clickety_clack 8 hours ago

I admit it’s a while since I’ve used windows, but it’s such a shock to hear that MS Paint isn’t just a point and click pixel coloring app anymore. It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.

I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.

SideQuark 8 hours ago

If you read the article instead of the headline…….. it’s adding a fairly standard mark to AI generated images to let’s others know, in the same manner a giant swath of the GebAI industry has agreed to.

trickypr 8 hours ago

I think their point is that paint shouldn’t have any GenAI features (or any new features other than compatibility)

buzer 2 hours ago

I don't think adding an identifier which can most likely be mapped back to user is "standard mark".

It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.

SilasX 8 hours ago

Even Notepad isn’t a dumb app anymore! They made breaking changes after 40 years so it has autocorrect, rich text, and Copilot.

If I wanted all of that, I would have used a different app!

pxoe 7 hours ago

I wanted dark mode, tabs, and autosave, and now I don't have to use a different app to get those, so that works out great for me. Not sure what "breaking changes" even means for that though. Did it suddenly stop being able to open text files? No, it still just works.

drdexebtjl 7 hours ago

IIRC they did make a breaking change by changing the default character encoding to UTF-8 without BOM.

They also started rendering and preserving Unix-style line endings (LF).

Very welcome breaking changes :)

pxoe 6 hours ago

That's a really fair point, but i'm not sure if that's what they meant by "breaking changes" if that was followed with "autocorrect, rich text, and Copilot"

bananaboy 6 hours ago

For a long time I used metapad as a notepad replacement https://en.wikipedia.org/wiki/Metapad (I even renamed the exe to notepad). Very fast and minimal.

travoc 5 hours ago

It automatically saves and reopens whatever you previously pasted in there. Quite a shock the first few times it happens. It's not a safe temporary holding area anymore.

jamesfinlayson 4 hours ago

Yeah I switched to Windows 11 recently and was a little annoyed by that - Notepad was always a place to paste formatted junk to get the plaintext - I don't need anything persisted.

Rohansi 4 hours ago

They also added a settings menu where you can go and turn all of the things you don't like off, including that.

bigstrat2003 an hour ago

Then they should've left those things off by default, rather than messing with the expected flow of the application for everyone.

mook 4 hours ago

Yeah, I've been working around that for now by uninstalling notepad. Which actually uninstalls the store app, which in turn exposes the actual notepad executable that ships with Windows. Really confusing, and will probably break in some future version of Windows.

I don't understand why they didn't just stuff all the AI things and new features in Write, where it belongs…

titzer 4 hours ago

I don't use Windows, but I have to say that TextEdit on the Mac is absolute crap. Literally every default is wrong. Text is too small, looks like crap, cut-and-paste always brings absolutely crappy styling with it, its autocomplete and autocorrect is bad and wrong and annoying. No one at Apple uses this application with any regularity and it shows.

pxoe 7 hours ago

Background removal is really useful though, saves a bunch of time.

Unfortunately, some of the regular paint tools like eraser don't erase in a smooth antialiased way and just end up looking jagged (also only a square shape for eraser...no eraser brush mode unfortunately), so it ends up being a better looking option (well, when it works properly, which it does often enough to be useful). For whatever reason a bunch of tools and transforms (scaling, rotating), just produce such garbage jagged looking results, it's not serviceable even for those basics.

cj 6 hours ago

Pixelation was a feature back in the 90’s and 2000’s.

But yea, I guess it’s a bug in 2026.

pxoe 6 hours ago

It's been a "bug" for several decades now. Not everything was of shitty jagged quality in either 90s or 00s. Particularly when using some more capable image editors.

cj 6 hours ago

If you’re actually intended to Paint in MS Paint, as in create things from scratch, you need to limit the upper end of quality for it to be usable.

Otherwise you might as well use photoshop.

(But no I’m not kidding myself, I realize the days of using Paint to actually Paint are over)

pxoe 6 hours ago

There's a bunch of smaller editors that don't have such problems, like paint.net for example. It's an arbitrary "limit" (accidental even) stemming purely from bad quality implementation of basic features, not from how basic that feature set is.

cj 5 hours ago

I like the original commenter’s compromise.

