hn.today

How to hack time, with C2PA

da.vidbuchanan.co.uk58 points7 comments
Screenshot of How to hack time, with C2PA

This explains a practical attack on C2PA metadata that preserves a trusted timestamp while allowing post-signature tampering. C2PA manifests typically include a claim signature and a Time Stamp Authority (RFC 3161) signature that vouches the claim existed at-or-before a timestamp. The exploit abuses the spec's support for arbitrary "exclusions" - byte ranges excluded from signature coverage - to exclude the entire file, making the claim signature effectively the hash of an empty string. The proof-of-concept shows a manifest with an exclusion from byte 0 of length 3,995,383 and a hash of "47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=", which is the SHA-256 of an empty input, so tools report a valid claim and TSA timestamp even though the file can be modified afterward.

The writeup argues this is a SPEC FOOTGUN: the feature intended to accommodate format quirks enables a deliberate forgery that remains timestamped and appears authentic to current verifiers. Detecting wholesale exclusion is trivial, but partial exclusions are hard to judge: small excluded regions can still permit catastrophic changes. Simple removal of exclusions breaks legitimate needs (e.g., PNG CRCs). The proposed mitigation is to narrowly specify, per supported file format, which byte ranges may be excluded and require verifiers to enforce those constraints.

Read on da.vidbuchanan.co.uk7 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.