‹ BackHN Continuity

Thread

Spymarks, not Watermarks

698 points · 171 comments · possibilistic

  1. Retro_Dev · · focus · HN ↗
    Spymarks just seem like another word for <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Steganography" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn&#x27;t watermark, an image compressor we are certain can&#x27;t watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered&#x2F;announced) by saying that our memes won&#x27;t be reposted, images or work stolen, etc... but honestly I&#x27;d rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.
    1. wodenokoto · · focus · HN ↗
      &gt; Spymarks just seem like another word for <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;…" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;…

      Stop using links instead of words. Your comment is literally unreadable without going on to other websites.

      1. fumplethumb · · focus · HN ↗
        I appreciate the link.
      2. gorgoiler · · focus · HN ↗
        (The word is “steganography”.)
      3. zxexz · · focus · HN ↗
        the word is the last segment of the url. very readable
        1. faithful_droog · · focus · HN ↗
          It was cropped to just displaying as <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wi" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wi.. on my mobile screen - so not really readable here.
          1. Normal_gaussian · · focus · HN ↗
            and on desktop for me
          2. lozf · · focus · HN ↗
            Does the shorter enwp.org&#x2F;Steganography render any better? It&#x27;s quite handy for English Wikipedia links.

            (Edit: hmm, without the &quot;https:&#x2F;&#x2F;&quot; it seems to depend on the browsers ability to recognise a URL.)

            1. abustamam · · focus · HN ↗
              I think any length of link would have been fine if commenter just put

              &quot;for stenography (link)&quot;

              Or to use another HNism

              &quot;Stenography[1]&quot;

              Those interested could click it, those not could still read the comment.

        2. TeMPOraL · · focus · HN ↗
          Not on mobile it isn&#x27;t. Unless they really are saying we should stop using English Wikipedia.
      4. teitoklien · · focus · HN ↗
        idk, loved their comment. Stop giving &quot;Stop&quot; orders to others.

        :D

      5. azatom · · focus · HN ↗
        Stop using link mutiliating tools!

        What will be the next? I will be unable to see the domain of a link on hover&#x2F;longtap and have to trust random links like on a search engine?

        MUTINY against hn!

      6. amelius · · focus · HN ↗
        &gt; Stop using links instead of words.

        No, the words could contain steganography. Use links to be safe!

      7. Retro_Dev · · focus · HN ↗
        My bad folks - future links I share will be better displayed (as a foot note).
    2. dragonwriter · · focus · HN ↗
      Spymarks an application of steganography, not a different name for it.

      &gt; On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced

      That doesn&#x27;t help with things like the typical use of SynthID where the spymarking is done by the same process generating the content, so there is never a clean comparator. (It also wouldn&#x27;t be useful anytime it is inplemented as part of a transformation—compression, etc. —step, for the same reason.)

      1. Normal_gaussian · · focus · HN ↗
        Additionally, verifying that your generator doesn&#x27;t add such a mark is practically impossible for the majority.
        1. sitkack · · focus · HN ↗
          When someone else controls distribution, they also control the spark, each request could serve up a different payload. So innocuous images could encode ids, tracking receivers as well as originators.
        2. dragonwriter · · focus · HN ↗
          You can verify the absence of any particular mark if you have sufficient information about the mark, but, you are right, the whole reason spymarks are steganographic is so that they can escape detection absent that information, which is important for the spying-on-the-user use case.
    3. speerer · · focus · HN ↗
      &gt; ... particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open.

      This has been going on for a while with Facebook. They seem to embed custom metadata tags so that images shared outside the platform can be traced back:

      <a href="https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;31120222&#x2F;iptc-metadata-automatically-added-to-uploaded-images-on-facebook" rel="nofollow">https:&#x2F;&#x2F;stackoverflow.com&#x2F;questions&#x2F;31120222&#x2F;iptc-metadata-a...

    4. okaleniuk · · focus · HN ↗
      The vulnerability of steganography is that is has to pretend that signal is noise. Remove the noise - and the signal is gone. I&#x27;m pretty sure that the simplest gaussian blur will remove the spymark from any picture.

      Or... add some noise. Just align the last bit of every pixel channel with a random bit sequence - and Bob&#x27;s your uncle.

      1. busssard · · focus · HN ↗
        &quot;just&quot; yes, you &quot;just&quot; have to do it every time. and so does everyone else. sadly we live in a society of comfort, where people do not even remove the trackers from links, so why would you expect they add a blur to images...
        1. okaleniuk · · focus · HN ↗
          My point is, it&#x27;s easier to remove a spymark than a watermark.
      2. pjc50 · · focus · HN ↗
        .. both of which visibly degrade quality.
        1. okaleniuk · · focus · HN ↗
          Try.
          1. minitech · · focus · HN ↗
            I tried both options, and both options visibly* degraded quality while failing to remove my hidden message. Consider that good schemes are already designed to be resilient in the face of lossy image compression, which is a lot more disruptive than the things you suggested.

            * the 7-bit quantization + 1-bit noise option not by much, but still, visible

    5. pjc50 · · focus · HN ↗
      This is a straightforward example of how the positive or negative valence of a piece of tech depends entirely on how it&#x27;s used.

      You just need to address three questions:

      - who controls what information is going in? (that is, what is the process by which the tech companies who control all the tech are using it)

      - who controls what information is coming out? (that is, is the steganographic format open enough that anyone can read it, or does it depend on having a key)

      - what legal regulation is this subject to? (does sneaking individuals name and address into their photographs incur you massive GDPR liabilities when it is discovered?)

      Note that there&#x27;s a widespread precedent: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Printer_tracking_dots" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Printer_tracking_dots

    6. stillsut · · focus · HN ↗
      I actually wrote a library to do stego with LLM outputs last year and it turned out to be an almost exact implementation of the Anthropic watermark algo.

      Repo here <a href="https:&#x2F;&#x2F;github.com&#x2F;sutt&#x2F;innocuous" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sutt&#x2F;innocuous. It works with last year&#x27;s llama.cpp. Check out the &quot;Use Cases&quot; and &quot;How it works&quot; sections in the readme if you&#x27;re interested.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.