How to hack time, with C2PA
6 hours ago
- The author demonstrates hacking C2PA metadata by using exclusion ranges to sign an empty string, allowing post-timestamp alteration of a file.
- C2PA has two signatures: a claim signature from the device and a timestamp signature from a Time Stamp Authority (TSA) meant to prove data existed before a given time.
- The vulnerability lies in the C2PA spec allowing arbitrary byte ranges to be excluded from signature calculations, enabling the entire file to be excluded and signed as empty.
- This exploit was used to create a valid timestamp for a photoshopped lottery ticket image, without needing to attack the TSA itself.
- Fixing this is difficult because exclusions are necessary for certain file formats (e.g., PNG CRC checksums), so a format-specific list of allowed exclusions is recommended.