C2PA (Coalition for Content Provenance and Authenticity) is a standards organization that enables media content to carry cryptographically verifiable provenance metadata, documenting who created the content, how it was modified, and its chain of custody through the production and distribution process. Unlike DRM (Digital Rights Management), which focuses on controlling access and protecting revenue, C2PA focuses on preserving evidence of origin and changes to content. The system uses assertions (labeled data about content creation, edits, and capture devices), claims (bundles of assertions), and manifests (signed documents binding metadata to content) to create a tamper-evident record. While C2PA can verify that content was signed by a specific creator and detect unauthorized modifications, it does not verify the truth of the content itself, nor does it function as an AI detector or content moderator.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
C2PA: Content Authenticity, Credentials, and Building Trust in Media
Added:[music] Well, hello everybody and welcome. Happy New Year. It is 2026. I'm Joel Welch, uh your host. I'll be mostly working behind the scenes today. I'm I'm really really really excited about this webcast. This is the first webcast in a series uh that uh we have uh partnered with the uh women in streaming media and I'll introduce your moderator and your speaker in just a bit. I have a little bit of housekeeping to do. I want to do that right now and get out of the way so you can get right to the content.
So today's topic is C2PA uh content authenticity credentials and building trust in media.
Uh I have to thank AJA always always I was telling uh the moderator well over a decade that these folks have uh sponsored Simpy webcasts and and I'm happy to have them sponsor the uh uh webcast with women in streaming media as well.
This is the full schedule. I'm not going to go through each of them, but these are the five. We actually may have a sixth one. Keep your fingers crossed.
Um, but today is January 14th, 2026. And you can see that every month we will have one. And the people who are speaking are uh uh technology leaders.
They're women. uh and they are uh part of the the uh community who are moving streaming media forward.
I do have a disclaimer. Um this webcast is presented for informationational purposes only. Views and opinions expressed are those of the presenters and do not necessarily reflect those of simp women stream women in streaming media or their members. Reference to any specific company, product or service is not a promotion, endorsement or recommendation by simply or women in streaming media.
Our speakers today are Emily Bergen. Uh she is our moderator. She is representing uh women in streaming media. And our speaker is going to be Olga Kenko. She is a COO and co-founder of uh Easy DRM.
So, hello Emily.
How are you? [laughter] >> I'm very welcome, thank you, Joe.
>> Good. I am going to turn the floor over to you for your uh uh any opening remarks that you have. And when you're ready to bring Olga on screen, let me know.
>> Perfect. Yeah, just really quick for me, I'm super super super excited to have this collaborative webcast series between women in streaming media and Simy and the fact that we are have this opportunity to platform such a diverse range of speakers over a huge range of technical um streaming media topics. Um, obviously our first today is Olga Kenko, uh, CEO of Easy DR DRM. And hello, Olga.
>> Hi, Emily. Good to see you.
>> Very excited. And yeah, I think we're ready to start, Joe.
>> Perfect. Hello everybody. Thank you very much for joining me and thank you very much for taking the time to learn a little bit about C2PA.
As we were preparing for this presentation and this webinar um there's a lot of conversation about whether or not how deep technical or high level we should go with this and I am taking the approach that uh given the fact that for a lot of people C2PA might be something you've heard about but it's a fairly new concept I took the approach of taking more of a high level um understanding and setting more of a terminology um level set of what CGPA is, how you work with it, and um what it actually does and does not do. Um because I know that even up to this point at so many conferences, people approach us and say, "Oh, you guys do CPA? What is that?" Um C2 I can talk about C2PA for hours and hours and hours. So, I'm doing my best to fit what I can in this hour presentation. So, without further ado, um welcome and thank you for joining me.
Um, as I said, my name is Olga Cornenko.
I'm the COO and co-founder of EasyDM and a very huge fan of all things dog and the company is Easr. We have been f we were founded in uh 2023 and as I put that on the presentation, I kind of realized that oh my god, the company is almost 23 years old. Um, which is kind of scary. We started out as a DRM as a service company, but it's a hosted managed um service and with adding on to CTPA to our um um offering, we are becoming more of a video security vendor. We have been involved with C2PA since uh 2022 and it is actually very wonderful to see how the organization has grown over the past three years and what started out with a very small list of members is grown to a very very large page. I mean eventually at the end of the presentation I'll put in a bunch of useful links and you can see what the membership uh list is like and also if you wanted to join please do uh any input and information that is you know that C2PA uses we all need input from all the different aspects of the members of the industry. Also, I wanted to say I saw the other day that Simy has recently moved to the new head offers in White Plains, which is about 25 minutes away from my house. It could have been I could have done this presentation from the head office. It would have been kind of an interesting place to be. Um, but any um why why is C2PA even a conversation? What is it? Why do we need it? Well, today media is everywhere, but do we really know what we're looking at?
I don't know about you, but I oftentimes look at content and on somewhere online and go, well, I saw this, but I don't know if it's true. I don't know where it came from. I don't know what the source of it is. So, I saw this. I don't know if I believe it, but it was educational, interesting, cool, entertaining, right?
Um, and in today's world, deep fakes or any content that's modified can spread like wildfire and faster than, you know, um, anything. and things get cut, reused, and things are taken out of content. And when we look at content, we don't really know what we're looking at. In fact, I think I just saw a story that a couple days ago in St. Louis, there was an issue with the fact that some monkeys got loose and when they got loose, people started creating AI videos and sharing them. And then the officials didn't really know if the story was real. How many monkeys? And like there were obvious things that were happening where there was an image of the monkeys taking a selfie with a goat and the St. Louis arch. Obviously that's AI. But at a press conference, one of the reporters asked one of the officials if they actually know if the monkeys are real.
and the reporter and uh the official basically turned around and said, "Yeah, we had one verified sighting by a police officer of one monkey, but that's all we know." And when you are at the point where officials and reporters don't know if an event is happening is true, that becomes kind of terrifying. Um, so as discerning consumers of the content, we should probably be trying to figure out where the content came from and who created it. Was it ever modified since it's been published? And from a media company standpoint, we should be able to answer the question, well, yes, we did post this content and this is what we posted and this is what's valid and this is what we can um basically prove that was out there and nothing else outside of the scope of what we posted should be out there. And also you can a um C2PA also can address AI concerns if AI has been used within the content. Um so when we start talking about CTPA you will hear about two organizations. The founding organization is something called CAI which is the content authenticity initiative. It was founded in November of 2019 and the aim of the organization was to drive feature exploration, creation of open source tools and fostering of of an overall community around this movement for content authenticity.
But you obviously can't have open source tools if you don't have standards.
So C2PA was born to do the standards part of it. C2PA, the term we completely interchangeably use for provenence, just like we use the term Google for looking things up. Uh, but C2PA actually stands for Coalition for Content Provenence and Authenticity. And it was established in February of 2021.
And the um idea behind that organization is to actually set and develop standards dedicated to certifying the source and history of media content. So from a functionality and focus standpoint, C2PA is a technical specifications organization that is primarily concerned with just creating and setting and maintaining standards. And CI emphasizes the community and the um fostering and dissemination of those standards to the to the people if you will.
Um but when we joined the organization there was a lot of conversation about why as a at that point DRM vendor we were joining the conversation and also why can't we just use DRM to do this and the answer is pretty simple um they DRM is very good at um solving for the the business side of things the figuring out who can view the content or addressing the question of who can view the content and enforcing business and licensing rules and overall it was designed to protect and enforce revenue. At no point in time does DRM ever care about creator identity or edit history or chain of content uh custody. In fact, once you DRM something, you can no longer change the content. So if you were to DRM a piece of content as it came out of camera, you would have to und it, make changes to it, and DRM it again, and that loses the chain of custody right there.
So just to kind of iterate, C2PA is a set of standards that define a way to attach cryptographically verifiable provenence metadata to an asset. By in no way is C2PA a truth verifier, content moderator, an AI detector or DRM. And when I say truth certifier or content moderator, what I mean by that is I can create a video and sign it and talk at length about my black shirt. We can all see I'm not wearing a black shirt. But if I am talking about a black shirt, then two things might be happening. If the video is signed by me, then Olga probably might be losing her mind. Um, the alternative to that is if the video doesn't have a signature or is signed by somebody else, somebody could have taken my video and overlaid the word black over white and made it sound like I'm losing my mind. But at the end of the day, C2PA will never ever ever tell you that the context of the video is false.
Um, so it would never correct the color of the shirt I'm wearing, but it will tell you this video was created by Olga.
It will also not tell you what's in the content in general. Uh, it may or may not tell you if AI was involved. And as I said, it's not DRM. It's not responsible for rights of any kind. And in fact, DRM and C2PA go hand in hand together.
And if you look at C2PA from a perspective of provenence in art, because we all understand provenence in art. C2PA is basically trying to address the same exact question, provenence of digital content. So C2PA looks at the questions of who created this piece of content, if it was modified, the steps it took as it traveled through the internet, potentially if it was changed in the process. Um, and it also is very much responsible for truth and transparency of this piece of content.
Whereas the flip side of that DRM, if you go back to my art example, is the part that talks about the payment behind it. If there are any rules, like if I buy a Van Go, let's pretend I can buy a Van Go. Um, if I have to make sure that it has to spend some time in a museum because it can't be completely hid from the world or whatever. I'm making stuff up. I have no idea what's involved. I'm buying a Vang Go. But it is around revenue protection for that piece of content. So let's jump into C2PA. The core underlying concepts of C2PA are as follows. You have assertions which is the information that covers uh different aspects of asset creation, edits, capture device and many many other things.
