04
Provenance beats detection
Asking whether an image looks fake is a losing race. Asking where it came from is a question with an answer — and there is now a signed, checkable way to record it.
7 min read
Detection asks a question about pixels: does this look generated? That question gets harder every year and will not get easier.
Provenance asks a question about history: where did this file come from, and what has been done to it since? That question does not get harder. It only requires that someone recorded the answer.
What C2PA is
The Coalition for Content Provenance and Authenticity is an industry standard for attaching a signed manifest to a media file. The consumer-facing name is Content Credentials.
The manifest can record what device or software created the file, what edits were applied, and who signed the assertion. It is cryptographically signed, so tampering with it is detectable, and it can be checked by anyone.
Support exists in some cameras, in several editing applications, and in some generative tools, which use it to mark their own output.
What it does not do
This part is routinely overstated, so state it plainly.
It is not a truth badge. A signed manifest tells you a file’s claimed history and who vouched for it. It says nothing about whether the scene was staged, whether the caption is accurate, or whether the signer is honest.
Absence proves nothing. Almost every social platform strips metadata on upload. A screenshot has none. A photograph forwarded through three chat apps has none. Treating missing credentials as suspicious would flag the overwhelming majority of genuine images on the internet.
Presence can be laundered. Re-photograph a screen, or run a file through a tool that re-signs it, and you have a fresh manifest attached to old content.
So: presence is evidence, absence is not, and neither is proof.
The everyday version
Most of the time you will not have credentials. You still have provenance questions, and they are the ones that work:
- Where did this first appear? Not where you saw it — the earliest instance. Reverse image search, and sort by date.
- Who published it under their own name? A named person or outlet has something to lose. An account created last month does not.
- Does anything else corroborate it? Another angle, another source, a building you can locate on a map.
- What does the caption claim beyond the image? Most misleading images are real photographs with a false story attached. The pixels are fine; the sentence is the lie.
That fourth point catches more than all the forensics combined. Recycled disaster photographs, protest crowds from a different country, footage from a different decade.
The tool on this site
The metadata inspector on the homepage reads what is in a file you drop into it, in your browser, and tells you whether camera data or a C2PA manifest is present.
It deliberately does not give you a verdict on authenticity, because it cannot, and neither can anything else that claims to.
Verification is not a machine you feed an image into. It is a set of questions about the world.