Remix.run Logo
weberer 6 hours ago

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.

Terr_ 4 hours ago | parent | next [-]

> a unique identifier into every image you create

Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]

Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.

In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.

[0] https://www.eff.org/issues/printers

Rendello an hour ago | parent | next [-]

> It's very likely your printer is secretly adding marks to the page

It's most likely how the FBI caught NSA leaker Reality Winner:

> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.

https://en.wikipedia.org/wiki/Reality_Winner

varispeed 2 hours ago | parent | prev [-]

and then in few years a new mono-mustachioed or mono-browed leader will emerge who declares memes a blasphemy punishable by death and will call up all the telemetry gathered to punish all involved.

Terr_ an hour ago | parent [-]

"I don't worry because I have nothing to hide, based on my perfectly accurate perception of today's political and legal forces in my state and nation which will stay safely static forever."

fishfasell 5 hours ago | parent | prev | next [-]

Exactly. Forget the AI aspect, this is entirely to identify users for any purposes they deem necessary. People are ignoring the surveillance state aspect of this. Reminds me of the device id debacle they have attached to their outbounds Windows network calls

hiccuphippo 2 hours ago | parent | prev | next [-]

Can this also be weaponized? Get an innocuous image from someone you don't like, grab their GUID, add it to another image, sent it to the thin skinned politician in power.

red_admiral 4 hours ago | parent | prev | next [-]

> every image you create

*with the help of AI*. Does in fact make a difference.

tavavex an hour ago | parent [-]

While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that.

I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.

nemomarx 6 hours ago | parent | prev | next [-]

Does it trigger on non AI images? The post doesn't say so at least.

Someone1234 5 hours ago | parent [-]

It does kind of say: The GUID is coming from the moderation endpoint, which is hit when you generate a local or cloud AI image based on your prompt. If there is no prompt, there is no endpoint, and likely no GUID.

Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.

londons_explore 5 hours ago | parent [-]

The fact that local ai image generation uses an online moderation API is a bit worrying too....

Why not just mod the app to not call this API?

nvme0n1p1 5 hours ago | parent | next [-]

Since the watermarker runs locally, you could also do the reverse: generate some porn with a different open model, then run that code to tag it as "Content watermarked by Microsoft Responsible AI"

szatkus 23 minutes ago | parent | prev | next [-]

I don't think they use a model that would run smoothly on most hardware that normal people use.

Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.

iririririr 16 minutes ago | parent [-]

did you even read the article? you're wrong on all points.

autoexec an hour ago | parent | prev [-]

Probably both so they can change what they censor without waiting for you to run windows update and also so they can collect your information (IP, timestamp, etc) to associate with whatever you did

qurren 6 hours ago | parent | prev | next [-]

> address

Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.

Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.

BitwiseFool 6 hours ago | parent | next [-]

Windows 11 effectively forces users to register with a Microsoft account. Once that's established, all it takes is for an unaware user to fill out an e-commerce form and save an address for auto-fill.

jborean93 4 hours ago | parent | next [-]

> Windows 11 effectively forces users to register with a Microsoft account.

While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.

clear0250 4 hours ago | parent | prev [-]

> Windows 11 effectively forces users to register with a Microsoft account.

It takes zero effort to bypass that with Rufus, if you set up your own pc.

BitwiseFool 4 hours ago | parent | next [-]

My comment was in regard to the average PC user. The kinds of folks who would never install an operating system and would likely agree to use Edge while signed in to their Microsoft account.

0cf8612b2e1e 3 hours ago | parent [-]

Microsoft has also been pushing hard for Recall and recording all local activity forever. Not impossible to imagine that anything looking like a home address “somehow” gets ingested in the telemetry.

AngryData 3 hours ago | parent | prev [-]

A bypass existing is good, needing a bypass in the first place is still a problem.

cuu508 6 hours ago | parent | prev | next [-]

> Make sure you register mailing addresses with your credit card institutions

Sorry for a dumb question but what would one use as a mailing address? Rent a PO box, or use a mail forwarding service, something like that?

qurren 6 hours ago | parent [-]

Any of a number of virtual mailbox services which can receive mail for you, e.g. anytimemailbox.com but there are several. You can either pick up in person, or they offer services like mail forwarding, opening and scanning, etc.

Besides privacy against leaking your sleeping-address to businesses, they're also convenient for avoiding package theft if that's a problem in your area, and receiving/forwarding mail if you travel a lot for extended periods of time.

I'd recommend against PO boxes because (1) they get rejected by some services (2) UPS and FedEx won't deliver to them.

Because these businesses have to register as CMRAs and you have to sign a notarized form for them to legally receive mail for you, some services will still detect it and not let you use the address, but my experience for the most part has been that most US financial institutions let you enter a "residential/legal address" (no CMRAs allowed) and a "mailing address" (CMRAs allowed) separately, and the mailing address usually becomes your billing address.

nekusar 4 hours ago | parent [-]

Or.....Install Linux and bypass all this stupidity.

They will move faster to track each and every one of you, all the while shoving ads and garbage down each of your respective machines... and you all pay for it?!

0cf8612b2e1e an hour ago | parent | next [-]

Surely I am safe running VSCode on my Linux machine. No chance it would upload a bunch of personal telemetry without my say so.

nekusar an hour ago | parent [-]

Use VSCodium. It's the FLOSS branch with Microsoft tracking shit removed.

https://github.com/VSCodium/vscodium

nemomarx 4 hours ago | parent | prev [-]

You still want the virtual mailing address for other reasons honestly. Even if your os isn't tracking you or leaking things giving your real address to any business could lead to it being leaked because no one cares about security, etc. If that's in your threat model you should be using a good proxy mailer

nekusar 4 hours ago | parent [-]

Perhaps so. But the problem at hand here is that MS Windows has so lost the plot of being an OS for users, to ABUSING users.

