>a screen attack still works: photograph a screen displaying an AI image and you get a signed photo of a fake
you don't need to do that just photograph a screen.
This seems close to worthless in "identifying real photos vs AI" for someone actually wanting to do something bad with an AI image, although probably very useful at identifying which phone took a photo when ("the root of trust stays inside Apple's Private Cloud Compute") seen as it's not an entirely local solution a bad actor government could use their powers to completely abuse this.
its conflicting desiderata: a videographer doesn't want to constantly power a device to maintain provable continuity, but screen attacks necessitate such a scheme
a continuous stream of video from factory to customer to observation should prevent screen attacks, if there is a trustworthy framework for processing and checking the absence of screen slide-ins etc.
if geolocation data can be captured in the same signature, that would be a good enough approximation for most relevant cases I think.
GNSS signals can be relatively easily faked because the original signals are very weak so overpowering them doesn't require much broadcast power.
ah, damn.