@cks @glyph @Techmeme @gvwilson
I think it's simpler than that - the signature just means “this image was signed by this camera” or “this photo-editor binary” or “this publication’s CMS”. The signatures can chain obviously. A publication knows its staff’s (camera/editor) keys (and can check free-lancers’) and it publishes its own pubkeys for anyone to check.
Where does OSS get excluded?
I really don’t think there’s anything wrong with this picture.