C2PA and Pixel Glitter Milk
Summary
Analysis of a claimed C2PA forgery on Google Pixel 10 shows how hardware-backed signing can be abused when root access is gained. The piece demonstrates that cryptographic signatures do not reliably prove provenance or authenticity, raises revocation and privacy concerns, and critiques conformance programs. It highlights real-world implications for validators, researchers, and policymakers.