How to Hack Time, With C2PA
A C2PA exclusion flaw lets a signer timestamp nothing, then change the file undetected.
David Buchanan shows that C2PA's exclusion ranges let a signer exclude an entire file, so the claim signature and RFC 3161 timestamp cover only the SHA-256 of an empty string. He timestamped a real photo, then photoshopped winning EuroMillions numbers into it after the 28 August 2026 draw without invalidating the manifest; current verifiers did not flag it. He argues that simply banning full-file exclusions is insufficient because small excluded regions can still change an image, and that the spec should define allowed exclusions per format. The write-up does not attack the timestamp authority itself and notes Google's separate on-device timestamp on the Pixel 10 was not evaluated.