Qué cambió, y cuándo
Every change to the detector or the wording, with the reason. Mistakes are listed too, because a record that only contains improvements is not a record.
- The verdict is now the card's headline instead of a small pill beside the file name, set at the same weight as the file size. A reader had to work out what the card had decided, on the one question they arrived with. The answer, the strength bar and one sentence about this particular file now sit at the top; the paragraph that is the same for every file with that verdict is folded away.
- Still no percentage, and here is the arithmetic behind that. A reader asked for one like the rival tools print. The published benchmark for open-source detectors puts the best of them at 35 to 42 percent on the newest commercial generators — Flux 21, Firefly 18, Midjourney v7 24 — and a model small enough to run inside a browser at 51 to 68 percent before any real-world compression. A number from that would be wrong often and confidently. The rival tool in question, asked about a photograph of a real person that had been retouched, answered "97% FAKE".
- Removed Clarity and Google Analytics from the page that holds the file picker. A security review pointed out that any script on that page can read the selected file. Neither of them does, but that is a promise about somebody else's code, and the central claim of this site should not rest on one. With nothing third-party on the page, the claim is a property of the page and anybody can check it in a network tab. Every other page keeps its analytics; visit counts are unaffected, since Cloudflare counts requests without a script.
- That change surfaced an older mistake: every article was being served with the home page's body class, because articles pass no route and the check was for an empty one. They had been picking up column widths meant for the analyser.
- Fixed the strength scale showing its label and explanation in English inside the Russian card. The lookup used the wrong helper: everything the detector writes is translated under an "m." prefix, the bare key found nothing, and the English fallback quietly took over. A fallback that hides the failure it exists to cover is worse than having none. There is now a check that renders a Russian card and fails on any sentence in it that contains no Cyrillic.
- Rebuilt the verdict legend. The badge sat in a fixed column beside its explanation, where half the labels did not fit and wrapped onto two lines; since they run from two words to eight and differ again in every language, no column width was ever going to be right. The badge now sits on its own line above what it means. The same page now also explains the strength scale, which it had not mentioned at all.
- And a mistake worth recording, because this log would be dishonest without it: while making that change a comment in the stylesheet was closed one line too early. The sentence after it became stray text, the browser stopped reading there, and every rule below was discarded. The site was live with no styling at all until it was spotted by looking at the deployed page. Nothing in the test suite checked that the stylesheet was CSS, only that certain strings appeared in it, so everything passed. The audit now asks the parser directly.
- Added a strength scale to every result: five rungs, from "settled by mathematics" down to "nothing left in this file to read". It is not a confidence percentage and it never will be. There is no dataset here that could say what share of files like yours are generated, so a number in that place would be a decoration. What the rungs measure is how conclusive the evidence is, which is a different question with a real answer, and each rung is named in words so you can argue with it.
- Note that the scale does not run from "real" to "AI". A photograph carrying camera data sits below a file with a suspicious structure, not because it is more genuine but because forgeable evidence settles less than a pattern does. The verdict says which way the answer points; the scale says how much weight it can hold.
- Put the one rule worth knowing before the upload rather than after it: bring the original file, not a screenshot. A screenshot is a fresh photograph of a screen and carries nothing about the picture on it, so the answer is always "cannot tell" — which people were reading as "nothing suspicious found", the opposite of what it means. There is now a list on the how-it-works page of what to bring and what can never answer.
- The audit had been running every page-level test with cryptography switched off, because the test browser ships no WebCrypto and nobody had noticed. A signed file came back "cannot tell" in those tests and passed. The real API is lent to them now, and there is an assertion that a signed file reaches the top rung in the page and not only in the engine.
- The SynthID worker, which is not wired up yet, got a switch that stops it spending money without a redeploy, and its daily ceiling was lowered from 2000 to 300. Its documentation used to say the counters let "a few extra requests" through under a burst. That was wrong: the storage has no atomic increment, so the overshoot is bounded by how fast somebody can send requests, not by the number in the code. Better to know that now than from a bill.
