4 ms·
Article calls this steganography but...I'm not sure it really is, as the payload is hidden in the file format's metadata...not _encoded_ into the pixel data.
by acron0 13y ago
Article calls this steganography but...I'm not sure it really is, as the payload is hidden in the file format's metadata...not _encoded_ into the pixel data.
- nmc 13y agoSteganography is about hiding, not necessarily encoding. One of the earliest examples of steganography comes from ancient Greece: the king of Miletus would shave the head of his messenger, write the message on the top of the head, then let the hair grow back to hide the writing; the recipient would then shave the messenger again to see the message. I do not think this qualifies as encoding.
- sesqu 13y agoThis does qualify as (very poor) encoding, to me - the malicious code is stored in padded ASCII, which has to be decoded to unpadded before being interpreted. It doesn't use metadata, though, and I wouldn't call it steganography, since the image the data is in is never intended to be seen.
- nmc 13y agoBy such a definition, any form of expression is encoding, isn't it?
- sesqu 13y agoPretty much, except in coding theory you have to be explicit about your alphabet. Hall took this further, by positing that in television, viewers use individual and heterogeneous decoders. Anyway, the point is that the channel used to communicate the message in this case is unconventional, and that's why I consider encoding to occur. A casual observer would assume the datastream to encode an image, not a program, and as such the program can be said to be explicitly encoded, rather than implicitly.
- rpsw 13y agoFWIW, The article seems to be mistaken. The code listed is retrieving the payload from the pixel data. It uses getImageData, which returns the pixel data of the canvas in an array of RGBA values. It then loops through and retrieves a character from every red pixel.