I admit it’s a while since I’ve used windows, but it’s such a shock to hear that MS Paint isn’t just a point and click pixel coloring app anymore. It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.
I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.
If you read the article instead of the headline…….. it’s adding a fairly standard mark to AI generated images to let’s others know, in the same manner a giant swath of the GebAI industry has agreed to.
I don't so much mind about Paint, but modern Notepad is completely unusable. We had "Notepad but with Rich Text formatting" -- it was called WordPad and no-one used it so they eventually deleted it.
The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.
Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]
Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.
In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.
> It's very likely your printer is secretly adding marks to the page
It's most likely how the FBI caught NSA leaker Reality Winner:
> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.
and then in few years a new mono-mustachioed or mono-browed leader will emerge who declares memes a blasphemy punishable by death and will call up all the telemetry gathered to punish all involved.
"I don't worry because I have nothing to hide, based on my perfectly accurate perception of today's political and legal forces in a state and country which will stay static forever."
Exactly. Forget the AI aspect, this is entirely to identify users for any purposes they deem necessary. People are ignoring the surveillance state aspect of this. Reminds me of the device id debacle they have attached to their outbounds Windows network calls
Can this also be weaponized? Get an innocuous image from someone you don't like, grab their GUID, add it to another image, sent it to the thin skinned politician in power.
While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that.
I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.
It does kind of say: The GUID is coming from the moderation endpoint, which is hit when you generate a local or cloud AI image based on your prompt. If there is no prompt, there is no endpoint, and likely no GUID.
Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
Since the watermarker runs locally, you could also do the reverse: generate some porn with a different open model, then run that code to tag it as "Content watermarked by Microsoft Responsible AI"
Probably both so they can change what they censor without waiting for you to run windows update and also so they can collect your information (IP, timestamp, etc) to associate with whatever you did
Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.
Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.
Windows 11 effectively forces users to register with a Microsoft account. Once that's established, all it takes is for an unaware user to fill out an e-commerce form and save an address for auto-fill.
> Windows 11 effectively forces users to register with a Microsoft account.
While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.
My comment was in regard to the average PC user. The kinds of folks who would never install an operating system and would likely agree to use Edge while signed in to their Microsoft account.
Microsoft has also been pushing hard for Recall and recording all local activity forever. Not impossible to imagine that anything looking like a home address “somehow” gets ingested in the telemetry.
Any of a number of virtual mailbox services which can receive mail for you, e.g. anytimemailbox.com but there are several. You can either pick up in person, or they offer services like mail forwarding, opening and scanning, etc.
Besides privacy against leaking your sleeping-address to businesses, they're also convenient for avoiding package theft if that's a problem in your area, and receiving/forwarding mail if you travel a lot for extended periods of time.
I'd recommend against PO boxes because (1) they get rejected by some services (2) UPS and FedEx won't deliver to them.
Because these businesses have to register as CMRAs and you have to sign a notarized form for them to legally receive mail for you, some services will still detect it and not let you use the address, but my experience for the most part has been that most US financial institutions let you enter a "residential/legal address" (no CMRAs allowed) and a "mailing address" (CMRAs allowed) separately, and the mailing address usually becomes your billing address.
Or.....Install Linux and bypass all this stupidity.
They will move faster to track each and every one of you, all the while shoving ads and garbage down each of your respective machines... and you all pay for it?!
You still want the virtual mailing address for other reasons honestly. Even if your os isn't tracking you or leaking things giving your real address to any business could lead to it being leaked because no one cares about security, etc. If that's in your threat model you should be using a good proxy mailer
Perhaps so. But the problem at hand here is that MS Windows has so lost the plot of being an OS for users, to ABUSING users.
All these fixes and repairs ignore the fact that abusing people pays. Surveillance capitalism pays, and provides a revenue stream for Microsoft to further exploit.
> This is broadly impractical for the average citizen.
No it's not. Sign up for a virtual mailbox for $15-$25/month.
> A scalable solution would be to make this sort of thing illegal.
I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.
It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.
> No it's not. Sign up for a virtual mailbox for $15-$25/month.
Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.
It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.
At least in the US it's not even a good method either. Own a house? Boom, your information is publically available and you won't be able to remove it without a court order, which in most states is impossible to get. In most states, you don't even need to own a house, decide to vote? You information again is publically available. Tie your real name to a single account to purchase something, and you are trackable. Want privacy? You'd need to remove yourself from the internet, dump your phone, destroy your ID and work underground for cash. We can push against iot, and people have been forever, but at the end of the day the government will always they have a vested interest in being able to identify it's citizens.
> Sign up for a virtual mailbox for $15-$25/month.
That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.
Ahhh okay if that's what they meant, then yes, I 100% agree and apologize in advance.
I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.
I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.
They (the ones wanting to make privacy illegal) are just the ones that want to develop the tools and consume the data for it because it'll be good for their resume or some bullshit, or they're just intrinsically broken humans.
> IANAL but they are not a government or financial institution and do not have a right to that information.
As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.
Seems to me that it's a challenge to make an apple account without adding a credit card to your account as well. A carfully chosen Linux distro (so many options!) is the way to avoid the brunt of these privacy issues, lots of open software calls home in some way or another so user beware!
