Part I looked at a camera that does everything itself. Apple Reference Image signs a photo inside the sensor, develops it on Apple’s servers, keeps its own list of revoked sensors, and checks that list on Apple’s own devices. Every step that decides whether a photo counts happens inside one company. That made it a clean place to ask the question this series is about. When a system makes a decision people have to live with, how would anyone question it? Apple’s published account explains how its credential is granted and how it is withdrawn. It does not explain how a withdrawal could be challenged.
Most photographs will never live inside one company like that. They move through a system where the camera maker, the company that issues the digital certificate, the people who write the checking software, the platform that shows the result, and the newsroom or court that acts on it are all different organizations. Each makes its own decision. Whether a particular photograph gets believed comes out of all of those decisions together.
This piece is about that arrangement. Who decides what, what the published documents say those parties owe each other, and where the decision finally turns into something that happens to a photographer. Part I stated the hypothesis this series is testing, that a system which makes decisions people have to live with, and never says how those decisions can be questioned, uses up their willingness to go along with it. Part II does not test that hypothesis. Its job is to map who is making the decisions, because the question of accountability can’t be asked properly until that map exists.
The pug in the jet
In August 2025 Nikon added Content Credentials to the Z6 III through firmware 2.00. Content Credentials are the consumer-facing name for C2PA, the industry standard for attaching a signed record of where an image came from. When a Z6 III took a picture with the feature on, the camera signed it with a secret key and attached a certificate, a kind of digital ID issued by a certificate authority, that tells anyone checking the file whose key made the signature. Anyone checking the file later could confirm it came off that camera and had not been changed since.
Within weeks, a forum researcher who posts as Horshack found a way around it. As DPReview reported, he used the camera’s multiple exposure feature to feed it an image that did not come from its sensor, and the camera signed the result as a genuine capture. His demonstration image was an AI-generated picture of a pug flying a jet. It carried a valid Nikon credential.
Nikon suspended the service. It also announced that the certificates loaded onto cameras between the launch and the suspension “will be invalidated,” which meant every credential issued in that window, including those on photographs taken honestly by photographers who had done nothing wrong. As Digital Camera World put it, those images could no longer serve as proof of where they came from.
That was a reasonable response to a real forgery. It also depended on something Nikon did not control.
Invalidating a certificate only works if the software checking a photo goes and asks whether the certificate is still good. The tools most people used to check C2PA credentials at the time did not ask by default. PetaPixel found that the invalidated credentials kept passing in those tools, and only failed when someone changed a setting to force the check. Horshack filed a request asking the maintainers of c2patool, the standard’s command-line checker, to make revocation checking the default. Nikon had no way to make anyone else’s software listen.
So three different parties made three different decisions. Nikon decided to invalidate. The people who built the checking tools had already decided, some time earlier, not to check for invalidation unless asked. And whoever received one of those photos, whether a person, a newsroom, or a platform working behind the scenes, got whatever answer their checker gave, usually without knowing that the choice of checker mattered.
The result was more than one outcome. An honest photographer’s credential was now dead in one checker and valid in another, and the photographer had no way to know which checker any given editor, client, or court was running. The photographer could check their own credential and get an answer. What they could not know was which answer any particular recipient would get.
Why it is still true, for two different reasons
That was September 2025. Most of it still holds a year later, for two separate reasons that are easy to blur together.
The first reason is a design choice in the standard itself. A credential can carry proof, captured when it was signed, that its certificate was good at that moment. C2PA’s security guidance says a credential can be “validated indefinitely” even if its certificate is later revoked or expires. That is deliberate, and mostly sensible. An honest photograph taken this year should not stop counting in five years because a certificate was retired for some unrelated reason.
The main open-source library for reading C2PA credentials is c2pa-rs, maintained under the Content Authenticity Initiative, and c2patool is built on it. In its current settings, the option to go online and ask whether a certificate has been revoked since is off unless someone turns it on. With it off, the checker relies on the status information the credential carried when it was signed.
Nikon’s case is where that design and the maker’s intent collide. Nikon was not retiring certificates for a routine reason. Its camera had been shown to sign images it should not have signed, so Nikon wanted every credential from that window to stop counting as proof, going backward. A checker that judges a credential by its status at signing time sees those credentials as good, because at signing time they were. The same design that protects an honest photo from a later, unrelated revocation is the one that let the compromised window keep passing.
Leaving the online check off also has a real argument for it. The C2PA specification makes the check optional, and asking a certificate authority about a certificate tells that authority which certificate you are holding. When a camera uses a fresh certificate for every photo, as Google’s Pixel does, that means telling it which photo you are looking at. The library’s settings file does not say why its maintainers chose the default, but the tradeoff has a sound argument on both sides.
The second reason is a bug, and it runs in the opposite direction. With online checking turned on, c2pa-rs can report a good certificate as revoked. In one reproduction filed against the library, a photo signed by a consumer app was checked at a moment when the certificate authority’s clock ran about two seconds ahead of the checker’s. The library reported the certificate as revoked and treated the signer as untrusted. The same response, checked again two minutes later, came back clean. A second report describes the same problem with older “good” responses. As of this writing, a fix is under review and may well be merged by the time you read this.
Those are two different failures from two different configurations. With online checking off, a credential its maker has tried to withdraw retroactively keeps passing. With it on, a good credential can, under specific timing conditions, be reported as revoked. Put side by side, they mean a photographer still cannot count on the same answer from every checker.
Taken alone, none of this is a legitimacy problem. It is software disagreeing with other software, which happens in every distributed system while its implementations mature. What turns a technical disagreement into a question about authority is what happens when the answer reaches someone who has to act on it.



