MS Paint and Photos inivisibly watermark even locally generated output with GUID
100 points by ComputerGuru 2 hours ago | 41 comments

weberer 25 minutes ago
The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.
reply
qurren 15 minutes ago
> address

Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.

Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.

reply
cuu508 5 minutes ago
> Make sure you register mailing addresses with your credit card institutions

Sorry for a dumb question but what would one use as a mailing address? Rent a PO box, or use a mail forwarding service, something like that?

reply
BitwiseFool 9 minutes ago
Windows 11 effectively forces users to register with a Microsoft account. Once that's established, all it takes is for an unaware user to fill out an e-commerce form and save an address for auto-fill.
reply
nemomarx 24 minutes ago
Does it trigger on non AI images? The post doesn't say so at least.
reply
ComputerGuru 2 hours ago
AI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible (cannot be disabled and happens silently in the background with no user notice) watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end).

Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.

In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.

reply
nemomarx 41 minutes ago
I'd like to know more about the GUID part and how easy is it so deanonymize yeah.

But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.

reply
stronglikedan 39 minutes ago
> AI-generated text warning

This seems incorrect to me. Are you basing that on the use of bullet points?

reply
NuclearPM 47 minutes ago
I don’t understand the warning.
reply
phainopepla2 36 minutes ago
They're saying that the blogpost is at least partially AI-generated.
reply
like_any_other 47 minutes ago
[dead]
reply
JoeBOFH 40 minutes ago
I had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.
reply
initramfs 29 minutes ago
I guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).
reply
aqfamnzc 15 minutes ago
Paint.net is named after the dot net framework and is not referring to a URL or the internet as I understand it.
reply
erk__ 8 minutes ago
Paint.net actually just recently got ownership of paint.net, it only took 22 years: https://www.xda-developers.com/after-22-years-paintnet-downl...
reply
initramfs 12 minutes ago
ah, right, i vaguely recall that now. But why/how would it know AI was used, outside of a local LLM, weird it would say that AI was used (unless it's referring to the software itself).
reply
a1o 14 minutes ago
They aren’t saying that, paint.net is an open source application, Paint is the descendant of MSPaint.
reply
Delphiza 36 minutes ago
I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.
reply
torginus 34 minutes ago
Well if that's any reassurance, you can generate a meme picture using AI, then paste it into Paint to add some funny text. That way you can get the best of both worlds.
reply
VCFundedGenYer 24 minutes ago
Keep an eye on this.

A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.

MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.

reply
nemomarx 46 minutes ago
Interesting. I really didn't think watermarks would end up going anywhere, but maybe with enough adoption we can have easy ai generated content flagging after all?
reply
dotancohen 35 minutes ago
Not every generative AI model will watermark. Especially not adversarial and disinformation models.
reply
AaronAPU 30 minutes ago
So as usual, exactly the things you want it to work on it won’t.
reply
jambalaya8 3 minutes ago
I mean, workarounds wouldn't be hard, just annoying, anyway. Like an extra step or two (take a screenshot, change the image format, wipe the metadata; or print, take photo with camera, clean up in something like gimp, same other steps).
reply
initramfs 26 minutes ago
Thanks Microsoft, for adding my signature so I won't have to claim authorship when it ends up in a museum in 200 years, and the NSA archives are declassified for art historians filing a FOIA in 2226, who find out, "yep, it was from his PC."
reply
sixothree 43 minutes ago
I think it would be nice if all cameras digitally signed pictures. You could prove the photo was real.
reply
avidruntime 2 minutes ago
When I was in photography class in college, I created backplates in photoshop for still life portraits of small trinkets I was photographing. The photos were taken on black and white film and developed in the campus dark room. Led to some impressive photos. In our class's critiques, I explained how it was done. A lot of peers went from impressed to meh'd. The point: the black and white film laundered the new-age manipulation, and a digitally signed photo from a modern camera remains vulnerable to the same premise.
reply
spicyjpeg 17 minutes ago
If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitable devices and used to decrypt as much content as possible before the device gets blacklisted entirely (harming all legitimate owners in the process).
reply
hypfer 7 minutes ago
I don't think that that's a good idea, because it implies trust when there actually isn't any.

Being signed with something just means that whoever has that key could've done that. That might be the owner of a specific camera, but it might also be the camera manufacturer, anyone else in the supply chain, or anyone who dumped the key.

Imagine fake evidence signed with the same key as your camera uses being used in court against you. And the court believes it because it has this signature attached and those computers are very secure and all.

Exactly that will happen. Not widespread, of course, but it will.

reply
deadbabe 3 minutes ago
Imagine today where a photo is submitted as evidence and the court believes it even without signatures.
reply
hypfer 2 minutes ago
Precisely. Now take that, but glue a "the machine has cryptographically proven that this is legit" to that.
reply
615341652341 39 minutes ago
The hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”
reply
sixothree 4 minutes ago
I was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me.

But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.

reply
WalterGR 37 minutes ago
What would prevent someone from applying the same algorithm on a computer to sign arbitrary images?
reply
wzdd 2 minutes ago
Or, you know, using the totally-real-picture camera to take a photo of an AI-generated scene?
reply
arjie 30 minutes ago
Presumably the OP is proposing something like a TPM attached to the image sensor that signs the sensor output or something like that. You can’t sign it because you can’t get the key out. The key could be per-camera and be a published list.

I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.

reply
ixwt 29 minutes ago
Keys could be stored in something like TPM on Camera, and could sign the image. The key could then be verified from the camera itself to prove the authenticity of the image.

If we as a society deemed it necessary, the camera manufacturer could also provide a list of keys for devices they have manufactured. And an image/key could be provided, and the manufacturer could verify the authenticity that way.

The TPM signing could be tied into the sensor hardware itself, making it difficult, but not impossible, to sign arbitrary images with the TPM.

reply
iAMkenough 26 minutes ago
If I steal your camera while you're on vacation, do I then gain proof of ownership of your photos?

If I need to reset TPM, how do I reclaim photos I took previously?

reply
sixothree 12 minutes ago
Finally a legitimate use for NFTs. /s
reply
dotancohen 34 minutes ago
Asymetric keys
reply
gigel82 13 minutes ago
I'm honestly surprised they don't upload the entire image to apply the watermark server-side, to the point that I'd like someone else to repeat this investigation and confirm it's not happening.

Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".

reply
deadbabe 6 minutes ago
It is already fairly trivial to write a universal watermark remover, an LLM can do it for you.
reply
sehw 22 minutes ago
[dead]
reply