2026.09.17
How photo metadata works. How it could.
Open any photo you've taken and read the metadata. Make. Model. Lens, down to the serial number. Firmware revision. Focal length, aperture, shutter, ISO, flash state, colourspace, GPS if enabled. Forty-odd fields describing the machine.
The field for who took it is called Artist, tag 0x013B. It entered the TIFF specification in 1988, which is basically older than the internet. Your camera has never written a byte to it, probably.
Your phone unlocked with your face seconds before the shutter fired. It is signed in to your mail, your bank, your photo library. Open its camera settings and look for the option to put your name in your own photographs. iOS doesn't have one. Android doesn't have one. A DSLR buries an owner-name field three menus deep, blank from the factory.
And once the shutter fires, the omission is permanent. There is no deeper copy to dig out. Not with motivation, not with a warrant. A court can compel almost anything except a byte that was never written.
Every field describes the instrument.
None describe the human.
Since 2023 you can buy a camera that cryptographically signs every frame at capture: Leica's M-series with Content Credentials, built on the C2PA standard. Worth being precise about what the signature says.
So the signed file proves which machine. The name is sealed but never certified, the time is whatever the operator chose, and the whole thing is validated by a consortium membership list.
One more fact for scale: United States law already makes it actionable to strip or falsify attribution metadata: 17 U.S.C. §1202, "copyright management information," which courts have held includes an EXIF field. The legal machinery for bylines has existed since 1998. It has nothing to enforce, because the field is empty.
Write the field. At capture, by default. The contents are the photographer's choice: a handle, a legal name, or blank. But the field is written, the way the date is written. A claim of authorship is falsifiable and legally meaningful the moment it exists; it does not need to be unforgeable to be useful, any more than a signature on a painting does.
Sign as the person, not the camera. The key that signs belongs to the human and lives in hardware they hold; the camera's own identity rides along as a witness, one field among the forty. Legal name, location, anything beyond the byline: all of it rides as salted hashes, fixed at the moment of capture, readable by no one. Picture what that buys. Three years on, Jake Jenkins can prove this photo is his without telling a soul where he stood. The day a dispute turns real, he reveals the location to a court. That one field, nothing else. It verifies against the file forever, because it was in there the whole time. Today's standards give each field two states, published or destroyed. Sealed is the state Jake needs, and it's the one nobody ships.
Bound the time from both sides. A clock the operator sets can't testify. Two things that can:
Both bounds rest on one fact: anyone who could predict the next block would take the mining reward, not fake a photograph. Created after the one, sealed before the other. The claimed capture time either falls inside that window or the file impeaches itself. A verified claim then reads: this name, on these bytes, inside this hour. No consortium, no vendor account, no camera clock asked to be honest.
None of this proves the pixels are real. Point any signed camera at a screen displaying a rendered image and every check above passes, correctly, because every claim above is true. What it proves is narrower: a specific person put their name on specific bytes inside a specific window of time. That is what authorship has ever been.
Fields describing the machine: forty-odd.
Fields describing you: one, since 1988.
Bytes your camera has written to it: