HeadlinesBriefing HeadlinesBriefing.com

How to Hack Time Using C2PA Metadata

Hacker News •
×

By David Buchanan (aka retr0id), 2nd October 2026

The most impressive hacking stunt from cinema history comes from Kung Fury (2015), in which Hackerman hacks time itself. But what would I do with the ability to hack time? Personally I'm more afraid of the butterfly effect, so I'd just go back a few hours to tell myself the winning lottery numbers. As it happens, that's exactly what I did, according to the cryptographically unforgeable C2PA metadata of this image.

A typical C2PA manifest contains two signatures. The first is the "claim" signature, and in the case of a camera app the claim might be something like "this is a captured photograph, taken at these GPS coordinates, at this time". There's also a second signature from a Time Stamp Authority (TSA), which asserts "yes, I saw this hash at this timestamp".

If the TSA mechanism is secure, how are we going to hack time? We're going to use the spec footgun: C2PA allows for arbitrary "exclusions" — byte ranges within the file which are excluded from signature calculations. A malicious signer can deliberately use a large exclusion range, excluding the entire file to produce a valid signature over an empty string. This allows the file to be tampered with after the fact, without invalidating the signature.

So I really did take a picture of a lottery ticket, and attach a valid C2PA signature with a valid trusted timestamp. But I crafted the manifest to exclude the whole file, allowing me to photoshop it after the numbers were announced, without invalidating any of the signatures.

Source: Hacker News · Summarized by HeadlinesBriefing