Once those assertions are put together and wrapped, um, they're called a claim.
The security piece of the whole technology is a signature. And once all of the content is put together with the assertions, the claims, and it's signed and it is bound to an asset, that generates a manifest. Yes, we now have another manifest we have to keep track of. It's another term. Um, C2PA manifest.
Um the assertions are labeled data typically in seabore structure which represent declarations about an asset.
And when I say about an asset, I actually do genuinely mean about the creation of the asset and it has nothing to do with the content of the asset unless somebody specifically makes that comment. But you can talk about metadata of the camera. You can talk about like as you see on the right hand side, it says that the device that took this specific image in the example was a Canon camera. Um, this example lists a location. I know there's been a conversation with NCTPA whether or not location and coordinates should be part of this conversation. Um, I leave it up to them to discuss. I do think it's important. Um, assertions also keep track of whether or not an asset was ever edited, compressed, cropped. Maybe in a video, you can take out a certain piece when somebody takes a, I don't know, drinks a some water in the middle of a presentation and you want to crop that out um or something. And it can also have AI disclosures.
But um and then once all those assertions are put together, they are put together into a claim. And the security piece of that, as I've mentioned, there's a signature.
To sign your claim, you need to use an X509 certificate. And the signing can be done by either hardware, software or identity. What do I mean by that?
Hardware is a camera. So in our previous example when it said it was taken by a Canon camera there are most of the camera manufacturers are now members of C2PA. I know that Sony is working on a first on the first video camera that can do signing from the camera. I know that um Nikon and Canon and like are all members and they're working on that as well. You can also sign your content by software which will be your example of um [snorts] the Adobe Photoshop for anybody who's currently using Adobe Photoshop. If you go digging through it, there is a C2PA piece where you can sign the content or identity. An identity would be me. I or Cornenko say that this is my content and I you know if it comes back if I said something incorrect or correct you can trace it back to me and eventually once all the content well once all the metadata is signed and um bound generates a manifest.
You can have an active manifest which is the most valid one and in this example you can see multiple manifests. The very first one that's the one that's all the way in the back on the image is the one that says 2.3.6.
It talks about the camera and it says that the camera was used to take this image at the specific location at this specific time.
Then the second manifest is the um edit suite manifest. It's the one in the middle. And eventually you can see that uh image that the the part of the image that says 2.3.4 before it says manifest, but below it it says 2.3.7 active manifest. That is what the current active manifest is. And you can see um what process this in this point it's a photo what steps it took to got to get to you.
Um all of the manifests and all the content all of the metadata is linked to the content securely through a hard binding via a hash and the manifest can be attached to um the content in two different ways. It can be embedded or it can be external.
Embedded in the content uh means that every time a piece of content is emailed or somehow propagated in the world, all of the metadata goes with it.
So regardless of where you are in the world, if you have access to this piece of content, you can see what the C2PA provenence information is that goes with the content. The downside to that is that you have a lot of data and the more information you get, the bigger the data gets. So you have exponent potentially a huge giant piece of uh contact giant file that um you have to keep either emailing or somehow moving around. And additionally, if there's something wrong in the metadata or it somehow has to get updated, in order to update an uh embedded um manifest, you have to update every single copy of that manifest. On the flip side of that is an external uh manifest which can be stored at a provider or somewhere in the cloud. Um we easyd offer a service like that. Um, but what we allow our customers to do is to also make changes to that manifest.
Uh, and why would you do that? Imagine if you A just typo something or B it's more of a sensitive area and this asset this photo was taken in a politically questionable area and now somebody is trying to go after the photographer either death threats or what have you because obviously those things happen.
So you can make changes to the manifest and actually redact the name of the photographer and then that change will propagate to every single piece copy of that content that's out in the world.
Additionally, I mean we can get into it into more details, but you can also do things like um you can make it so that Associated Press can see the name of the photographer internal to the org, but outside of the org, you no longer can.
There's a lot of things that are done to protect photographers and also make sure that you can have control over the manifest.
So in a typical photographic workflow, um you would have a camera that captures the image and hopefully signs it. Then you have some sort of an editing suite like a Photoshop that you make changes to it. You, you know, adjust the photograph, crop it, do whatever you want to do with it. Sign it. Then it goes to a publishing app. that app signs it and eventually consumer uses some sort of a validator to verify the signature in the chain. Um a validator is can be um any app or any player that supports the um C2PA provenence information and I'll show you that in a few seconds. But even if you take this photographic workflow, if I go back one slide. So we have the camera, the editing tool, the publisher and the the verifier, right? The validator. This is the camera is the very back um slide. That is your camera, the the original manifest. The second one is your editing tool and the third one is your compression tool. And then it goes out to the people's if you will.
So, what does it look like in real life?
