bots don't cry

@botsdontcry1.bsky.social

Autoregressively sewing and generating garments from text guidance

The Adobe’s Content Authenticity bros have updated their verifier UX, after 6 years... It looks like they have expanded the attack surface... My 2 years old forgeries are working again! 🥳 Can you guess which Content Credential is forged, just by looking at the left column? 😬

BildBild

Higgsfield AI, another genAI wrapper, has started to use C2PA for its slop. It's not interoperable and supports only the legacy trust list. In short: Nothing for the end-user the C2PA is aimed at. But C2PA has always been for regulators: Higgsfield AI will probably be compliant with the EU-AI Act.

Nano Banana wrapped into Higgsfield AI C2PA. Somehow the "verifier" decided that the file was tampered, while it's not: It's only Higgsfield AI lacking the Google C2PA trustlist.Seedream 5.0 pro C2PA, wrapped with Higgsfield AI C2PA.
Somehow the "verifier" decided that BytePlus was on a trust list... while it's not.

3 multi-billion dollars AI companies. 2 Certificate Authorities. All bound by Google’s C2PA conformance program. A single chain of trust. A mille-feuille of failures. Image 1: Open AI genAI, SSL.com certificates Image 2: Open AI genAI, Trufo certificates

BildBild

Is the BBC being weaponized as a salesman for the AI industry? Despite years of C2PA failures, the BBC continues to push Adobe's narrative, the misleading "Nutrition label", and is now funding this exact, broken setup for Ukraine’s public media during an active information war. 🤮

bots don't cry@botsdontcry1.bsky.social · 3w ago

The BBC press release! Claiming "an unbroken chain of trust from the first shot through to publication". It requires all parties compatible trust lists, and implementations. Sony 📸certs are for Sony Ci Media Cloud workflows only💰, can't be used with the Adobe Cloud. www.bbc.co.uk/mediacentre/...

I found the demo: the image is not trusted by the official verifier, certificates missing. They patched it on their demo with their own certificates. With a nice biased BBC survey, to claim later that C2PA increase trust. Image taken 2026-05-31 + Photoshop & Lightroom suspilne.media/1333984-pere...

Exiftool:
Make                            : SONY
Camera Model Name               : ILCE-1M2
Orientation                     : Horizontal (normal)
Samples Per Pixel               : 3
X Resolution                    : 300
Y Resolution                    : 300
Resolution Unit                 : inches
Software                        : Adobe Photoshop 26.10 (Macintosh)
Modify Date                     : 2026:06:18 13:07:29
Artist                          : news
Copyright                       : suspilne
Exposure Time                   : 1/1000
F Number                        : 2.8
Exposure Program                : Manual
ISO                             : 100
Sensitivity Type                : Recommended Exposure Index
Recommended Exposure Index      : 100
Exif Version                    : 0232
Date/Time Original              : 2026:05:31 16:08:13
Create Date                     : 2026:05:31 16:08:13
Offset Time                     : +03:00
Offset Time Original            : +03:00
Offset Time Digitized           : +03:00
Shutter Speed Value             : 1/1000
Aperture Value                  : 2.8
History Software Agent          : Adobe Photoshop Lightroom Classic 14.5.1 (Macintosh), Adobe Photoshop 26.10 (Macintosh)
Adobe Camera Raw:
Crop Angle -0.4
Exposure -0.15
Contrast 5
Highlights -20
Shadows 22
Whites 15
Blacks -5
Vibrance 5
Clarity 5
Dehaze 5
Sharpening 40
Noise Reduction 15
Color Noise Reduction 25
Enable Lens Corrections On
BildBildBild
bots don't cry@botsdontcry1.bsky.social · 4w ago

Looks like the BBC is spinning their C2PA implementation disaster. And @contentauth.bsky.social is in need of PR since they can't afford Wired advertorials anymore. It’s not working! 😬 but a total win for the journalists who got 2 new cameras out of the deal. corp.suspilne.media/en/top-stori...

Yes, it's a bit expensive for 2 cameras and 2 lines of javascript, I hope they could grab as much as lenses as possible and were not forced to buy Adobe or Sony subscriptions

Bing Image Creator has lost its Content Credentials, no more C2PA for its users. A moment of silence for Microsoft Responsible AI Governance Framework, just in time to troll the EU AI Act. Why retiring a flawed technology?, couldn't Copilot fix it?

BildBild

The "scenarios" depicted in the report are already the reality of C2PA, conformant or not. page 9 about "conforming product" is really misleading, up to the url. The conformance list in short: Google. An advertising company, for a report on c2pa privacy. 😅 library.witness.org/product/c2pa...

