Edit to add: I just tested LibreOffice/26.2.5.2 and it is not injecting a UUID into the metadata either for a ODT or a DOCx (2007) file. I do not have native MS Office available on hand to test at the moment. I do see these UUIDs in published government documents but cannot swear to exactly what step of the pipeline is stamping them. Definitely on files that predate the AI integration push by Microsoft.
> Watermarking carries no identifying information and can’t be traced to a specific person, organization, or chat;
Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.
In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.
A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.
MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.
I don't understand that people still buy an OS from a company that actively hates it's customers.
The amount of things they pull should not even be succesful on a OS you get paid FOR to use.
I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.
1. The watermark only applied to AI-generated contents through the in-app AI (copilot/cocreator, etc). If you draw something by hand it is not watermarked
2. Privacy implications: I believe your MS account is linked to the prompt and the GUID. And the GUID is embedded into the image as both an insivible watermark and a file-level C2PA metadata. I did not write about this very deeply in my blogpost, but when I do an image generation, it deducts my AI credits (yes, MS gives you like 60 free AI credits), so MS surely knows where the prompt is coming from. Though I am not sure about their storage and retention, e.g., do they actually store the data, and if they do, for how long, etc
Anyone disturbed about that ? It's your computer, running locally, but Microsoft can tell you 'no'.
It's like you want to open a folder and it asks permission to Microsoft.
Prompt moderation, GUID insertion, watermark insertion; track anything and everything, probably done in the name of "protect the children".
Anyone not deep in tech will accept the "think of the children" defense without much worry, and anyone who is deep in tech already knows that if you really want an OS that doesn't spy on you, you need to go to a *nix of some flavor.
The request is JSON and contains at least these fields:..."prompt": "..."
Local SD (especially the earlier versions) is already uncensored, so they're effectively crippling it with additional spyware that phones home to tell Microsoft what you're doing and asking whether they approve of it. IMHO the invisible watermark isn't the worst part, but rather the fact that MS is logging every interaction you have with the model, which doesn't ever need to leave your machine.
Virtually all commercial printers embed an invisible identifier on every page printed.
I wonder whether Arthur Conan Doyle had the idea before the police started using typewriter typeface wear and tear for forensics.
"Cannot run local AI model, no network connection".
The more you think about it, the more it really is the same: https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=...
If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats.
See e.g. PPM format: https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/...
These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.
With regards to Microsoft being ... uhm ... "transparent":
> The same page says that generated images:
> “will contain C2PA manifest helping users identify that it is an AI generated image.”
> [...] That is a meaningful disclosure of remote filtering and C2PA metadata.
> C2PA manifest contains a GUID identifying the invisible pixel watermark
> Calling the feature “Content Credentials” is accurate, but it does not > make this prompt-associated identifier obvious to a Windows user.
I don't think this is accurate, because without that detective work, most people would have no idea that Microsoft tags and tracks the images here. This reminds me of printers printing identifiers to ID individuals. What this to me means is that I can no longer use any such Microsoft services, because there is no trust for me here. Microsoft sniffs on me, if I were to use these software products. AI is a big spy-op too.
Microsoft could easily admit "we watermark all your images, whether you like it or not", but corporate speak forbids this and they don't really admit to it. They do not use the word watermark officially, but their .dll names reveal it. That means they resort to deceit and propaganda.
It really is time to strengthen the whole open source ecosystem. I no longer want my taxpayer's money to go into traitorous US companies that abuse EU citizens here. (Note: the same would apply to EU companies, but the USA dominates the software sector, unfortunately. This also has to change permanently.)
My question..how does it work? Is it robust? I remember that young me hid data in pixels of png with simple stegonagraphy and it was a fun little project..but brittle. How exactly does the fingerprinting survive jpeg compression? Is it repeate over and over the images or is it just one area? If that one is pure black by chance the jpeg algorhitmen would erase it all no?
Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no".
Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.
There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.
But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.
convert file.jpg file.bmp; convert file.bmp file.jpg
Took me a moment to realize you're saying someone else generated it, rather than you did.
This seems incorrect to me. Are you basing that on the use of bullet points?
> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.
> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.
> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.
Personally it didn't bother me too much.
Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.
Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]
Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.
In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.
It's most likely how the FBI caught NSA leaker Reality Winner:
> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.
Did it get revealed that Apple did that? This is news to me
Also, C2PA, another technology mentioned in the article, means tampering is easily detected.
Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
Provided you bent the knee and created a Microsoft account.
*with the help of AI*. Does in fact make a difference.
I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.
Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.
Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.
As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.
Sorry for a dumb question but what would one use as a mailing address? Rent a PO box, or use a mail forwarding service, something like that?
Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.
Presumably USA are complicit in this spying on allied countries - did the countries know, is it a Five Eyes thing?
At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."
so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.
to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.
Personally I think there is a good argument for being able to distinguish AI generated image and video...
Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.
Not that much different from running Red Star OS from North Korea, actually.
I own an Xbox with an family account. Microsoft's account management is terrible. Their customer support is terrible (computer says no). Never again.
They can't win on that topic.
Now I would not want to appear to defend the mess they've created out of windows, that's not the point.
The only (and inevitable) solution at this point is for big tech to get micro-regulated like the banking industry. The same mindless greed that drove them to take control away from their customers will be responsible for the same control to be taken away from them.
Nonsense. They let anyone draw any pic they like.
What's the alternative? What if you work at literally any Fortune 500 company?
Also, if your laptop is work provided, your laptop is going to have little to no privacy no matter what.
Nothing is stopping you from using it for free at home, everyone is privileged in that regard.
And it was obvious to everyone else, I was talking about decisions you can take yourself. I'll try better in the future to be hyper explicit about this, so people who are looking for a reason to feel hurt will have a harder time.
IBM, SAP, Capital One, GE, Cisco, Intel, Deloitte offer a Mac/Windows choice program. Better than just one choice, and arguably a bit better of a privacy record than MS (especially of late)
Do you really think this is a problem confined to those who buy the OS they use?
If I wanted all of that, I would have used a different app!
I don't understand why they didn't just stuff all the AI things and new features in Write, where it belongs…
Doing so with MSPaint removes the app, so you need to find a clean older version..
It's a pixel-perfect modern clone (with some actually useful extras that won't get in the way unless you look for them), and yes, you can clone the repo and run it locally.
Unfortunately, some of the regular paint tools like eraser don't erase in a smooth antialiased way and just end up looking jagged (also only a square shape for eraser...no eraser brush mode unfortunately), so it ends up being a better looking option (well, when it works properly, which it does often enough to be useful). For whatever reason a bunch of tools and transforms (scaling, rotating), just produce such garbage jagged looking results, it's not serviceable even for those basics.
But yea, I guess it’s a bug in 2026.
It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.
We've probably lost the fight over GenAI marks, at least for now, and I do understand the need for them. However the same technology that can embed an invisible watermark that survives a round of photographing, printing, crumbling and scanning back - can be used to embed more information than just "it's AI generated". Encoding GUID is just a harbinger; as a next step, why not encode the app that produced the image? Also a hash of its license key? Hell, what's stopping an app from doing it itself, watermarking its own window before passing the pixels to OS for compositing?
"Robust GenAI watermark" today is "robust general-purpose DRM watermark" tomorrow :).
Other image editing applications can do all of that, but they take 10 years to launch (during which they will ask for focus) and 2 GB of RAM.
Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.
Did it?
Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise.
A sudden knock on your door might happen because of an ambigious search/propmt.
There are droves of people petitioning Valve to add kernel anti–cheat to CS2.
"I need it to work on a random Thursday, not wait for fsck after ever reboot"
It's also a bit rich especially to complain when Microsoft also suffers from forced autoupdates and the like.
I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.
"That's not up to you."
When people claim they have nothing to hide, always point out that's not up to their determination. That freaks them out, it disarms their shrink-from-confrontation move.
And you can point it out super fast, in a plain six word statement. No need to launch into a deep discussion unless prompted.
Alternatively, simply respond with: yes you do. When they reply: "what?" - "every single thing you have ever done wrong across your entire life." Everybody has done something they would prefer to keep hidden, the cowards just lie about it.
