I think that’s exactly how it’s going to work - you can’t force all ‘fake’ sources to have signatures- it’s too easy to make one without one for malicious reasons. Instead you have to create trusted sources of real images. Much easier and more secure
What are they starting to do that is shady and why do you think don’t respect privacy? (I couldn’t see anything on the document you mentioned)