10 ms·
MS Paint and Photos inivisibly watermark even locally generated output with GUID
- ComputerGuru 1mo agoAI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible (cannot be disabled and happens silently in the background with no user notice) watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end). Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account. In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.
- like_any_other 1mo ago[dead]
- NuclearPM 1mo agoI don’t understand the warning.
- phainopepla2 1mo agoThey're saying that the blogpost is at least partially AI-generated.
- nemomarx 1mo agoI'd like to know more about the GUID part and how easy is it so deanonymize yeah. But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.
- jijji 1mo agoThe article says that once converted to BMP all the metadata gets removed....so on linux: convert file.jpg file.bmp; convert file.bmp file.jpg
- jkaplowitz 1mo agoIt says that about the C2PA content credentials metadata, but not about the modified image pixels.
- kbelder 1mo agoConversion from jpg to bmp to jpg is a lossy process, so it may obscure the watermarked pixels.
- setopt 1mo agoSounds better to do postprocess filtering explicitly? For example, adding random noise with amplitude 1/255 (which should be as invisible as the watermark), followed by a smart blur that blurs more in directions where the colors are more similar (making the blur less obvious to humans). But this is all moot really, if MS Paint is watermarking shit, it’s better to just use something else. Nothing from Microsoft is trustworthy.
- StingyJelly 1mo agoor maybe add 3 lsb noise, then let local diffusion model denoise the image. (is there something like convolutional diffusion denoiser?)
- 1mo ago
- stronglikedan 1mo ago> AI-generated text warning This seems incorrect to me. Are you basing that on the use of bullet points?
- buzer 1mo agoThere are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g. > In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly. > That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion. > After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent. Personally it didn't bother me too much.
- Noaidi 1mo agoI have some better options. Stop using computers, or if you use a computer, use Linux. Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.
- furyofantares 1mo ago> AI-generated text warning (I submitted - but did not author - the piece) Took me a moment to realize you're saying someone else generated it, rather than you did.
- frig57 1mo agoHow do they add a watermark to local llm content?
- nemomarx 1mo agoInteresting. I really didn't think watermarks would end up going anywhere, but maybe with enough adoption we can have easy ai generated content flagging after all?
- dotancohen 1mo agoNot every generative AI model will watermark. Especially not adversarial and disinformation models.
- AaronAPU 1mo agoSo as usual, exactly the things you want it to work on it won’t.
- jambalaya8 1mo agoI mean, workarounds wouldn't be hard, just annoying, anyway. Like an extra step or two (take a screenshot, change the image format, wipe the metadata; or print, take photo with camera, clean up in something like gimp, same other steps).
- deltoidmaximus 1mo agoIt actually might make the new horrible world even worse. Imagine the populace getting used to a AI image detector flagging things as fake using this fairly easily defeated GUID marker system. Most people are just making memes or cat videos and don't even try to remove this so eventually the populace starts to believe these things actually work. Now some one slightly more sophisticated starts creating deepfakes of a woman and uploading them or fabricating video of an political event without this marker. The subject protests it's fake and AI generated but a loud majority of ignorants feed it into Microsoft AI detector and call you a liar and say it's confirmed real. Most people don't know any better and eat it up because a computer said so.
- Terr_ 1mo ago> the populace starts to believe US Social Security Numbers are a useful analogy: The designers knew they weren't something anyone could securely depend on, and told people not to do it... but companies did it anyway, for their own convenience and cheap security-theater. Ultimately a lot of individual victims suffered for it. It would have almost been better if one big incident blew the "knowing an SSN means something" myth apart early on.
- sixothree 1mo agoI think it would be nice if all cameras digitally signed pictures. You could prove the photo was real.
- 615341652341 1mo agoThe hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”
- sixothree 1mo agoI was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me. But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.
- Retr0id 1mo agoSigning doesn't really achieve anything when an attacker can manipulate the device into signing arbitrary pixels. Nobody knows how to make a camera that can distinguish honest vs deceptive photons.
- WalterGR 1mo agoWhat would prevent someone from applying the same algorithm on a computer to sign arbitrary images?
- dotancohen 1mo agoAsymetric keys
- arjie 1mo ago
- deleted 1mo ago[deleted]
- JoeBOFH 1mo agoI had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.
- initramfs 1mo agoI guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).