Bild
bots don't cry@botsdontcry1.bsky.social · 4w ago

New C2PA report! The authors probably had to walk on eggs to please the @contentauth.bsky.social plutocracy. But I can feel the satire: "The value of the ecosystem depends on it being governed as seriously as it is built." 🤣 bsky.app/profile/ingo...

New C2PA report! The authors probably had to walk on eggs to please the @contentauth.bsky.social plutocracy. But I can feel the satire: "The value of the ecosystem depends on it being governed as seriously as it is built." 🤣 bsky.app/profile/ingo...

@IngoBoltz@ingoboltz.bsky.social · 4w ago

Just out from the excellent folks over at Witness.org - With some contributions from yours truly. C2PA Content Credentials and the Surveillance Risk: Adversarial Scenarios and Governance Gaps in the Content Provenance Ecosystem - Library library.witness.org/...

Of course, The C2PA "Conformant" signers from Google & OpenAI completely wipe out Adobe's provenance, crafted with love & greed, to overwrite it with their own: tracking for Google and nothing for ChatGPT (whose timestamp certificate isn't even trusted to show a creation date).

Google Gemini: add the goose into the design of the first image, don't forget to multiply the eggsGoogle Gemini provenanceOpenAI ChatGPT: add the goose into the design of the first image, don't forget to multiply the eggs"informational": [
        {
          "code": "timeStamp.untrusted",
          "url": "self#jumbf=/c2pa/urn:c2pa:828c1382-57e9-4aa5-ac3b-5c9f0c2e602b/c2pa.signature",
          "explanation": "timestamp cert untrusted: OpenAI TSA Leaf"
        }
      ],
bots don't cry@botsdontcry1.bsky.social · last mo.

Adobe Firefly C2PA update! Adobe has brought back its fancy AI reference thumbnails, probably to impress some regulator. In their great kindness, they bundle them as PNG and duplicate them like a goose, probably to impress some trader. That's 7.3MB of AI slop that should only take up 1.0MB.

Adobe Firefly C2PA update! Adobe has brought back its fancy AI reference thumbnails, probably to impress some regulator. In their great kindness, they bundle them as PNG and duplicate them like a goose, probably to impress some trader. That's 7.3MB of AI slop that should only take up 1.0MB.

Bild

󠄳󠄢󠅀󠄱󠅄󠅈󠅄︀︁︀︀︀︄󠇎The latest Leica SL3-P camera ships, of course, with C2PA to prove "authenticity". Except It uses a vintage C2PA: only "interoperable" with other legacy software, like the Adobe ones. But it still does an excellent job proving your Affluentity.

Legacy. Fun fact, you can still edit the exif:DateTime and the xmp:Rating without breaking the signature

You may wonder how can Adobe @contentauth.bsky.social "Adobe content Authenticity" validates what other C2PA verifiers reject? It should be be the source of truth since it is the only one "conformant"? 🤣 It turns out that "Adobe content Authenticity" validates shit, literally, example:

remote manifest forged, urls can be renamed and redirected at will
bots don't cry@botsdontcry1.bsky.social · last mo.

C2PA verifiers in June 2026, in 4 screenshots: ❌ Official one: dead ❌ The “files never leave your device* (*except to call Adobe)”, by @andyparsons.net. ❌ A popular SEO‑bait edition. ✅ The “we upload everything to our servers” Adobe‑conformant. The signed image: shorturl.at/8IgkM Links in ALT

The Google C2PA lead is casually mansplaining "How the [Gemini/C2PA] architecture works". If the LLM is trained on conform C2PA for genAI: there was only the Google ones available (filled with proprietary data) at the time of training. This means the C2PA CAN NOT get explained to the end user.

That's not how the architecture works. Under the hood, full C2PA validation is performed by a conformant validator. Its results are then turned over to the LLM for explanation to the end user.

Great! OpenAI has rolled out a C2PA verifier, "for safer, more transparent AI‑slop provenance." The tool, vibe coded under an intern’s armpit, labels any C2PA‑signed AI output as if it were generated with OpenAI’s own systems. The genAI laundering season has officially begun. openai.com/verify/

BildBildBildBild

A research paper about Security Analysis of C2PA and its Implementation, not AI industry sponsored. "Our results show that the specifications and the current implemented C2PA ecosystem do not yet provide the guarantees required for reliable deployment or standards adoption." eprint.iacr.org/2026/804

Verifying Provenance of Digital Media: Security Analysis of C2PA and its Implementation

Generative AI and advanced editing tools enable malicious actors to create high-quality fake images that can facilitate fraud, attack reputations, and manipulate elections. We analyze security proper-...

eprint.iacr.org