In real life, you would see the logo of CR uh stands for content credentials.
And you would see that um attached to an image or a video. I quickly put together this post on LinkedIn yesterday. I also just as quickly took it down. So, for some reason you connect to me or we're connected on LinkedIn and you look for that and you don't see it. Yeah, because I took it down. I just wanted to have this as an example for the purposes of um this presentation. But the idea here is that once we post a CTPA sign image to LinkedIn in the top leftand corner you will see the CR and then if you click on the CR a separate window pops up that tells you that this content was signed by certificate issued to easy DRM you know blah blah blah blah blah. Um, and this is how LinkedIn displays it.
The other thing worth mentioning here that if you go out and you get a certificate and you sign something and you post it and for some reason you don't see that on LinkedIn is because C2PA also has this concept of a trust list. And a trust list is a C2PA maintained list of all the X509 certificate trust anchors like SSL.com or Digiert or something and you need to have a certificate. You need to get a certificate from those organizations in order for your content to be um for you to be able to sign content and then it has to be visible and then organizations can download the trust list. um because CTPA maintains that you would have to download to download it or link to it or have access to that list in order to be able to show provenence information from um from other people like LinkedIn does here. So this is a LinkedIn example. Um in a photography environment you would also see something like this. The penguins in the desert is a Adobe example. And if you look, I don't know if you can see too clearly, but there's the second line from the bottom says that there's an AI tool that was used to generate this image. Obviously, Penguins Desert, right? Um, and the image on the right, basically the same image from beforehand. This is the content authenticity initiatives verification tool that anybody can use and it also gives you information about CPA.
But we are here for the world of video because we're a motion picture, right?
So that's obviously also available in video. Um, this is an easy DRM product and uh that's the only product I know that's I'm showing it to you. We took the approach that we have a video that we purposefully act. This is a screen grab.
I wanted to make sure I have something to show before I go to a live demo and possibly shoot myself in the foot. Um, but what we have done is we've placed the CR information, the credential logo right next to the play button and it allows us to show credential information. So, let's see if I succeed.
Now, you see my video. Um, and if I press play, the video starts to play. And you see that the CR logo is has a red um X at the bottom of it. and the play stream the play button the stream video is red.
If I click on the CR it will tell you that segments from 00 to 20 seconds may have been tampered with. Our player at this point our solution knows that something was a miss with the content.
It could have been as simple as somebody just wanted to make sure that pieces of content were brighter or dimmer or something. It could have been anything.
But since the signi but since the content was not signed after the change was made we can't validate it. So we say the content might have been tempered with and then it continues on our videos. I said every 20 seconds something changes in it. So then it continues to tell you then from 40 to 55 it's going to get to 60 and then it's going to switch over. U may have been tampered with and now we go back into the content that is in the clear. it's has not been tempered and we tell you that the current status has passed.
Switch back.
Yes. Um there is a UX group within C2PA that talks about how this information should be displayed and how and where the logo goes and all of this other stuff. Right now there's not officially a consensus.
They're still working on that. So if you're coming across other products that are showing you this information and the placement is different like when you saw LinkedIn versus Adobe it's a decision made on the organization that created that tool. Uh because as I said there is no official um consensus of where this this logo and how this information should be displayed at the moment. We also at easyd have a demo of a live piece of content that does the same thing. Um, live is a little bit trickier than VA mostly because in the live world scenario, people connect at different times and they disconnect at different times and you are looking at a scenario where you can't really use the standard ways of referring to the first frame or the first segment. So, we do have a live demo, but it's DRM. And with a webinar like this, you would just see a black screen with DRM. And then I'm going to try to convince you that there's a video playing, and I really don't want to do that. So, [clears throat] at this point, um, if you would like to see a live video of that, please let us let me know and I will show you that.
>> We've, um, just got a question through from somebody at Symph. Hope you don't mind me interrupting, Olga. Um, somebody has asked what other social media media platforms currently are using that CR.
Um, is YouTube using it?
>> At the moment, to the best of my knowledge, LinkedIn is the only one.
>> Um, I am not sure about YouTube. I don't know. Um, I know that at the moment, and I'm going to slightly get into that in literally two slides about the fact that right now there's a lot of organizations that are working on that. Um, but at the moment, uh, the only one I know of is LinkedIn. I could be 100% wrong and if I don't know, then I apologize.
So, how does the validation of a claim happen? A whole bunch of steps go into the process and one of the things and at the end of the day we have to validate a bunch of different steps. One of them is making sure that there the claim structure is correct and the canonicalization of that struct that claim is correct. We validate the signature of the claim. We also validate the trust chain and we also check on the binding whether or not it's hard or soft and confirm that the hash has not been modified and all sorts of things. And at the end of the day the tools you use the tool you use to validate the um claim returns either verified, untrusted or tampered. Um, so as you saw in the video, in this in our video previously, we say that the content may have been tampered with because we don't know what happened to it. There's not a signature and there is not enough information to us for us to say anything else. So, we just don't know. Uh, and those are usually the three options that we get as a return, verified, untrusted, or tampered.
