Sign in

hackerfactor.bsky.social

@hackerfactor.bsky.social
80 followers 6 following 50 posts

Computer security specialist, forensic researcher, and founder of FotoForensics. Sleep is not necessary.

PostsRepliesMedia
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/06/2025
The Hacker Factor Blog: The Big Bulleted List of C2PA Issues hackerfactor.com/blog/index.p... I'm often asked if I have a list of C2PA problems. Yes, yes I do. Here's the current 27-page bulleted list. Any one of these issues should make companies reconsider any C2PA adoption plans and run away.
hackerfactor.com
020
hackerfactor.bsky.social @hackerfactor.bsky.social · 11/05/2025
Leopards! Faces!
040
hackerfactor.bsky.social @hackerfactor.bsky.social · 18/04/2025
The Hacker Factor Blog: C2PA and Authentication Updates hackerfactor.com/blog/index.p... C2PA won't stop fake IDs, BBC made their bad example worse, Microsoft's validation service is offline, and Truepic's gives bad results. But good news: UMBC is formally evaluating C2PA, SEAL, and related tech.
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
031
hackerfactor.bsky.social @hackerfactor.bsky.social · 07/04/2025
The Hacker Factor Blog: Safety in Numbers hackerfactor.com/blog/index.p... Simple tips to stay safe online when attending a protest.
hackerfactor.com
Safety in Numbers - The Hacker Factor Blog
021
hackerfactor.bsky.social @hackerfactor.bsky.social · 12/03/2025
The Hacker Factor Blog: Sign Here hackerfactor.com/blog/index.p... Don't trust signatures in PDF files. They are too easy to forge and alter.
hackerfactor.com
Sign Here - The Hacker Factor Blog
011
hackerfactor.bsky.social @hackerfactor.bsky.social · 03/03/2025
The Hacker Factor Blog: Crashing Arizona's C2PA Pilot hackerfactor.com/blog/index.p... The Arizona Secretary of State released a pilot program that demonstrates C2PA signing. Every example demonstrates how C2PA does NOT work.
hackerfactor.com
Crashing Arizona's C2PA Pilot - The Hacker Factor Blog
131
Reposted by hackerfactor.bsky.social
DrArchivalGenomics @ehekkala.bsky.social · 15/02/2025
🧪 #StandForScience
2217
hackerfactor.bsky.social @hackerfactor.bsky.social · 15/02/2025
Wow. Definitely rewriting history.
100
hackerfactor.bsky.social @hackerfactor.bsky.social · 09/02/2025
Happy Superb Owl day.
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 03/02/2025
The Hacker Factor Blog: ShmooCon and C2PA Forgeries www.hackerfactor.com/blog/index.p... At ShmooCon, Microsoft presented on C2PA but didn't address any of the problems. To demonstrate the ineffectiveness of C2PA, I walk through step-by-step how to create an authenticated forgery.
hackerfactor.com
ShmooCon and C2PA Forgeries - The Hacker Factor Blog
031
hackerfactor.bsky.social @hackerfactor.bsky.social · 11/01/2025
"Courts are adversaries"? I disagree. They are supposed to be impartial. It's up to the prosecution and defense to show evidence. Email can be used as evidence. What's the problem here?
100
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/01/2025
Wait... I don't get it. Doesn't publishing the old secret keys mean that someone (anyone) can backdate any email and make it appear is if it was sent? That's going to seriously impact legal cases that include email as evidence.
320
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/01/2025
Today, most spam is either from: (A) A domain lacking both SPF and DKIM. (Many mail servers outright reject these emails.) (B) A compromised mail server. (C) A server that didn't authenticate/validate their users very well (KYC) and permits relaying spam.
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/01/2025
The caveat is that DKIM signs as the server, not the user. Any user who is allowed to use the server can get a valid DKIM signature. But that's the KYC problem.
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/01/2025
SPF and DKIM dramatically reduce spam. SPF ensures that the sender is allowed to send. DKIM prevents MitM alterations, IP hijacking, and ensures that the email really did come from the sender.
210
hackerfactor.bsky.social @hackerfactor.bsky.social · 10/01/2025
Looking at my mail logs. Every single email that has invalid DKIM is spam. My DMARC emails regularly receive reports of unauthorized senders who failed the SPF and DKIM checks. While DKIM isn't perfect, it dramatically reduces spam.
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 01/01/2025
Do Russian airplanes have balconies? "Accidentally" falling off balconies seems like the #1 cause of death in Russia. They should have better building regulations.
020
hackerfactor.bsky.social @hackerfactor.bsky.social · 30/12/2024
Going by statistics of airplane vs car. You're less likely to be involved in an accident in an airplane. However, you are more likely to survive an accident in a car.
170
hackerfactor.bsky.social @hackerfactor.bsky.social · 27/11/2024
Here's a link to the larger (readable) diagram. Very interesting! media.springernature.com/m2048/spring...?
media.springernature.com
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
It's been 3 years. (That Starling Labs picture is from April 2021.) *None* of the issues demonstrated by that picture have been resolved today.
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
I just noticed that @adamrose.bsky.social is the COO of Starling Labs. Starling Labs' C2PA demonstration authenticated a picture that had alterations and inconsistent metadata. What they did by accident can easily be used for intentional fraud. hackerfactor.com/blog/index.p...
bsky.app
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
More reviews: hackaday.com/2023/11/30/f.... Hackaday describes how to use Adobe's C2PA solution to create authenticated forgeries.
hackaday.com
Falsified Photos: Fooling Adobe’s Cryptographically-Signed Metadata
Last week, we wrote about the Leica M11-P, the world’s first camera with Adobe’s Content Authenticity Initiative (CAI) credentials baked into every shot. Essentially, each file is signe…
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
Sample external reviews: spectrum.ieee.org/meta-ai-wate... Article says Meta's AI Watermarking, but talks about C2PA's approach. "Flimsy, at best". www.technologyreview.com/2023/07/31/1... MIT Tech review says C2PA will "not stem the harm of machine-generated misinformation."
