Watermarks that spy on users are no mere watermarks

697 points•possibilistic•9 days ago•171 comments•

171 comments

Retro_Dev9 days ago
Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't watermark, an image compressor we are certain can't watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered/announced) by saying that our memes won't be reposted, images or work stolen, etc... but honestly I'd rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.
dragonwriter9 days ago
Spymarks an application of steganography, not a different name for it.

> On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced

That doesn't help with things like the typical use of SynthID where the spymarking is done by the same process generating the content, so there is never a clean comparator. (It also wouldn't be useful anytime it is inplemented as part of a transformation—compression, etc. —step, for the same reason.)

Normal_gaussian9 days ago
Additionally, verifying that your generator doesn't add such a mark is practically impossible for the majority.
speerer9 days ago
> ... particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open.

This has been going on for a while with Facebook. They seem to embed custom metadata tags so that images shared outside the platform can be traced back:

https://stackoverflow.com/questions/31120222/iptc-metadata-a...

wodenokoto9 days ago
> Spymarks just seem like another word for https://en.wikipedia.org/…

Stop using links instead of words. Your comment is literally unreadable without going on to other websites.

teitoklien9 days ago
idk, loved their comment. Stop giving "Stop" orders to others.

:D

amelius9 days ago
> Stop using links instead of words.

No, the words could contain steganography. Use links to be safe!

zxexz9 days ago
the word is the last segment of the url. very readable
azatom9 days ago
Stop using link mutiliating tools!

What will be the next? I will be unable to see the domain of a link on hover/longtap and have to trust random links like on a search engine?

MUTINY against hn!

gorgoiler9 days ago
(The word is “steganography”.)
stillsut8 days ago
I actually wrote a library to do stego with LLM outputs last year and it turned out to be an almost exact implementation of the Anthropic watermark algo.

Repo here https://github.com/sutt/innocuous. It works with last year's llama.cpp. Check out the "Use Cases" and "How it works" sections in the readme if you're interested.

pjc508 days ago
This is a straightforward example of how the positive or negative valence of a piece of tech depends entirely on how it's used.

You just need to address three questions:

- who controls what information is going in? (that is, what is the process by which the tech companies who control all the tech are using it)

- who controls what information is coming out? (that is, is the steganographic format open enough that anyone can read it, or does it depend on having a key)

- what legal regulation is this subject to? (does sneaking individuals name and address into their photographs incur you massive GDPR liabilities when it is discovered?)

Note that there's a widespread precedent: https://en.wikipedia.org/wiki/Printer_tracking_dots

xp849 days ago
These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.

First the low-end laptops and phones (and probably later, most of them) will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home. I assume this is something Apple will, to their credit, refuse to do[1] but I don't think other OEMs will have any qualms based on what they already do with their TVs.

[1] (though they don't do this kind of thing out of altruism, but because their cash cow is app store rents and fat hardware margins, not third-party advertising.)

qurren9 days ago
Apple is just Stockholm Syndrome at scale. I wouldn't trust anything they say about privacy, especially given how closed their ecosystem and hardware is.
BlaDeKke9 days ago
They lacking in the AI race is an indicator that they value privacy more then competitors.
ifh-hn9 days ago
I don't think you can count apple out like that. They will likely implement it themselves though. This would be in addition to their always listening AI watch and intelligence features.
SV_BubbleTime9 days ago
Apple’s always on watch has a declared 15 second buffer for live audio, and a worse scenario of summarizing your conversations for later but.. they tell you about it proudly. They also tell you how they’ve managed to do it while keeping privacy focused.

It’s your choice if you believe them or not, I like Apple and I wouldn’t use that feature.

The pretending that this is the same thing, that Apple is sneaking something past you when they’re showing you that they’re trying to do it right is a bad faith argument.

diasdevops9 days ago
I’m a bit unfamiliar with current laws, but are there any rules that would prohibit companies from doing this in interest of user privacy? I know at this point privacy is long dead but there are certain things that do get called out and shut down.
DannyBee9 days ago
Apples largest area of growth is literally services and advertising. They even make a huge deal of it in their investor calls. Have for at least the past 3 years.

