Live data from Hacker News

MS Paint and Photos inivisibly watermark even locally generated output with GUID

xusheng.dev

51–60 of 467 posts

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#51

I think it would be nice if all cameras digitally signed pictures. You could prove the photo was real.

If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitabl…

I've done this btw. I went for the Pixel Camera app since they were the ones bragging the hardest about their "security". Writeup + PoC should be dropping some time tomorrow. Despite 90+ days from initial report, it remains unpatched.

Some proof: https://verify.contentauthenticity.org/?source=https://retr0...

I could also paste a privkey + cert chain in here but el goog's lawyers might not like that.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#52
post #19

Earlier quoted context omitted.

What would prevent someone from applying the same algorithm on a computer to sign arbitrary images?

Presumably the OP is proposing something like a TPM attached to the image sensor that signs the sensor output or something like that. You can’t sign it because you can’t get the key out. The key could be per-camera and be a published list. I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.

Please note: A well-funded organization, like a government, can derive the keys from the TPM hardware using an electron microscope.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#53
post #30
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

> address Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information. Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.

This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#55

Earlier quoted context omitted.

The hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”

I was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me. But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text a…

Signing doesn't really achieve anything when an attacker can manipulate the device into signing arbitrary pixels.

Nobody knows how to make a camera that can distinguish honest vs deceptive photons.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#56
post #43

Earlier quoted context omitted.

Imagine today where a photo is submitted as evidence and the court believes it even without signatures.

Precisely. Now take that, but glue a "the machine has cryptographically proven that this is legit" to that.

Yes, it's a disaster waiting to happen.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#58
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#59
post #53
post #30

Earlier quoted context omitted.

> address Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information. Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.

This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.

> This is broadly impractical for the average citizen.

No it's not. Sign up for a virtual mailbox for $15-$25/month.

> A scalable solution would be to make this sort of thing illegal.

I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.

It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#60
post #58
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

> This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."

Post reply on HN