‹ BackHN Continuity

Thread

Spymarks, not Watermarks

698 points · 171 comments · possibilistic

  1. Retro_Dev · · focus · HN ↗
    Spymarks just seem like another word for <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Steganography" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn&#x27;t watermark, an image compressor we are certain can&#x27;t watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered&#x2F;announced) by saying that our memes won&#x27;t be reposted, images or work stolen, etc... but honestly I&#x27;d rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.
    1. stillsut · · focus · HN ↗
      I actually wrote a library to do stego with LLM outputs last year and it turned out to be an almost exact implementation of the Anthropic watermark algo.

      Repo here <a href="https:&#x2F;&#x2F;github.com&#x2F;sutt&#x2F;innocuous" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sutt&#x2F;innocuous. It works with last year&#x27;s llama.cpp. Check out the &quot;Use Cases&quot; and &quot;How it works&quot; sections in the readme if you&#x27;re interested.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.