Um, and to kind of add on to the previous question that was just asked about what are the social media steps, what other social media companies use it, I honestly know of only LinkedIn.
Um, I also know that right now C2PA provenence metadata is lost a lot and uh, it's basically at this point I put it on the slide as an engineering challenge. I don't know if it's necessarily a challenge mostly because I think people are not ready to start solving it yet. Uh but it is it's not malicious at the moment if there's no uh metadata.
But there's a lot of organizations out there that just don't know about this technology to begin with are not ready to dive in, don't have budgets or you know what have you. But oftentimes metadata is lost through transcoding.
It's lost on social platforms. We quickly just to confirm tested Facebook yesterday and it doesn't contain um provenence metadata. And if they don't, I'm going off the logic that um Instagram probably does not. I know for a fact that if I send a signed piece of content through WhatsApp or Telegram, it loses that. My personal bane of my existence right now is HubSpot. Once you upload a piece of content through them, they resample the content and they wipe away um C2PA metadata, but also there's a lot of legacy tools that don't know about this uh technology. And of course, screen sharing, if I take a picture of the screen, if I, you know, or whatever, none of that obviously supports provenence.
But at the end of the day, the idea with provenence metadata long-term is knowing that if there is no metadata, that should be a questionable thing.
Right now, we're not there yet. But the more the technology develops and the more and further down the process we go, I would like to just make sure that we all understand that if there's no metadata, we should be questioning it a lot.
Um, so how does it work in a workflow?
Come on. Okay. Um, in a newsroom workflow, I'm sorry I'm reusing this image, but it was very much appropriate and applicable in the most simplified basic way. You capture the content, you ingest it, you edit it, you publish it, and then you archive it.
um in today's world more and more content comes from um just regular people. How many times have we seen news, you know, publications even on TV and they're showing a video that was shot by a bystander to some event. um any person, any device can be a reporter in today's world. And knowing whether or not that piece of content is real, legitimate, cropped, specifically re-edited for some malicious purpose becomes vital to any newsroom. I mean, go back to my example with the, you know, monkeys in the beginning when people are just sending these pictures of monkeys in St. Louis. um and uh officer police officers and uh animal control just don't know if they're even real images. I mean, some obviously are fake, but some may or may not be real.
And part of that is for a news organization to actually know if the piece of content where it came from and if further down the line people can prove that the piece of content is legitimate for legal purposes. Um, but also just knowing in their archives where it came from, what day who who took it and so on. And also I know that a lot of news organizations are starting to sign their archives just so further down the line if they reuse the content or use it for specific purposes they can prove that yes this footage happened in New York on such and such day as opposed to in Los Angeles on a completely different day in a completely different century. Right? And also I know that C2PA was been used to prove or disprove propaganda from other countries where somebody takes a video from BBC crops it and publishes it and claims that BBC said this. BBC can turn around and say, "Hey, we did not say this because here's the version we have and this is the signed one and um what you have does not have our signature. So this was not our content." I mean, take this podcast, webcast, if you will. Um, once Cynthy publishes it, we would have a video of everything I said. And if I said something wrong, I will own that obviously, right? But if somebody and if Cinty signs it, we will have a true record of what was said here today. But if for some reason somebody some sort of a malicious actor wants to make either me or Cynthy or women in streaming media look silly, they can take this video, make changes to it and then publish a competing version where I'm talking about my black shirt and you know all sorts of other things and um we would be able to take the signed version and say hey this is what we published. This other version we don't know what that is. somebody is being evil and you should ignore that. Um, and that's basically the point of C2PA in general.
We've um got a question through Olga from Felix. Are is C2PA susceptible to age-old potential of CA spoofing from a malicious actor?
there. Um, there is a lot of effort that goes into making sure that in order to sign content, you have a valid certificate.
I mean, can you spoof things? I'm going to go yes. If you put in enough effort and hard work into it, you can spoof, fake, or do anything. Um, but the effort goes into making sure you have a correct certificate and not like I can't just go out and get a certificate from SSL.com.
I would have to prove a lot of things in order to validate who I am and prove that I am who I say I am that I represent this company or a news organization or what have you. So, a lot of it goes into the the certificate.
Um, and I think I'm going to touch upon this in just a few slides, but also we can talk I wanted to talk about a question of do people do some people care about anything that we're doing here? Do people care about provenence of content or they're just going to believe whatever is put in front of them? That is a whole other side of this conversation. But I think the the short answer to your question is we as an organization and I say we because we're members of CTPa are trying to make it very very hard. But can you hack something if you try hard enough? I'm going to go. Yes.
>> Thank you.