Considering putting linux on a 2nd PC
If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.
Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.
For something that just works I recommend Fedora or Ubuntu. It's what I'd put on my mom or wife's PC.
Currently using Omarchy on my laptop though which is a tad more exotic, it's Arch + Hyprland and is pretty polished for that stack (at least the current version, 4.0) but still a tiny bit of jank.
Imaging every pdf file, every image, every office documents, and every video has a hidden record of the associated Microsoft accounts of all computers it has ever passed through. This should sell well, and realistically nobody can stop them. Why haven't Microsoft done this much earlier?
That sounds like a privacy violation that the DPAs should look into.
Edit: Apparently it's disclosed somewhere. Still, that defeats the entire point of local generation...
And federally, the C2PA strongly encourages digital providence albeit without legal consequences... yet.
All AI content coming from companies that service the US market are watermarking things.
Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".
And ironically, I think that this one is kinda fair. I mean, you specifically asked your software to generate whatever pseudo-random bytes it wishes to loosely based on some text prompt. It did that. Now, apparently, these pseudo-random bytes turn out to be personally identifiable. So what? I suppose they didn't claim their PRNG to be cryptography-grade. They could even make it seem like an accident, should they be bothered to. Make it way less obvious.
Now if it would insert watermarks on save (like printers do), that would be really outrageous. But when you trust software to produce "whatever", you probably shouldn't be really mad about it doing anything more than you asked to.
Why? What needs tobe moderated locally?
Extremely odd way to write. Are the writer's own thoughts invisible to him or her?
this also reminds me of what got me hooked on CS in the first place: a simple java steganography app in cmsc150
It's possible a very bad curator with a terrible taste in art might select slop to display, but I was refering to "fine art" or at least finer art that is digital.
It's also not whataboutism, the comment specifically wondered how else were being surrupticously tracked without our knowledge. This is a concrete example and I think many would be surprised such tracking also exists outside the digital realm.
Maybe. Question is, was that a false positive, or merely a bad user-facing message?
Assuming you didn't have any AI-generated images caught in the screenshot (e.g. some advert - plenty of those even in Microsoft apps like Weather, nowadays), what if - and I'm speculating here; I don't know if anyone actually does it yet, but it's so obvious they eventually will -
- what if parts of your screenshot already had an invisible watermark on it, like the ones for tagging AI images? You can imagine an app rendering its window to texture, and embedding a watermark on those pixels before sending it over to the system compositor, and the reasons have nothing to do with AI.
Watermarks are DRM tech. "AI generated" is just a specific kind of metadata that can be put in one, and a huge red herring for discussions.
It's only a matter of time before we'll need to have software for detecting and removing real-time watermarks from display output at OS level. (Unless, of course, platforms decide to add app window live watermarking as a "feature", and given the story with remote attestation, I think it's more than likely.)
Now some one slightly more sophisticated starts creating deepfakes of a woman and uploading them or fabricating video of an political event without this marker. The subject protests it's fake and AI generated but a loud majority of ignorants feed it into Microsoft AI detector and call you a liar and say it's confirmed real. Most people don't know any better and eat it up because a computer said so.
Some proof: https://verify.contentauthenticity.org/?source=https://retr0...
I could also paste a privkey + cert chain in here but el goog's lawyers might not like that.
Being signed with something just means that whoever has that key could've done that. That might be the owner of a specific camera, but it might also be the camera manufacturer, anyone else in the supply chain, or anyone who dumped the key.
Imagine fake evidence signed with the same key as your camera uses being used in court against you. And the court believes it because it has this signature attached and those computers are very secure and all.
Exactly that will happen. Not widespread, of course, but it will.
But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.
I suppose a dedicated fraudster could still stage an appropriate scene. An appropriately lit matte image might even suffice.
If we as a society deemed it necessary, the camera manufacturer could also provide a list of keys for devices they have manufactured. And an image/key could be provided, and the manufacturer could verify the authenticity that way.
The TPM signing could be tied into the sensor hardware itself, making it difficult, but not impossible, to sign arbitrary images with the TPM.
People take RAW photos. Load it up in a RAW editing tool. Manipulate it. Then load it in Gimp. Manipulate some more.
