The certificates for HTTPS certify that you're communicating with someone the CA verified has control over some domain name. They don't require the CA to exercise any control over the endpoint device or for the user to cede any.
If you want the camera sensor in your phone to certify that the user hasn't altered the image, the device can't be in the control of the user.