You've seen the little "cr" badge start showing up on images. Do you know what it actually proves — and what it doesn't? It's not a vibe check. It's a COSE-signed certificate chain sitting inside a JUMBF box in a JPEG's APP11 segment (or a PNG caBX chunk). The signature proves two things and only two: which tool or camera signed the manifest, and that the pixel data hasn't changed since. That's the entire guarantee. The digitalSourceType field inside that manifest is what tells LinkedIn's badge to say "AI-generated" instead of "camera capture" — trainedAlgorithmicMedia vs digitalCapture. LinkedIn reads it. X is rolling out the same read. Where it stops: no manifest, no proof either way. The chain says nothing about who the human behind the tool is, and most images in circulation still carry no manifest at all — that's normal, not suspicious. snapWONDERS validates the full chain on every upload — signature, hash binding, source type — and feeds it into the authenticity score. Full breakdown: https://kennethbspringer.au/2026/07/09/think-twice-before-claiming-ai-work-as-your-own-what-c2pa-content-credentials-prove/?utm_source=mastodon&utm_medium=social&utm_campaign=article-10 #OSINT #digitalforensics #infosec #C2PA #contentauthenticity