Top
Best
New

Posted by possibilistic 14 hours ago

Spymarks, Not Watermarks(brand.io)
531 points | 129 comments
Retro_Dev 10 hours ago|
Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't watermark, an image compressor we are certain can't watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered/announced) by saying that our memes won't be reposted, images or work stolen, etc... but honestly I'd rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.
dragonwriter 8 hours ago||
Spymarks an application of steganography, not a different name for it.

> On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced

That doesn't help with things like the typical use of SynthID where the spymarking is done by the same process generating the content, so there is never a clean comparator. (It also wouldn't be useful anytime it is inplemented as part of a transformation—compression, etc. —step, for the same reason.)

Normal_gaussian 2 hours ago||
Additionally, verifying that your generator doesn't add such a mark is practically impossible for the majority.
sitkack 54 minutes ago||
When someone else controls distribution, they also control the spark, each request could serve up a different payload. So innocuous images could encode ids, tracking receivers as well as originators.
speerer 5 hours ago|||
> ... particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open.

This has been going on for a while with Facebook. They seem to embed custom metadata tags so that images shared outside the platform can be traced back:

https://stackoverflow.com/questions/31120222/iptc-metadata-a...

wodenokoto 8 hours ago|||
> Spymarks just seem like another word for https://en.wikipedia.org/…

Stop using links instead of words. Your comment is literally unreadable without going on to other websites.

teitoklien 8 hours ago|||
idk, loved their comment. Stop giving "Stop" orders to others.

:D

zxexz 8 hours ago||||
the word is the last segment of the url. very readable
faithful_droog 7 hours ago|||
It was cropped to just displaying as https://en.wikipedia.org/wi.. on my mobile screen - so not really readable here.
lozf 2 hours ago|||
Does the shorter enwp.org/Steganography render any better? It's quite handy for English Wikipedia links.

(Edit: hmm, without the "https://" it seems to depend on the browsers ability to recognise a URL.)

Normal_gaussian 2 hours ago|||
and on desktop for me
TeMPOraL 7 hours ago|||
Not on mobile it isn't. Unless they really are saying we should stop using English Wikipedia.
azatom 4 hours ago||||
Stop using link mutiliating tools!

What will be the next? I will be unable to see the domain of a link on hover/longtap and have to trust random links like on a search engine?

MUTINY against hn!

gorgoiler 8 hours ago||||
(The word is “steganography”.)
fumplethumb 8 hours ago|||
I appreciate the link.
okaleniuk 4 hours ago||
The vulnerability of steganography is that is has to pretend that signal is noise. Remove the noise - and the signal is gone. I'm pretty sure that the simplest gaussian blur will remove the spymark from any picture.

Or... add some noise. Just align the last bit of every pixel channel with a random bit sequence - and Bob's your uncle.

busssard 3 hours ago||
"just" yes, you "just" have to do it every time. and so does everyone else. sadly we live in a society of comfort, where people do not even remove the trackers from links, so why would you expect they add a blur to images...
xp84 13 hours ago||
These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.

First the low-end laptops and phones (and probably later, most of them) will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home. I assume this is something Apple will, to their credit, refuse to do[1] but I don't think other OEMs will have any qualms based on what they already do with their TVs.

[1] (though they don't do this kind of thing out of altruism, but because their cash cow is app store rents and fat hardware margins, not third-party advertising.)

qurren 9 hours ago||
Apple is just Stockholm Syndrome at scale. I wouldn't trust anything they say about privacy, especially given how closed their ecosystem and hardware is.
BlaDeKke 8 hours ago||
They lacking in the AI race is an indicator that they value privacy more then competitors.
someguynamedq 45 minutes ago|||
No, it's an indicator that reinventing every technology to work with your own private software/hardware stack has costs
bigyabai 8 hours ago||||
No, it's just a sign of Apple holding a decades-long grudge against Nvidia to their own detriment.
BlaDeKke 7 hours ago||
And there are no alternatives to Nvidia?
stymaar 6 hours ago||
Why do you think NVDA is the most valuable company on planet Earth?
bigbuppo 5 hours ago||
Because they're engaging in Enron-esque accounting tricks but because they admit what they're doing it's not illegal?
embedding-shape 4 hours ago|||
So they're lacking in the FOSS department because they value privacy? They lack in the human rights department because they value... What?
ifh-hn 12 hours ago|||
I don't think you can count apple out like that. They will likely implement it themselves though. This would be in addition to their always listening AI watch and intelligence features.
diasdevops 11 hours ago|||
I’m a bit unfamiliar with current laws, but are there any rules that would prohibit companies from doing this in interest of user privacy? I know at this point privacy is long dead but there are certain things that do get called out and shut down.
account42 5 hours ago||
Yeah and then they'll have to give every affected user a free Unicorn and everyone will live happily ever after.
SV_BubbleTime 12 hours ago|||
Apple’s always on watch has a declared 15 second buffer for live audio, and a worse scenario of summarizing your conversations for later but.. they tell you about it proudly. They also tell you how they’ve managed to do it while keeping privacy focused.