No - there is a huge difference between "this AI created this image" and "this user did it" - the first we need more of, and the second is a big privacy concern. The article does not say anything about identifying a user.
A guid isn’t a user id, if it is in this case, it’s an abuse of how guid is used, at least colloquially. I haven’t read enough to understand if it is user / machine id, I.e. only globally unique in the sense it’s a globally unique entity identifier.
As the article explained, the EU does not mandate a prompt-specific GUID, only the ability to identify the content as AI-generated. The highly privacy-invasive level of provenance tracking which Microsoft has added goes beyond the EU’s new mandates.
This a variant of the provenance scheme: C2PA its implemented by all major Camera maker, and Google it seems, Apple support it with 3rd party apps on iPhone, but they have something called "Apple Reference Image" brewing.
Personally I think there is a good argument for being able to distinguish AI generated image and video...
> I think there is a good argument for being able to distinguish AI generated image and video...
Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.
AI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible (cannot be disabled and happens silently in the background with no user notice) watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end).
Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.
In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.
I'd like to know more about the GUID part and how easy is it so deanonymize yeah.
But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.
A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.
MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.
It is quite likely that Snipping Tool is also doing this. Every camera also leaves device specific signature because of its inherent silicon sensor defects.
If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats.
These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.
I had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.
I guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).
ah, right, i vaguely recall that now. But why/how would it know AI was used, outside of a local LLM, weird it would say that AI was used (unless it's referring to the software itself).
MS Paint wanted to add the "this is AI" tag on a picture they just resized. OP didn't like that, so they went and downloaded Paint.Net to avoid having to deal with (MS) Paint shenanigans.
I was stating that MS Paint mis categorized a Print Screen screenshot as AI generated when pasted. Which pushed me to install PaintdotNet onto my laptop instead.
I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.
Well if that's any reassurance, you can generate a meme picture using AI, then paste it into Paint to add some funny text. That way you can get the best of both worlds.
This is gonna sound a bit harsh, but from the outside it genuinely looks like Microsoft is actively looking for new ways to degrade and humiliate their users. (And having no trouble finding them!)
Interesting find. Overall it makes sense from a deepfake-fighting perspective and EU requirements. But what's concerning is that users aren't really told about this, as far as I can tell. Would be cool if someone checked if it can be bypassed, like swapping the DLL or intercepting the API call. But yeah, it's another step toward every digital trace becoming personally identifiable...
This reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)
the GUID is the giveaway that it's not about protecting artists, it's about being able to prove provenance later. nobody embeds a unique id in a local file for the user's benefit.
> Some say "i do nothing illegal" "have nothing to hide".
I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.
When people claim they have nothing to hide, always point out that's not up to their determination. That freaks them out, it disarms their shrink-from-confrontation move.
And you can point it out super fast, in a plain six word statement. No need to launch into a deep discussion unless prompted.
Alternatively, simply respond with: yes you do. When they reply: "what?" - "every single thing you have ever done wrong across your entire life." Everybody has done something they would prefer to keep hidden, the cowards just lie about it.
Essentially any Linux distro protects privacy. You'd kinda have to go out of your way to find one that doesn't, because there's no online account connected to your install for any of them.
If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.
Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.
Why have you linked a bug report for a niche userland application that may be causing disk corruption as evidence against linux reliability? That seems like a pretty uninformed conclusion.
This supports my initial reply. This was an f2fs bug in a bleeding edge kernel released only seven days earlier. The thread suggests perfectly reasonable mitigations, especially for an arch user: use the lts kernel or downgrade to 6.8.9.
If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.
I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.
Ok fair point, here's plenty more of the same on stable. My point is Linux is always fine right until it isn't. Then you're back to a day of debugging your update.
I have the same issue on Windows 11. It's been bugging me to press a button or "check my drive" on every startup for at least half a year, no matter how often I let it run the check...
Thanks Microsoft, for adding my signature so I won't have to claim authorship when it ends up in a museum in 200 years, and the NSA archives are declassified for art historians filing a FOIA in 2226, who find out, "yep, it was from his PC."
No, I wasn't suggesting that. I was saying that if there was digital art (human made) aesthetically significant that a curator would want to display it in a museum, Microsoft's GUID supplied to a data collection agency would make it possible to retrieve if ever/whenever that data were declassified (assuming it isn't purged)
It's possible a very bad curator with a terrible taste in art might select slop to display, but I was refering to "fine art" or at least finer art that is digital.
Ya know, this would probably be pointless but if I were a programmer (I'm not -and refuse to be a vibe coder) I'd probably just grab appropriate libraries and make my own replacements for this shit. GLTK+ (?) is an obvious choice to use for recreating mspaint, and to replace notepad -I was told making a simple editor was an excercise they have you do when you learn programming to begin with?
I already replaced the 'solitaire' games suite with pysol running on WSL2 and it's a vast improvement!
tldr -if MS is going to screw us, why don't we mitigate it by using replacements?
Until proven otherwise via open-source audits and reproducible binaries, you should assume that all commercial photo editing software is embedding watermarks in any way they can get away with. This includes the professional software that you pay quite expensive licenses for. You should also assume that even if they're not today, they will eventually be coerced into doing so, in the same way that printers embed tracking dots.