- aqfamnzc 1mo agoPaint.net is named after the dot net framework and is not referring to a URL or the internet as I understand it.
- initramfs 1mo agoah, right, i vaguely recall that now. But why/how would it know AI was used, outside of a local LLM, weird it would say that AI was used (unless it's referring to the software itself).
- dr_zoidberg 1mo agoMS Paint wanted to add the "this is AI" tag on a picture they just resized. OP didn't like that, so they went and downloaded Paint.Net to avoid having to deal with (MS) Paint shenanigans.
- initramfs 1mo agoAh, that makes more sense. Thanks for pointing it out. I guess MSPaint scans for that now on Windows 10 and 11, or just 11?
- erk__ 1mo agoPaint.net actually just recently got ownership of paint.net, it only took 22 years: https://www.xda-developers.com/after-22-years-paintnet-downloadable-from-url-paintnet/ https://www.xda-developers.com/after-22-years-paintnet-downl...
- Delphiza 1mo agoI get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.
- torginus 1mo agoWell if that's any reassurance, you can generate a meme picture using AI, then paste it into Paint to add some funny text. That way you can get the best of both worlds.
- jacquesm 1mo agoYou can watermark AI without leaking who did it. That's just using AI to add yet another layer of user tracking.
- account42 1mo agoIf an adversary knows how the watermark is embedded they can replace it with noise so its not like you can rely on these watermarks anyway.
- inigyou 1mo agoYeah you can do that, and it's a crime
- initramfs 1mo agoThanks Microsoft, for adding my signature so I won't have to claim authorship when it ends up in a museum in 200 years, and the NSA archives are declassified for art historians filing a FOIA in 2226, who find out, "yep, it was from his PC."
- Scaled 1mo agoMs paint slop being hung in a museum? Now that's a dystopian future!
- initramfs 1mo agoNo, I wasn't suggesting that. I was saying that if there was digital art (human made) aesthetically significant that a curator would want to display it in a museum, Microsoft's GUID supplied to a data collection agency would make it possible to retrieve if ever/whenever that data were declassified (assuming it isn't purged) It's possible a very bad curator with a terrible taste in art might select slop to display, but I was refering to "fine art" or at least finer art that is digital.
- initramfs 1mo agoAccording to It's FOSS, :It's FOSS 3h • Microsoft quietly embeds a hidden tracking identifier in every AI-generated image you create using Paint or Photos on Windows. A researcher discovered that these apps embed a server-issued GUID (a globally unique identifier) as an invisible watermark in locally generated AI images. The watermark is tied to the prompts you type. And since those prompts are associated with your Microsoft account, Microsoft could "theoretically" trace any watermarked image back to the user who created it. This is recycling an idea from the 80s. Back then, laser printer manufacturers added tiny yellow dot patterns to every printed page. With this, they could identify the printer. Now Microsoft has brought the same idea to AI image generation, and added it to two of the most widely used default Windows apps. Microsoft had disclosed its AI safety measures in official documentation, but the practical implication, that your output image file carries an invisible fingerprint linked to your identity, was never clearly mentioned, of course. The researcher found this by reading Microsoft's own published documentation and analyzing the watermarking mechanics. AI watermarking is a requirement by law in the EU. But "this image was generated by AI" is different than "this image was generated by AI by Mr. Winston Smith". For anyone who values privacy, this is something to worry about. If you generate an image locally, on your own device, why should it carry a tag that can identify you to the company whose software you used? But then, anyone who values their privacy won't be using Microsoft Windows anyway." Since the cat is out of the bag, I wouldn't be surprised if Microsoft generates an invisible watermark for ALL files and not just AI generated ones. The real story is that since AI watermarks are possible, there is no technical barrier to them adding personal EXIF metadata to a file where it can't be seen, removed, or decrypted, whether it is media, a document or other file.
- weberer 1mo agoThe AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.
- frollogaston 1mo agoWell yeah they know my John Doe info
- pizzafeelsright 1mo agoadd your IP, location, provider, computer specs, dimensions, screen info, nearby devices, etc etc etc Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.
- nemomarx 1mo agoDoes it trigger on non AI images? The post doesn't say so at least.