Will the final result have the signature?
And if it does, what use would it be?
Each piece of software in the chain must use TPM-like technologies (yes, even GIMP) to make sure it's running a "legitimate" build of the software, on "legitimate" hardware, and re-sign the file at each step along the way (using keys provisioned during some flavour of remote attestation flow, or using a RA-authenticated remote-signing oracle).
The final file embeds every preceding manifest, so you can "verify" all the way back to the original.
If this all sounds patently unworkable, that's because it is.
No. You'd only ever be able to show that key material belonging to $specific_camera was used to sign/mark the image.
Was the camera manufacturer breached? Did somebody on the factory floor steal some keys during the provisioning step? Or did somebody build their own photo-sensor simulator and plug _that_ in to the camera's motherboard to feed it a "real" image? Before going _that_ far, just point the unmodified camera at a sufficiently high resolution display...
> build their own photo-sensor simulator and plug _that_ in to the camera's motherboard to feed it a "real" image?
Already been done!
https://hackerfactor.com/blog/index.php?/archives/1102-C2PA-...
TL;DR: Strong cryptography over untrusted data does not make the data more trustworthy.
"I think it would be nice if all typewriters had their unique fine-detail type artifacts registered with the government. You could tell exactly who authored a given document."
I think it would be nice if you took these ideas back to Stalinist Russia where they belong.
I already replaced the 'solitaire' games suite with pysol running on WSL2 and it's a vast improvement!
tldr -if MS is going to screw us, why don't we mitigate it by using replacements?
https://w2.eff.org/Privacy/printers/docucolor/
Seems like the algorithm is simple enough that they did it just by looking at some prints
So? Still the weapon worked.
I am not willing to pay the price of sending every bit I create to some megacorporation's server or stamp it with my only identity so the computer can tell me what's AI and what isn't. Especially not while the average quality settles into an uncanny valley that's often discernible with the naked eye, both for text and images.
Their images? I don't know how they'll be able to prove that.
While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.
It takes zero effort to bypass that with Rufus, if you set up your own pc.
Even in places with strong privacy regulations requiring businesses not to collect data they don’t need, businesses apparently get away with asking this.
Because of the volume of stolen credit card numbers. If you have the address, you are much less likely to be someone using stolen CCs. Seriously, most of the crooks are that lazy. So the real reason is the credit card processing companies.
Also, post 911, there is this thing called "know your customer". It was set up to fight money laundering and financing terrorists.
And as soon as you connect with telephony systems (e.g. VoIP numbers) or rent out servers, some countries' telecom KYC laws apply that also force MS to collect validated address data.
Because handling that PII is not only cheap, it’s profitable!
Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239
"I haven’t read enough to understand". Oh, now I know the answer to my question
The more complex the rules become, the more difficult it will be for alternative providers to exist, unless they have explicit carve outs. So far, with age verification and user id laws, there doesn't seem to be much appetite from politicians to create exceptions for open source and smaller projects. By comparison, in the US the regional banks have special exemptions for many of the really onerous regs, which is why they are still a bunch of them.
They also started rendering and preserving Unix-style line endings (LF).
Very welcome breaking changes :)
The inclusion of autocorrect (that I mentioned) would be example here: previously, it would accept whatever text you gave it verbatim. Now, it will sometimes change non-dictionary strings to dictionary words.
(Another thing that bothered me was that, on the update, it forgot my font settings and I had to work to re-find them.)
I'm happy to admit my phrasing was confusing, but not enough so that you would be unable to see the relevant failure mode.
Notepad addresses a specific use case (dumb text editor). If you have a different use case, there are other applications that handle it.
Nobody knows how to make a camera that can distinguish honest vs deceptive photons.
All the slippery slope nonsense on this page has failed so many times it’s not worth debating. If you don’t like this tool, use another. When they embed your social security number and face and address in the mark get back to me.
I assume regular home users may have different expectations for what Paint should be able to do.
People are entitled to privacy because they enjoy it. No further justification is needed.
:It's FOSS
3h •
Microsoft quietly embeds a hidden tracking identifier in every AI-generated image you create using Paint or Photos on Windows.
