Fri 4 Sept 2026
The first comprehensive independent security analysis of the C2PA content provenance specification (Golaszewski et al., April 2026 — UMBC Cyber Defense Lab, NSA, Hacker Factor) proved that C2PA fails all of its claimed security goals and all essential goals a provenance system requires. Timestamps can be replaced without detection because nothing in the signed data references the timestamp; conforming validators are not required to check certificate revocation, allowing compromised keys to forge apparently valid provenance; and different conforming validators produce contradictory results on the same media. California's SB 942 and the EU AI Act Article 50 both mandate C2PA-based content credentials as of August 2026 — but the specification versions in production (2.2–2.4) cannot guarantee the integrity of the timestamps, geographic locations, or AI-origin labels that these laws require platforms to display.
Not submitted.
public
Advanced
- proof format
- opentimestamps
- status
- failed
- privacy
- public
- created
- 2026-09-04 04:01:41 UTC