- Someone1234 1mo agoIt does kind of say: The GUID is coming from the moderation endpoint, which is hit when you generate a local or cloud AI image based on your prompt. If there is no prompt, there is no endpoint, and likely no GUID. Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
- londons_explore 1mo agoThe fact that local ai image generation uses an online moderation API is a bit worrying too.... Why not just mod the app to not call this API?
- VCFundedGenYer 1mo agoKeep an eye on this. A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension. MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.
- Gud 1mo agoI would avoid junk from Microsoft entirely.
- sehw 1mo ago[dead]
- gigel82 1mo agoI'm honestly surprised they don't upload the entire image to apply the watermark server-side, to the point that I'd like someone else to repeat this investigation and confirm it's not happening. Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".
- dagaci 1mo agoGoogling you can see the source code for watermarking here https://github.com/microsoft/InvisMark https://github.com/microsoft/InvisMark
- petjuh 1mo agoHow resistant is it to dithering? Can you just add +-1 randomly to each pixel r,g and b values and throw it off?
- red_admiral 1mo agoProbably not, if it's this kind of thing: https://en.wikipedia.org/wiki/Perceptual_hashing https://en.wikipedia.org/wiki/Perceptual_hashing
- account42 1mo agoRandomizing bit 0 might not be enough but if you know the algorithm used (and you do in this case because it is applied locally) then you can always replace the embedded data with random noise.
- jasonmp85 1mo ago[dead]
- naniel 1mo agoawesome breakdown of the process you took. reverse-engineering is crazy now with AI. IP is dead this also reminds me of what got me hooked on CS in the first place: a simple java steganography app in cmsc150
- petjuh 1mo agoThis reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)
- srean 1mo agoNot only USSR. I wonder whether Arthur Conan Doyle had the idea before the police started using typewriter typeface wear and tear for forensics.
- kvuj 1mo agoYou have no idea how deep this rabbit hole goes. Search for EFF printers secret tracking. Virtually all commercial printers embed an invisible identifier on every page printed.
- esafak 1mo agoIt was about money anti-counterfeiting. https://en.wikipedia.org/wiki/Printer_tracking_dots https://en.wikipedia.org/wiki/Printer_tracking_dots
- SV_BubbleTime 1mo agoThere is always a legit reason. It’s just never the only reason.
- inigyou 1mo agoAre they still doing the EURion constellation, too? You can embed that in anything.
- imhoguy 1mo agoNow I need to see if agentic reverse engineering of printer firmware can actually remove that "feature" for good.
- kube-system 1mo agoVirtually all color laser printers and copiers.
- phendrenad2 1mo agoThis muddle of an article makes it totally unclear to me if this GUID is attached by the AI generation call or every image I edit in MS Paint. I'm going to assume the former unless they release a clarification. Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.
- david_shaw 1mo ago> Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save. Did it?
- red_admiral 1mo agoAssuming the watermark works like the upcoming AI watermark for text, then it uses the content's entropy to embed the information. An all-black image doesn't have much entropy, so it's unlikely you'd find anything.
- phendrenad2 1mo agoI guess that makes sense. So import an image of the mandelbrot set you generated and save it, and see if any pixels change.
- luciana1u 1mo ago[flagged]
- kylepomykala 1mo ago[flagged]
- pmkary 1mo ago[flagged]
- red_admiral 1mo agoMisleading title: the watermark applies to AI generated/edited images. That includes local models. Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no". Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.
- SV_BubbleTime 1mo agoDon’t care. There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.
- phendrenad2 1mo agoDon't care that you don't care. This distinction does matter to a lot of people, because to many people there's a huge difference.
- saejox 1mo agoThese days i cant recommend Windows to anybody. Even gamers should move to linux. Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise. A sudden knock on your door might happen because of an ambigious search/propmt.
- tapland 1mo agoThere's a huge number of gamers moving to things like CachyOS. Some are stuck because of Valorant, LoL or Battlefield DRM, but it's a big move lately.
- avadodin 1mo agoI'd never play one of those games but the excuse for the kernel modules spying on you is usually anti-cheat not DRM as they are online games. There are droves of people petitioning Valve to add kernel anti–cheat to CS2.
- account42 1mo agoIt's both and the main reason why anti-cheat is needed is the central matchmaking model, which is itself a form of DRM. If people were still hosting smaller community-moderated servers there would not be a need for invasive anti-cheat but people could also pay on cracked servers without paying.
