| ▲ | Spymarks, Not Watermarks(brand.io) |
| 298 points by possibilistic 7 hours ago | 68 comments |
| |
|
| ▲ | TeMPOraL 2 minutes ago | parent | next [-] |
| Privacy is always the most popular for some reason, but also the least consequential and relevant angle in the real life. Watermarks are not "spymarks". They're DRM. I wouldn't worry about advertisers tracking conversions. I would worry about the "analog hole" being closed. Think of no longer being able to even photograph your phone screen, because pixels on it carry digital watermark that's robust enough to survive being photographed - I.e. the kind currently used to tag AI generated images - and then every phone and computer refusing to display resulting photo because the app disallowed capturing its pixels. |
|
| ▲ | Retro_Dev 3 hours ago | parent | prev | next [-] |
| Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't watermark, an image compressor we are certain can't watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered/announced) by saying that our memes won't be reposted, images or work stolen, etc... but honestly I'd rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures. |
| |
| ▲ | dragonwriter an hour ago | parent | next [-] | | Spymarks an application of steganography, not a different name for it. > On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced That doesn't help with things like the typical use of SynthID where the spymarking is done by the same process generating the content, so there is never a clean comparator. (It also wouldn't be useful anytime it is inplemented as part of a transformation—compression, etc. —step, for the same reason.) | |
| ▲ | wodenokoto 2 hours ago | parent | prev [-] | | > Spymarks just seem like another word for https://en.wikipedia.org/… Stop using links instead of words. Your comment is literally unreadable without going on to other websites. | | |
|
|
| ▲ | xp84 6 hours ago | parent | prev | next [-] |
| These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen. First the low-end laptops and phones (and probably later, most of them) will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home. I assume this is something Apple will, to their credit, refuse to do[1] but I don't think other OEMs will have any qualms based on what they already do with their TVs. [1] (though they don't do this kind of thing out of altruism, but because their cash cow is app store rents and fat hardware margins, not third-party advertising.) |
| |
| ▲ | qurren 3 hours ago | parent | next [-] | | Apple is just Stockholm Syndrome at scale. I wouldn't trust anything they say about privacy, especially given how closed their ecosystem and hardware is. | | |
| ▲ | BlaDeKke an hour ago | parent [-] | | They lacking in the AI race is an indicator that they value privacy more then competitors. | | |
| ▲ | bigyabai an hour ago | parent [-] | | No, it's just a sign of Apple holding a decades-long grudge against Nvidia to their own detriment. | | |
|
| |
| ▲ | ifh-hn 6 hours ago | parent | prev | next [-] | | I don't think you can count apple out like that. They will likely implement it themselves though. This would be in addition to their always listening AI watch and intelligence features. | | |
| ▲ | diasdevops 5 hours ago | parent | next [-] | | I’m a bit unfamiliar with current laws, but are there any rules that would prohibit companies from doing this in interest of user privacy? I know at this point privacy is long dead but there are certain things that do get called out and shut down. | |
| ▲ | SV_BubbleTime 5 hours ago | parent | prev [-] | | Apple’s always on watch has a declared 15 second buffer for live audio, and a worse scenario of summarizing your conversations for later but.. they tell you about it proudly. They also tell you how they’ve managed to do it while keeping privacy focused. It’s your choice if you believe them or not, I like Apple and I wouldn’t use that feature. The pretending that this is the same thing, that Apple is sneaking something past you when they’re showing you that they’re trying to do it right is a bad faith argument. | | |
| ▲ | microtonal 37 minutes ago | parent | next [-] | | It’s absolutely not a bad faith argument. They proudly tell you about iMessage being end-to-end encrypted. The part where it’s practically only encryption at rest, because everyone enables iCloud backups without ADP is hidden somewhere in a footnote. | |