All these fixes and repairs ignore the fact that abusing people pays. Surveillance capitalism pays, and provides a revenue stream for Microsoft to further exploit.

The only way to win is not to play.

rexpop 6 hours ago | parent | prev | next [-]

This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.

qurren 5 hours ago | parent [-]

> This is broadly impractical for the average citizen.

No it's not. Sign up for a virtual mailbox for $15-$25/month.

> A scalable solution would be to make this sort of thing illegal.

I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.

It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.

ygjb 4 hours ago | parent | next [-]

> No it's not. Sign up for a virtual mailbox for $15-$25/month.

Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.

It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.

AbsurdCensor 2 hours ago | parent [-]

At least in the US it's not even a good method either. Own a house? Boom, your information is publically available and you won't be able to remove it without a court order, which in most states is impossible to get. In most states, you don't even need to own a house, decide to vote? You information again is publically available. Tie your real name to a single account to purchase something, and you are trackable. Want privacy? You'd need to remove yourself from the internet, dump your phone, destroy your ID and work underground for cash. We can push against iot, and people have been forever, but at the end of the day the government will always they have a vested interest in being able to identify it's citizens.

qurren 9 minutes ago | parent [-]

[dead]

autoexec an hour ago | parent | prev | next [-]

> Sign up for a virtual mailbox for $15-$25/month.

That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.

nemomarx 5 hours ago | parent | prev | next [-]

I think they meant make what Microsoft is doing illegal?

or make it illegal to ask for address, etc. definitely a little more effective than mailboxes

qurren 5 hours ago | parent [-]

Ahhh okay if that's what they meant, then yes, I 100% agree and apologize in advance.

I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.

I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.

Modified3019 an hour ago | parent | prev | next [-]

> No it's not. Sign up for a virtual mailbox for $15-$25/month.

You are out of touch.

theideaofcoffee 4 hours ago | parent | prev [-]

They (the ones wanting to make privacy illegal) are just the ones that want to develop the tools and consume the data for it because it'll be good for their resume or some bullshit, or they're just intrinsically broken humans.

mschuster91 5 hours ago | parent | prev [-]

> IANAL but they are not a government or financial institution and do not have a right to that information.

As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.

sellmesoap 21 minutes ago | parent [-]

Seems to me that it's a challenge to make an apple account without adding a credit card to your account as well. A carfully chosen Linux distro (so many options!) is the way to avoid the brunt of these privacy issues, lots of open software calls home in some way or another so user beware!

herf 5 hours ago | parent | prev | next [-]

No - there is a huge difference between "this AI created this image" and "this user did it" - the first we need more of, and the second is a big privacy concern. The article does not say anything about identifying a user.

serf 5 hours ago | parent | next [-]

a GUID isn't an indicator, it's a fingerprint.

so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.

to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.

dmantis 5 hours ago | parent | prev [-]

Article literally says it adds a guid, not a binary field indicating that the image is ai generated.

refulgentis 5 hours ago | parent [-]

A guid isn’t a user id, if it is in this case, it’s an abuse of how guid is used, at least colloquially. I haven’t read enough to understand if it is user / machine id, I.e. only globally unique in the sense it’s a globally unique entity identifier.

themaninthedark 5 hours ago | parent | next [-]

Microsoft Can Track Users via a Windows Device ID https://news.ycombinator.com/item?id=48815196

Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239

4 hours ago | parent [-]
[deleted]
dylan604 4 hours ago | parent | prev [-]

They stated the GUID is used to identify the prompt used to generate the image. How are you confused as to not being able to identify the user?

"I haven’t read enough to understand". Oh, now I know the answer to my question

refulgentis 3 hours ago | parent [-]

[flagged]

frollogaston 5 hours ago | parent | prev | next [-]

Well yeah they know my John Doe info

pizzafeelsright 4 hours ago | parent [-]

add your IP, location, provider, computer specs, dimensions, screen info, nearby devices, etc etc etc

Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.

pjc50 5 hours ago | parent | prev | next [-]

This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

mosura 4 hours ago | parent | next [-]

Why would the EU possibly object to this? It is exactly what they want.

baby_souffle 5 hours ago | parent | prev | next [-]

> This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."

red_admiral 4 hours ago | parent [-]

But the EU mandates watermarking of AI content.

jkaplowitz 4 hours ago | parent [-]

As the article explained, the EU does not mandate a prompt-specific GUID, only the ability to identify the content as AI-generated. The highly privacy-invasive level of provenance tracking which Microsoft has added goes beyond the EU’s new mandates.

TiredOfLife 4 hours ago | parent | prev [-]

Watermarking ai generated stuff is mandated by EU

thayne 3 hours ago | parent [-]

Do they require the watermark to be a unique token that can be associated with PII?

flockonus 4 hours ago | parent | prev | next [-]

[flagged]

Scaled 3 hours ago | parent [-]

I am a human and I upvoted the comment immediately. Do not underestimate the wide ranging hate for age verification. Even my normie friends are against it. Meta/etc have been buying those laws but at the cost of more and more people waking up to privacy activism. I predict in a couple years it'll backlash as people first fight against AV, and then fight for more broad privacy reform in the US. At least for myself, I had never been actively calling my reps until the AV laws.

dagaci 5 hours ago | parent | prev [-]

This a variant of the provenance scheme: C2PA its implemented by all major Camera maker, and Google it seems, Apple support it with 3rd party apps on iPhone, but they have something called "Apple Reference Image" brewing.

Personally I think there is a good argument for being able to distinguish AI generated image and video...

akersten 5 hours ago | parent [-]

> I think there is a good argument for being able to distinguish AI generated image and video...

Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.