- 1970-01-01 1mo agoOthers say "I need it to work on a random Thursday, not wait for fsck after ever reboot" https://github.com/IceWhaleTech/CasaOS/issues/1104 https://github.com/IceWhaleTech/CasaOS/issues/1104
- toilet 1mo agoI have the same issue on Windows 11. It's been bugging me to press a button or "check my drive" on every startup for at least half a year, no matter how often I let it run the check...
- clear0250 1mo agoSolution: Don't AI generate images! I think this is a good way to discourage people from making slop.
- kibwen 1mo agoUntil proven otherwise via open-source audits and reproducible binaries, you should assume that all commercial photo editing software is embedding watermarks in any way they can get away with. This includes the professional software that you pay quite expensive licenses for. You should also assume that even if they're not today, they will eventually be coerced into doing so, in the same way that printers embed tracking dots.
- account42 1mo agoYou should however not accept this state of affairs even if you exclusively use open source software because the next step is that it become illegal to have photo editing software that doesn't include the tracking information needed to protect the children, fight terrorists or whatever the boogeyman of the day is.
- cupantae 1mo agoAs a linux fan I just love all these changes Microsoft have been introducing
- account42 1mo agoAs another Linux fan, I don't. What Microsoft does to their users changes the overton window of what's acceptable in tech. Before you know it there will be a politician demanding that all software systems that don't implement such tracking will be outlawed and there will be no one left to speak up to you because they are all already used to the tracking so why should you get a pass.
- cucumber3732842 1mo agoExactly. North Star linux was doing this 20yr ago. And now Microsoft thinks it's ok to do it.
- pmkary 1mo agoWith every new thing Microsoft goes trying so hard to come out as the good person, but they just cannot help themselves but to inject their evil. It had to be changed with Nadla coming, but their enshitification is just keeps getting worse and worse. What on Earth is this.
- megous 1mo agoSolved by not using closed source SW, period.
- andai 1mo agoThis is gonna sound a bit harsh, but from the outside it genuinely looks like Microsoft is actively looking for new ways to degrade and humiliate their users. (And having no trouble finding them!)
- andai 1mo agoMy honest reaction: https://files.catbox.moe/4ylzsq.png https://files.catbox.moe/4ylzsq.png
- deleted 1mo ago[deleted]
- alightsoul 1mo agoYet another reason to switch to Linux.
- imnotr0b0t 1mo agoInteresting find. Overall it makes sense from a deepfake-fighting perspective and EU requirements. But what's concerning is that users aren't really told about this, as far as I can tell. Would be cool if someone checked if it can be bypassed, like swapping the DLL or intercepting the API call. But yeah, it's another step toward every digital trace becoming personally identifiable...
- two_handfuls 1mo agoThis is not ok.
- claiir 1mo agoKind of sad how all these technical blogs just reek of Claude text these days. Hard read when it’s obviously padded by an LLM…
- deleted 1mo ago[deleted]
- clickety_clack 1mo agoI admit it’s a while since I’ve used windows, but it’s such a shock to hear that MS Paint isn’t just a point and click pixel coloring app anymore. It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something. I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.
- darig 1mo ago[dead]
- SideQuark 1mo agoIf you read the article instead of the headline…….. it’s adding a fairly standard mark to AI generated images to let’s others know, in the same manner a giant swath of the GebAI industry has agreed to.
- trickypr 1mo agoI think their point is that paint shouldn’t have any GenAI features (or any new features other than compatibility)
- SideQuark 1mo ago[flagged]
- qu4z-2 1mo agoI don't so much mind about Paint, but modern Notepad is completely unusable. We had "Notepad but with Rich Text formatting" -- it was called WordPad and no-one used it so they eventually deleted it.
- brudgers 1mo agoPeople used Wordpad and thus other people had trouble opening RTF files.
- rnd0 1mo agoYa know, this would probably be pointless but if I were a programmer (I'm not -and refuse to be a vibe coder) I'd probably just grab appropriate libraries and make my own replacements for this shit. GLTK+ (?) is an obvious choice to use for recreating mspaint, and to replace notepad -I was told making a simple editor was an excercise they have you do when you learn programming to begin with? I already replaced the 'solitaire' games suite with pysol running on WSL2 and it's a vast improvement! tldr -if MS is going to screw us, why don't we mitigate it by using replacements?
