The author demonstrates a proof-of-concept exploit of C2PA's Time Stamp Authority (TSA), showing how the second-layer cryptographic timestamp in C2PA manifests can be manipulated to assert pre-existence of content before an event. By forging a TSA-signed manifest claiming to show winning EuroMillions numbers hours before the draw, the article highlights a potential trust gap in C2PA's two-signature architecture.
Background
C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard for embedding tamper-evident metadata into digital media. The author previously showed that the claim signature in C2PA can be freely self-signed; this follow-up examines whether the TSA second signature provides meaningful protection against manipulation.
- Source
- Lobsters
- Published
- Oct 3, 2026 at 07:58 PM
- Score
- 7.0 / 10