| ▲ | pjerem 35 minutes ago | parent | prev | next [-] | | > Apple’s always on watch has a declared 15 second buffer for live audio, and a worse scenario of summarizing your conversations for later Even if you trust them, maybe as an user you can be ok with that. As a non-user who will talk with people wearing Apple Watches, I disagree being recorded and my conversations with the watch owner summarized. Where do I disagree for that ? | |
| ▲ | defrost 4 hours ago | parent | prev | next [-] | | Will they surrender logs for a legal discovery request? e.g. Johnny's accused of something white collar, did he ever make any prompts that suggest how early on he was aware of {X} and further indicate how he moved to frame it? That's a requirement that varies by country. | | |
| ▲ | SV_BubbleTime 3 hours ago | parent [-] | | Have you read anything about the feature? They’re asserting that all the audio is done on device, and the results of encrypted so they can’t access them even from the backups. Unlike… EVERY… other tech company, it is in Apple’s interest to be privacy-focused. Even if you just have to believe them, which you do pretty much, they’re the biggest name pushing for privacy in the world right now. They make more on selling devices than they make on ads and behaviors. It’s in their interest to not lie. | | |
| ▲ | microtonal 32 minutes ago | parent | next [-] | | Read the actual privacy brief. Even though the audio transcription is done on device. For Siri recap, a condensed transcription (which mostly removes superfluous words, etc.) goes to their PCC servers. So even though their servers do not get raw audio, their servers do get transcriptions, which is nearly the same privacy-wise. Of course, at that point it depends on how much you trust their PCC. | |
| ▲ | ierukah an hour ago | parent | prev [-] | | > It’s in their interest to not lie. Oh, really? |
|
| |
| ▲ | ifh-hn 4 hours ago | parent | prev [-] | | I'm not pretending anything, nor did I imply they were sneaking anything in. It's a bad faith argument to pretend I was doing that, which is ironic but not unexpected from an apple fan... |
|
| |
| ▲ | N_Lens an hour ago | parent | prev [-] | | “Next we just need to mark the consumer’s retina and brain to ensure our ads truly went through” | | |
|
|
| ▲ | gorgoiler an hour ago | parent | prev | next [-] |
| I feel like there’s some security engineering calculus that would be useful here? You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted? There must be value in having a visible vs an invisible watermark, or in declaring that a work is watermarked without revealing the hidden mark, or having two marks — one that is publicly verifiable and another that is hidden? If the process itself can be defeated through adding entropy (or more generally by revealing the watermark algorithm) then is that not security through obscurity, which is to say it is a one-shot rather than a general system that is doomed to become obsolete over time? Something feels off about a technology based on being hidden but whose only value is in being revealed but I feel dumb for not being able to be more specific about what feels wrong! It could simply be that anyone who can verify the presence of the watermark also now has a tool to tell them when they’ve successfully scrubbed the watermark off the work, so the verify tool has to be kept secret which in turn limits its usefulness. |
| |
| ▲ | jstanley 3 minutes ago | parent [-] | | If you think SynthID-Image can be easily defeated by adding entropy I invite you to give it a try. I spent half a day messing around with it and I was very impressed by how robust it is. I couldn't get OpenAI to stop detecting their own SynthID without completely trashing the image. |
|
|
| ▲ | Morromist 5 hours ago | parent | prev | next [-] |
| The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become. Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be replaced with "winding" like "her gently curving thighs" with "her gently winding thighs" But I'm sure there are some intricacies I don't understand. Anyway, very cool website, thanks for sharing it~! |
| |
|
| ▲ | r3trohack3r 36 minutes ago | parent | prev | next [-] |
| Reminds me of the micro patterns from inkjet printers https://en.wikipedia.org/wiki/Printer_tracking_dots |
| |
|
| ▲ | bronlund 28 minutes ago | parent | prev | next [-] |
| It's like that fart gas trail, but for machines :D |
|
| ▲ | pavo-etc 7 hours ago | parent | prev | next [-] |
