logoalt Hacker News

Spymarks, Not Watermarks

460 pointsby possibilisticyesterday at 11:03 PM117 commentsview on HN

Comments

Retro_Devtoday at 2:49 AM

Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't watermark, an image compressor we are certain can't watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered/announced) by saying that our memes won't be reposted, images or work stolen, etc... but honestly I'd rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.

show 4 replies
xp84today at 12:21 AM

These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.

First the low-end laptops and phones (and probably later, most of them) will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home. I assume this is something Apple will, to their credit, refuse to do[1] but I don't think other OEMs will have any qualms based on what they already do with their TVs.

[1] (though they don't do this kind of thing out of altruism, but because their cash cow is app store rents and fat hardware margins, not third-party advertising.)

show 3 replies
paweladamczuktoday at 7:22 AM

It increasingly seems to me like the only way to prevent value to be extracted from myself is to stop engaging with new tech altogether.

show 2 replies
rbtmstoday at 10:03 AM

Thanks for the article. I hadn't heard of SynthID before and it's good to.

It's a shame however, how low quality and vibecoded the live examples are. The first example says "Toy example; not SynthID.", the second one is a generic spectrogram and the third one has an identification space too small to be useful (173 in decimal). I was hoping to see more realistic scenarios to learn how these new watermarks are being applied, instead of generic steganography.

Morromisttoday at 1:27 AM

The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.

Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be replaced with "winding" like "her gently curving thighs" with "her gently winding thighs"

But I'm sure there are some intricacies I don't understand. Anyway, very cool website, thanks for sharing it~!

show 2 replies
swiftcodertoday at 7:36 AM

A number of prominent corporations used to embed these in the background images of their internal webpages, so that leakers could be identified from the screenshots they shared. Caused a whole fun adversarial loop where journalists had to transcribed and/or redraw screenshots before publishing to avoid exposing the identity of leakers...

show 1 reply
gorgoilertoday at 5:15 AM

I feel like there’s some security engineering calculus that would be useful here?

You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?

There must be value in having a visible vs an invisible watermark, or in declaring that a work is watermarked without revealing the hidden mark, or having two marks — one that is publicly verifiable and another that is hidden?

If the process itself can be defeated through adding entropy (or more generally by revealing the watermark algorithm) then is that not security through obscurity, which is to say it is a one-shot rather than a general system that is doomed to become obsolete over time?

Something feels off about a technology based on being hidden but whose only value is in being revealed but I feel dumb for not being able to be more specific about what feels wrong! It could simply be that anyone who can verify the presence of the watermark also now has a tool to tell them when they’ve successfully scrubbed the watermark off the work, so the verify tool has to be kept secret which in turn limits its usefulness.

show 2 replies
encrypted_voidtoday at 6:31 AM

Spooky stuff. This will take surveillance to a whole new level. This is basically email read-receipt tracker, but for all of the digital content. They will know the whole trail - from originator to how it spread. Who read what and when. Big brother will always be watching.

ameliustoday at 10:11 AM

This is what we should have used so we could practically claim the output of AI ignored our copyright.

world2vectoday at 9:21 AM

Way offtopic but I like the light/dark mode of that website with several very sensible choices.

voidUpdatetoday at 6:58 AM

> Spymarks are certainly not great for whistleblowers or anyone who doesn’t want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about.

How do you spymark text that someone else wrote? You can't change the words or they'd notice

show 1 reply
Enneatoday at 7:42 AM

Reminds me of Blizzard embedding data inside World of Warcraft screenshots (link goes to a small write-up from 2012 in a forum focused on video game cheats; sorry, could not find a better source): https://www.ownedcore.com/forums/world-of-warcraft/world-of-...

itaketoday at 8:11 AM

Apple rejected my app for removing c2pa metadata.

I don't think its fair to say that metadata on apps will be safely removable in the future.

ForHackernewstoday at 10:30 AM

> A spymark is a hidden signal that makes your work traceable without your knowledge or consent.