> It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.

Apple Text Edit vs Pages.

razster 6 hours ago

I've been using ComfyUI to do fine background and watermark removal. Might take a look into that as an alternative. Run Flux.2 Klein or Comfyui's own workflow.

pxoe 6 hours ago

Key point, saves a bunch of time. Copy, paste, click button, done in three seconds. The app is also just there, preinstalled. It's great precisely because it doesn't require "looking into" anything. Yes, there's a bunch of other apps and services, but that's all besides that point. It also works pretty much on any pc made in past decade and half without crazy gpu/vram requirements for a relatively miniscule task.

vunderba 6 hours ago

If you don’t mind CLI, rembg is a good option for background removal. It lets you swap between different models depending on the type of image so you can use something like `birefnet` for photorealistic images and `toonout` for illustrations.

https://github.com/danielgatis/rembg

alterom 5 hours ago

JSPaint to the rescue:

https://jspaint.app/

It's a pixel-perfect modern clone (with some actually useful extras that won't get in the way unless you look for them), and yes, you can clone the repo and run it locally.

a-dub 2 hours ago

it is kind of interesting when you think about it. what utility does something like paint actually have? did it ever have any real utility? (icon editing?) it always kinda felt like a demo that came with early versions of windows that didn't actually do anything useful.

Aerroon 2 hours ago

Cropping and editing screenshots (eg add red circle) in a very lightweight application.

Other image editing applications can do all of that, but they take 10 years to launch (during which they will ask for focus) and 2 GB of RAM.

opan an hour ago

Used to be you saved and shared screenshots by pasting into Paint and saving it. Printscreen didn't save a file and only some programs (Skype) let you paste the screenshot directly from the clipboard. That's how I remember it anyway.

fchicken 12 minutes ago

It'll literally be like printers "cannot print this black/white document, low on cyan".

"Cannot run local AI model, no network connection".

The more you think about it, the more it really is the same: https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=...

weberer 13 hours ago

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.

nemomarx 13 hours ago

Does it trigger on non AI images? The post doesn't say so at least.

Someone1234 12 hours ago

It does kind of say: The GUID is coming from the moderation endpoint, which is hit when you generate a local or cloud AI image based on your prompt. If there is no prompt, there is no endpoint, and likely no GUID.

Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.

londons_explore 12 hours ago

The fact that local ai image generation uses an online moderation API is a bit worrying too....

Why not just mod the app to not call this API?

nvme0n1p1 11 hours ago

Since the watermarker runs locally, you could also do the reverse: generate some porn with a different open model, then run that code to tag it as "Content watermarked by Microsoft Responsible AI"

autoexec 8 hours ago

Probably both so they can change what they censor without waiting for you to run windows update and also so they can collect your information (IP, timestamp, etc) to associate with whatever you did

szatkus 7 hours ago

I don't think they use a model that would run smoothly on most hardware that normal people use.

Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.

iririririr 7 hours ago

did you even read the article? you're wrong on all points.

szatkus 7 hours ago

Frankly, I only skimmed it. Now I see that "On Copilot+ PCs, image generation is local but prompt moderation remains remote".

I don't have a Copilot PC, but if you still need to pay MS to run the model on your own hardware it's laughable.

qurren 13 hours ago

> address

Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.

Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.

BitwiseFool 13 hours ago

Windows 11 effectively forces users to register with a Microsoft account. Once that's established, all it takes is for an unaware user to fill out an e-commerce form and save an address for auto-fill.

clear0250 11 hours ago

> Windows 11 effectively forces users to register with a Microsoft account.

It takes zero effort to bypass that with Rufus, if you set up your own pc.

BitwiseFool 11 hours ago

My comment was in regard to the average PC user. The kinds of folks who would never install an operating system and would likely agree to use Edge while signed in to their Microsoft account.

