“an attacker does not need the raw key material! As root, they can ask StrongBox to use these keys to sign whatever data they like”
C2PA sells the idea that a cryptographic signature proves a photo came out of a real camera. Buchanan roots a fully patched Pixel with a public one-click exploit and gets the phone’s own secure element to sign whatever he hands it. The hardware attacks are worse because existing devices cannot be patched against them. A verification scheme that produces confident green checkmarks on forged images is more dangerous than no scheme at all.