You can't C2PA your way out of a post-truth society
I ended up quite-posting the same thread on both Mastodon and Bluesky this morning in response to different, but related stimuli.
Given that my posts are auto-deleted after a certain period of time on Mastodon, I thought I'd save what I said here so I can come back to it in future.
Note: I mention 'C2PA' which is now widely known as the Content Credentials standard. Although I think there are some ways they can be used together, given my work around Verifiable Credentials, I prefer to use 'C2PA' to avoid muddying the waters.
I'm sympathetic to the intentions behind "sign everything to ensure it's real" but, in practice, there is no such thing as capital-t Truth on the internet.
What I mean is, there is so much information buzzing around that people use it not to seek out something beyond themselves, but to bolster worldviews and opinions they already hold.
For example, people create obviously-AI images of disaster zones over which people emote. When it's pointed out that these are synthetic, the response isn't to retract the emotion (if that were even possible) nor to affirm the correctness of the interlocutor.
No, the response is to say that the AI-generated image captures "a truth" about the situation. No amount of C2PA is going to counter that.
So what's the answer, Doug? Education and immersion. We learn to swim by getting in the water, and having more experienced people (and lifeguards) around us.
The trouble, to continue the metaphor, is that our "teachers" are just other people on the internet struggling to keep up with ever more sophisticated tools, and our "lifeguards" are the very companies pushing the product.
Governments are like sleepy leisure centre managers who start to wonder why so many people are drowning and otherwise failing to learn to swim.