Nikon's Image Authentication Insecure
silanea writes "Elcomsoft claims to have broken Nikon's Image Authentication system which — apparently only in theory — ensures that a photograph is authentic and not tampered with through a digital signature. They were able to extract the signing key from a camera and use it to have a modified image pass the software verification, rendering the rather expensive feature mostly marketed to law enforcement all but useless. So far Nikon has not given a statement. Canon's competing system was cracked by the same company last December."
Whew - I've always hated having to wear a ski mask when I "work". Now I can just claim image tampering.
He's getting rather old, but he's a good mouse.
This is great news, because now people will be able to cast doubt on images when there is cause to instead of being told "it's not possible it's a fake, it's signed". You know that if someone cracked it publicly someone else (probably many someone else's) have cracked it in private, and have kept around the ability to forge photographs in case of emergency... that ability is now reduced.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Just take a picture of the photo-shopped image with your Nikon camera. Bam! That was sure hard to crack.
I think the authorities will still say "it's not possible it's a fake, it's signed" and it'll be up to the victim (or the victim's lawyer) to know that the signage has been broken.
The last time I was stopped in a speed trap (on motorcycle), I knew it was coming up (they always put a speed trap in this particular construction zone on weekends because people ignore the temporary "35" signs 'cause there's nobody working on Sunday, but I digress) and had slowed way down before taking the turn, but was waved over anyway. I was pretty sure he'd tracked the (obviously faster) car one lane over instead of me, and said so. He said "the gun can't be wrong, I had a firm lock on you." I can see the stupid radar gun in his hand right there, and it's not like there's a scope on it, or even if he actually had me in crosshairs, that it could tell the difference between a slow moving object in the foreground and a much faster object in the background. I maintained that he could not possibly have locked on me, because he would have read 33 MPH, which is what my speedo was displaying at the time. I said it obviously had "locked" on the car that passed me shortly after the corner. The cop said that this was impossible, radar guns don't make that kind of mistake.
Well hell, there's a huge body of evidence that radar guns make "mistakes" all the time. I laid out exactly how the error could have occurred, he continued to insist that the gun can't make mistakes. I finally said "ok, whatever. We'll see what the judge says." He went away, talked to his cohorts for awhile, came back and issued me a "verbal warning", let me go. Now, I strongly suspect that if I'd acted like I knew nothing about the technical details of radar guns, I'd have gotten a ticket.
Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.