Wednesday, November 30, 2011

Hackers circumvent industrystandard image signatures


Photos taken with
professional Canon cameras
can be embedded with an
ODD signature (Original
Decision Data). This is
designed to ensure that the
photo cannot be altered or
retouched without being
detected. However Dmitry Sklyarov, a safety expert from
ElcomSoft, has now showed how he can forge this signature,
at the CONFidence 2.0 hacker trade fair. The expert read
out and analyzed the fi rmware of his Canon EOS 30D using
a self-built adapter. He then reverse-engineered the secret
encryption code and was thus able to forge ODD signatures
and deceive the offi cial Canon signature reader, known as
the OSKE3 Security Kit. Canon is aware of this shortcoming
but has not commented on it till now. News agencies and
insurance providers have been using ODD for years in order
to be able to check the authenticity of a photo—such as its
recording time and place. Several controversial photo edits
have made the news in the past few years, embarassing the
responsible agencies and leading to allegations of bias or
manipulation of the news.

No comments:

Post a Comment