So, as we were preparing for this uh presentation, I I was asked to kind of touch upon CTPA and the entertainment and sports workflow. And I don't even know where begin to touch that topic. Uh I don't know remotely enough about the workflows to be able to talk about it and how would you put that in a slide or two in an hour presentation, right? I don't think that's possible. So the few points that I would like to get across when it comes to C2PA and specifically I mean any workflow in general but also workflows that are high stress large scale fastpace big budget or vice versa super duper tight budgets live or near live is that knowing things like which camera which venue or location which operator produced certain things a make things move and work smoother.
smoother and b create a strong anchor for the rest of the content in the chain knowing if the piece of content was somehow modified, edited, cropped or what have you. Having that information recorded is also super duper vital because especially in today's world where people clip things and send this off and I said content goes around everywhere and things get clipped out of context having I don't know I think I've heard something about a fake or an alternate um trailer for a movie being made. I mean, that can ruin a movie. And if the fake trailer is good enough and it ruins the movie, then all of this work that went into it might suffer. Well, will suffer. Being able to show, well, this is legitimate and being able to take down the fake ones is very important. Or protecting an identity or an image of an actor or an athlete based on what they might have said or didn't say. uh because they're caught on camera saying something and then it gets clipped. One word gets taken out and we have a completely different picture of this person where their identity affecting the movie yet again might also be something that we would all want to think about further down the line.
Um so if you wanted to get involved with CDPA, what do you do? Just like any project, start small. One workflow, one asset type, one distribution path, one validator, nothing crazy things that you can control fairly simple, but involve as many teams as early as possible. The engineering team obviously has to be involved. Editorial, legal is of the utmost importance, content security, a cyber security, product, and purchasing. Do we really need to spend all of this money on this one camera or a bunch of these cameras that can um add provenence at the camera? Do we care? Do we not? All of those things are important to be able to address and then internally set expectations of what C2PA will and will not do.
Um we all have to understand that CTPA is to is here not to certify the truth.
It is here to preserve evidence of origin and change. Um and it will preserve evidence via cryptographic metadata and provenence and thus it will increase transparency, build trust and certify brand reputation. it will in no way, shape or form prevent misuse, prove any sort of a truth or enforce legal rights.
And um I think this is where I also want to set expectations for externally for people because just like I said in that question, sometimes people just don't care about the content they consume, especially if the content supports their own narrative. Um, and I think for me that is probably one of the most terrifying things in the world. Like you can bring a horse to water but you can't force it to drink.
The same thing here. There are people like the people who don't believe in science or the fact that the world is not flat. They will probably not care that this piece of content that 100% supports their narrative um does not have a signature or we don't know where it came from. Um but I also think we as consumers need to demand that content should have provenence and we can check it. Um and also we as industry people also have to make sure we educate people around us, our parents, our siblings, our children because I know for a fact that my parents have no idea what CTPA is and my sister who's younger than me doesn't either. So it's up to us to educate um our people around us. I know that Microsoft has been putting a lot of work into education of um around the technology as does CI. I mean it's literally their job, right?
But I don't know how much of it gets outside of our industry and how much of it goes to the people's. So we have to educate it and we have to demand it. And in my ideal world scenario, I open a browser and I can specify don't show me anything that doesn't have provenence in it. And right now, this would be a completely blank page with no photos, videos, right? But down the line, as we get more and more into this technology, we should be able to um see more content and then decide whether or not I believe this or not based on the creator or an organization that published it.
That's my two cents. like mic drop kind of a moment. Um, so I know you guys, this is brings me almost to the end of my presentation. I know that you guys will get this presentation at the end.
So I put in a whole bunch of links to make sure that you can use those links um and browse around and learn more about the organization authenticity uh content authenticity.org is CI cta.org is obviously C2PA. CTPA has recently released um the newest version of their spec. I think it's like a week old if that and it's spec 2.3 if you wanted to dig through that. The verify content authenticity is your verification tool to doublech check content. Um the conformance explorer is a um live version like it's a list of all the live version of CTPA conforming products. There are currently two levels of conformance. Level one is for lack of a better word word almost like a self-certification and level two is actually certified by C2PA and they double check that when I claim that we do what we do. We actually do those things. Um and I'm very proud to say that ECDM is one of the two level two conforming products right now and the other one is Google. Um, if you wanted to get your hands dirty with this technology, go to the GitHub link and play around, you can actually download stuff and see stuff. Uh, and the COG is, uh, something I didn't even get into.
So, I think we can have a whole hour and just COG alone, but COG stands for creator assertions working group. And the main goal of the group is to basically allow content creators to link their digital identities to the content they produce so that they own the content and they ensure transparency for people not just organizations.
And on that note, thank you very very much. If you would like to get a hold of me, I can be reached at all corno easy.com. And I am here for questions.