| I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example. Tech like SynthID I see a net positive especially since it doesn't degrade text quality. I dream about a browser extension running at all times that makes text more translucent based on the confidence of LLM writing[0]. This article's suggestion of using it to unmask whistleblowers is very interesting and not something I'd thought about though. Still not convinced that spymark is a better name though. [0]: Sean Goedecke's Deckard is close but it would rather invisible than bright red https://www.seangoedecke.com/deckard/ |
| |
| ▲ | autoexec 6 hours ago | parent | next [-] | | > spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example. The article calls out watermarks intended to deter counterfeiting as explicitly being not spymarks. Watermarks can tell you about the items marked, not about the person using/creating it. | |
| ▲ | pixl97 6 hours ago | parent | prev | next [-] | | These spy marks are a great way to teach AI how to create a hidden communication channel in plain sight. | | |
| ▲ | aesthesia 5 hours ago | parent | next [-] | | Due to their essentially cryptographic nature, I don't think SynthID et al are very easy for LLMs to speak natively. They have other ways of doing steganography. | | |
| ▲ | dragonwriter an hour ago | parent [-] | | LLMs with access to tools like code execution don't need channels they can “speak natively". |
| |
| ▲ | SV_BubbleTime 5 hours ago | parent | prev [-] | | Yea, it’s AGI, and it’s been really helpful! Oddly enough it’s just really loves sharing cat memes with the other instances! Weird, but not at all like all those dooms day scenarios guessed it would be… |
| |
| ▲ | lukewarm707 7 hours ago | parent | prev | next [-] | | the spymark tracks you. it is negative. | |
| ▲ | Ygg2 4 hours ago | parent | prev | next [-] | | It's the difference between watermark or marked bills. One is proof of authenticity, other is tracking tool. | |
| ▲ | shevy-java 6 hours ago | parent | prev | next [-] | | I think they are always negative. Including on bank notes. I wonder if we could have a real, open and direct democracy. All the models we have right now work via indirect clowns. Then again, looking at how some people vote, perhaps direct democracy can only work if people are clever. | | |
| ▲ | GuB-42 4 hours ago | parent | next [-] | | The problem with direct democracy is not that people are dumb, it is that they are incompetent. To do politics right take skills, and I don't expect the average mechanic to be better at it than the average politician is at fixing cars. How should I know if we should subsidize organic farming, ban alcohol sale after 8PM, or increase the defense budget? At least in theory, politicians are professionals who deal with these kinds of questions, they are supposed to know the technical and social implications, or find experts to help them if they don't. Some people think they know, and judging by how stupid most of their ideas are, they don't. I don't blame them, it is just not their field, and my ideas are probably just as stupid anyways. | |
| ▲ | mvlipwig 5 hours ago | parent | prev | next [-] | | If checking for counterfeit bills becomes harder, trust in the currency is degraded. Once that happens, vendors will either incentive digital payments (which are definitionally tracked), switch to a tracked currency, or barter more. Trust in bills is super easy to take for granted. | | | |
| ▲ | dgoldstein0 4 hours ago | parent | prev [-] | | Eh bank notes have watermarks just to make them harder to forge. They also have serial numbers, but as almost no businesses pay attention to them they aren't really used to track transactions. The provenance of a particular bank note isn't that interesting beyond knowing whether it's a forgery. The problem with these spymarks is that they can be used to include data that's completely invisible to users - even potentially to sophisticated users and the programs that consume the marked files. So while I can make an informed decision whether to share a picture, I may not be informed about any spymarks. Vs a normal watermark that aren't designed to be invisible. |
| |
| ▲ | rizonio 6 hours ago | parent | prev [-] | | "tracking watermark" seems clearer to me than "spymark" | | |
| ▲ | autoexec 4 hours ago | parent [-] | | Spymark or even just "tracker" would better at conveying the purpose. I think the goal is to find a single word that means "tracking watermark" or "a watermark that tracks you" because right now companies are pushing the term "watermark" to obscure what the marks are actually for. |
|
|
|
| ▲ | initramfs 4 hours ago | parent | prev | next [-] |
| https://web.archive.org/web/20210909094124/https://www.vice.... |
|
| ▲ | edg5000 4 hours ago | parent | prev | next [-] |
