idjey/AntiAi: Overlaying Cryptographic Trust on the Deepfake Web
How a NestJS backend and a client-side browser extension bypass platform gatekeepers to mathematically prove video authenticity.
- AntiAi bypasses platform gatekeepers by using a browser extension as the ultimate arbiter of video authenticity.
- The system achieves Web3-grade cryptographic verification using standard Web2 infrastructure, avoiding the high costs and poor UX of blockchains.
- A centralized transparency log in PostgreSQL maintains an auditable trail of Ed25519 signatures, allowing for instant revocation if a creator's keys are compromised.
Bypassing the Platform Gatekeepers
The internet has a deepfake problem, and the platforms hosting the content are moving too slowly to fix it. Instead of waiting for YouTube or X to build native cryptographic verification, idjey/AntiAi takes a radically pragmatic approach. It effectively hijacks the user interface using a browser extension to deliver cryptographic proof directly to the viewer. This extension-first architecture means the system doesn't need permission from corporate gatekeepers to establish trust.
By overlaying a mathematically verifiable network on top of existing platforms, creators can definitively prove authorship. The extension handles the heavy lifting of verifying signatures client-side, ensuring that the video you are watching was actually uploaded by the claimed creator and hasn't been tampered with or generated by unauthorized AI.
The Mathematics of Authorship
The core of AntiAi is a robust NestJS backend monorepo that handles the complex lifecycle of a cryptographic proof. When a creator publishes a video, the system uses the YouTube Data API to paginate and sync their ecosystem. The apps/api service then uses the @noble/ed25519 library to sign the video metadata, producing a high-security Edwards-curve signature.
Security is paramount in the signing process. The system implements a strict 8-digit OTP protocol with exponential backoff to protect the creator's dashboard, ensuring that only authorized users can trigger the issueProof function.
async function issueProof(videoId: string, creatorId: string) {
const video = await this.videosService.getVideoWithChannel(videoId, creatorId);
if (!video) throw new UnauthorizedException();
const privateKey = await this.keyManagement.getActiveKey(creatorId);
const payload = this.buildMetadataPayload(video);
const signature = await ed25519.sign(payload, privateKey);
return this.transparencyLog.create({
data: {
videoId,
creatorId,
payloadB64: Buffer.from(payload).toString('base64'),
signatureB64: Buffer.from(signature).toString('base64'),
status: 'active'
}
});
}
Pragmatism Over Blockchain
The obvious question for any modern authenticity project is: why isn't this a smart contract? AntiAi deliberately avoids the blockchain, opting instead for a "Web2.5" approach. By storing base64 signatures in a standard PostgreSQL database, it eliminates gas fees, wallet friction, and slow transaction times, while still maintaining the mathematical integrity of the Ed25519 signatures.
| Feature | AntiAi (Web2.5) | On-Chain (Web3) | Platform Native (Web2) |
|---|---|---|---|
| Cryptographic Proof | Yes | Yes | No |
| Platform Dependency | None | None | Total |
| User Transaction Cost | Zero | Gas Fees | Zero |
| Revocation Speed | Instant | Slow | Instant |
The Transparency Log
While the database is centralized, it operates as a public transparency log. Every issued proof is recorded, creating a forensic audit trail. The public verification API allows the browser extension to check not just the mathematical validity of a signature, but its current business status.
If a creator's keys are compromised, or their subscription expires, the backend can instantly mark the proof as revoked. This ensures that business logic and key rotation can sit cleanly on top of the immutable cryptographic layer, providing a practical, real-world solution to the deepfake crisis.