Interesting. I really didn't think watermarks would end up going anywhere, but maybe with enough adoption we can have easy ai generated content flagging after all?
I mean, workarounds wouldn't be hard, just annoying, anyway. Like an extra step or two (take a screenshot, change the image format, wipe the metadata; or print, take photo with camera, clean up in something like gimp, same other steps).
It actually might make the new horrible world even worse. Imagine the populace getting used to a AI image detector flagging things as fake using this fairly easily defeated GUID marker system. Most people are just making memes or cat videos and don't even try to remove this so eventually the populace starts to believe these things actually work.
Now some one slightly more sophisticated starts creating deepfakes of a woman and uploading them or fabricating video of an political event without this marker. The subject protests it's fake and AI generated but a loud majority of ignorants feed it into Microsoft AI detector and call you a liar and say it's confirmed real. Most people don't know any better and eat it up because a computer said so.
With every new thing Microsoft goes trying so hard to come out as the good person, but they just cannot help themselves but to inject their evil. It had to be changed with Nadla coming, but their enshitification is just keeps getting worse and worse. What on Earth is this.
This muddle of an article makes it totally unclear to me if this GUID is attached by the AI generation call or every image I edit in MS Paint. I'm going to assume the former unless they release a clarification.
Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.
Assuming the watermark works like the upcoming AI watermark for text, then it uses the content's entropy to embed the information. An all-black image doesn't have much entropy, so it's unlikely you'd find anything.
If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitable devices and used to decrypt as much content as possible before the device gets blacklisted entirely (harming all legitimate owners in the process).
I've done this btw. I went for the Pixel Camera app since they were the ones bragging the hardest about their "security". Writeup + PoC should be dropping some time tomorrow. Despite 90+ days from initial report, it remains unpatched.
I don't think that that's a good idea, because it implies trust when there actually isn't any.
Being signed with something just means that whoever has that key could've done that. That might be the owner of a specific camera, but it might also be the camera manufacturer, anyone else in the supply chain, or anyone who dumped the key.
Imagine fake evidence signed with the same key as your camera uses being used in court against you. And the court believes it because it has this signature attached and those computers are very secure and all.
Exactly that will happen. Not widespread, of course, but it will.
The hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”
I was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me.
But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.
Presumably the OP is proposing something like a TPM attached to the image sensor that signs the sensor output or something like that. You can’t sign it because you can’t get the key out. The key could be per-camera and be a published list.
I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.
That's assuming they don't just have a backdoor inserted expressly for this purpose. Now only the rich or powerful can produce an "authentic" recording of an event and the same system can be used to hunt down whistleblowers and political enemies by looking up who bought the camera.
Keys could be stored in something like TPM on Camera, and could sign the image. The key could then be verified from the camera itself to prove the authenticity of the image.
If we as a society deemed it necessary, the camera manufacturer could also provide a list of keys for devices they have manufactured. And an image/key could be provided, and the manufacturer could verify the authenticity that way.
The TPM signing could be tied into the sensor hardware itself, making it difficult, but not impossible, to sign arbitrary images with the TPM.
The point of the key (as the for some reason dead comment points out), is not to prove who took the photo, but what device took the photo. Just as if someone stole a hardware token with a PGP key on could impersonate the owner. The key itself doesn't prove a person, just a device.
If a key was reset, a revocation of the original key could be issued, showing that the key was associated with the device for this particular time span. And then the new key registered.
This is ripe for abuse though, so resetting a TPM might not be accepted for this use case. I'm not certain in which case you'd want to reset a TPM for this use case though. Unless you took enough photos with the device to risk a birthday attack if you were using something like ECDSA.
In the imaginary dream world that Adobe, Google et al live in, the final file does indeed have a signature.
Each piece of software in the chain must use TPM-like technologies (yes, even GIMP) to make sure it's running a "legitimate" build of the software, on "legitimate" hardware, and re-sign the file at each step along the way (using keys provisioned during some flavour of remote attestation flow, or using a RA-authenticated remote-signing oracle).
The final file embeds every preceding manifest, so you can "verify" all the way back to the original.
If this all sounds patently unworkable, that's because it is.
OK, but given that GIMP is a general purpose tool, what use is the signature if all of them verify it, when I can drastically change the image to whatever I want it to be?
The manifests at each step can embed a thumbnail (although this is optional, iiuc!), so looking at the thumbnail history it should be obvious that the edit was significant.
When I was in photography class in college, I created backplates in photoshop for still life portraits of small trinkets I was photographing. The photos were taken on black and white film and developed in the campus dark room. Led to some impressive photos. In our class's critiques, I explained how it was done. A lot of peers went from impressed to meh'd. The point: the black and white film laundered the new-age manipulation, and a digitally signed photo from a modern camera remains vulnerable to the same premise.
No. You'd only ever be able to show that key material belonging to $specific_camera was used to sign/mark the image.
Was the camera manufacturer breached? Did somebody on the factory floor steal some keys during the provisioning step? Or did somebody build their own photo-sensor simulator and plug _that_ in to the camera's motherboard to feed it a "real" image? Before going _that_ far, just point the unmodified camera at a sufficiently high resolution display...
