Live data from Hacker News

MS Paint and Photos inivisibly watermark even locally generated output with GUID

xusheng.dev

281–290 of 467 posts

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#281

Earlier quoted context omitted.

did you even read the article? you're wrong on all points.

Frankly, I only skimmed it. Now I see that "On Copilot+ PCs, image generation is local but prompt moderation remains remote". I don't have a Copilot PC, but if you still need to pay MS to run the model on your own hardware it's laughable.

No, you don’t need to pay for using on-device models.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#282
post #134

Earlier quoted context omitted.

Ms paint slop being hung in a museum? Now that's a dystopian future!

No, I wasn't suggesting that. I was saying that if there was digital art (human made) aesthetically significant that a curator would want to display it in a museum, Microsoft's GUID supplied to a data collection agency would make it possible to retrieve if ever/whenever that data were declassified (assuming it isn't purged) It's possible a very bad curator with a terrible taste in art might select slop to display, bu…

According to It's FOSS,

:It's FOSS

3h •

Microsoft quietly embeds a hidden tracking identifier in every AI-generated image you create using Paint or Photos on Windows.

A researcher discovered that these apps embed a server-issued GUID (a globally unique identifier) as an invisible watermark in locally generated AI images.

The watermark is tied to the prompts you type. And since those prompts are associated with your Microsoft account, Microsoft could "theoretically" trace any watermarked image back to the user who created it.

This is recycling an idea from the 80s. Back then, laser printer manufacturers added tiny yellow dot patterns to every printed page. With this, they could identify the printer.

Now Microsoft has brought the same idea to AI image generation, and added it to two of the most widely used default Windows apps.

Microsoft had disclosed its AI safety measures in official documentation, but the practical implication, that your output image file carries an invisible fingerprint linked to your identity, was never clearly mentioned, of course.

The researcher found this by reading Microsoft's own published documentation and analyzing the watermarking mechanics.

AI watermarking is a requirement by law in the EU. But "this image was generated by AI" is different than "this image was generated by AI by Mr. Winston Smith".

For anyone who values privacy, this is something to worry about. If you generate an image locally, on your own device, why should it carry a tag that can identify you to the company whose software you used?

But then, anyone who values their privacy won't be using Microsoft Windows anyway."

Since the cat is out of the bag, I wouldn't be surprised if Microsoft generates an invisible watermark for ALL files and not just AI generated ones. The real story is that since AI watermarks are possible, there is no technical barrier to them adding personal EXIF metadata to a file where it can't be seen, removed, or decrypted, whether it is media, a document or other file.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#285
Okay, there are watermarks on AI stuff, interesting, not good but everyone else already talked about.

My question..how does it work? Is it robust? I remember that young me hid data in pixels of png with simple stegonagraphy and it was a fun little project..but brittle. How exactly does the fingerprinting survive jpeg compression? Is it repeate over and over the images or is it just one area? If that one is pure black by chance the jpeg algorhitmen would erase it all no?

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#286

Okay, there are watermarks on AI stuff, interesting, not good but everyone else already talked about. My question..how does it work? Is it robust? I remember that young me hid data in pixels of png with simple stegonagraphy and it was a fun little project..but brittle. How exactly does the fingerprinting survive jpeg compression? Is it repeate over and over the images or is it just one area? If that one is pure black…

I'm pretty sure the robustness of watermarking has been a solved problem for at least 30 years, I remember visiting the mit media lab in the mid 90s and they were explaining how they could watermark digital audio by imperceptibly adjusting the acoustics as if the walls of the room the audio has been recorded in were changing distance relative to the microphone according to a wave function

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#287

Earlier quoted context omitted.

Why would they need to subpoena Microsoft and why will Microsoft hand them the data if someone doesn't like my meme? I understand what you are trying to say but it does not make a whole lot of sense even from Microsoft pov. They are not bound by law to hand over personal data to anyone without a warrant issued. If a warrant is issued then it is their lawful duty to give that data, the same would be done by you if you…

Watermarking is just one puzzle piece in the surveillance state; the legislation around it another.

I would say the watermarking is not really a puzzle piece at all when it comes to the surveillance state, which was my point. They don't need watermarking to know who you are or to get information about you. So why would they work on this really visibile method if their intention was to progress the survelliance state? Microsoft with all their resources (and assuming it is an evil corporation purely acting from the state's interest to spy on you) will use this to track you?

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#288
post #93

Earlier quoted context omitted.

I guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).

I was stating that MS Paint mis categorized a Print Screen screenshot as AI generated when pasted. Which pushed me to install PaintdotNet onto my laptop instead.

> mis categorized a Print Screen screenshot as AI generated

Maybe. Question is, was that a false positive, or merely a bad user-facing message?

Assuming you didn't have any AI-generated images caught in the screenshot (e.g. some advert - plenty of those even in Microsoft apps like Weather, nowadays), what if - and I'm speculating here; I don't know if anyone actually does it yet, but it's so obvious they eventually will -

- what if parts of your screenshot already had an invisible watermark on it, like the ones for tagging AI images? You can imagine an app rendering its window to texture, and embedding a watermark on those pixels before sending it over to the system compositor, and the reasons have nothing to do with AI.

Watermarks are DRM tech. "AI generated" is just a specific kind of metadata that can be put in one, and a huge red herring for discussions.

It's only a matter of time before we'll need to have software for detecting and removing real-time watermarks from display output at OS level. (Unless, of course, platforms decide to add app window live watermarking as a "feature", and given the story with remote attestation, I think it's more than likely.)

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#289

Earlier quoted context omitted.

It says that about the C2PA content credentials metadata, but not about the modified image pixels.

Conversion from jpg to bmp to jpg is a lossy process, so it may obscure the watermarked pixels.

Sounds better to do postprocess filtering explicitly? For example, adding random noise with amplitude 1/255 (which should be as invisible as the watermark), followed by a smart blur that blurs more in directions where the colors are more similar (making the blur less obvious to humans).

But this is all moot really, if MS Paint is watermarking shit, it’s better to just use something else. Nothing from Microsoft is trustworthy.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#290

I admit it’s a while since I’ve used windows, but it’s such a shock to hear that MS Paint isn’t just a point and click pixel coloring app anymore. It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something. I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.

If you read the article instead of the headline…….. it’s adding a fairly standard mark to AI generated images to let’s others know, in the same manner a giant swath of the GebAI industry has agreed to.

It's a problem on so many levels.

We've probably lost the fight over GenAI marks, at least for now, and I do understand the need for them. However the same technology that can embed an invisible watermark that survives a round of photographing, printing, crumbling and scanning back - can be used to embed more information than just "it's AI generated". Encoding GUID is just a harbinger; as a next step, why not encode the app that produced the image? Also a hash of its license key? Hell, what's stopping an app from doing it itself, watermarking its own window before passing the pixels to OS for compositing?

"Robust GenAI watermark" today is "robust general-purpose DRM watermark" tomorrow :).

Post reply on HN