
Alex Bores, ehemaliger Palantir-Politiker, sagt, KI-Deepfakes seien ein „lösbares Problem“, wenn wir eine kostenlose, jahrzehntealte Technik zurückbringen, die weitverbreitet HTTPS übernommen hat – die Verwendung digitaler Zertifikate zur Überprüfung der Authentizität einer Website
https://fortune.com/2025/12/27/alex-bores-ai-deepfakes-solvable-problem-c2pa-free-open-source-standard/

34 Kommentare
How the hell is that going to solve anything? I can deepfake whatever I want in my computer and spread it like wildfire in social media or Whatsapp. What will HTTPS solve then?
ah yes cause everyone is going to legitimate verified sites for that kinda stuff. these guys are gonna be shocked when decentralized becomes a huge thing
As usual, tech company leadership knows nothing about tech.
I was thinking this the other day, it’s easy to digitally sign content with web of trust, always has been. Deepfakes should be a non problem for politics.
Why am I not surprised this dingbat is a data scientist and not a software engineer.
All modern browsers already block access to sites by default not using https or using invalid certificates. It takes a lot of effort to get around those blocks, and the people that would be easily fooled by deep fakes are probably not the same people who would go to greater lengths to bypass https protections
I read the article wondering what does he know about HTTPS that I don’t, and the answer is – „nothing“. He knows nothing about it.
It’s true that it is an easily solvable problem.
Start making and publishing extremely embarrassing deepfakes about politicians like there is no tomorrow and it will be solved in no time by the people in charge
Ah yes, HTTPS will prevent people from running software on local machines and using decentralized supercomputer clusters.
The solution is to create a middle man to sell you the certificates who will probably indiscriminately sell the certs to anyone who applies.
Sounds about right.
Oh good, another unqualified executive
What would stop anyone from generating a cert for a deepfake?
What does he mean bring it back???
ROFL… It’s trivial to hit up Let’s Encrypt and generate a certificate
Surprised he didn’t suggest NFTs as the solution, more Galaxy-brained
Edit: reading the article, and while his plan is a little better than „just use https“, it’s not really much more effective. Basically would require image generators to digitally sign images and declare them made by AI… Even if you got the major AI image generators to agree, it would be pretty trivial to strip and then there’s everyone running models on their personal machine who could sign it however they wanted. *<Insert BartSimpsonYouTried.gif>*
Seem unfeasible to implement. Media size would explode.
Also, this is only loosely related to HTTPS, yes, it would use asymmetric cryptography but that’s not strictly specific to HTTPS, IMO.
If they just used that same energy to create a fair, open and digital voting system.
Folks haven’t read the article, have they?
> Bores pointed to a “free open-source metadata standard” known as C2PA, short for the Coalition for Content Provenance and Authenticity, which allows creators and platforms to attach tamper-evident credentials to files. The standard can cryptographically record whether a piece of content was captured on a real device, generated by AI, and how it has been edited over time.
Back to the “just put it on the blockchain!” way of thinking
If 40% of people don’t just believe everything they see on Facebook or Twitter, and only got news from actual journalistic outlets, then sure.
But the news industry is dying, journalism doesn’t have a clear easy profit model, AI is only accelerating that, and a huge fraction of the population doesn’t understand even the basics of digital media literacy.
So…… this amounts to a big “trust us bro”. Which like, no, I don’t think that I will.
Dude might as well have said “I don’t know how technology works”
*”You keep using that word. I do not think it means what you think it means.”*
Yeah but what he isn’t taking into account is that I don’t know what that means.
What do you mean bring back? It’s still in use all over the world
He’s talking about content signing but I don’t see how this works. Are browsers going to start refusing to display content embedded into a page that isn’t signed by some trusted provider?
I guess some famous person can say, „I will sign all official photos and videos of me, so you know they are actually me“. Ok, sure, but do we get most of our information about these people from their official PR folks? The people releasing papparazi shots are likely the same people who might release AI fakes, so they can sign either thing.
Don’t get it.
If someone said this in an interview, the interview would be over.
thats not how this works, Jesus
Another technologist that is trying to apply a technological solution to what is fundamentally a social problem caused by technology. Taking this approach creates a Chokepoint on information. If we can only trust what’s cryptographically verified we need to be able to trust(the social meaning of the word not the cryptography meaning) a small number of organizations to deliver us the truth. Organizations that may not want certain news stories to get out. So we just swapped one problem, not being able to believe what we see, for another problem, having powerful organizations control what we see. Neither is good.
digital certificates dont solve layer 8 issues
“Legitimate, provenance data”. He’s talking about new orgs trading amongst themselves, not just some shite people plop on FB or X, which means that this is good for one tier of what people watch, but not what your idiot cousin is inhaling like a huffer in an alley.
Holy fuck burn this whole thread. Bunch of idiots yapping about an awfully worded title.
https://c2pa.org is what he is talking about. And he’s correct if we want to know that an image actually came from the camera of a CNN photographer or something like that. Does it solve every issue? No but verifying the source is a valid approach.
I completely agree. I charge $1000 per machine to upgrade to the HTTPS, but have a corporate bundle rate enterprise price £800.
I’ve actually been thinking for a while about how browsers should have a way to determine if there is a deepfake or if text is generated and it hides the content and displays a „THIS IS GENERATED BY AN AI CLICK HERE IF YOU STILL WANT TO SEE/READ THIS“ and that way people who would prefer to only look at real content can. The same should be true for TV. And, users can disable this protection if they desire to see it all automatically instead. But, by default it would be protected by default for everyone, almost like an adblocker.
It would apply to news websites, emails, reddit, other social media, instagram, tiktok, youtube, pinterest, discord, etc.
In order to make this work, the idea of passing raw text might need to be a thing of the past and all text will have to be encapsulated in a container format instead. And, when you copy paste text, you won’t just be copying the text but the containerized text and when you paste it you’re pasting it along with its container which retains its origins; whether human or AI.
Unfortunately, this would open up a dystopian privacy invasion future if done incorrectly, the container should know it’s from a human not which human or which identifiable machine originated it. The container’s purpose is just to indicate which LLM created it or if not, then „None.“ which means human.
Yup that’s it. They want shit to fail.
I can see adobe coming up with a method around this idea… FFS .SJPG – I can see it now lol