A researcher discovered that these apps embed a server-issued GUID (a globally unique identifier) as an invisible watermark in locally generated AI images.
The watermark is tied to the prompts you type. And since those prompts are associated with your Microsoft account, Microsoft could "theoretically" trace any watermarked image back to the user who created it.
This is recycling an idea from the 80s. Back then, laser printer manufacturers added tiny yellow dot patterns to every printed page. With this, they could identify the printer.
Now Microsoft has brought the same idea to AI image generation, and added it to two of the most widely used default Windows apps.
Microsoft had disclosed its AI safety measures in official documentation, but the practical implication, that your output image file carries an invisible fingerprint linked to your identity, was never clearly mentioned, of course.
The researcher found this by reading Microsoft's own published documentation and analyzing the watermarking mechanics.
AI watermarking is a requirement by law in the EU. But "this image was generated by AI" is different than "this image was generated by AI by Mr. Winston Smith".
For anyone who values privacy, this is something to worry about. If you generate an image locally, on your own device, why should it carry a tag that can identify you to the company whose software you used?
But then, anyone who values their privacy won't be using Microsoft Windows anyway."
Since the cat is out of the bag, I wouldn't be surprised if Microsoft generates an invisible watermark for ALL files and not just AI generated ones. The real story is that since AI watermarks are possible, there is no technical barrier to them adding personal EXIF metadata to a file where it can't be seen, removed, or decrypted, whether it is media, a document or other file.
But this is all moot really, if MS Paint is watermarking shit, it’s better to just use something else. Nothing from Microsoft is trustworthy.
Essentially all of that country's businesses that are close to the regime need to be considered hostile.
We don't need to wait a few years, the revolution already happened; the insurrectionists were freed. These companies paid their tributes, in dollars, to the regime.
Maybe next ML will be integrated into software suites to enforce that regime's lies? Most Western governments use such software, the distributers of which have already shown they'll act in the regimes interests against supposed allies...
Some servers allow joining without a Microsoft account even these days, but probably can't play on any of the servers you regularly play on, if you don't have a Microsoft account.
Why not just mod the app to not call this API?
Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.
No it's not. Sign up for a virtual mailbox for $15-$25/month.
> A scalable solution would be to make this sort of thing illegal.
I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.
It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.
Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.
It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.
That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.
or make it illegal to ask for address, etc. definitely a little more effective than mailboxes
I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.
I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.
You are out of touch.
Besides privacy against leaking your sleeping-address to businesses, they're also convenient for avoiding package theft if that's a problem in your area, and receiving/forwarding mail if you travel a lot for extended periods of time.
I'd recommend against PO boxes because (1) they get rejected by some services (2) UPS and FedEx won't deliver to them.
Because these businesses have to register as CMRAs and you have to sign a notarized form for them to legally receive mail for you, some services will still detect it and not let you use the address, but my experience for the most part has been that most US financial institutions let you enter a "residential/legal address" (no CMRAs allowed) and a "mailing address" (CMRAs allowed) separately, and the mailing address usually becomes your billing address.
They will move faster to track each and every one of you, all the while shoving ads and garbage down each of your respective machines... and you all pay for it?!
That's exposed in the USPS API for address validation. Which the USPS is starting to charge for access. Everyone doing address validation in the US eventually uses that service (sometimes through a go-between).
Inserting a tracker that can personally identify me without my explicit opt-in consent is a GDPR breach. I'm surprised you do not not this.
The whole EU vision is they know what the little people do all the time, think all the time, and spend their money on all the time. For the children, obviously.
In the meantime, the GDPR is your friend. The amount of FUD spread about it on here by those working in Adtech (and whose very salaries are dependent on invading peoples privacy) is insane.
He still streams on Twitch, he got a temporary week "long" ban and then came back claiming it was a virus or an accident while also claiming he has a porn addiction problem... but don't worry he's very "sorry" (to have been caught).