0cf8612b2e1e 10 hours ago

Microsoft has also been pushing hard for Recall and recording all local activity forever. Not impossible to imagine that anything looking like a home address “somehow” gets ingested in the telemetry.

AngryData 10 hours ago

A bypass existing is good, needing a bypass in the first place is still a problem.

jborean93 11 hours ago

> Windows 11 effectively forces users to register with a Microsoft account.

While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.

rexpop 13 hours ago

This is broadly impractical for the average citizen. A scalable solution would be to make this sort of thing illegal.

qurren 12 hours ago

> This is broadly impractical for the average citizen.

No it's not. Sign up for a virtual mailbox for $15-$25/month.

> A scalable solution would be to make this sort of thing illegal.

I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.

It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.

nemomarx 12 hours ago

I think they meant make what Microsoft is doing illegal?

or make it illegal to ask for address, etc. definitely a little more effective than mailboxes

qurren 12 hours ago

Ahhh okay if that's what they meant, then yes, I 100% agree and apologize in advance.

I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.

I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.

ygjb 11 hours ago

> No it's not. Sign up for a virtual mailbox for $15-$25/month.

Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.

It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.

AbsurdCensor 9 hours ago

At least in the US it's not even a good method either. Own a house? Boom, your information is publically available and you won't be able to remove it without a court order, which in most states is impossible to get. In most states, you don't even need to own a house, decide to vote? You information again is publically available. Tie your real name to a single account to purchase something, and you are trackable. Want privacy? You'd need to remove yourself from the internet, dump your phone, destroy your ID and work underground for cash. We can push against iot, and people have been forever, but at the end of the day the government will always they have a vested interest in being able to identify it's citizens.

Modified3019 8 hours ago

> No it's not. Sign up for a virtual mailbox for $15-$25/month.

You are out of touch.

autoexec 8 hours ago

> Sign up for a virtual mailbox for $15-$25/month.

That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.

qurren 7 hours ago

Technically true but I don't think their engineering is advanced enough that it actually happens that way.

mschuster91 12 hours ago

> IANAL but they are not a government or financial institution and do not have a right to that information.

As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.

sellmesoap 7 hours ago

Seems to me that it's a challenge to make an apple account without adding a credit card to your account as well. A carfully chosen Linux distro (so many options!) is the way to avoid the brunt of these privacy issues, lots of open software calls home in some way or another so user beware!

drdexebtjl 7 hours ago

We gotta stop normalizing that. Why do you need my address to receive my money? My birth date?

Even in places with strong privacy regulations requiring businesses not to collect data they don’t need, businesses apparently get away with asking this.

pjc50 12 hours ago

This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

baby_souffle 12 hours ago

> This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."

red_admiral 11 hours ago

But the EU mandates watermarking of AI content.

jkaplowitz 11 hours ago

As the article explained, the EU does not mandate a prompt-specific GUID, only the ability to identify the content as AI-generated. The highly privacy-invasive level of provenance tracking which Microsoft has added goes beyond the EU’s new mandates.

mosura 11 hours ago

Why would the EU possibly object to this? It is exactly what they want.

TiredOfLife 11 hours ago

Watermarking ai generated stuff is mandated by EU

thayne 10 hours ago

Do they require the watermark to be a unique token that can be associated with PII?

drdexebtjl 7 hours ago

It doesn’t need to be a personally identifiable watermark.

dagaci 12 hours ago

This a variant of the provenance scheme: C2PA its implemented by all major Camera maker, and Google it seems, Apple support it with 3rd party apps on iPhone, but they have something called "Apple Reference Image" brewing.

Personally I think there is a good argument for being able to distinguish AI generated image and video...

akersten 12 hours ago

> I think there is a good argument for being able to distinguish AI generated image and video...

Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.

herf 12 hours ago

No - there is a huge difference between "this AI created this image" and "this user did it" - the first we need more of, and the second is a big privacy concern. The article does not say anything about identifying a user.

dmantis 12 hours ago

Article literally says it adds a guid, not a binary field indicating that the image is ai generated.

refulgentis 12 hours ago

A guid isn’t a user id, if it is in this case, it’s an abuse of how guid is used, at least colloquially. I haven’t read enough to understand if it is user / machine id, I.e. only globally unique in the sense it’s a globally unique entity identifier.

themaninthedark 12 hours ago

Microsoft Can Track Users via a Windows Device ID https://news.ycombinator.com/item?id=48815196

Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239

dylan604 11 hours ago

They stated the GUID is used to identify the prompt used to generate the image. How are you confused as to not being able to identify the user?

"I haven’t read enough to understand". Oh, now I know the answer to my question

serf 12 hours ago

a GUID isn't an indicator, it's a fingerprint.

so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.

to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.

frollogaston 12 hours ago

Well yeah they know my John Doe info

pizzafeelsright 11 hours ago

add your IP, location, provider, computer specs, dimensions, screen info, nearby devices, etc etc etc

Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.

fishfasell 12 hours ago

Exactly. Forget the AI aspect, this is entirely to identify users for any purposes they deem necessary. People are ignoring the surveillance state aspect of this. Reminds me of the device id debacle they have attached to their outbounds Windows network calls

red_admiral 11 hours ago

> every image you create

*with the help of AI*. Does in fact make a difference.

tavavex 8 hours ago

While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that.

I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.

Terr_ 11 hours ago

> a unique identifier into every image you create

Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]

Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.

In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.

[0] https://www.eff.org/issues/printers

varispeed 9 hours ago

and then in few years a new mono-mustachioed or mono-browed leader will emerge who declares memes a blasphemy punishable by death and will call up all the telemetry gathered to punish all involved.

Terr_ 8 hours ago

"I don't worry because I have nothing to hide, based on my perfectly accurate perception of today's political and legal forces in my state and nation which will stay safely static forever."

pbhjpbhj 5 hours ago

You know a certain dictator denies access to the country they control based on whether visitors "like" them? They use a private militia, funded by stealing from taxpayers, in contravention to that country's laws, to target citizens who are not supporters of them. Some of those citizens get shipped abroad to foreign prisons by these militia. Others get shot in summary executions in the streets - the controlling regime covers it up with false media reports, and uses corrupt judges to evade scrutiny ... a certain software company support that regime, even acting against foreign scrutiny on their behalf.

Essentially all of that country's businesses that are close to the regime need to be considered hostile.

We don't need to wait a few years, the revolution already happened; the insurrectionists were freed. These companies paid their tributes, in dollars, to the regime.

Maybe next ML will be integrated into software suites to enforce that regime's lies? Most Western governments use such software, the distributers of which have already shown they'll act in the regimes interests against supposed allies...

Terr_ 4 hours ago

I had assumed parent-poster was making a sincere but humorous point, as opposed to sarcastically dismissing the risks of a change in management, but I suppose it's ambiguous.

Rendello 8 hours ago

> It's very likely your printer is secretly adding marks to the page

It's most likely how the FBI caught NSA leaker Reality Winner:

> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.

https://en.wikipedia.org/wiki/Reality_Winner

hiccuphippo 9 hours ago

Can this also be weaponized? Get an innocuous image from someone you don't like, grab their GUID, add it to another image, sent it to the thin skinned politician in power.

dbmnt 4 hours ago

No, because the GU in GUID stands for globally unique. Adding it to a second image would cause a detectable collision.

Also, C2PA, another technology mentioned in the article, means tampering is easily detected.

pbhjpbhj 6 hours ago

That was largely my read of the situation too - it would be a colossal GDPR breech against every EU user, surely? That's got to be a €Billion fine??

