Signing the raw image data wouldn't require also signing the EXIF metadata. For privacy, you could later strip out everything except the raw image and the camera's signature and still prove that the image is unaltered.

What are you signing it with, though? A unique key that only exists on your device... so it will perfectly tie a photo to a specific camera.

Even if you didn't know who owned the camera, you could identify other pictures taken by that same camera, and information in those photos might let you figure out who owns the camera.

I think he's saying the existence of a camera signature is the privacy issue maybe.

You can remove it all.

If authenticity later becomes an issue you can produce the original.

What if the camera doesn't give you an original but just a signed image?