I think you may have an outdated view here

N_Lens9 days ago
“Next we just need to mark the consumer’s retina and brain to ensure our ads truly went through”
EvanAnderson9 days ago
DRM helemts - an idea whose time has come: https://web.archive.org/web/20020802214412/http://www.oreill...
plagiarist8 days ago
Google is probably unironically working on remote attestation for eye implants right now
_carbyau_9 days ago
Smart glasses could be able to tell what got through to the retina at least.

But fuck it, just brand all our brains with "SLA Industries".(fictional dystopian corporation ruling future)

leot9 days ago
As synthetic image fidelity gets closer and closer to indistinguishable from genuine pictures, what, exactly can one do to tell the difference absent something like SynthID?

Who, exactly, is the "[email protected]" whose only attributable contribution is FUD regarding SynthID (and what are their motives)?

paweladamczuk9 days ago
It increasingly seems to me like the only way to prevent value to be extracted from myself is to stop engaging with new tech altogether.
opan9 days ago
What's sad is even if you retreat to retro computing/gaming or only listen to old music, you'll likely still run into people online or at meet-ups vibe coding, making ai remixes of songs or generating music videos. Not even the old stuff is safe unless you do it offline by yourself. So you go out and try to find like-minded individuals and these spaces are still infiltrated and tainted. It reminds me a bit of radiation, how everything was just tainted decades ago, they have to salvage low background steel from sunken ships to make Geiger counters because everything else is irradiated.

I still use IRC on the daily, but someone mentions Discord at least once a month on there, and sometimes tries to whisk people away to that side. There are also people hooking up LLMs to IRC bots and joining them to channels without permission, then when you complain or kick/ban their bot you're somehow treated as the rude one. It's very hard to entirely get away from all the crap anymore.

someguynamedq9 days ago
You're going to have a hard time if you can't bear to even be around people who play around with AI
webdoodle8 days ago
I ditched my smartphone nearly 7 years ago now. I quit online gaming before that. I described it like this to the head of AI for the state of Montana: "I'm airgapping myself against how this technology will be abused."
Havoc9 days ago
I’d say it’s still possible in niche areas of the web. eg hn - clearly they have an agenda but it isn’t tracking you

So I’m not writing off tech as a whole just the adtech companies being a lost cause.

phainopepla29 days ago
We are the standing reserve
Morromist9 days ago
The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.

Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be replaced with "winding" like "her gently curving thighs" with "her gently winding thighs"

But I'm sure there are some intricacies I don't understand. Anyway, very cool website, thanks for sharing it~!

Worta9 days ago
Related to this idea, there are interesting papers that explicitly examine the adversarial case. Basically, besides the provider hiding watermarks, one could also think of an adversary training a model to exhibit this behaviour depending on the Input of the prompt. So if you use the manipulated model, not only information about the author that the platform knows is encoded, but also, e.g. one-time tokens from your email. This works surprisingly well (albeit with the naive approach still noticeable in most cases).

TrojanStego: https://arxiv.org/abs/2505.20118 Improvement: https://arxiv.org/abs/2606.09411

suopspaces9 days ago
Might one suggest "pneumatic" ?
shevy-java9 days ago
> A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership.

We also recently had this with LG spy-TVs. Cars here in the EU also spy on people, allegedly to show how alert they are. Perhaps they sneakily upload that information somewhere ... Facebook also has the spy-glasses now. People getting angry about Flock-spy-cameras.

It seems we are now in the age of spying of everyone at all times. Future spying will be done via even smaller devices.

snvzz9 days ago
People are most afraid of cameras, somehow.

The concern is valid, but microphones are far worse. They're simpler, smaller, extremely sensitive to sound and an order of magnitude cheaper, both the mic itself as well as any spying with it.

It is possible to record voice using few bytes, to send later. It's further possible to transcribe cheaply into text, and analyze said text.

And mics are already everywhere, including in devices that do not need them, as well as speakers that can be rewired by software to act as microphones.

Read the full thread on Hacker News →

Related stories