The state of this Amazon-owned streaming platform is wild... and that's without even looking at the rampant antisemitism (their second top political streamer, Hasan Piker, currently has a bipartisan US House resolution (H.Res.1239) in progress calling him and Candace Owens out for their antisemitism), repeated call for violence (their top political streamer, Asmongold, was recently banned for a few days for calling for the murder of immigrant's children by ICE) and the repeated reckless/distracted car and even truck driving streams with some even leading to accidents (luckily enough without any deadly one... yet).
All these are against Twitch rules, but the staff and even the CEO (who cosplays as a streamer) selectively apply the rules and unban the streamers who are under contract with Twitch or are well connected with the staff.
I have no idea why Amazon or Twitch shareholders have not cleaned house already (e.g. ousting the CEO and the people in charge of the moderation), especially considering the fact that even with all these transgressions, Twitch isn't profitable after years of activity.
They are waiting for someone to actually die I think, with clear links to Twitch... if that ever happens there are plenty of evidence that Twitch and Amazon know what is going on and barely does anything about it.
To answer your question of why, it's probably because they make money.
Otherwise you might as well use photoshop.
(But no I’m not kidding myself, I realize the days of using Paint to actually Paint are over)
https://www.reddit.com/r/archlinux/comments/1cvwo93/arch_run...
If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.
I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.
https://bugzilla.kernel.org/show_bug.cgi?id=218770
https://lore.kernel.org/linux-f2fs-devel/20240409203411.1885...
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07280.html
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07260.html
https://bugzilla.suse.com/show_bug.cgi?id=1226043
https://lists.opensuse.org/archives/list/bugs@lists.opensuse...
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/15478...
US Social Security Numbers are a useful analogy: The designers knew they weren't something anyone could securely depend on, and told people not to do it... but companies did it anyway, for their own convenience and cheap security-theater. Ultimately a lot of individual victims suffered for it.
It would have almost been better if one big incident blew the "knowing an SSN means something" myth apart early on.
https://transparency.ky.gov/search/Pages/SalarySearch.aspx#/...
> and work underground for cash
My sister was a member of Scientology for 2 decades and she was encouraged to do this. As a result, she has almost no Social Security earnings and her Social Security check is about 1/4 of what she would be getting if she reported (and paid taxes to the government instead of to her "church") her income.
> decide to vote? Your information again is publicly available
I ran for elected office in the past. When I asked the voter registration office for a "walking list", they only checked that I did get on the ballot and I was provided with a list of every registered voter in the district I was running for. It had names, addresses, phone numbers, political party and a list of what elections you voted in (I think it went back 8 years). Some people were rather upset that I had access to that information when I knocked on their door and asked them to vote for me.
Linux does experience regressions, but your argument conflates upstream development, bleeding edge releases, and stable distro releases. Those distinctions are fundamental to how linux distributions work, and these links don't support the claim you're making.
Yep. Good catch, I think you win the argument. These are all distros that are under development and their underlying issues should never be called-out as handing the user frustration as they willingly chose to become a victim of the kernel.
If the TPM signs the original image taken by the camera, then even the slightest image processing on another device would invalidate the signature. Routine changes like cropping, scaling, converting between image formats / quality levels, or applying image filters would invalidate the signature.
An adversary can manipulate the date/time settings on the camera and forge evidence to frame someone. "This cryptographically signed photo, with timestamp, proves that you were here at this time!"
And camera sensors can get damaged and need replacement. But if replacement of the TPM-and-sensor chip is allowed, then you can just as well replace it with a sensor from another camera. In which case a signature from a specific TPM+sensor doesn't prove that a specific camera took the photo, at best it might be evidence that a specific camera model took the photo.
If the manufacturer will happily ship a replacement TPM+sensor for a specific camera, someone can fraudulently claim that their sensor is broken and be given a new TPM+sensor for the same camera. And there will now be multiple TPM+sensors in existence that have the same key. Since this module can be switched between cameras, there could be multiple cameras that signed a given picture.
To ship (identical) replacement TPMs, the manufacturer would also need to know the private keys of all the cameras, so the manufacturer could forge arbitrary signatures at will.
Finally maybe the manufacturer doesn't want to deal with the above problems and decides that repairing the camera's TPM is not allowed after all, or that only the manufacturer is allowed to repair a camera, but then they may be in violation of right-to-repair laws in several jurisdictions.