"I think it would be nice if all pens added a unique isotopic tracer signature to their ink. You could tell exactly who wrote everything."
"I think it would be nice if all typewriters had their unique fine-detail type artifacts registered with the government. You could tell exactly who authored a given document."
I think it would be nice if you took these ideas back to Stalinist Russia where they belong.
I'm honestly surprised they don't upload the entire image to apply the watermark server-side, to the point that I'd like someone else to repeat this investigation and confirm it's not happening.
Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".
This is a standard mark for AI generated images using a format agreed upon by most of the GenAI world to help people not get tricked by fake images. It’s exactly according to spec, is widely announced, and is widely used.
It’s shocking how immediately off the rails this topic went with the conspiracy crowd.
I admit it’s a while since I’ve used windows, but it’s such a shock to hear that MS Paint isn’t just a point and click pixel coloring app anymore. It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.
I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.
If you read the article instead of the headline…….. it’s adding a fairly standard mark to AI generated images to let’s others know, in the same manner a giant swath of the GebAI industry has agreed to.
I think their point is that paint shouldn’t have any GenAI features (or any new features other than compatibility)
Yes, using original paint in 16 colors saved to PCX in 640x480 should be enough for anybody.
Or we could let owners of properties add features as they see fit.
I don't so much mind about Paint, but modern Notepad is completely unusable. We had "Notepad but with Rich Text formatting" -- it was called WordPad and no-one used it so they eventually deleted it.
Even Notepad isn’t a dumb app anymore! They made breaking changes after 40 years so it has autocorrect, rich text, and Copilot.
If I wanted all of that, I would have used a different app!
The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.
> a unique identifier into every image you create
Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]
Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.
In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.
[0] https://www.eff.org/issues/printers
> It's very likely your printer is secretly adding marks to the page
It's most likely how the FBI caught NSA leaker Reality Winner:
> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.
https://en.wikipedia.org/wiki/Reality_Winner
and then in few years a new mono-mustachioed or mono-browed leader will emerge who declares memes a blasphemy punishable by death and will call up all the telemetry gathered to punish all involved.
"I don't worry because I have nothing to hide, based on my perfectly accurate perception of today's political and legal forces in a state and country which will stay static forever."
Exactly. Forget the AI aspect, this is entirely to identify users for any purposes they deem necessary. People are ignoring the surveillance state aspect of this. Reminds me of the device id debacle they have attached to their outbounds Windows network calls
Can this also be weaponized? Get an innocuous image from someone you don't like, grab their GUID, add it to another image, sent it to the thin skinned politician in power.
> every image you create
*with the help of AI*. Does in fact make a difference.
While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that.
I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.
Does it trigger on non AI images? The post doesn't say so at least.
It does kind of say: The GUID is coming from the moderation endpoint, which is hit when you generate a local or cloud AI image based on your prompt. If there is no prompt, there is no endpoint, and likely no GUID.
Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
The fact that local ai image generation uses an online moderation API is a bit worrying too....
Why not just mod the app to not call this API?
I don't think they use a model that would run smoothly on most hardware that normal people use.
Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.
Since the watermarker runs locally, you could also do the reverse: generate some porn with a different open model, then run that code to tag it as "Content watermarked by Microsoft Responsible AI"
Probably both so they can change what they censor without waiting for you to run windows update and also so they can collect your information (IP, timestamp, etc) to associate with whatever you did
> address
Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.
Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.
Windows 11 effectively forces users to register with a Microsoft account. Once that's established, all it takes is for an unaware user to fill out an e-commerce form and save an address for auto-fill.
> Windows 11 effectively forces users to register with a Microsoft account.
While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.
> Windows 11 effectively forces users to register with a Microsoft account.
It takes zero effort to bypass that with Rufus, if you set up your own pc.
My comment was in regard to the average PC user. The kinds of folks who would never install an operating system and would likely agree to use Edge while signed in to their Microsoft account.
Microsoft has also been pushing hard for Recall and recording all local activity forever. Not impossible to imagine that anything looking like a home address “somehow” gets ingested in the telemetry.
A bypass existing is good, needing a bypass in the first place is still a problem.
> Make sure you register mailing addresses with your credit card institutions
Sorry for a dumb question but what would one use as a mailing address? Rent a PO box, or use a mail forwarding service, something like that?
Any of a number of virtual mailbox services which can receive mail for you, e.g. anytimemailbox.com but there are several. You can either pick up in person, or they offer services like mail forwarding, opening and scanning, etc.
Besides privacy against leaking your sleeping-address to businesses, they're also convenient for avoiding package theft if that's a problem in your area, and receiving/forwarding mail if you travel a lot for extended periods of time.
I'd recommend against PO boxes because (1) they get rejected by some services (2) UPS and FedEx won't deliver to them.
Because these businesses have to register as CMRAs and you have to sign a notarized form for them to legally receive mail for you, some services will still detect it and not let you use the address, but my experience for the most part has been that most US financial institutions let you enter a "residential/legal address" (no CMRAs allowed) and a "mailing address" (CMRAs allowed) separately, and the mailing address usually becomes your billing address.
Or.....Install Linux and bypass all this stupidity.
