The Internet Copies Perfectly and Remembers Nothing
By: SASHA
We have built an internet that can copy anything perfectly and remember almost nothing about it. A photograph can be duplicated a million times without losing a pixel, yet each copy arrives with nothing attached: no record of who made it, who owns it, or whether anyone agreed to it being there. We treat that as the natural order of things. It is worth asking why we accept it.
For a marketplace, the cost of that amnesia is not abstract. The image is where your users make their decisions and where your team makes its riskiest calls: what to list, what to remove, who to believe when a dispute hardens into a claim. Almost all of that visual evidence shows up with no verifiable history at all. So the platform does the only thing it can. It guesses, then hopes the guess is defensible later.
We keep solving provenance backwards
When we try to fix this, we reach for the source. Trust the verified account, the known seller, the sender. That holds until the account is compromised, resold, or simply lying, and it tells you nothing about the content itself. The other reflex is to pin a label to the outside of the file, a credit or a metadata field. That lasts right up to the first crop, screenshot or re-save, which is to say it vanishes at the precise moment the content leaves your control.
Picture the everyday version. One stolen product photo reappears across a dozen scam listings. You can see that the images match. What you cannot show is which upload came first, who actually holds the rights, or whether the person in the frame ever consented to appear at all. The duplication is obvious. The truth underneath it is gone.
Reactive moderation is the same bet in different clothes. Let everything in, wait for a report, investigate after the fact. It is trust first and verify after the harm, and it scales worst exactly when you need it most. The question worth sitting with is a different one. What if the object had to speak for itself, carrying a history that no crop or repost could quietly strip away?
What would actually have to be true
Take that question seriously and the bar turns out to be high. A durable approach has to satisfy three things at once, and most attempts manage one or two.
It has to survive transformation. Provenance that breaks when an image is resized or screenshotted is decoration, not evidence. The record has to live inside the content rather than beside it, and stay readable after the compression and re-posting that real distribution guarantees.
It has to carry permission, not just origin. Knowing where an image came from is the easy half. The harder and more useful half is whether it was allowed to be used this way, in this place, by this account. Consent and context are what let you act, rather than merely attribute.
It has to protect privacy while doing both. This is the part almost everyone underestimates, and it is where the real difficulty lives.
The tension nobody wants to name
A system that records who made every image, who touched it and where it traveled is, seen from a slightly different angle, a surveillance layer. Solve provenance carelessly and you build the most complete tracking infrastructure the visual internet has ever had, then hand it to whoever happens to control the ledger. That is not a reason to avoid the problem. It is the reason to treat the design as seriously as the threat.
So the genuinely interesting question of this decade is not whether we can prove where an image came from. We can. It is whether we can prove origin and consent without compiling a dossier on the people in the frame. Provenance and privacy have to be solved together, or neither one holds. A provenance system that leaks identity will be rejected by the very creators it claims to protect, and it should be.
Why this stops being theoretical
Two forces are pressing on the same point at once. Synthetic and manipulated images have moved from novelty into the everyday fraud stack, so "it looks real" is no longer a standard anyone can lean on. Meanwhile the rules are catching up, from the TAKE IT DOWN Act to the EU's Digital Services Act, the disclosure expectations under the EU AI Act, and the UK Online Safety Act. Each one, in its own language, asks platforms to know what they are hosting and to show their work. Amnesia is quietly turning into a liability.
Where this leaves the rest of us
This is the bet we are making at SASHA. We build a patented, invisible signature that lives in the pixels themselves, survives cropping, screenshotting and heavy compression, carries permission and context rather than personal data, and can be read back in milliseconds. SASHA doesn’t store or scan the content of an image when decoding the signatures, which is our answer to the privacy question above rather than a footnote to it. It already runs at scale with institutions whose entire business is the integrity of an image, including the 160-year-old news agency Ritzau and Aller, the leading publisher of magazines and weeklies in Denmark and the Nordics. SASHA sits inside the coalitions writing the standards for this space, from C2PA to the Content Authenticity Initiative.
The tool is the method, but the shift is the future. For thirty years we have asked people to judge an image by trusting its source. The next decade will belong to the platforms that let the image speak for itself, and that manage to do it without spying on the people it depicts. That is a harder problem than a bigger moderation queue. It is also the only version worth solving.
Every image deserves a voice, and its own digital DNA.
For more check out: https://www.sasha.eu/





Comments