"Spymark": A New Word for AI Watermarks That Secretly Track You
Writer Brandon Thomas argues that a subset of so-called watermarks deserve their own name — “spymarks” — because they are hidden, non-consensual tracking signals rather than visible marks of authenticity. Unlike a copyright overlay or banknote security feature, a spymark is embedded imperceptibly in the pixels, audio waveform, or word choices of a file, where the user can neither see nor easily remove it. He points to Google’s SynthID, whose SynthID-O variant can reportedly pack a 136-bit payload into a 512x512 image — enough for a 64-bit database identifier tied to a user’s identity plus 72 bits of error correction — and notes that OpenAI and others are building similar systems at scale.
The core distinction is control and intent. Standard metadata like EXIF or ID3 tags is documented, inspectable, and strippable; spymarks are opaque, encode identifiers useless to the user, and are engineered to survive compression, re-encoding, and metadata removal. The technique predates generative AI — 1980s printer tracking dots are an early example, and the open-source audiowmark tool has hidden AES-protected 128-bit payloads in audio since 2018. Companies frame the technology as a way to flag AI-generated content, but Thomas contends they have layered robust tracking onto that premise.
The piece is a rhetorical and privacy argument as much as a technical one: renaming the technology, Thomas says, front-loads the surveillance risk that the neutral word “watermark” obscures. His warning scenario is a world where every device is attested and every post carries an account-linked identifier, letting content spread — and the people spreading it — be traced back from a single JPEG or tweet, a prospect he calls “halfway between now and 1984.”
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.