They will move faster to track each and every one of you, all the while shoving ads and garbage down each of your respective machines... and you all pay for it?!
Surely I am safe running VSCode on my Linux machine. No chance it would upload a bunch of personal telemetry without my say so.
Use VSCodium. It's the FLOSS branch with Microsoft tracking shit removed.
https://github.com/VSCodium/vscodium
You still want the virtual mailing address for other reasons honestly. Even if your os isn't tracking you or leaking things giving your real address to any business could lead to it being leaked because no one cares about security, etc. If that's in your threat model you should be using a good proxy mailer
Perhaps so. But the problem at hand here is that MS Windows has so lost the plot of being an OS for users, to ABUSING users.
All these fixes and repairs ignore the fact that abusing people pays. Surveillance capitalism pays, and provides a revenue stream for Microsoft to further exploit.
The only way to win is not to play.
This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.
> This is broadly impractical for the average citizen.
No it's not. Sign up for a virtual mailbox for $15-$25/month.
> A scalable solution would be to make this sort of thing illegal.
I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.
It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.
> No it's not. Sign up for a virtual mailbox for $15-$25/month.
Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.
It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.
At least in the US it's not even a good method either. Own a house? Boom, your information is publically available and you won't be able to remove it without a court order, which in most states is impossible to get. In most states, you don't even need to own a house, decide to vote? You information again is publically available. Tie your real name to a single account to purchase something, and you are trackable. Want privacy? You'd need to remove yourself from the internet, dump your phone, destroy your ID and work underground for cash. We can push against iot, and people have been forever, but at the end of the day the government will always they have a vested interest in being able to identify it's citizens.
> Sign up for a virtual mailbox for $15-$25/month.
That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.
I think they meant make what Microsoft is doing illegal?
or make it illegal to ask for address, etc. definitely a little more effective than mailboxes
Ahhh okay if that's what they meant, then yes, I 100% agree and apologize in advance.
I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.
I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.
> No it's not. Sign up for a virtual mailbox for $15-$25/month.
You are out of touch.
They (the ones wanting to make privacy illegal) are just the ones that want to develop the tools and consume the data for it because it'll be good for their resume or some bullshit, or they're just intrinsically broken humans.
> IANAL but they are not a government or financial institution and do not have a right to that information.
As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.
Seems to me that it's a challenge to make an apple account without adding a credit card to your account as well. A carfully chosen Linux distro (so many options!) is the way to avoid the brunt of these privacy issues, lots of open software calls home in some way or another so user beware!
No - there is a huge difference between "this AI created this image" and "this user did it" - the first we need more of, and the second is a big privacy concern. The article does not say anything about identifying a user.
a GUID isn't an indicator, it's a fingerprint.
so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.
to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.
Article literally says it adds a guid, not a binary field indicating that the image is ai generated.
A guid isn’t a user id, if it is in this case, it’s an abuse of how guid is used, at least colloquially. I haven’t read enough to understand if it is user / machine id, I.e. only globally unique in the sense it’s a globally unique entity identifier.
Microsoft Can Track Users via a Windows Device ID https://news.ycombinator.com/item?id=48815196
Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239
They stated the GUID is used to identify the prompt used to generate the image. How are you confused as to not being able to identify the user?
"I haven’t read enough to understand". Oh, now I know the answer to my question
Well yeah they know my John Doe info
add your IP, location, provider, computer specs, dimensions, screen info, nearby devices, etc etc etc
Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.
This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.
Why would the EU possibly object to this? It is exactly what they want.
> This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.
At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."
But the EU mandates watermarking of AI content.
As the article explained, the EU does not mandate a prompt-specific GUID, only the ability to identify the content as AI-generated. The highly privacy-invasive level of provenance tracking which Microsoft has added goes beyond the EU’s new mandates.
Watermarking ai generated stuff is mandated by EU
Do they require the watermark to be a unique token that can be associated with PII?
This a variant of the provenance scheme: C2PA its implemented by all major Camera maker, and Google it seems, Apple support it with 3rd party apps on iPhone, but they have something called "Apple Reference Image" brewing.
Personally I think there is a good argument for being able to distinguish AI generated image and video...
> I think there is a good argument for being able to distinguish AI generated image and video...
Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.
AI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible (cannot be disabled and happens silently in the background with no user notice) watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end).
Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.
In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.
I'd like to know more about the GUID part and how easy is it so deanonymize yeah.
But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.
The article says that once converted to BMP all the metadata gets removed....so on linux:
convert file.jpg file.bmp; convert file.bmp file.jpg
It says that about the C2PA content credentials metadata, but not about the modified image pixels.
> AI-generated text warning (I submitted - but did not author - the piece)
Took me a moment to realize you're saying someone else generated it, rather than you did.
> AI-generated text warning
This seems incorrect to me. Are you basing that on the use of bullet points?
How do they add a watermark to local llm content?
I don’t understand the warning.
They're saying that the blogpost is at least partially AI-generated.
I have some better options. Stop using computers, or if you use a computer, use Linux.
Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.
Keep an eye on this.
A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.
MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.
It is quite likely that Snipping Tool is also doing this. Every camera also leaves device specific signature because of its inherent silicon sensor defects.
If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats.
See e.g. PPM format: https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/...
These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.
