By David Buchanan (aka retr0id), 25 th August 2026 You might have heard that C2PA is a technology that will miraculously save us from rampant AI forgeries, by having cameras cryptographically sign the images they capture. Hooray for cryptography ! Sorry. That's not going to work. There's a lot going on here, so I'll try to get to the point as quickly as possible: C2PA camera apps on the Android platform rely on Key Attestation and/or Google Play Integrity , to prevent users from tampering with the app to sign arbitrary files (as opposed to data from the device's image sensor). Being able to sign arbitrary files breaks C2PA's trust model . Root privilege escalation exploits break Android's Key Attestation security model, and Play Integrity likewise. Android devices can be rooted via low-cost hardware fault injection attacks . Hardware vulnerabilities in existing devices cannot be patched (there's nuance here, discussed later).…