- inigyou 1mo agoI would've thought the obvious API to recreate mspaint was Win32
- cyteeditor 1mo ago[flagged]
- SideQuark 1mo ago[flagged]
- angry_octet 1mo agoIt is quite likely that Snipping Tool is also doing this. Every camera also leaves device specific signature because of its inherent silicon sensor defects. If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats. See e.g. PPM format: https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/ppm_info.html https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/... These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.
- threecheese 1mo agoIf Anthropic can manipulate text to add a watermark, what’s preventing providers from doing the same to generated images? Modifying the container format can’t protect you from a signature in the image’s visual representation, unless you apply noise to that (and know it’s enough noise/the right kind of noise to counteract whatever unknown technique they’ve applied).
- angry_octet 1mo agoAnthropic's watermarking technique is possible, and worryingly could effect low frequency choices (eg as I said, with object placement or style). However, this has to be a generation time decision, you can't really do that with a small edit. In fact small edits tend to be detectable spectrally.
- ranger_danger 1mo agoMisleading title IMO... here they are using "locally generated output" to specifically mean only AI-generated images, not your "500hrs in MS Paint" hand-made masterpiece.
- LeBit 1mo agoDo we really need more examples of why local LLMs are an absolute necessity?
- tgsovlerkhgsel 1mo ago> In other words, “generated locally” does not mean that the complete operation is local. That sounds like a privacy violation that the DPAs should look into. Edit: Apparently it's disclosed somewhere. Still, that defeats the entire point of local generation...
- mococa 1mo agoCould microslop be more evil?
- __MatrixMan__ 1mo agoThey're pretty bad, but yes I think so.
- userbinator 1mo agoafter a local Stable Diffusion image generation The request is JSON and contains at least these fields:..."prompt": "..." Local SD (especially the earlier versions) is already uncensored, so they're effectively crippling it with additional spyware that phones home to tell Microsoft what you're doing and asking whether they approve of it. IMHO the invisible watermark isn't the worst part, but rather the fact that MS is logging every interaction you have with the model, which doesn't ever need to leave your machine.
- TonyStr 1mo agoWhat happens if you try to use this feature without being connected to the internet? Will it refuse to run the local AI model?
- seriocomic 1mo ago"inivisibly"? for 9 hours this was invisible...
- aucisson_masque 1mo ago> On Copilot+ PCs, image generation is local but prompt moderation remains remote Anyone disturbed about that ? It's your computer, running locally, but Microsoft can tell you 'no'. It's like you want to open a folder and it asks permission to Microsoft.
- zdragnar 1mo agoI would be surprised that anyone is surprised by this. They've been making local accounts harder and harder now to the point of being impossible. Anyone not deep in tech will accept the "think of the children" defense without much worry, and anyone who is deep in tech already knows that if you really want an OS that doesn't spy on you, you need to go to a *nix of some flavor.
- fchicken 1mo agoI'm disturbed by everything. Prompt moderation, GUID insertion, watermark insertion; track anything and everything, probably done in the name of "protect the children".
- inigyou 1mo agoThat's nothing new. Ever tried to develop a driver? Or replace a system file? Or install an app on iOS not from the store? That war was lost two decades ago with the iPhone
- emsign 1mo ago> The two apps send the prompt to a remote server for moderation Why? What needs tobe moderated locally?
- fchicken 1mo agoFucking spyware. Soon it'll literally be "you need a license to use this technology" if we're not there in some form or another already.
- inigyou 1mo agoIt literally already is? What happens if you pirate windows but don't do it properly?
- fchicken 1mo agoIt'll literally be like printers "cannot print this black/white document, low on cyan". "Cannot run local AI model, no network connection". The more you think about it, the more it really is the same: https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=vector https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=...
- account42 1mo agoExcept once printed its at least hard to remove the dots. Image based watermarks are trivial to destroy if you know they are there.
- fchicken 1mo agotbh so is circumventing those dots. It doesn't make it any better
- JacobKfromIRC 1mo agoHow do you circumvent printer dots? I don't see how that could be trivial.
- globular-toast 1mo agoUse free software. Proprietary software is used by its owners to control you. This is nothing new, just another example to add to the countless ones we already have.
- Schlagbohrer 1mo ago"Apparently, the recent Claude Code text-watermark announcement also played a role in prompting me to think about this possibility." Extremely odd way to write. Are the writer's own thoughts invisible to him or her?