- An audit of the new trust list check found a hole in the old one, and it was the worse of the two. Certificate chains were verified link by link but nothing asked whether a link was allowed to be a link. The listed authorities sell ordinary signing certificates to anybody; holding one, you could have used it to issue a certificate calling itself Reuters and this tool would have shown a valid signature from Reuters. OpenSSL refuses that chain outright. Now so do we: an issuer must declare itself a certificate authority, path length limits are enforced, and the signer must not be one.
- A file whose certificate chain does not hold up used to still read "Origin verified" and print the forged name. It now reads as tampered, and the name is withheld, because repeating it is doing the forger's work.
- The trust list check looked only at the top of the chain. Several listed authorities are intermediates whose own parents are not listed, Adobe's among them, so a real Adobe file shipping its full chain would have been reported as coming from an unknown authority. Every position is checked now.
- "Vouched for by a recognised authority" could appear beneath "Origin record fails" on a transplanted manifest, arguing against the verdict above it. The certificate really is genuine in that case; it just belongs to a different photograph.
- Smaller ones from the same audit: a certificate presented for a purpose its issuer excluded is refused; an expired certificate no longer reads as vouched for; unreadable certificates abort instead of silently renumbering the chain; and the trust list matcher now verifies the links itself rather than trusting its caller to have done it.
- Added the trust list check. A signed file's certificate chain is now matched against the C2PA Conformance Program's published list of authorities, in your browser, alongside everything else. Until today the honest answer was "valid signature from an unknown signer", which is true and useless. It is matched by verifying a signature against the authority's key, never by comparing names, because a name is the one part of a certificate anybody can type.
- That check found a bug in the existing code. The certificate's signature algorithm names the hash, not the curve, and we had been inferring one from the other. One of the twenty-two authorities on the list uses a P-521 key, so every chain under it would have been read as unverifiable. The curve now comes from the key itself.
- Rewrote what the pages say about certificates. The limits page said "we show you the manifest; the official verifier checks the signing chain", and two articles said the same. That is no longer true, and a limit you have quietly stopped having still misleads people while it sits there.
- A placeholder in one new sentence never got its value, so "any of the 22 authorities" rendered as "any of the authorities". It read like ordinary prose and no test noticed. There is now a test that renders every finding and fails on any placeholder left standing.
- New mark and social cards. The old one was a tick in a rounded square, which is the badge every generated interface wears and which claims something has been approved. It is now four registration brackets around a point.
- Took the machine-made look off the writing and the page: 192 em dashes out of the English text, the indigo-violet accent, the centred symmetry, and a hand-drawn arrow pointing at the one large box on the screen.
- Wrote up the SynthID screenshot test as a guide, because the crop instruction is not documented anywhere and the uncropped answer is confidently wrong.
- Fixed a screenshot check that called any 1920x1080 PNG export a screenshot, and that could print 'this is a screenshot' underneath a verified cryptographic signature.
- Tested whether a SynthID watermark survives a screenshot rather than repeating what the documentation implies. It does, but only when the picture is cropped away from its surroundings first.
- Stopped the result card hedging four separate times about one finding while an item above it was badged as a strong sign.
- Recognised screenshots taken on macOS. They carry an XMP packet, so the old check, which required a file with no metadata at all, missed the most common screenshot there is.
- Removed advertising claims from the privacy policy and the FAQ. The site carries no advertising and the pages said otherwise.
- Calibrated the structural signals down hard after a reader reported real photographs coming back as probably AI. A false positive on a real photograph is worse than no answer.
- Cryptographic C2PA verification in the browser, including the binding between the signature and these exact bytes, which is the part a transplanted manifest is designed to defeat.
- Published the source under AGPL so the claim that nothing is uploaded can be checked instead of believed.
Written in English only. The entries describe specific edits, and translating them by machine into four languages would be worse than this note.