>> Perfect. Thank you so so much. We've actually got quite a few to get through.
>> Okay, I will do my best.
>> Absolutely. Yeah, we've got another one from Felix. Are phone manufacturers aligned and moving towards adding the option for CTPA verification for content captured on an iPhone or a Google Pixel, for example?
>> Well, I can give you a perfect example of a phone that I currently own. Um it is my um Samsung because Samsung's a member and my Samsung Galaxy 25 phone that was released about a year ago um actually supports the full stack of C2PA for um any content that is generated by AI. So I obviously sadly never tested it. I keep talking about it, mentioning in different panels and every time I do this at a piano I'm like I should have tested this. Um I think the part of the issue is it goes back to COG is that I don't have a certificate to say this content is generated by Olga.
>> So that is a whole separate part of it.
But for anything that I use on this phone to generate using AI, I could sign it that this was AI generated from my phone and whatever other information they would like to append to it.
>> Wow, that's amazing. Is that a manual process to market as AI or does that is that automatically done via the phone?
>> So, as I test up, I haven't tried it yet.
>> Okay.
>> I should do this and I'm totally for not having done this, but I will um >> I will follow up on that. Um >> not at all. Um we've got a question from Polly. How important is C2PA and what difference is going to make to the live uh to the streaming landscape as it evolves rapidly?
>> Um in general streaming your life I guess for me it is a question of knowing and so so I can answer from two perspectives >> the consumer and the media industry. I think as a consumer I'll I'll start that one. I think it's important.
We all travel, right? We all, most of us have kids. We all travel with kids.
Imagine if you're somewhere anywhere in the world, and you wanted to, you know, let your kids watch some TV and you pull up a local app because your app only allows, you know, whatever. You can't view content because you're in a foreign country. Um, and you want to put up a Disney movie. You sure it's Disney? You sure it's not been modified? Are you sure there's not a couple of I don't know f bombs in there?
If the content is signed by Disney, you know that it's Disney and you're more comfortable to set it up for your kids.
Um, on the flip side of that, you know, we can look at something like betting. If I am in the world of betting and I see the scores that are posted, if that is signed, I know that, you know, based on my bet, I either won or lost. But there are organizations, potentially um malicious ones, that might try to fake scores just to not have to pay out. Uh if you have a signature, you know where it came from. Or if it's a signature by the by the bad betting company, uh and you know it's fake, you don't trust them again. Um but it's a conversation about that. And then in the world of sports, I mean knowing that this or movies, I think things like Trayors, things that are out there publicly, I do think it matters.
Um, but as and also to prove the fact that this is what the studio produced.
This is our version of the movie or a podcast, webcast, anything because this this technology can also be applied to audio. um cuz it just verifies the fact that it does come from you.
>> That actually really nicely leads onto another question from Andrew. Is C2PA only for video stills or is there a version of authentication for music audio as well?
>> Yes, there is a version for audio, there is a version for video and there is a version for live video and there's various different working groups within C2PA that are working on it. And this is my shameless plug. If you would like to contribute, please join C2PA. It's free.
And contribute to the group that is important to you.
>> Absolutely. Perfect. Um, somebody's anonymously asked, could it be tied to the blockchain to avoid the spoofing and have a validated chain of custody?
>> That is a conversation you need to have with C2PA and their technical standards team.
Um I mean there is part of it that is blockchainish in this technology. Anything past that I am not the person who wrote the technology. So if you would like to contribute to that I'm going to smile again and say join CTPA. Um but yes there is um there's a lot of effort around making sure the signature is secure that the provenence is secure and so on and so forth.
>> And a question from Felix. Is there a collaboration between CCPA and Verify Media by Fox Media around standards and integrations?
>> Honestly, I don't know. I have absolutely no idea. I do know that in the grand scheme of things, CTP is working with all the other um organizations within our industry like Dash and Salon.
>> Uh and there's a lot of conversation around that. That specific one, I apologize. I do not know.
>> Question from Mackie. How about text and ledgers?
>> What do you mean? Does it apply to text?
Uh, at the m I do not think so. Um, it is for media assets only that I am aware of.
>> Amazing. Thank you.
Do we have any more questions from anybody?
>> That is the final question in the queue at the moment. Although um uh Mackie uh just uh followed up with uh he meant those are covered currently in the C2PA.
So text and ledgers uh apparently are covered according to mechi.
Then I learned something. Thank you, Mackie, very much.
>> I knew just as as soon as I said no questions in the queue, something would pop up.
>> Of course.
>> Always does.
>> So there I think that I learned a lot. I learned an awful lot. Thank you, Olga.