If I need to reset TPM, how do I reclaim photos I took previously?
If a key was reset, a revocation of the original key could be issued, showing that the key was associated with the device for this particular time span. And then the new key registered.
This is ripe for abuse though, so resetting a TPM might not be accepted for this use case. I'm not certain in which case you'd want to reset a TPM for this use case though. Unless you took enough photos with the device to risk a birthday attack if you were using something like ECDSA.
Also plenty of groups fighting against racism and antisemitism have come out against him (ADL, AJC), it's easy to Google.
That House resolution is just the latest good indication that it's not just some isolated incidents.
Piker's only answers are that he's taken "out of context" or that he's "joking", there's literally no context that make his public statements better or less antisemitic though, if you have any I'm interested. He also publicly voice his support to groups that are openly antisemitic (Hamas and Hezbollah) and recognized as FTOs (Foreign Terrorist Organization) by the US government.
Now, it's his First Amendment right to be this way but Twitch/Amazon share a responsibility when they platform this content, and even more when they apply moderation selectively, in my opinion that should forfeit their Section 230 protection. They are deliberately shaping the discourse on their platform by permanently banning other streamers with opposing views and never taking similar actions against Piker.
"Fun" fact, Twitch even had to carve out their own rules because Hasan Piker couldn't stop himself from calling Jews in general or some groups of Jews "zionist pig-dogs" and "inbred": https://www.nbcnews.com/tech/twitch-changes-hateful-content-...
EDIT: Regarding the bills of attainder, it likely doesn't apply here because they aren't trying to punish these two antisemites specifically, they just use them as examples of the proliferation of antisemitic content on platforms like Twitch and want Congress to condemn this practice and encourage platforms to address the issue.
He must've really pissed someone off to get his own hate site. I think we all know who he pissed off. That hate site would be illegal in the EU btw.
Skimming them and picking one that doesn't fully meet your criteria, then call it a "hate site" and then use vagueries like:
> He must've really pissed someone off to get his own hate site. I think we all know who he pissed off.
Tells me you have no interest in engaging in this in good faith.
Also nobody cares if a website quoting someone being hateful would be illegal outside of the USA. Piker is an American citizen, spewing hateful antisemitism on an American platform... but nice attempt at a red herring.
All these fixes and repairs ignore the fact that abusing people pays. Surveillance capitalism pays, and provides a revenue stream for Microsoft to further exploit.
The only way to win is not to play.
I don't have a Copilot PC, but if you still need to pay MS to run the model on your own hardware it's laughable.
I genuinely wish you were right, but you are so naive it is frightening.
> The amount of FUD spread about it on here by those working in Adtech
You are confused. You are arguing with people that want to protect privacy. The EU demonstrably is not doing that, as WhatsApp gets ever more de facto mandated by the day.
> It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.
Apple Text Edit vs Pages.
When you cite a parade of bullshit I'm not obligated to refute all of it. A representative sample is enough to demonstrate that it's bullshit and that the bullshit asymmetry principle applies.
The same goes with not addressing all the other points made and sourced in my messages above.
The fact is that there are enough blatant and contextualized statements in that list and the rest of the points I've made. They show his antisemitism.
Piker is openly supporting Hezbollah and Hamas "10-toes down", again irrefutalbly antisemitic terrorist organizations.
Most recently he had a slew of Democrat figures at the national level either denouncing him or distancing themselves, again, for his antisemitic comments (Hakeem Jeffries, Corey Booker, Josh Gottheimer, Hillary Scholten, Jeremy Moss, Abdul El-Sayed and so on).
This happened because Hasan Piker rambled about Jews, and specifically American Jews being responsible for the antisemitism they endure and that they shouldn't be surprised if someone "takes action" against them if they continue to want a state for Jews:
> And if Jews in America keep putting this idea out there that they are singularly invested in Israel, eventually someone's going to come around and take action, not against the state of Israel, mind you, but against American Jews.
> [...]
> You're running around basically tying your entire identity to a country that inevitably will be seen as, basically, Jewish ISIS... You're making antisemitism worse.
But keep running around saying "bullshit" if you want, it won't change facts.