- jojobas 1mo agoYou might think you have control over what causes you to think this or that, but that's only an illusion.
- 4d4m 1mo agoGross. Unnecessary. Anti consumer.
- p0w3n3d 1mo agoIt's for our safety, so when Kathy in the primary school steals Beatrice's picture in paint, miss Wallingford will tell who was the original author
- burnoutdv 1mo agoOkay, there are watermarks on AI stuff, interesting, not good but everyone else already talked about. My question..how does it work? Is it robust? I remember that young me hid data in pixels of png with simple stegonagraphy and it was a fun little project..but brittle. How exactly does the fingerprinting survive jpeg compression? Is it repeate over and over the images or is it just one area? If that one is pure black by chance the jpeg algorhitmen would erase it all no?
- nmg 1mo agoI'm pretty sure the robustness of watermarking has been a solved problem for at least 30 years, I remember visiting the mit media lab in the mid 90s and they were explaining how they could watermark digital audio by imperceptibly adjusting the acoustics as if the walls of the room the audio has been recorded in were changing distance relative to the microphone according to a wave function
- account42 1mo agoThere is no robust-without-qualifiers watermarking. There is only robustness against common operations but as soon as someone is actually trying to remove the watermark they can at the very least use exactly the same technique to embed random noise instead to overwrite your watermark.
- shevy-java 1mo agoGreat detective work. With regards to Microsoft being ... uhm ... "transparent": > The same page says that generated images: > “will contain C2PA manifest helping users identify that it is an AI generated image.” > [...] That is a meaningful disclosure of remote filtering and C2PA metadata. > C2PA manifest contains a GUID identifying the invisible pixel watermark > Calling the feature “Content Credentials” is accurate, but it does not > make this prompt-associated identifier obvious to a Windows user. I don't think this is accurate, because without that detective work, most people would have no idea that Microsoft tags and tracks the images here. This reminds me of printers printing identifiers to ID individuals. What this to me means is that I can no longer use any such Microsoft services, because there is no trust for me here. Microsoft sniffs on me, if I were to use these software products. AI is a big spy-op too. Microsoft could easily admit "we watermark all your images, whether you like it or not", but corporate speak forbids this and they don't really admit to it. They do not use the word watermark officially, but their .dll names reveal it. That means they resort to deceit and propaganda. It really is time to strengthen the whole open source ecosystem. I no longer want my taxpayer's money to go into traitorous US companies that abuse EU citizens here. (Note: the same would apply to EU companies, but the USA dominates the software sector, unfortunately. This also has to change permanently.)
- fithisux 1mo agoDon't use them if it does not fit your requirements. The last ten years I am more that happy with Lazpaint or Libreoffice Draw. The last year I have added Imglass to the mix.
- blablabla123 1mo agoActually Microsoft is doing this since the 90s with Word documents. Did they ever pause this practice?
- grugdev42 1mo agoUse this instead!!! https://jspaint.app/ https://jspaint.app/
- lesspassiveobse 1mo agoRedStar OS (North Korea linux) already did this 10 years ago. Nice to see the west catching up.
- mg794613 1mo agoMy goodness, this has nothing to do with AI problems. I don't understand that people still buy an OS from a company that actively hates it's customers. The amount of things they pull should not even be succesful on a OS you get paid FOR to use.
- alex_duf 1mo agoNot that I love Microsoft, but they would get a lot of heat if they let anybody generate harmful content as well. They can't win on that topic. Now I would not want to appear to defend the mess they've created out of windows, that's not the point.
- deleted 1mo ago[deleted]
- someguyornotidk 1mo agoThey have only themselves to blame for this. They've spent decades developing technology to spy on and micro-regulate what their captive customers can do with their property. Now that they have this technology, it's only logical that they be held responsible for misuse. The only (and inevitable) solution at this point is for big tech to get micro-regulated like the banking industry. The same mindless greed that drove them to take control away from their customers will be responsible for the same control to be taken away from them.
- xmcqdpt2 1mo agoBe careful what you wish for. I'm sure Microsoft and Google would love the kind of regulation we apply to big banks. It has become a moat that makes it impossible for other (snaller/foreign) financial institutions to compete because they don't have massive specialized regulatory departments. The more complex the rules become, the more difficult it will be for alternative providers to exist, unless they have explicit carve outs. So far, with age verification and user id laws, there doesn't seem to be much appetite from politicians to create exceptions for open source and smaller projects. By comparison, in the US the regional banks have special exemptions for many of the really onerous regs, which is why they are still a bunch of them.
