The pitch: trust the sensor, sign at capture, and make every later edit a proof instead of a lie.
2 comments
The hard problem here is not just tamper detection, it's chain of custody. Once media leaves the camera, you want to know whether an edit was a crop, a color correction, or a full-on splice, and old approaches mostly leaned on EXIF blobs, watermarks, or institutional trust that falls apart pretty fast.
Signing at capture makes sense because it moves the trust anchor to the sensor instead of some later uploader, but then you immediately get all the annoying questions around key management, revocation, and what happens when devices get stolen or firmware gets updated. I also wonder how much of the ecosystem actually wants a proof of edits versus just a plausible stamp that says
Signing at capture doesnt buy you much if the sensor or its firmware is compromised, or if the shot was staged in the first place. It proves provenance from a particular device, not truth, and people keep collapsing those two things.