Top
Best
New

Posted by possibilistic 15 hours ago

Spymarks, Not Watermarks(brand.io)
558 points | 133 commentspage 3
miladyincontrol 8 hours ago|
Tbh I usually just apply a 'watermark' of jpg compression to images, even if yes the original image never lives as jpg. Easily viewable with ELA even if saved as other formats, resized, etc.
shevy-java 14 hours ago||
> A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership.

We also recently had this with LG spy-TVs. Cars here in the EU also spy on people, allegedly to show how alert they are. Perhaps they sneakily upload that information somewhere ... Facebook also has the spy-glasses now. People getting angry about Flock-spy-cameras.

It seems we are now in the age of spying of everyone at all times. Future spying will be done via even smaller devices.

snvzz 10 hours ago|
People are most afraid of cameras, somehow.

The concern is valid, but microphones are far worse. They're simpler, smaller, extremely sensitive to sound and an order of magnitude cheaper, both the mic itself as well as any spying with it.

It is possible to record voice using few bytes, to send later. It's further possible to transcribe cheaply into text, and analyze said text.

And mics are already everywhere, including in devices that do not need them, as well as speakers that can be rewired by software to act as microphones.

minimaxir 14 hours ago||
Out of frustration with SynthID being closed-source with weird dubious ways to verify if an image has the watermark, I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be hidden. The intent is for non-corporations to use it as a defense against the use of spying/AI by making it easy for normal people to prove providence, but I have a feeling nowadays most are not going to see it that way so I am unsure if I will release it.
Uehreka 12 hours ago||
How can you prove provenance if anyone can use it? The point of SynthID is that Apple makes the hardware and OS and can reliably insert the watermark/signature between when the camera takes the photo and when it becomes available to any 3rd party software.

Because they have this pathway only they can access, their key and signature can be trusted. I’m not gonna trust Joe Schmoe’s signature that “No I didn’t use AI” unless I already trust Joe Schmoe (and in which case, he doesn’t need a watermark, I’ll just believe him when he says it).

codedokode 5 hours ago||
How can you prove that the photo is taken by real person and not brought by men in black suits and signed by Apple?
fn-mote 14 hours ago||
If you just posted your link here with that comment, I’m sure you’d get a bunch of traffic.
codedokode 5 hours ago||
This is another reminder that commercial companies will always rat you out and betray.
viccis 15 hours ago||
Watermarking has referred to this "spy" use case for quite some time. Digital items purchased for download often have them, for example. Even before the rise of digital downloads, screeners for movies had them.
r3trohack3r 9 hours ago||
Reminds me of the micro patterns from inkjet printers

https://en.wikipedia.org/wiki/Printer_tracking_dots

anon48293 9 hours ago|
Yes the article mentions them..
bronlund 9 hours ago||
It's like that fart gas trail, but for machines :D
suopspaces 13 hours ago||
Can my friend print adversarial yellow doots and such?
silverFork 15 hours ago||
if it is specifically about pictures then wouldn't an analog copy clean it up? What about adding new spymark on top of it?

If it is text, copying text alone and not the file will it not remove it? Massage the text with Ai and vola spymark gone, don't you think?

fn-mote 14 hours ago|
> copying text alone and not the file will it not remove it

No. The mark is hidden in the word choices.

See the demo in the article.

silverFork 13 hours ago||
[dead]
ForHackernews 4 hours ago|
> A spymark is a hidden signal that makes your work traceable without your knowledge or consent.

It's not "your work" it's the bloody AI's work! That's the whole point.

More comments...