| A lot of the discussion is about AI vs no AI, which is valid, but I care about local AI vs centralized AI. Hopefully hardware will become more affordable. A hopefully irrational fear I have is that it'll be like house prices: only ever goes up. |
| |
|
| ▲ | injidup an hour ago | parent | prev | next [-] |
| Wouldn't synthid type watermarking fall under GDPR. Personally identifiable information attached by third party to content in the expectation that it would be published and trackable? |
| |
| ▲ | j16sdiz 36 minutes ago | parent [-] | | GDPR have lots of board exemption. When some processing is required by eu or eu member state law, that processing doesn't need explicit consent. One could also argue the watermark tracks the generated content, not the person | | |
| ▲ | anon48293 25 minutes ago | parent [-] | | That’s not how it works. If it can uniquely identify the user it’s personal information as per GDPR. And therefore illegal in this implementation. |
|
|
|
| ▲ | layer8 6 hours ago | parent | prev | next [-] |
| Weirdly the article doesn’t mention steganography. Arguably it isn’t quite the same, because the aim of steganography isn’t typically to add an identification, but something like “steganomark” would seem to be fitting. |
|
| ▲ | minimaxir 6 hours ago | parent | prev | next [-] |
| Out of frustration with SynthID being closed-source with weird dubious ways to verify if an image has the watermark, I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be hidden. The intent is for non-corporations to use it as a defense against the use of spying/AI by making it easy for normal people to prove providence, but I have a feeling nowadays most are not going to see it that way so I am unsure if I will release it. |
| |
| ▲ | Uehreka 4 hours ago | parent | next [-] | | How can you prove provenance if anyone can use it? The point of SynthID is that Apple makes the hardware and OS and can reliably insert the watermark/signature between when the camera takes the photo and when it becomes available to any 3rd party software. Because they have this pathway only they can access, their key and signature can be trusted. I’m not gonna trust Joe Schmoe’s signature that “No I didn’t use AI” unless I already trust Joe Schmoe (and in which case, he doesn’t need a watermark, I’ll just believe him when he says it). | |
| ▲ | fn-mote 5 hours ago | parent | prev [-] | | If you just posted your link here with that comment, I’m sure you’d get a bunch of traffic. |
|
|
| ▲ | shevy-java 6 hours ago | parent | prev | next [-] |
| > A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership. We also recently had this with LG spy-TVs. Cars here in the EU also spy on people, allegedly to show how alert they are. Perhaps they sneakily upload that information somewhere ... Facebook also has the spy-glasses now. People getting angry about Flock-spy-cameras. It seems we are now in the age of spying of everyone at all times. Future spying will be done via even smaller devices. |
| |
| ▲ | snvzz 2 hours ago | parent [-] | | People are most afraid of cameras, somehow. The concern is valid, but microphones are far worse. They're simpler, smaller, extremely sensitive to sound and an order of magnitude cheaper, both the mic itself as well as any spying with it. It is possible to record voice using few bytes, to send later. It's further possible to transcribe cheaply into text, and analyze said text. And mics are already everywhere, including in devices that do not need them, as well as speakers that can be rewired by software to act as microphones. |
|
|
| ▲ | suopspaces 5 hours ago | parent | prev | next [-] |
| Can my friend print adversarial yellow doots and such? |
|
| ▲ | viccis 7 hours ago | parent | prev | next [-] |
| Watermarking has referred to this "spy" use case for quite some time. Digital items purchased for download often have them, for example. Even before the rise of digital downloads, screeners for movies had them. |
|
| ▲ | silverFork 7 hours ago | parent | prev | next [-] |
| if it is specifically about pictures then wouldn't an analog copy clean it up? What about adding new spymark on top of it? If it is text, copying text alone and not the file will it not remove it? Massage the text with Ai and vola spymark gone, don't you think? |
| |
| ▲ | fn-mote 5 hours ago | parent [-] | | > copying text alone and not the file will it not remove it No. The mark is hidden in the word choices. See the demo in the article. |
|
|
| ▲ | mirelahmd 7 hours ago | parent | prev [-] |
| There have been quite a few similar |