It's not "your work" it's the bloody AI's work! That's the whole point.

edg5000today at 2:06 AM

A lot of the discussion is about AI vs no AI, which is valid, but I care about local AI vs centralized AI. Hopefully hardware will become more affordable. A hopefully irrational fear I have is that it'll be like house prices: only ever goes up.

show 1 reply
miladyincontroltoday at 6:36 AM

Tbh I usually just apply a 'watermark' of jpg compression to images, even if yes the original image never lives as jpg. Easily viewable with ELA even if saved as other formats, resized, etc.

layer8yesterday at 11:50 PM

Weirdly the article doesn’t mention steganography. Arguably it isn’t quite the same, because the aim of steganography isn’t typically to add an identification, but something like “steganomark” would seem to be fitting.

show 1 reply
injiduptoday at 5:22 AM

Wouldn't synthid type watermarking fall under GDPR. Personally identifiable information attached by third party to content in the expectation that it would be published and trackable?

show 1 reply
pavo-etcyesterday at 11:33 PM

I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.

Tech like SynthID I see a net positive especially since it doesn't degrade text quality. I dream about a browser extension running at all times that makes text more translucent based on the confidence of LLM writing[0].

This article's suggestion of using it to unmask whistleblowers is very interesting and not something I'd thought about though. Still not convinced that spymark is a better name though.

[0]: Sean Goedecke's Deckard is close but it would rather invisible than bright red https://www.seangoedecke.com/deckard/

show 7 replies
shevy-javatoday at 12:10 AM

> A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership.

We also recently had this with LG spy-TVs. Cars here in the EU also spy on people, allegedly to show how alert they are. Perhaps they sneakily upload that information somewhere ... Facebook also has the spy-glasses now. People getting angry about Flock-spy-cameras.

It seems we are now in the age of spying of everyone at all times. Future spying will be done via even smaller devices.

show 1 reply
minimaxirtoday at 12:33 AM

Out of frustration with SynthID being closed-source with weird dubious ways to verify if an image has the watermark, I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be hidden. The intent is for non-corporations to use it as a defense against the use of spying/AI by making it easy for normal people to prove providence, but I have a feeling nowadays most are not going to see it that way so I am unsure if I will release it.

show 2 replies
codedokodetoday at 9:00 AM

This is another reminder that commercial companies will always rat you out and betray.

bronlundtoday at 5:48 AM

It's like that fart gas trail, but for machines :D

r3trohack3rtoday at 5:41 AM

Reminds me of the micro patterns from inkjet printers

https://en.wikipedia.org/wiki/Printer_tracking_dots

show 1 reply
viccisyesterday at 11:27 PM

Watermarking has referred to this "spy" use case for quite some time. Digital items purchased for download often have them, for example. Even before the rise of digital downloads, screeners for movies had them.

suopspacestoday at 1:35 AM

Can my friend print adversarial yellow doots and such?

silverForkyesterday at 11:28 PM

if it is specifically about pictures then wouldn't an analog copy clean it up? What about adding new spymark on top of it?

If it is text, copying text alone and not the file will it not remove it? Massage the text with Ai and vola spymark gone, don't you think?

show 1 reply
Jeff2Servetoday at 10:42 AM

[dead]

vladsiutoday at 4:13 AM

[dead]

in_absentiatoday at 1:30 AM

[flagged]

show 2 replies
mirelahmdyesterday at 11:15 PM

There have been quite a few similar

the_gipsytoday at 7:23 AM

> Why give it a new name?

> > Because I always wanted to coin something. Please don't forget me.

TeMPOraLtoday at 6:14 AM

Privacy is always the most popular for some reason, but also the least consequential and relevant angle in the real life.

Watermarks are not "spymarks". They're DRM. I wouldn't worry about advertisers tracking conversions. I would worry about the "analog hole" being closed. Think of no longer being able to even photograph your phone screen, because pixels on it carry digital watermark that's robust enough to survive being photographed - I.e. the kind currently used to tag AI generated images - and then every phone and computer refusing to display resulting photo because the app disallowed capturing its pixels.

show 1 reply