安全研究员David Buchanan发现了C2PA内容认证协议的一个重大漏洞1。该漏洞通过利用协议中的"exclusions"(排除范围)特性,使攻击者可以对整个文件进行签名,而实际签名内容却为空1。即使签名和时间戳验证仍显示为有效,攻击者也能在此状态下篡改图像1。
这一漏洞的原因在于C2PA允许任意指定字节范围排除,被排除的字节不计入签名计算,因此攻击者可以排除整个文件,生成对空字符串的有效签名1。由于时间戳签名基于声明签名,而声明签名可以是对空内容的签名,这导致时间戳证明变得无效1。Buchanan演示了通过该漏洞制造虚假彩票中奖时间戳的概念验证,揭示了现有C2PA验证工具无法有效检测此类攻击1。
Dr. Neal Krawertz在2025年6月发布的C2PA缺陷列表中已指出了大范围排除问题1,且所有现有C2PA验证工具都未能将这种攻击标记为异常1。研究者对Google Pixel 10采用的"设备上可信时间戳"实现的安全性表示高度怀疑1。由于PNG等文件格式因CRC32校验需要exclusion机制,完全移除该特性目前不可行1。
Security researcher David Buchanan has discovered a critical vulnerability in the C2PA content authentication protocol that allows attackers to forge valid signatures and timestamps on digital files while leaving the signed content empty 1. By exploiting the "exclusions" feature—which permits certain byte ranges to be excluded from signature calculations—an attacker can sign an entire file while the actual signed content amounts to nothing, generating a valid signature with the hash value 47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU= 1.
The vulnerability becomes particularly dangerous because timestamp signatures are anchored to claim signatures, and when a claim signature itself covers empty content, the timestamp's authentication guarantee becomes meaningless 1. Buchanan demonstrated a proof of concept that fabricates fraudulent lottery winning timestamps, yet all existing C2PA verification tools fail to flag such attacks as anomalous 1. While PNG and similar file formats rely on the exclusion mechanism to accommodate CRC32 checksums, completely removing this feature is not feasible, leaving the protocol structurally vulnerable 1. Google Pixel 10's implementation of "on-device trusted timestamps" has prompted Buchanan to express serious doubts about its security, and the issue was already documented in Dr. Neal Krawertz's list of C2PA defects published in June 2025 1.
评论
还没有评论,欢迎留下第一条。