Presumably USA are complicit in this spying on allied countries - did the countries know, is it a Five Eyes thing?

altmanaltman an hour ago

Why would they need to subpoena Microsoft and why will Microsoft hand them the data if someone doesn't like my meme? I understand what you are trying to say but it does not make a whole lot of sense even from Microsoft pov. They are not bound by law to hand over personal data to anyone without a warrant issued. If a warrant is issued then it is their lawful duty to give that data, the same would be done by you if you were in their shoes or your office or your family. Law is not optional to follow. But Microsoft doesn't need to do watermarking on memes to track you or to do this as a war against "internet anonymity".

adrianN 23 minutes ago

Watermarking is just one puzzle piece in the surveillance state; the legislation around it another.

fchicken 14 minutes ago

It's like Snowden said (paraphrasing): "If privacy comes from policy, the policy can be changed on a whim, and in effect you have no privacy at all"

ComputerGuru 14 hours ago

AI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible (cannot be disabled and happens silently in the background with no user notice) watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end).

Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.

In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.

stronglikedan 13 hours ago

> AI-generated text warning

This seems incorrect to me. Are you basing that on the use of bullet points?

buzer an hour ago

There are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g.

> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.

> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.

> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.

Personally it didn't bother me too much.

Noaidi 12 hours ago

I have some better options. Stop using computers, or if you use a computer, use Linux.

Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.

furyofantares 11 hours ago

> AI-generated text warning (I submitted - but did not author - the piece)

Took me a moment to realize you're saying someone else generated it, rather than you did.

frig57 10 hours ago

How do they add a watermark to local llm content?

aucisson_masque 23 minutes ago

> On Copilot+ PCs, image generation is local but prompt moderation remains remote

Anyone disturbed about that ? It's your computer, running locally, but Microsoft can tell you 'no'.

It's like you want to open a folder and it asks permission to Microsoft.

zdragnar 16 minutes ago

I would be surprised that anyone is surprised by this. They've been making local accounts harder and harder now to the point of being impossible.

Anyone not deep in tech will accept the "think of the children" defense without much worry, and anyone who is deep in tech already knows that if you really want an OS that doesn't spy on you, you need to go to a *nix of some flavor.

fchicken 15 minutes ago

I'm disturbed by everything.

Prompt moderation, GUID insertion, watermark insertion; track anything and everything, probably done in the name of "protect the children".

VCFundedGenYer 13 hours ago

Keep an eye on this.

A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.

MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.

JoeBOFH 13 hours ago

I had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.

initramfs 13 hours ago

I guess it shouldn't be surprising if an application called "paint.net" can determined if AI was used when connected to the internet. (I have used Paint.net more than a decade ago).

aqfamnzc 13 hours ago

Paint.net is named after the dot net framework and is not referring to a URL or the internet as I understand it.

erk__ 13 hours ago

Paint.net actually just recently got ownership of paint.net, it only took 22 years: https://www.xda-developers.com/after-22-years-paintnet-downl...

a1o 13 hours ago

They aren’t saying that, paint.net is an open source application, Paint is the descendant of MSPaint.

Ajedi32 12 hours ago

Paint.net is freeware, but it is not open source.

JoeBOFH 11 hours ago

I was stating that MS Paint mis categorized a Print Screen screenshot as AI generated when pasted. Which pushed me to install PaintdotNet onto my laptop instead.

dagaci 13 hours ago

Googling you can see the source code for watermarking here https://github.com/microsoft/InvisMark

Delphiza 13 hours ago

I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.

jacquesm 12 hours ago

You can watermark AI without leaking who did it. That's just using AI to add yet another layer of user tracking.

andai 9 hours ago

This is gonna sound a bit harsh, but from the outside it genuinely looks like Microsoft is actively looking for new ways to degrade and humiliate their users. (And having no trouble finding them!)

cupantae 11 hours ago

As a linux fan I just love all these changes Microsoft have been introducing

userbinator 5 hours ago

after a local Stable Diffusion image generation

The request is JSON and contains at least these fields:..."prompt": "..."

Local SD (especially the earlier versions) is already uncensored, so they're effectively crippling it with additional spyware that phones home to tell Microsoft what you're doing and asking whether they approve of it. IMHO the invisible watermark isn't the worst part, but rather the fact that MS is logging every interaction you have with the model, which doesn't ever need to leave your machine.

petjuh 12 hours ago

This reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)

srean 12 hours ago

Not only USSR.