- hn9rsvy2gx 1mo ago[dead]
- luciana1u 1mo ago[flagged]
- ozereray1 1mo agoInjecting hidden GUIDs into local files without explicit user consent is a massive privacy overreach. It makes you wonder what other local tools are silently tagging user generated content.
- soupspaces 1mo agohttps://en.wikipedia.org/wiki/Information_Awareness_Office https://en.wikipedia.org/wiki/Information_Awareness_Office
- nojs 1mo agoThe question is whether LLM providers are going to do this. Anthropic currently says they don’t, but it’s impossible to verify: > Watermarking carries no identifying information and can’t be traced to a specific person, organization, or chat; https://www.anthropic.com/news/claude-text-watermark https://www.anthropic.com/news/claude-text-watermark
- trollbridge 1mo agoProbably just means they haven't (yet) figured out how to do the watermarking carrying enough bits of data to encode a GUID.
- Eddy_Viscosity2 1mo agoIt could also mean they are lying. It could be they are being forced to downplay how good the watermarking is because gov agencies want that tool available to them without people knowing about it. We'll have to wait for the next Snowden to find out.
- trollbridge 1mo agoIn other words, plausible deniability. “We aren’t watermarking your text.” (Today, and we’ll start tomorrow.)
- martin_a 1mo ago
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- hojinkoh 1mo agoMicrosoft is in a pretty good position to do something that can be valuable to certain institutions. Imaging every pdf file, every image, every office documents, and every video has a hidden record of the associated Microsoft accounts of all computers it has ever passed through. This should sell well, and realistically nobody can stop them. Why haven't Microsoft done this much earlier?
- Kvarnek 1mo agoThe visible watermark toggle giving users a false sense of control while the invisible GUID persists regardless is the worst part. People who turn off the watermark think they opted out.
- codedokode 1mo agoCommercial companies with closed-source software, cloud software will always betray you.
- deleted 1mo ago[deleted]
- xushengdev 1mo agoXusheng here! I have not gone through all comments, but wish to clarify a few things: 1. The watermark only applied to AI-generated contents through the in-app AI (copilot/cocreator, etc). If you draw something by hand it is not watermarked 2. Privacy implications: I believe your MS account is linked to the prompt and the GUID. And the GUID is embedded into the image as both an insivible watermark and a file-level C2PA metadata. I did not write about this very deeply in my blogpost, but when I do an image generation, it deducts my AI credits (yes, MS gives you like 60 free AI credits), so MS surely knows where the prompt is coming from. Though I am not sure about their storage and retention, e.g., do they actually store the data, and if they do, for how long, etc
- assistant1 1mo ago[dead]
- not_a_bot_4sho 1mo agoScanning the comments, I see some curiosity and outrage but little recognition that this is legally required in places like California and Colorado and Texas and probably some more places. And federally, the C2PA strongly encourages digital providence albeit without legal consequences... yet. All AI content coming from companies that service the US market are watermarking things.
- cyteeditor 1mo ago[flagged]
- m3047 1mo agoPeople worried about other people tracking them while using local stable diffusion models built on fraudulently obtained training content, to produce images which cannot be owned. Thug on thug violence.
- krick 1mo agoObviously it's bad and we can all say "fuck Microsoft" once more, but "we" probably don't use Windows anyway, right? I have no idea, really, but if you willingly use closed-source spyware that is notorious (for AT LEAST 15 years) for all kinds of invasive telemetry it forces upon you, you probably wouldn't find this new piece of information concerning anyway. And ironically, I think that this one is kinda fair. I mean, you specifically asked your software to generate whatever pseudo-random bytes it wishes to loosely based on some text prompt. It did that. Now, apparently, these pseudo-random bytes turn out to be personally identifiable. So what? I suppose they didn't claim their PRNG to be cryptography-grade. They could even make it seem like an accident, should they be bothered to. Make it way less obvious. Now if it would insert watermarks on save (like printers do), that would be really outrageous. But when you trust software to produce "whatever", you probably shouldn't be really mad about it doing anything more than you asked to.