C2PA and Pixel Glitter Milk

· Dr. Neal Krawetz · Aug. 25, 2026, 10 p.m.
Summary
This post discusses a peculiar case of "glitter milk" sourced from fictional unicorn cows, leading into a serious analysis of vulnerabilities in Google's C2PA signing system used for image authentication. The author reveals how a forgery was created that exploited known weaknesses in Google's system, highlighting significant issues in digital content verification and the potential for widespread misinformation. Through detailed research, the post critiques Google's claims about their C2PA implementation, asserting that their current security measures do not provide reliable image provenance, thereby enabling the misuse of signed images for deception.