← Writing

We Need a Chain of Custody for Reality

Someday, a kid is going to watch footage of the Nuremberg trials. Or Hitler declaring war. Or the towers falling on the morning of September 11th. And they will have no way to know if it's real.

Not because they're careless, or gullible, or bad at media literacy. Because by then, no one alive will remember a time when video was self-evidently true. The distrust won't be a crisis they live through. It will be the ambient condition of their world — normal, unremarkable, the water they swim in. That is what makes it worse than a crisis. A crisis gets fought. This just becomes how things are.

Why detection can't save us

The instinct is to fight synthetic media with better detection. Build a model that can spot a deepfake. Ship it, update it, stay ahead.

This doesn't work, and it's worth being precise about why. Every detector trains the next generation of generators to defeat it. This is the same arms race we've run before — spam filters, malware, CAPTCHAs — and in every one of those, offense wins in the long run. The detector has to be right every single time. The generator only has to win once. Detection can buy time. It cannot be the permanent answer, because the permanent answer has to survive generators that don't exist yet.

Don't detect fakes. Prove originals.

Flip the problem. Instead of trying to catch what's fake after the fact, cryptographically sign what's real at the moment of capture.

Here's the mechanism: a camera or phone signs the media with a private key the instant it's recorded — a mathematical proof, generated by hardware, tied to that specific device and that specific moment. The corresponding public key is registered with a neutral, verifiable authority. Anyone, forever after, can check: was this recorded by this device, at this time, and has it been altered since?

This isn't speculative. The pieces already exist. Apple's Secure Enclave does something structurally similar for device security. Canon already ships a camera with Content Authenticity Initiative signing built into the hardware. Certificate authorities and blockchain timestamping solve adjacent problems — proving something existed, unmodified, at a specific point in time. The parts are sitting on the shelf. Nobody has assembled them into something that works at civilizational scale.

What's actually at stake

Most people who think about this problem stop at "I might get fooled by a fake video." That's true, but it's not the real cost.

The real cost is what happens to the last hundred years of footage — everything recorded before a signing standard existed — once it's sitting alongside an ocean of new, unsigned, unverifiable media, forever after. If we don't build the infrastructure now, the unsigned past doesn't get grandfathered in as trustworthy. It gets swept into the same bucket of doubt as everything else. Every historical document we currently take on faith becomes permanently unauthenticatable by comparison to what comes after.

We're not just risking future deception. We're risking the retroactive collapse of confidence in everything that came before — because the world will have fully adjusted to assuming nothing can be verified, and old footage won't get special treatment just for being old.

The proposal

What needs to exist is not complicated to describe, even if it's hard to build.

A public, non-vendor-controlled signing standard. Device manufacturers building it in at the hardware level, as a default, not an opt-in feature buried in settings. A registration authority structured like a public utility — accountable, neutral, permanent — not a consortium of companies with their own commercial incentives sitting on the board.

The Content Authenticity Initiative, backed by Adobe, BBC, and Microsoft, is trying. It's a real effort and it deserves credit for existing. But a vendor consortium is not the same thing as public infrastructure. Certificate authorities and DNS work because they're structured to survive the interests of any single company. This needs the same structure, at the same scale, treated with the same seriousness.

The urgency is not rhetorical. The cost of building this rises every year we don't — the population of unsigned, unverifiable media keeps growing, and the population of people who remember a world where video was trustworthy by default keeps shrinking. This is a closing window, not an open-ended problem we can get to eventually.

The last generation that remembers

Go back to the kid watching that footage, decades from now, uncertain whether any of it is real. The difference between that world and one where they can pull up a cryptographic signature and know — actually know — that a piece of footage is authentic, is being decided right now, by what gets built in the next several years, not the next several decades.

We are, right now, the last generation of people who remember what it felt like to trust a photograph or a video by default. That's not a nostalgic observation. It's the reason we're the only ones with the standing to build the thing that preserves it for everyone after us.