I had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.
I guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).
Paint.net is named after the dot net framework and is not referring to a URL or the internet as I understand it.
Paint.net actually just recently got ownership of paint.net, it only took 22 years: https://www.xda-developers.com/after-22-years-paintnet-downl...
ah, right, i vaguely recall that now. But why/how would it know AI was used, outside of a local LLM, weird it would say that AI was used (unless it's referring to the software itself).
MS Paint wanted to add the "this is AI" tag on a picture they just resized. OP didn't like that, so they went and downloaded Paint.Net to avoid having to deal with (MS) Paint shenanigans.
Ah, that makes more sense. Thanks for pointing it out. I guess MSPaint scans for that now on Windows 10 and 11, or just 11?
I was stating that MS Paint mis categorized a Print Screen screenshot as AI generated when pasted. Which pushed me to install PaintdotNet onto my laptop instead.
They aren’t saying that, paint.net is an open source application, Paint is the descendant of MSPaint.
Paint.net is freeware, but it is not open source.
I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.
You can watermark AI without leaking who did it. That's just using AI to add yet another layer of user tracking.
Well if that's any reassurance, you can generate a meme picture using AI, then paste it into Paint to add some funny text. That way you can get the best of both worlds.
Googling you can see the source code for watermarking here https://github.com/microsoft/InvisMark
This is gonna sound a bit harsh, but from the outside it genuinely looks like Microsoft is actively looking for new ways to degrade and humiliate their users. (And having no trouble finding them!)
Interesting find. Overall it makes sense from a deepfake-fighting perspective and EU requirements. But what's concerning is that users aren't really told about this, as far as I can tell. Would be cool if someone checked if it can be bypassed, like swapping the DLL or intercepting the API call. But yeah, it's another step toward every digital trace becoming personally identifiable...
As a linux fan I just love all these changes Microsoft have been introducing
Misleading title: the watermark applies to AI generated/edited images. That includes local models.
Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no".
Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.
Don’t care.
There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.
Kind of sad how all these technical blogs just reek of Claude text these days. Hard read when it’s obviously padded by an LLM…
This reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)
You have no idea how deep this rabbit hole goes. Search for EFF printers secret tracking.
Virtually all commercial printers embed an invisible identifier on every page printed.
Now I need to see if agentic reverse engineering of printer firmware can actually remove that "feature" for good.
Virtually all color laser printers and copiers.
It was about money anti-counterfeiting.
https://en.wikipedia.org/wiki/Printer_tracking_dots
There is always a legit reason. It’s just never the only reason.
Not only USSR.
I wonder whether Arthur Conan Doyle had the idea before the police started using typewriter typeface wear and tear for forensics.
Sure, try to scan, photocopy, edit in photoshop or print US money today.
the GUID is the giveaway that it's not about protecting artists, it's about being able to prove provenance later. nobody embeds a unique id in a local file for the user's benefit.
These days i cant recommend Windows to anybody. Even gamers should move to linux.
Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise.
A sudden knock on your door might happen because of an ambigious search/propmt.
There's a huge number of gamers moving to things like CachyOS. Some are stuck because of Valorant, LoL or Battlefield DRM, but it's a big move lately.
> Some say "i do nothing illegal" "have nothing to hide".
I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.
The best response is always:
"That's not up to you."
When people claim they have nothing to hide, always point out that's not up to their determination. That freaks them out, it disarms their shrink-from-confrontation move.
And you can point it out super fast, in a plain six word statement. No need to launch into a deep discussion unless prompted.
Alternatively, simply respond with: yes you do. When they reply: "what?" - "every single thing you have ever done wrong across your entire life." Everybody has done something they would prefer to keep hidden, the cowards just lie about it.
Just because I have nothing to hide doesn't mean I have anything I want you to see.
People are entitled to privacy because they enjoy it. No further justification is needed.
Anyone got tips or guides to starting a linux OS that protects privacy without sacrificing utility?
Considering putting linux on a 2nd PC
Essentially any Linux distro protects privacy. You'd kinda have to go out of your way to find one that doesn't, because there's no online account connected to your install for any of them.
If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.
Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.
omarchy.org
many games work flawlessly on Linux now. enough to make the switch anyways. a lot more than on mac.
Others say
"I need it to work on a random Thursday, not wait for fsck after ever reboot"
https://github.com/IceWhaleTech/CasaOS/issues/1104
Why have you linked a bug report for a niche userland application that may be causing disk corruption as evidence against linux reliability? That seems like a pretty uninformed conclusion.
This isn't a one-off niche user. Just look for more of these. You will find them.
https://www.reddit.com/r/archlinux/comments/1cvwo93/arch_run...
This supports my initial reply. This was an f2fs bug in a bleeding edge kernel released only seven days earlier. The thread suggests perfectly reasonable mitigations, especially for an arch user: use the lts kernel or downgrade to 6.8.9.
If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.
I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.
Ok fair point, here's plenty more of the same on stable. My point is Linux is always fine right until it isn't. Then you're back to a day of debugging your update.
https://bugzilla.kernel.org/show_bug.cgi?id=218770
https://lore.kernel.org/linux-f2fs-devel/20240409203411.1885...