spectrum.ieee.org
Meta's Flimsy AI Watermarking Plan Won’t Save Democracy
Watermarks are too easy to remove to offer any protection against disinformation
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
SEAL is based on the publicly reviewed and widely adopted DKIM for securing email. There are few independent reviews of C2PA, and they are all negative -- C2PA does not provide validation. (My own blog repeatedly demonstrates weaknesses in the C2PA solution.)
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
In response to a challenge by C2PA's chief architect to come up with a different solution, I created SEAL. SEAL provides a tamper-proof signature, authenticates the signer, and prevents signature impersonations. SEAL is also smaller, faster, and supports more file formats than C2PA.
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
Hello Adam Rose and Bots Don't Cry, I just saw this thread. C2PA is an Adobe-centric solution that does not validate content, metadata, or signatures. Because it is based on "trust", it does nothing to prevent forgeries or false attribution.
120
hackerfactor.bsky.social @hackerfactor.bsky.social · 25/11/2024
The Old Western "The Garamond brothers are back and they're going after the Courier," declared Arielle. "Don't worry," Roman replied. "The New Times reported that there's a new Serif in town."
110
hackerfactor.bsky.social @hackerfactor.bsky.social · 22/11/2024
The Hacker Factor Blog: Signed and SEALed hackerfactor.com/blog/index.p... SEAL can now digitally sign over two dozen different common file formats, including images, audio, video, and documents.
hackerfactor.com
Signed and SEALed - The Hacker Factor Blog
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 22/11/2024
Can you make sure it streams on Roku? Sometimes your tech folks forget...
020
hackerfactor.bsky.social @hackerfactor.bsky.social · 21/11/2024
Thank you!
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 21/11/2024
I keep hearing the lots of people are moving to Bluesky, but are people actually using it?
310
hackerfactor.bsky.social @hackerfactor.bsky.social · 19/11/2024
It's not just leopards eating faces. They all have leopards.
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 23/09/2024
Adobe's study about the Adobe sponsored solution found that Adobe's users demand Adobe's solution. news.adobe.com/news/news-de... It's written by Adobe's Head of Responsible Innovative Communications, who is working on Adobe's C2PA and CAI. Yup, no bias in these findings! (sarcasm emoji: 💩)
news.adobe.com
Adobe Study Reveals U.S. Consumers Demand Robust Misinformation Safeguards Ahead of 2024 Presidential Election
New Adobe study finds that majority of U.S. consumers are concerned about misinformation in the lead up to the 2024 presidential election To protect themselves against misinformation, most consumers w...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 27/08/2024
Another option: Check the copyright page in the book. (It's usually the 4th printed page.) There should be a credit for the cover art. But I agree: he should take this up with the publisher before making public accusations on Bluesky.
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 27/08/2024
One interesting fact: Authors almost never have a say about the cover artwork. That's all from the publisher. (I'm definitely no John Scalzi, but I had no say in my books titles and little influence over the cover art. I was allowed to reject one cover art one time.) Talk to the publisher.
010
hackerfactor.bsky.social @hackerfactor.bsky.social · 29/05/2024
Hold up... You're a "micro celebrity"? I thought I only followed "big names". Does this mean one of the cats is the real celebrity? (And if so, which one?????)
120
hackerfactor.bsky.social @hackerfactor.bsky.social · 21/05/2024
Wait... your spouse GAVE YOU MONEY for it? That only happens to me along with the phrase "now will you leave me alone?"
030
hackerfactor.bsky.social @hackerfactor.bsky.social · 09/05/2024
The Hacker Factor Blog: C2PA from the Attacker's Perspective www.hackerfactor.com/blog/index.p... I recently participated in a panel discussion about C2PA. As part of the attacker's perspective, I demonstrated how to trivially alter C2PA's cryptographically signed time stamp.
hackerfactor.com
C2PA from the Attacker's Perspective - The Hacker Factor Blog
011
hackerfactor.bsky.social @hackerfactor.bsky.social · 05/05/2024
The Hacker Factor Blog: Upcoming IPTC Conference Presentation. I'm on a panel taking about C2PA! Show up and ask questions! www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 21/04/2024
The Hacker Factor Blog: The Jitter Bug Part 2 www.hackerfactor.com/blog/index.p... Finally figured out how to stop the random CPU crashes! (At least, I really think so this time.)
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 15/04/2024
The Hacker Factor Blog: VIDA: The Simple Life www.hackerfactor.com/blog/index.p... A simple, free, and decentralized solution for media authentication. (A better solution than C2PA.)
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 01/04/2024
The Hacker Factor Blog: Introducing: The Brick www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 27/03/2024
The Hacker Factor Blog: Clear The DEC www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 13/03/2024
The Hacker Factor Blog: The Great Kate Debate www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 08/03/2024
The Hacker Factor Blog: IEEE, BBC, and C2PA www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 04/03/2024
The Hacker Factor Blog: C2PA's Time Warp www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 16/02/2024
I've been following some news feeds on BlueSky. However, many of them are for paywalled content. I've started muting any news account that posts clickbait headlines that link to a paywall. (First up? Financial Times ft.com .)
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 15/02/2024
The Hacker Factor Blog: The Jitter Bug www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 09/02/2024
The Hacker Factor Blog: 12 Years at FotoForensics www.hackerfactor.com/blog/index.p...
000
hackerfactor.bsky.social @hackerfactor.bsky.social · 05/02/2024
The Hacker Factor Blog: Save The Date www.hackerfactor.com/blog/index.p...
000