Live data from Hacker News

MS Paint and Photos inivisibly watermark even locally generated output with GUID

xusheng.dev

301–310 of 467 posts

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#301

It is quite likely that Snipping Tool is also doing this. Every camera also leaves device specific signature because of its inherent silicon sensor defects. If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats. See e.g. PPM format: https://www.cs.swarthmore.edu…

If Anthropic can manipulate text to add a watermark, what’s preventing providers from doing the same to generated images? Modifying the container format can’t protect you from a signature in the image’s visual representation, unless you apply noise to that (and know it’s enough noise/the right kind of noise to counteract whatever unknown technique they’ve applied).

Anthropic's watermarking technique is possible, and worryingly could effect low frequency choices (eg as I said, with object placement or style). However, this has to be a generation time decision, you can't really do that with a small edit. In fact small edits tend to be detectable spectrally.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#302

Earlier quoted context omitted.

> It's very likely your printer is secretly adding marks to the page It's most likely how the FBI caught NSA leaker Reality Winner: > Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker. https://en.wikipedia.org/wiki/Reality_Winner

This seems like something that could be confirmed by reverse engineering a printer’s firmware? Surely someone has done that?

It is confirmed and the algorithm has been reverse engineered, though not by looking at firmware

https://w2.eff.org/Privacy/printers/docucolor/

Seems like the algorithm is simple enough that they did it just by looking at some prints

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#303
post #129
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

> a unique identifier into every image you create Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0] Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account,…

So what you're saying is we should use linux?

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#305
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

> Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account.

Provided you bent the knee and created a Microsoft account.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#306

Earlier quoted context omitted.

> Windows 11 effectively forces users to register with a Microsoft account. It takes zero effort to bypass that with Rufus, if you set up your own pc.

A bypass existing is good, needing a bypass in the first place is still a problem.

A bypass existing is actually not good because that's how the frog is boiled. Ignorant users get an account while power user are placated for now. Then at some point the bypass is removed and when power users speak up they will be told shut down by all the drones with "you have needed an account for years, why are you throwing a fuss now".

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#307
post #206

Earlier quoted context omitted.

> Sign up for a virtual mailbox for $15-$25/month. That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.

Technically true but I don't think their engineering is advanced enough that it actually happens that way.

Why not? Collecting Wifi access point SSIDs to enhance locating has been bog standard in the industry.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#308
post #59
post #53

Earlier quoted context omitted.

This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.

> This is broadly impractical for the average citizen. No it's not. Sign up for a virtual mailbox for $15-$25/month. > A scalable solution would be to make this sort of thing illegal. I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in…

Yet another subscription plus the hassle of managing that mailbox is impractical for most people.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#309

Earlier quoted context omitted.

We gotta stop normalizing that. Why do you need my address to receive my money? My birth date? Even in places with strong privacy regulations requiring businesses not to collect data they don’t need, businesses apparently get away with asking this.

The problem is CC processors. You can get away as a merchant with just a number and expiration date, that's the minimum you need to process a CC payment, but you pay exorbitantly higher fees. The more details you collect and pass on, the lower your processor's risk fee will be because the more info, the more likely it is that the customer is actually the cardholder and not using fraudulently obtained data. And as soo…

Even without the CC processor requirements they would want to be able to identify you in case of a payment dispute. Digital payments are more like an IOU than like cash.
Post reply on HN