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07280.html
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07260.html
https://bugzilla.suse.com/show_bug.cgi?id=1226043
https://lists.opensuse.org/archives/list/bugs@lists.opensuse...
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/15478...
https://bugs.launchpad.net/bugs/63175
I have the same issue on Windows 11. It's been bugging me to press a button or "check my drive" on every startup for at least half a year, no matter how often I let it run the check...
Same thing happened to me recently
Genuine question: does Linux have an AI image editor as easy to use as the win11 paint/photos?
This is not ok.
How resistant is it to dithering? Can you just add +-1 randomly to each pixel r,g and b values and throw it off?
Probably not, if it's this kind of thing: https://en.wikipedia.org/wiki/Perceptual_hashing
awesome breakdown of the process you took. reverse-engineering is crazy now with AI. IP is dead
this also reminds me of what got me hooked on CS in the first place: a simple java steganography app in cmsc150
Thanks Microsoft, for adding my signature so I won't have to claim authorship when it ends up in a museum in 200 years, and the NSA archives are declassified for art historians filing a FOIA in 2226, who find out, "yep, it was from his PC."
Ms paint slop being hung in a museum? Now that's a dystopian future!
No, I wasn't suggesting that. I was saying that if there was digital art (human made) aesthetically significant that a curator would want to display it in a museum, Microsoft's GUID supplied to a data collection agency would make it possible to retrieve if ever/whenever that data were declassified (assuming it isn't purged)
It's possible a very bad curator with a terrible taste in art might select slop to display, but I was refering to "fine art" or at least finer art that is digital.
Ya know, this would probably be pointless but if I were a programmer (I'm not -and refuse to be a vibe coder) I'd probably just grab appropriate libraries and make my own replacements for this shit. GLTK+ (?) is an obvious choice to use for recreating mspaint, and to replace notepad -I was told making a simple editor was an excercise they have you do when you learn programming to begin with?
I already replaced the 'solitaire' games suite with pysol running on WSL2 and it's a vast improvement!
tldr -if MS is going to screw us, why don't we mitigate it by using replacements?
Until proven otherwise via open-source audits and reproducible binaries, you should assume that all commercial photo editing software is embedding watermarks in any way they can get away with. This includes the professional software that you pay quite expensive licenses for. You should also assume that even if they're not today, they will eventually be coerced into doing so, in the same way that printers embed tracking dots.
Interesting. I really didn't think watermarks would end up going anywhere, but maybe with enough adoption we can have easy ai generated content flagging after all?
Not every generative AI model will watermark. Especially not adversarial and disinformation models.
So as usual, exactly the things you want it to work on it won’t.
I mean, workarounds wouldn't be hard, just annoying, anyway. Like an extra step or two (take a screenshot, change the image format, wipe the metadata; or print, take photo with camera, clean up in something like gimp, same other steps).
It actually might make the new horrible world even worse. Imagine the populace getting used to a AI image detector flagging things as fake using this fairly easily defeated GUID marker system. Most people are just making memes or cat videos and don't even try to remove this so eventually the populace starts to believe these things actually work.
Now some one slightly more sophisticated starts creating deepfakes of a woman and uploading them or fabricating video of an political event without this marker. The subject protests it's fake and AI generated but a loud majority of ignorants feed it into Microsoft AI detector and call you a liar and say it's confirmed real. Most people don't know any better and eat it up because a computer said so.
With every new thing Microsoft goes trying so hard to come out as the good person, but they just cannot help themselves but to inject their evil. It had to be changed with Nadla coming, but their enshitification is just keeps getting worse and worse. What on Earth is this.
This muddle of an article makes it totally unclear to me if this GUID is attached by the AI generation call or every image I edit in MS Paint. I'm going to assume the former unless they release a clarification.
Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.
Assuming the watermark works like the upcoming AI watermark for text, then it uses the content's entropy to embed the information. An all-black image doesn't have much entropy, so it's unlikely you'd find anything.
> Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.
Did it?
Solved by not using closed source SW, period.
Solution: Don't AI generate images! I think this is a good way to discourage people from making slop.
I think it would be nice if all cameras digitally signed pictures. You could prove the photo was real.
If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitable devices and used to decrypt as much content as possible before the device gets blacklisted entirely (harming all legitimate owners in the process).
I've done this btw. I went for the Pixel Camera app since they were the ones bragging the hardest about their "security". Writeup + PoC should be dropping some time tomorrow. Despite 90+ days from initial report, it remains unpatched.
Some proof: https://verify.contentauthenticity.org/?source=https://retr0...
I could also paste a privkey + cert chain in here but el goog's lawyers might not like that.
I don't think that that's a good idea, because it implies trust when there actually isn't any.
Being signed with something just means that whoever has that key could've done that. That might be the owner of a specific camera, but it might also be the camera manufacturer, anyone else in the supply chain, or anyone who dumped the key.
Imagine fake evidence signed with the same key as your camera uses being used in court against you. And the court believes it because it has this signature attached and those computers are very secure and all.
Exactly that will happen. Not widespread, of course, but it will.
Imagine today where a photo is submitted as evidence and the court believes it even without signatures.
Precisely. Now take that, but glue a "the machine has cryptographically proven that this is legit" to that.
