Live data from Hacker News

MS Paint and Photos inivisibly watermark even locally generated output with GUID

xusheng.dev

311–320 of 467 posts

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#311

Earlier quoted context omitted.

> It's very likely your printer is secretly adding marks to the page It's most likely how the FBI caught NSA leaker Reality Winner: > Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker. https://en.wikipedia.org/wiki/Reality_Winner

This seems like something that could be confirmed by reverse engineering a printer’s firmware? Surely someone has done that?

No need to reverse engineer, printers are required to do this for decades.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#312
post #286

Okay, there are watermarks on AI stuff, interesting, not good but everyone else already talked about. My question..how does it work? Is it robust? I remember that young me hid data in pixels of png with simple stegonagraphy and it was a fun little project..but brittle. How exactly does the fingerprinting survive jpeg compression? Is it repeate over and over the images or is it just one area? If that one is pure black…

I'm pretty sure the robustness of watermarking has been a solved problem for at least 30 years, I remember visiting the mit media lab in the mid 90s and they were explaining how they could watermark digital audio by imperceptibly adjusting the acoustics as if the walls of the room the audio has been recorded in were changing distance relative to the microphone according to a wave function

There is no robust-without-qualifiers watermarking. There is only robustness against common operations but as soon as someone is actually trying to remove the watermark they can at the very least use exactly the same technique to embed random noise instead to overwrite your watermark.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#313

I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.

If an adversary knows how the watermark is embedded they can replace it with noise so its not like you can rely on these watermarks anyway.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#314
post #24

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war again…

> Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Provided you bent the knee and created a Microsoft account.

I was forced to create multiple as part of the mojang migration - truly a nightmarish experience to use their AuthN, haven’t seen something quite as bad since

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#315

It'll literally be like printers "cannot print this black/white document, low on cyan". "Cannot run local AI model, no network connection". The more you think about it, the more it really is the same: https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=...

Except once printed its at least hard to remove the dots. Image based watermarks are trivial to destroy if you know they are there.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#316

Earlier quoted context omitted.

> every image you create *with the help of AI*. Does in fact make a difference.

While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that. I wonder if in ten years we'll have a horrifying world where everything that leaves a mach…

There is a certain convergence of wills here: watermarking AI products on the one hand, and infusing AI into everything on the other hand. When you layer generative AI into Notepad, once just a raw text buffer, then you’re setting the stage for watermarking everything because AI touches everything.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#317

As a linux fan I just love all these changes Microsoft have been introducing

As another Linux fan, I don't. What Microsoft does to their users changes the overton window of what's acceptable in tech. Before you know it there will be a politician demanding that all software systems that don't implement such tracking will be outlawed and there will be no one left to speak up to you because they are all already used to the tracking so why should you get a pass.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#318
post #70

This reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)

Sure, try to scan, photocopy, edit in photoshop or print US money today.

Or EU money.

https://en.wikipedia.org/wiki/EURion_constellation

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#319
post #311

Earlier quoted context omitted.

This seems like something that could be confirmed by reverse engineering a printer’s firmware? Surely someone has done that?

No need to reverse engineer, printers are required to do this for decades.

You'd still need to reverse engineer it to build a better firmware without this anti-feature.

Re: MS Paint and Photos inivisibly watermark even locally generated output with GUID

#320
post #311

Earlier quoted context omitted.

This seems like something that could be confirmed by reverse engineering a printer’s firmware? Surely someone has done that?

No need to reverse engineer, printers are required to do this for decades.

And the reason why it refuses to print this B&W document when yellow is empty.
Post reply on HN