It’s your choice if you believe them or not, I like Apple and I wouldn’t use that feature.

The pretending that this is the same thing, that Apple is sneaking something past you when they’re showing you that they’re trying to do it right is a bad faith argument.

microtonal 7 hours ago|||
It’s absolutely not a bad faith argument. They proudly tell you about iMessage being end-to-end encrypted. The part where it’s practically only encryption at rest, because everyone enables iCloud backups without ADP is hidden somewhere in a footnote.
kennyadam 2 hours ago|||
Not even able to enable ADP in the UK these days :(
embedding-shape 4 hours ago|||
Wonder if they proudly tell Chinese users (or visitors to China) that suddenly their data is going to a different place than usual, servers outside of Apple's control?
pjerem 7 hours ago||||
> Apple’s always on watch has a declared 15 second buffer for live audio, and a worse scenario of summarizing your conversations for later

Even if you trust them, maybe as an user you can be ok with that. As a non-user who will talk with people wearing Apple Watches, I disagree being recorded and my conversations with the watch owner summarized.

Where do I disagree for that ?

maccard 5 hours ago|||
With the person wearing the watch. It’s no different to someone walking around with a lapel mic
totetsu 5 hours ago|||
Where could I disagree with all my family members sending their dna to 23andme?
defrost 10 hours ago||||
Will they surrender logs for a legal discovery request?

e.g. Johnny's accused of something white collar, did he ever make any prompts that suggest how early on he was aware of {X} and further indicate how he moved to frame it?

That's a requirement that varies by country.

codedokode 4 hours ago|||
Yes? What other answer could be there?
Pannoniae 2 hours ago||
"No" is also an answer. Sadly one which isn't considered by many people :)
SV_BubbleTime 9 hours ago|||
Have you read anything about the feature?

They’re asserting that all the audio is done on device, and the results of encrypted so they can’t access them even from the backups.

Unlike… EVERY… other tech company, it is in Apple’s interest to be privacy-focused.

Even if you just have to believe them, which you do pretty much, they’re the biggest name pushing for privacy in the world right now. They make more on selling devices than they make on ads and behaviors. It’s in their interest to not lie.

microtonal 7 hours ago|||
Read the actual privacy brief. Even though the audio transcription is done on device. For Siri recap, a condensed transcription (which mostly removes superfluous words, etc.) goes to their PCC servers. So even though their servers do not get raw audio, their servers do get transcriptions, which is nearly the same privacy-wise.

Of course, at that point it depends on how much you trust their PCC.

account42 5 hours ago||||
It's their interest to be privacy focused ... to the extend that they don't let other companies have free access to their users data.

But make no mistake, Apple itself is an ad company and that sets all the incentives that matter.

ierukah 7 hours ago|||
> It’s in their interest to not lie.

Oh, really?

ifh-hn 11 hours ago|||
I'm not pretending anything, nor did I imply they were sneaking anything in. It's a bad faith argument to pretend I was doing that, which is ironic but not unexpected from an apple fan...
DannyBee 1 hour ago|||
Apples largest area of growth is literally services and advertising. They even make a huge deal of it in their investor calls. Have for at least the past 3 years.

I think you may have an outdated view here

N_Lens 8 hours ago||
“Next we just need to mark the consumer’s retina and brain to ensure our ads truly went through”
EvanAnderson 7 hours ago|||
DRM helemts - an idea whose time has come: https://web.archive.org/web/20020802214412/http://www.oreill...
_carbyau_ 7 hours ago|||
Smart glasses could be able to tell what got through to the retina at least.

But fuck it, just brand all our brains with "SLA Industries".(fictional dystopian corporation ruling future)

paweladamczuk 5 hours ago||
It increasingly seems to me like the only way to prevent value to be extracted from myself is to stop engaging with new tech altogether.
opan 4 hours ago||
What's sad is even if you retreat to retro computing/gaming or only listen to old music, you'll likely still run into people online or at meet-ups vibe coding, making ai remixes of songs or generating music videos. Not even the old stuff is safe unless you do it offline by yourself. So you go out and try to find like-minded individuals and these spaces are still infiltrated and tainted. It reminds me a bit of radiation, how everything was just tainted decades ago, they have to salvage low background steel from sunken ships to make Geiger counters because everything else is irradiated.

I still use IRC on the daily, but someone mentions Discord at least once a month on there, and sometimes tries to whisk people away to that side. There are also people hooking up LLMs to IRC bots and joining them to channels without permission, then when you complain or kick/ban their bot you're somehow treated as the rude one. It's very hard to entirely get away from all the crap anymore.

someguynamedq 44 minutes ago||
You're going to have a hard time if you can't bear to even be around people who play around with AI
Havoc 5 hours ago||
I’d say it’s still possible in niche areas of the web. eg hn - clearly they have an agenda but it isn’t tracking you

So I’m not writing off tech as a whole just the adtech companies being a lost cause.

swiftcoder 5 hours ago||
A number of prominent corporations used to embed these in the background images of their internal webpages, so that leakers could be identified from the screenshots they shared. Caused a whole fun adversarial loop where journalists had to transcribed and/or redraw screenshots before publishing to avoid exposing the identity of leakers...
miki123211 5 hours ago|
Watermarks are often just another form of DRM.

