Hacker News new | past | comments | ask | show | jobs | submit login

Wow, thanks for the detailed reply. My initial thought was you could make sure evidence submitted in court hasn't been edited (ie photoshop someone at a crime scene, or add someone to a pic for an alibi), but there could be a few uses. The problem with exif data is as you say it's trivial to strip, but it might be a stepping point towards another "secure" format (sjpeg?)



If you want truly secure format for these kinds of applications the best thing you can do is to sign the data externally (or wrap the whole file in some signed container, which seems to be the preferred solution for EU's EIdAS and related stuff).

On the other hand I have seen totally insecure, but effective hack for formats with embedded metadata: include some kind of value in there that is usually prominently displayed by OS and applications but store it in somewhat broken way such that applications trying to preserve the metadata will break it even more and it would become unreadable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: