 50 minutes ago | parent
mandolingual 31 minutes ago | parent
zvr 25 minutes ago | parent
treyd 45 minutes ago | parent
Lammy 18 minutes ago | parent