| But what about if: …the signature included the depth measured by the autofocus system across the image? …or a tiny stereo image was included to capture depth? …or a mini video in the ten seconds before and after the photo was taken? …and the key is in a tamper proof HSM? …and the key is deleted the moment the camera detects the case being taken apart? I know that it is a losing battle to try to build such hardware when offline attackers have essentially infinite time to dismantle even the most elaborate systems — no such thing as an un breakable safe, only how long it takes to break into it, etc — but I feel these are valid counter measures, are they not? |
I would add a few more measures:
* Keys are regenerated for each device in the charging dock and are only valid until next recharge or a timeout.
* There is a sign-out process for the cameras that ties them to the operator.
* Police officers have no control over when the camera is recording, the camera instead controls this.
* Lower resolution data is streamed and synced to a cloud in real time, along with interesting data such as GPS, local BT/WiFi devices, etc.
As for privacy, British police are using more and more evasive camera technology out in public spaces, it's about time they were forced to wear it themselves. I want even the pencil pushers in the offices to be forced to wear it.