upvote
You'd need to jailbreak the camera sensor chip and the phone's secure element. Which isn't exactly impossible either, but it's harder. I don't think it has been done yet (but I'm sure it will be at some point).
reply
On top of that, they have a revocation system in place to try and deal with that eventuality.
reply
It all depends on when or if Apple actually activates this system. Unless Apple can prove when a compromise first took place, they would have to retro-actively classify all iPhone pictures taken before discovery of such an exploit as "potentially fake".

Plenty of certification bodies refuse to revoke their given certifications because of brand damage or effects on their customers. That's why cryptographic verification of things like Secure Boot are basically broken on most systems by default.

If an independent security researcher does it and Apple rolls out fixes a month later, I can see it happening. If it turns out a government agency hacked the platform "at some point", I have my doubts Apple will retroactively reject all of their iPhones' signatures.

reply
deleted
reply
It seems like the two signatures on device are processed on the camera sensor itself, and then post processing is signed by the SEP. Neither of these would be compromised even if you have a full jailbreak.
reply