Featured image for The Silicon Root of Trust: What Secure Capture Can—and Cannot—Prove

The Silicon Root of Trust: What Secure Capture Can—and Cannot—Prove

September 23, 2026 by Gerardo I. Ornelas

Author profile

Editorial Series: The Trust Stack: Architecture, Identity & the Battle for Authentic Media — Part III of V

Target Question: Can hardware capture attestation prove that a photo or video is real?

Direct Answer: Hardware capture attestation can show that a device produced a file under recorded conditions and that its provenance was not silently altered. It cannot prove the scene was truthful, the operator had consent, or a publisher is authorized to use the media. Secure capture strengthens the first link in the evidence chain; it does not complete the judgment.


The Silicon Root of Trust

When software can generate a convincing image in seconds, the camera starts to look like the last honest witness.

That intuition is moving provenance closer to the sensor. Instead of adding claims after an image enters an editing workflow, secure-capture systems sign evidence when light becomes data.

Hardware can anchor a capture event. It cannot decide what the event means or what anyone may do with the result.


What Hardware-Backed Capture Changes

Ordinary dates, device names and locations can be edited. A later signature protects a file from that point forward, but cannot establish what happened before signing.

Leica’s M11-P uses dedicated hardware to store a certificate and sign images when Content Credentials are enabled. Sony’s Camera Authenticity Solution supports camera signatures, editing-history checks, server-time verification, modification analysis and, in supported workflows, 3D detection. Truepic records time, date, device and location signals while flagging manipulation.

These systems differ, but share one move: establish provenance near capture and preserve an inspectable record as media travels.

That can help a newsroom identify an original camera file, an insurer evaluate inspection media, or an investigator document collection. The key phrase is evidence about—not proof of everything.

A strong system may support claims that a device produced an asset, a protected key signed it at capture, conditions were recorded, and later changes are detectable.

Starling Lab’s work on vulnerable records and war-crimes evidence shows why this matters. Yet capture is one stage. Collection, storage, corroboration, testimony and legal procedure all affect whether evidence can be used.

A camera is a root of trust, not an evidentiary process.


The Scene Can Still Lie

A secure camera can honestly sign a photograph of a synthetic image displayed on a screen. A projector can place fabricated imagery into a real scene. An object can be staged. A replayed sensor stream may reach a signing component as if live.

The credential may accurately say the camera captured those photons. It cannot guarantee the event happened as a viewer imagines it.

C2PA’s explainer says provenance can provide evidence about origin, history and authenticity, but cannot determine whether an asset is true, accurate or factual. Its harms guidance warns that a valid manifest is not a truth judgment.

Defenses can raise the cost of deception. Sony describes 3D detection and modification analysis. Protected paths, server time and replay resistance can harden capture. Independent records can corroborate it. None turns physics into meaning.


Capture Evidence Is Not Authority

Hardware cannot answer what follows capture. Was the person allowed to photograph the subject? Did everyone consent? May an editor publish it? May an AI transform it?

  • Identity concerns who or what is involved.
  • Provenance records origin and history.
  • Authenticity asks whether a claim is credible.
  • Authority concerns the right to act.
  • A capability defines a permitted action.
  • Trust is the judgment built from those signals.

Secure capture can strengthen provenance and authenticity. It does not grant authority.


The Interface Should Show Claims

A complex evidence chain is often reduced to a green “verified” checkmark. The viewer then guesses what was checked.

Good provenance UX should say what claim was verified, who made it, which gaps remain, and what judgment still belongs to the viewer. It should not treat missing credentials as deception. C2PA warns that absence of a manifest does not mean an asset is false; witnesses may use unsupported devices or avoid identity-bearing systems.

A signal can help judgment without becoming a verdict.


Original Synthesis: Physics Gives Us a Boundary, Not an Answer

Secure capture begins the evidence chain earlier, inside a boundary harder to impersonate than ordinary software.

But origin is not truth, and evidence is not permission.

As media moves through editing, publication, distribution and reuse, each claim must remain precise. At each consequential boundary, systems must evaluate both where the asset came from and what the current actor is authorized to do.

Hardware can seal a moment. Trust still has to be earned around it.


Limits and Counterarguments

Secure capture adds cost, can expose metadata, depends on certificate governance and may create inequity if uncredentialed media is treated as suspect. In high-stakes work, partial, well-scoped assurance can still be better than none.


Where This Fits in The Trust Stack

  • Part I showed labels fail when ecosystems do not preserve them.
  • Part II showed personhood does not grant authority.
  • Part III strengthens capture evidence while locating its boundary.
  • Part IV will synthesize these limits into explicit, scoped, revocable authority at consequential action.

Sources & Further Reading


Frequently Asked Questions

Can C2PA prove truth?

No; it verifies provenance claims.

What is capture attestation?

Signed evidence about capture.

Can a verified camera photograph a deepfake?

Yes.

Does missing provenance mean fake?

No.


© Gerardo I. Ornelas

Systems architect, founder, and advisor for governed AI and trusted visibility.