upvote
These are "spy"marks, not watermarks:

https://brand.io/article/spymarks/

We need to inform everyone that this technology can encode database identifiers and enough entropy to uniquely identify you as an author (or downloader).

This extends to other forms of media as well.

reply
Cool post, but I'm wondering what would a realistic way to avoid this?

It's not really possible to ban steganography, is it?

> That future lies halfway between now and 1984. So let’s stay off that timeline, shall we?

> Call a spymark what it is. A spy tool used to spy on you and everyone you interact with.

reply
They are not spymarks if they don't encode any personal IDs and are merely used to indicate that an image was AI-generated. I don't think Google or OpenAI use SynthID to include personal data.
reply
>I don't think Google or OpenAI use SynthID to include personal data.

Why? I assume by default they are uniquely identifiable, because it just makes sense for them (tracking misuse at the very least), it's trivial to implement and trivial to hide or plausibly deny.

reply
Come on man, they're both advertising companies. Would you resist the opportunity to build that social graph and detect a known user anywhere on the internet?
reply
Of course. Privacy is a feature that increases their product value. Moreover, they could get into trouble with the GDPR if they secretly included tracking information in their images.
reply
So the obvious move is that marketing materials sing how it’s super private, while actual steganography encodes everything to uniquely identify you. If someone discovers something wave it away (and crack down on pesky whistleblowers), eat the fines if the worst happens.
reply
That's not an obvious move, that's an non-obvious, cynical, "let's assume they are evil and don't care about heavy fines" interpretation.
reply
And there lies the rub. You can't verify if they do or don't embed such content. These companies are just like "trust me bro".
reply
Indeed and Google has built its empire through tracking users across the internet so it is really hard to trust that they won't..
reply
It's worth nothing that this IS Google.

Given that it's an ad company, they want something to connect what you're doing to the rest of their data, and they couldn't possibly keep the old image search results there if they want people to use this.

reply
It's presumably so they can rate-limit people who are trying to reverse-engineer or otherwise strip it (e.g. iteratively tweaking until it stops getting detected)
reply
> iteratively tweaking until it stops getting detected

I don't think that dodgy folks have any issue with registering thousands of IDs. I know that I used to regularly get approached by these Chinese companies that were selling good reviews of my free apps. They did this by having thousands of legit AppleID accounts that would download and rate the app.

I haven't been approached by one of these in a long time. I guess Apple figured out how to put the kibosh on them.

reply
I wonder how relevant this really is.

How hard can it be to download a set of real images and generated ones in order to train a model to detect and strip the watermark with minimal perceptual difference?

reply
Yeah I've been wanting to run a ton of Wikipedia images through the detector to see if fakes snuck in. Doesn't seem to be a practical way to do this. Even Open AIs tool has a low rate limit
reply
The EULA you have to accept hints that they are afraid you are going to abuse it to remove synthID - e.g, set up and edit and check loop
reply
That’s the justification, but the EULA incorporates Google’s regular consumer terms; which means what you upload can also be used for advertising and targeting; and basically any purpose whatsoever by Google.
reply
Any access to a watermark detector can be used to remove the watermark. Presumably they want to be able to track who is doing that.
reply
I've never seen it mentioned anywhere so I will just here complain that Google also removed the ability to paste images into Google Image search some years ago for no apparent reason. It worked great and I used it all the time.
reply
Click the little camera icon in the search box and it pops a modal that says Search any image with Google Lens.

The textbox below it says Paste image link, but you can actually paste an image from your clipboard here, too.

reply
And if it doesn't work on the Google home page, just go to images.google.com and do the same, it always works there for some reason.
reply
You’re a hero. So glad I complained. Why would they not just keep this working with the main text box focused…
reply
In similar fashion in the Android Play Store they moved the search off from the top bar. For some time they educated users that "oo the search is no longer here, you need to click there -> to get to the page with search!". That has stopped (for me?), but they still haven't found any other use for same place in the first view.

I suppose it was too convenient.

reply
No idea. I used it a lot too, not sure if pasting here worked from the beginning of them introducing this Google Lens thing or not.
reply
I wonder if it’s a deliberate anti-user decision to get more URLs and less pasted images.

URLs expand Googlebot’s indexes; pasted images don’t.

reply
If they wanted more urls they would allow mobile users to search by url instead of only allowing them to search by image.
reply
I might be missing something but Google Image Search still works for me.
reply
this + image translate with copy+paste is the only reason I ever use yandex of all places...
reply
OpenAI's tool is worse though, because it doesn't detect SynthID from non-OpenAI models. I just tried it with various images created by Imagen / Nano Banana.
reply
It's deliberate so that you can't find a way to bypass it.
reply