Yes, it's a disaster waiting to happen.
The hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”
I was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me.
But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.
Signing doesn't really achieve anything when an attacker can manipulate the device into signing arbitrary pixels.
Nobody knows how to make a camera that can distinguish honest vs deceptive photons.
And then some incriminating photo is made with your forged signature. "Not like that, not like that!"
What would prevent someone from applying the same algorithm on a computer to sign arbitrary images?
Presumably the OP is proposing something like a TPM attached to the image sensor that signs the sensor output or something like that. You can’t sign it because you can’t get the key out. The key could be per-camera and be a published list.
I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.
Please note: A well-funded organization, like a government, can derive the keys from the TPM hardware using an electron microscope.
Also note that there are plenty of viable attack methods that don't even require key extraction, such as asking the TPM to sign arbitrary data.
That's assuming they don't just have a backdoor inserted expressly for this purpose. Now only the rich or powerful can produce an "authentic" recording of an event and the same system can be used to hunt down whistleblowers and political enemies by looking up who bought the camera.
Keys could be stored in something like TPM on Camera, and could sign the image. The key could then be verified from the camera itself to prove the authenticity of the image.
If we as a society deemed it necessary, the camera manufacturer could also provide a list of keys for devices they have manufactured. And an image/key could be provided, and the manufacturer could verify the authenticity that way.
The TPM signing could be tied into the sensor hardware itself, making it difficult, but not impossible, to sign arbitrary images with the TPM.
If I steal your camera while you're on vacation, do I then gain proof of ownership of your photos?
If I need to reset TPM, how do I reclaim photos I took previously?
The point of the key (as the for some reason dead comment points out), is not to prove who took the photo, but what device took the photo. Just as if someone stole a hardware token with a PGP key on could impersonate the owner. The key itself doesn't prove a person, just a device.
If a key was reset, a revocation of the original key could be issued, showing that the key was associated with the device for this particular time span. And then the new key registered.
This is ripe for abuse though, so resetting a TPM might not be accepted for this use case. I'm not certain in which case you'd want to reset a TPM for this use case though. Unless you took enough photos with the device to risk a birthday attack if you were using something like ECDSA.
Finally a legitimate use for NFTs. /s
Or, you know, using the totally-real-picture camera to take a photo of an AI-generated scene?
Asymetric keys
How exactly would this work?
People take RAW photos. Load it up in a RAW editing tool. Manipulate it. Then load it in Gimp. Manipulate some more.
Will the final result have the signature?
And if it does, what use would it be?
In the imaginary dream world that Adobe, Google et al live in, the final file does indeed have a signature.
Each piece of software in the chain must use TPM-like technologies (yes, even GIMP) to make sure it's running a "legitimate" build of the software, on "legitimate" hardware, and re-sign the file at each step along the way (using keys provisioned during some flavour of remote attestation flow, or using a RA-authenticated remote-signing oracle).
The final file embeds every preceding manifest, so you can "verify" all the way back to the original.
If this all sounds patently unworkable, that's because it is.
OK, but given that GIMP is a general purpose tool, what use is the signature if all of them verify it, when I can drastically change the image to whatever I want it to be?
The manifests at each step can embed a thumbnail (although this is optional, iiuc!), so looking at the thumbnail history it should be obvious that the edit was significant.
Yeah - I totally would not support that!
When I was in photography class in college, I created backplates in photoshop for still life portraits of small trinkets I was photographing. The photos were taken on black and white film and developed in the campus dark room. Led to some impressive photos. In our class's critiques, I explained how it was done. A lot of peers went from impressed to meh'd. The point: the black and white film laundered the new-age manipulation, and a digitally signed photo from a modern camera remains vulnerable to the same premise.
> You could prove the photo was real.
No. You'd only ever be able to show that key material belonging to $specific_camera was used to sign/mark the image.
Was the camera manufacturer breached? Did somebody on the factory floor steal some keys during the provisioning step? Or did somebody build their own photo-sensor simulator and plug _that_ in to the camera's motherboard to feed it a "real" image? Before going _that_ far, just point the unmodified camera at a sufficiently high resolution display...
do you believe this should be mandated by regulation, or voluntarily offered by manufacturers as a value-add feature? ("all" implies the former.)
"I think it would be nice if all pens added a unique isotopic tracer signature to their ink. You could tell exactly who wrote everything."
"I think it would be nice if all typewriters had their unique fine-detail type artifacts registered with the government. You could tell exactly who authored a given document."
I think it would be nice if you took these ideas back to Stalinist Russia where they belong.
I'm honestly surprised they don't upload the entire image to apply the watermark server-side, to the point that I'd like someone else to repeat this investigation and confirm it's not happening.
Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".
It is already fairly trivial to write a universal watermark remover, an LLM can do it for you.
Without access to the code, I imagine it'd be extremely difficult even with unlimited API calls to the watermarker.
Yet another reason to switch to Linux.
My honest reaction: https://files.catbox.moe/4ylzsq.png
This is a standard mark for AI generated images using a format agreed upon by most of the GenAI world to help people not get tricked by fake images. It’s exactly according to spec, is widely announced, and is widely used.
It’s shocking how immediately off the rails this topic went with the conspiracy crowd.