Live data from Hacker News

DarkJPEG

n0where.net

21–27 of 27 posts

Re: DarkJPEG

#21
post #20

> Supported container types: [...] rand, which downloads a random image from Wikimedia; I honestly don't see the point of that container type. How much useful is steganography if the original JPEG is publicly available for comparison? How could anyone ever plausibly deny that? "You were emailing this image from Wikimedia, but made subtle modifications to the file. Can you explain this?" - "Umm ... I guess I downloade…

Resize it, or perform a similar change so the file sizes wouldn't match up.

Re: DarkJPEG

#22

is there any evidence that the steganography here is undetectable? i would have thought that uniformly random data in the low bits of an image's data (pixels or fourier coefficients or whatever) was a clear signature for anyone trying to find these things. aren't they naturally correlated in various ways? also, something like tineye can be used to retrieve web-sourced images for comparison, which would make any hidde…

also, something like tineye can be used to retrieve web-sourced images for comparison, which would make any hidden data really obvious (and a smooth gradient would be even more suspicious if the lowest bits weren't smooth). Smooth gradients are only smooth if you add noise to the lower bits, due to having only 256 color levels per channel. A comparison: http://imgur.com/0cJWm8t Those color bands are indeed only one c…

The banding is almost imperceptible though. I had to get close to the monitor and squint a lot to see it.

Re: DarkJPEG

#23
post #20

> Supported container types: [...] rand, which downloads a random image from Wikimedia; I honestly don't see the point of that container type. How much useful is steganography if the original JPEG is publicly available for comparison? How could anyone ever plausibly deny that? "You were emailing this image from Wikimedia, but made subtle modifications to the file. Can you explain this?" - "Umm ... I guess I downloade…

Resize it, or perform a similar change so the file sizes wouldn't match up.

Comrade Smith, you have emailing picture wikimedia's, but you altering it. Why it resized when you having fast internet connection? We know you hiding message with steganography and requesting key. You will remaining in solitary confinement until key given.

Re: DarkJPEG

#24

is there any evidence that the steganography here is undetectable? i would have thought that uniformly random data in the low bits of an image's data (pixels or fourier coefficients or whatever) was a clear signature for anyone trying to find these things. aren't they naturally correlated in various ways? also, something like tineye can be used to retrieve web-sourced images for comparison, which would make any hidde…

also, something like tineye can be used to retrieve web-sourced images for comparison, which would make any hidden data really obvious (and a smooth gradient would be even more suspicious if the lowest bits weren't smooth). Smooth gradients are only smooth if you add noise to the lower bits, due to having only 256 color levels per channel. A comparison: http://imgur.com/0cJWm8t Those color bands are indeed only one c…

oh, good point. the site should explain this for people like me and also clarify how many bits are available.

Re: DarkJPEG

#25
post #3

What, pray, is "SHA3 key generation"

That they're using SHA3 as a key generation function to convert a passphrase to a key for encryption? What else would it mean?

See the reply by capnrefsmmat

Re: DarkJPEG

#26
post #25

Earlier quoted context omitted.

That they're using SHA3 as a key generation function to convert a passphrase to a key for encryption? What else would it mean?

See the reply by capnrefsmmat

The wisdom of using a homegrown sha-3 based algorithm for key generation is separate from what "sha-3 key generation" means.

Re: DarkJPEG

#27
post #18

No one's worried about the entire concept? It seems a little counter-intuitive to tell someone else your secrets, so they can hide them.

I would argue that to most people who download the tor browser that is effectively what they are doing. As has been shown before, open and closed source products people use (including security software) has been time and time again proven to be insecure. I still would be somewhat wary to use this site for actual stuff I care about, but its a cool site and a cool little idea.

shown before where?
Post reply on HN