>> You're welcome. Um, if we ever want to do a more in-depth technical one, then let us know. We would love to do that, too. I am a big big supporter of making sure that this technology is known and is out there and I dream of a day when I tell people we do CTPA and nobody goes oh my god what is that is that another acronym we acronym we need to learn so um yes if you if we would like to do a more in-depth version of this absolutely I'm in >> absolutely but I should tell you and I want the audience to know as well you were and I it wasn't that selected you to speak, but um uh Women in Streaming wanted you to be the first in the series.
>> Pressure.
>> No, no, no. They thought it was very important and I think I think that they made a wise choice. My opinion only. My opinion only.
>> Well, thank you very much. I appreciate that. Um I always get nervous before I do these things. Um, so but yeah, as you said it correctly before because I care because I do want this information out there and property. So thank you very much to Simpy for organizing this and to women for in streaming media. I love being part of that organization. I think it's very very important. In fact, this was not a women in streaming media thing, but I was at a technical talking event in um Madrid the other day and I made a presentation and then a woman came up to me and said, "Thank you for doing this. I feel more comfortable now and maybe sometime in the course of the year I will make one myself now that I've seen a woman do it." So if that my action here today contributes to somebody being more comfortable talking about it, then I've achieved my goal.
>> Yeah, absolutely. Yeah, I think that speaks volumes to, you know, why we're here to collaborate and and get these presentations and these webcasts together. So yeah, thank you so much, Olga.
>> You have you have little uh applause emojis going up through the screen there. Um I do want there one more comment in the Q&A. um Q and it's from Paulie.
Paulie says, "Thank you, Olga. Legend as always."
>> You are most welcome.
>> Any closing comments?
>> No, I think I think I did my little, you know, soapbox mic drop thing when I say that we just we need to make sure we educate people and people around us about this technology. Um, I think I was on a panel with Paulie when I made a comment that, you know, if I tell about this my mother, she's going to look at me and go, you don't know what you're talking about. But if I talk to Paulie's mother about that, she's going to believe me. So maybe educate not just your relatives, but everybody else around you. Um, and make sure that people know about this technology and know what it means so that when it's becoming more and more prevalent, um, people understand. And as media industry people and vendors and participants, maybe if we start po posting content with C2PA in it, um, and then doing a little sidebar thing that says, "What am I looking at? Here's an explanation for this little logo thing, then that would be useful, too." The reason I say that HubSpot is the bane of my existence is parts of our website are on HubSpot, and we've been trying to sign our content, and it just won't let us. it just keeps taking signatures out. So, we're debating if we need to reinvent the wheel temporarily or fight with HubSpot and try to get them to put this through.
But, it is a slowmoving train.
I'm hoping it gets there. Um, but in the meantime, if we start to educate people and we know what this is once this technology starts popping up, kind of like HTTPS on websites, then we will be in a much better position.
>> Perfect. Emily, do you have any closing comments?
>> Um, no, not really. No, I'd just like to say thank you both for all the time and energy and work that you've put in to to make this happen. Um, and yeah, thank you, Olga. and I'm really looking forward to the rest in the webcast series from other women in streaming media speakers.
>> Absolutely. Absolutely. And Emily, um I want to thank you for serving as moderator and look forward to uh um having you uh in that role when whenever you can. Um people probably don't know that as of the first of the year you started a new gig. I won't say too much about it, but uh thank you for being here and thank you to your employees for being here. Um, personally, personally, as much as I panicked at the beginning in trying to describe, um, the series, uh, I think this is an important webcast series for Simpy, uh, because it it truly highlights, uh, the the the women that are leading the way in, uh, streaming media technology and and, um, I hope that we can continue to do these beyond the five or six that we have. um planned. So, thank you to to you both. I'm going to just take a moment here and and close things out. As I said, >> I'm sorry. I'm gonna butt in for a second. Joel, >> thank you to you so much for all the work that you put into this and for hurting cats and everything else that you do. It is I can imagine it is not an easy job. So, thank you to you as well.
>> You know, um I like doing it. Um, I've been doing it for a little while and I do appreciate the thanks. Um, yeah, thank you so much. So, that is the first in this important uh webcast series. Uh, and I'd like to thank everybody uh for being here. Um, we will have one next month uh February. Don't don't hold me to this. I think it's February 11th, uh, which is a Wednesday.
And I hope your year goes well. And as I I always say, uh, you know, throughout the year, please cherish the moments you have, uh, with your, uh, family, your loved ones, and your friends. And please uh, create lifelong memories because uh, they are important. And with that, we shall call it a day. Thank you. Take care. See you next month. Bye.
[music]
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

we're almost finished the house (ep.125)
JennaPhipps
347K views•2026-07-22

We Finally Know Where Saturn’s Rings Came From
astrumspace
79K views•2026-07-22

BIG BET: Cathie Wood goes ALL IN on Elon Musk
FoxBusiness
89K views•2026-07-22

MIC DROP: Smithsonian Director Called Out For Woke Propaganda
TheAmalaEkpunobi
37K views•2026-07-23