Digital Rights Management isn't just about restricting what you can do with the content, which is often futile anyway. Another way companies can manage their rights is by making sure pirates are properly identified and caught.

Morromist 11 hours ago||
The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.

Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be replaced with "winding" like "her gently curving thighs" with "her gently winding thighs"

But I'm sure there are some intricacies I don't understand. Anyway, very cool website, thanks for sharing it~!

Worta 4 hours ago||
Related to this idea, there are interesting papers that explicitly examine the adversarial case. Basically, besides the provider hiding watermarks, one could also think of an adversary training a model to exhibit this behaviour depending on the Input of the prompt. So if you use the manipulated model, not only information about the author that the platform knows is encoded, but also, e.g. one-time tokens from your email. This works surprisingly well (albeit with the naive approach still noticeable in most cases).

TrojanStego: https://arxiv.org/abs/2505.20118 Improvement: https://arxiv.org/abs/2606.09411

suopspaces 11 hours ago||
Might one suggest "pneumatic" ?
encrypted_void 6 hours ago||
Spooky stuff. This will take surveillance to a whole new level. This is basically email read-receipt tracker, but for all of the digital content. They will know the whole trail - from originator to how it spread. Who read what and when. Big brother will always be watching.
doc_ick 5 minutes ago|
Would you rather not know if what you read is llm generated? I would rather like to know if a book was written by an llm, and em dashes (or similar) will only be apparent for some models for some time.
gorgoiler 8 hours ago||
I feel like there’s some security engineering calculus that would be useful here?

You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?

There must be value in having a visible vs an invisible watermark, or in declaring that a work is watermarked without revealing the hidden mark, or having two marks — one that is publicly verifiable and another that is hidden?

If the process itself can be defeated through adding entropy (or more generally by revealing the watermark algorithm) then is that not security through obscurity, which is to say it is a one-shot rather than a general system that is doomed to become obsolete over time?

Something feels off about a technology based on being hidden but whose only value is in being revealed but I feel dumb for not being able to be more specific about what feels wrong! It could simply be that anyone who can verify the presence of the watermark also now has a tool to tell them when they’ve successfully scrubbed the watermark off the work, so the verify tool has to be kept secret which in turn limits its usefulness.

jstanley 7 hours ago||
If you think SynthID-Image can be easily defeated by adding entropy I invite you to give it a try.

I spent half a day messing around with it and I was very impressed by how robust it is. I couldn't get OpenAI to stop detecting their own SynthID without completely trashing the image.

dannyw 7 hours ago|||
Much prior art here, works against both Google and OpenAI's SynthID: https://github.com/0xROOTPLS/DeSynth
darkwater 5 hours ago||
Ah you just need to run a local model...
doc_ick 28 minutes ago||
Let me just get my tens of thousands of dollars I have waiting around to get a few sparks.
codedokode 4 hours ago|||
What about asking LLM to re-draw the image from scratch? Or pass through AI editor?
jstanley 3 hours ago||
Anything you generate with ChatGPT has SynthID on it.

The closest thing I found to "defeating" SynthID was to put in a normal photograph and ask ChatGPT to make some utterly trivial edit, and then the output got flagged with SynthID even though it is essentially an unmodified photograph.

djmips 2 hours ago||
OT (Off-Topic) It just occured to me that the PS1 disc protection scheme is a form of steganography.
rbtms 3 hours ago||
Thanks for the article. I hadn't heard of SynthID before and it's good to.

It's a shame however, how low quality and vibecoded the live examples are. The first example says "Toy example; not SynthID.", the second one is a generic spectrogram and the third one has an identification space too small to be useful (173 in decimal). I was hoping to see more realistic scenarios to learn how these new watermarks are being applied, instead of generic steganography.

voidUpdate 6 hours ago|
> Spymarks are certainly not great for whistleblowers or anyone who doesn’t want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about.

How do you spymark text that someone else wrote? You can't change the words or they'd notice

TeMPOraL 6 hours ago|
"Text someone else wrote" is already self-watermarking if it's long enough. The infamous "six lines written by the hand of the most honest of men" may not be enough to hang someone over it, but apparently it's more than enough to uniquely identify them by word choices alone.

Text the whistleblower only reports on, well, if they got it from a computer system, there's already precedent of altering word choices, typos and punctuation in e-mails and memos to create unique per-recipient or per-recipient-group versions, which allows companies to trace leaked transcripts reported by press back to source of the leak.

More comments...