Skip to navigation Skip to main content Skip to footer

Privacy and security challenges of content provenance and authenticity systems

03 August 2026

NCC Group have recently hosted two PHD researchers from the Cybersecurity Centre for Doctoral Training hosted at Universities of Bristol and Bath.  These collaborative research placements enable the students to engage with industry on short research projects aligned with their areas of research interest.

In this write up, Demi McCollum talks about her research looking into privacy and security challenges of content provenance and authenticity systems by analysing two recent papers looking at the content credentials standard developed by the Coalition for Content Provenance and Authenticity (C2PA).  This kind of research is vital in ensuring that emerging technologies and supporting ecosystems are developed to be as robust and transparent as possible so that the risk of security or privacy impacts, especially on those at increased risk, are minimised.

This placement focused on the Coalition for Content Provenance and Authenticity (C2PA) which is the emerging standard for digital content verification. Specifically, I focused on  where its promise of trustworthy provenance breaks down for people who need it most,  such as journalists working in active conflict zones. I started with WITNESS’ report on  C2PA’s surveillance risks [1], then progressed into wider literature; an independent  security analysis from the University of Maryland [2], the specifications themselves, and  the primary author of the WITNESS report Jacobo Castellanos’ own academic paper which develops the report’s findings in more technical depth [3]. This was followed by a direct conversation with Castellanos to discuss his findings and insights.

The primary output of my placement was a structural mapping of these two core research  domains. Castellanos’ paper analyses C2PA through a human-rights and privacy lens,  examining surveillance risks for journalists, activists and displaced populations arising  from issues like identity-binding and behavioural tracking. Conversely, the University of  Maryland Baltimore County (UMBC) paper provides a formal security analysis, testing  whether C2PA’s cryptographic guarantees hold up in practice. By analysing these papers  simultaneously, I mapped specific security failures identified by UMBC, such as weak  certificate revocation, metadata fingerprinting, and verification beaconing to show  exactly where a technical security gap quietly breaks, complicates or supports a privacy  mitigation proposed by Castellanos.

The value of this mapping is illustrated by three distinct types of interaction I identified  between the papers:

  • Convergence: In one case, both papers independently arrived at the same risk through entirely different methods. Castellanos identifies certificate specificity as a mechanism through which capture tools can be fingerprinted back to unique users. The UMBC paper empirically validates this; they showed that even a modern privacy fix, such as generating a unique certificate per photo, still leaves manifests carrying enough consistent metadata (like editing tool versions and action sequences) to link separate images back to the same device.
  • Empirical Validation: In another example, UMBC supplied empirical evidence for a risk Castellanos had stated only as a plausible pathway. UMBC revealed that public, web-based ‘upload-to-verify’ services receive the full media file, all provenance metadata, the user’s IP address, and the precise timing of verification. Moreover, they demonstrated that even client-side verification sends background requests pinging a server at one-minute intervals during an active session; exposing exactly when and for how long an investigator is evaluating content. 
  • Friction: In a third case, the technical findings actively complicate Castellanos’ argument rather than reinforce it. Castellanos’ and WITNESS treat C2PA’s longterm provenance chains as a longitudinal profiling risk that compounds over time. Conversely, UMBC’s evidence showed that signed content can quietly stop validating within a year due to temporal fragility, even when the underlying file remains unchanged. This technical decay suggests it undercuts how far back a reliable, automated profile could actually be built.

Ultimately, these intersections demonstrate that security and privacy in the C2PA ecosystem are deeply interdependent, at times validating and at other times disrupting one another’s assumptions.

My PhD in Cyber Security at the University of Bristol looks at privacy engineering for forcibly displaced populations using financial inclusion systems – such as mobile money, humanitarian cash transfer, and digital ID – where data disclosure is often structurally coerced rather than freely chosen, and where privacy harms propagate across whole communities rather than staying with one individual. Most existing privacy engineering is built around an individual, autonomous user model; my research is instead attemptingto build the threat modelling frameworks needed to conceptualise harm at a relational and aggregate level, under conditions of constraint. C2PA is not my core case study, but it has been a genuinely useful adjacent domain. The same structural problems occur here; an aggregation risk that individual-level assessment miss, a governance mechanism whose remedies do not hold once you check the technical layer beneath them, and at-risk populations exposed not by malicious intent but by how a system operates by design. Ultimately, this placement sharpened my understanding of structural harm more broadly, highlighting why we must analyse complex systems through a unified security and privacy lens.

Works Cited

[1] J. Castellanos, “C2PA Content Credentials and the Surveillance Risk: Adversarial Scenarios and Governance Gaps in the Content Provenance Ecosystem,” WITNESS, 2026.
[2] E. Golaszewski, N. Krawetz, A. Sherman, E. Zieglar, S. K. Matukumalli, R. Yus, C. Kegley, M. Barthel, W. Bowman, B. Barot and K. Kullman, “Verifying Provenance of Digital Media: Security Analysis of C2PA and its Implementation,” Cryptology ePrint, 2026. 
[3] J. C. Rivadeneira, “C2PA Content Credentials and the Surveillance Risk: Adversarial and Governance Gaps in the Content Provenance Ecosystem,” SSRN, no. 1, 2026.