Forgery of C2PA on a Pixel 10
Forgery of C2PA on a Pixel 10
Pixel 10 上的 C2PA 伪造事件
C2PA and Pixel Glitter Milk C2PA 与 Pixel“闪光牛奶”
The news has been full of incredible reports recently. Like this one: BREAKING: Iowa Farmers Discover “Glitter Milk” from Unicorn Cows. 最近新闻里充斥着各种不可思议的报道。比如这一条:突发新闻:爱荷华州农民发现来自独角兽奶牛的“闪光牛奶”。
As proof of this incredible story, we have a photo of a farmer milking a unicorn cow! According to the metadata: The photo is from a Google Pixel 10 Pro. The picture has cryptographically signed C2PA metadata. This data says it is “Created by Pixel Camera”. The C2PA metadata even includes a 1024x768 preview image of the photo. Everything in the cryptographically signed manifest is consistent with a real photo from a Google Pixel camera. 作为这则离奇故事的证据,我们有一张农民挤独角兽奶的照片!根据元数据:这张照片来自 Google Pixel 10 Pro。图片带有经过加密签名的 C2PA 元数据,显示其“由 Pixel 相机创建”。C2PA 元数据甚至包含了一张 1024x768 的预览图。加密签名清单中的一切都与 Google Pixel 相机拍摄的真实照片完全一致。
In my blogs, I have repeatedly detailed ways to create “authenticated forgeries” using C2PA. However, the one thing I cannot forge is the cryptographic signature itself. This picture has a valid X.509 certificate chain that traces back to the C2PA-managed trust list. The certificate is issued by Google for the Pixel cameras. To my knowledge, nobody can forge this signature; this was really signed by a Google Pixel camera. 在我的博客中,我曾多次详细介绍过如何利用 C2PA 创建“经过认证的伪造品”。然而,我唯一无法伪造的就是加密签名本身。这张照片拥有一个有效的 X.509 证书链,可以追溯到 C2PA 管理的信任列表。该证书由 Google 为 Pixel 相机颁发。据我所知,没有人能伪造这个签名;这确实是由 Google Pixel 相机签署的。
The cryptographic signature includes a signed timestamp. The timestamp is dated “2026-05-25 17:04:19 GMT” and the signer is Google. Again, I cannot forge this signed timestamp; this is real. 加密签名中包含一个已签名的时戳。该时戳日期为“2026-05-25 17:04:19 GMT”,签署方为 Google。同样,我无法伪造这个已签名的时戳;它是真实的。
The C2PA organization has a list of conforming products. If we upload this glitter-milk picture to Adobe’s Inspect service (a conforming product), it reports that this is a legitimate photo from a Pixel Camera, recorded on May 25, 2026. The Adobe-run Content Authenticity Initiative (CAI) provides C2PA implementations. Their CAI Verify validator reports that the contents shows “captured media”, came from Google LLC, issued by a Pixel Camera with a notation that it is “Conformant” (a conforming product), and includes a verified timestamp of “May 25, 2026 at 11:04 AM MDT”. C2PA 组织有一份合规产品列表。如果我们把这张“闪光牛奶”的照片上传到 Adobe 的 Inspect 服务(一个合规产品),它会报告这是一张来自 Pixel 相机的合法照片,拍摄于 2026 年 5 月 25 日。由 Adobe 运营的内容真实性倡议(CAI)提供了 C2PA 的实现方案。他们的 CAI Verify 验证器报告称,该内容显示为“捕获的媒体”,来自 Google LLC,由 Pixel 相机颁发,并标注为“合规”(即合规产品),且包含一个验证过的时戳:“2026 年 5 月 25 日上午 11:04 MDT”。
Everything says that this is a legitimate photo from a Google Pixel camera. There’s just one problem: It’s a forgery. The picture is AI generated and the news article is fiction, but Google’s signatures are real. 一切迹象都表明这是一张来自 Google Pixel 相机的合法照片。但有一个问题:它是伪造的。这张图片是由 AI 生成的,新闻报道也是虚构的,但 Google 的签名却是真实的。
Industry best practices for responsible disclosure suggest giving vendors 45-90 days to respond. Since we are 90 days past the vendor notification, I’m following industry best practices and making the details public. 负责任披露的行业最佳实践建议给予供应商 45-90 天的响应时间。由于距离我通知供应商已经过去了 90 天,我决定遵循行业最佳实践,将细节公之于众。
Nearly a year ago (September 2025), Google made a big announcement about the Pixel 10 product line. They explained “How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials”. 大约一年前(2025 年 9 月),Google 对 Pixel 10 产品线发布了重大公告。他们解释了“Pixel 和 Android 如何通过 C2PA 内容凭证为您的图像带来新的信任水平”。