I wonder whether Arthur Conan Doyle had the idea before the police started using typewriter typeface wear and tear for forensics.

kvuj 11 hours ago

You have no idea how deep this rabbit hole goes. Search for EFF printers secret tracking.

Virtually all commercial printers embed an invisible identifier on every page printed.

esafak 11 hours ago

It was about money anti-counterfeiting.

https://en.wikipedia.org/wiki/Printer_tracking_dots

SV_BubbleTime 11 hours ago

There is always a legit reason. It’s just never the only reason.

imhoguy 10 hours ago

Now I need to see if agentic reverse engineering of printer firmware can actually remove that "feature" for good.

kube-system 8 hours ago

Virtually all color laser printers and copiers.

testing22321 10 hours ago

Sure, try to scan, photocopy, edit in photoshop or print US money today.

angry_octet 8 hours ago

It is quite likely that Snipping Tool is also doing this. Every camera also leaves device specific signature because of its inherent silicon sensor defects.

If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats.

See e.g. PPM format: https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/...

These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.

threecheese 7 hours ago

If Anthropic can manipulate text to add a watermark, what’s preventing providers from doing the same to generated images? Modifying the container format can’t protect you from a signature in the image’s visual representation, unless you apply noise to that (and know it’s enough noise/the right kind of noise to counteract whatever unknown technique they’ve applied).

red_admiral 11 hours ago

Misleading title: the watermark applies to AI generated/edited images. That includes local models.

Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no".

Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.

SV_BubbleTime 11 hours ago

Don’t care.

There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.

phendrenad2 5 hours ago

Don't care that you don't care. This distinction does matter to a lot of people, because to many people there's a huge difference.

fchicken 16 minutes ago

Fucking spyware.

Soon it'll literally be "you need a license to use this technology" if we're not there in some form or another already.

luciana1u 12 hours ago

the GUID is the giveaway that it's not about protecting artists, it's about being able to prove provenance later. nobody embeds a unique id in a local file for the user's benefit.

emsign 19 minutes ago

> The two apps send the prompt to a remote server for moderation

Why? What needs tobe moderated locally?

imnotr0b0t 9 hours ago

Interesting find. Overall it makes sense from a deepfake-fighting perspective and EU requirements. But what's concerning is that users aren't really told about this, as far as I can tell. Would be cool if someone checked if it can be bypassed, like swapping the DLL or intercepting the API call. But yeah, it's another step toward every digital trace becoming personally identifiable...

claiir 8 hours ago

Kind of sad how all these technical blogs just reek of Claude text these days. Hard read when it’s obviously padded by an LLM…

tgsovlerkhgsel 6 hours ago

> In other words, “generated locally” does not mean that the complete operation is local.

That sounds like a privacy violation that the DPAs should look into.

Edit: Apparently it's disclosed somewhere. Still, that defeats the entire point of local generation...

LeBit 6 hours ago

Do we really need more examples of why local LLMs are an absolute necessity?

saejox 11 hours ago

These days i cant recommend Windows to anybody. Even gamers should move to linux.

Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise.

A sudden knock on your door might happen because of an ambigious search/propmt.

tapland 11 hours ago

There's a huge number of gamers moving to things like CachyOS. Some are stuck because of Valorant, LoL or Battlefield DRM, but it's a big move lately.

avadodin 6 hours ago

I'd never play one of those games but the excuse for the kernel modules spying on you is usually anti-cheat not DRM as they are online games.

There are droves of people petitioning Valve to add kernel anti–cheat to CS2.

1970-01-01 10 hours ago

Others say

"I need it to work on a random Thursday, not wait for fsck after ever reboot"

https://github.com/IceWhaleTech/CasaOS/issues/1104

toilet 10 hours ago

I have the same issue on Windows 11. It's been bugging me to press a button or "check my drive" on every startup for at least half a year, no matter how often I let it run the check...

quik95 10 hours ago

Same thing happened to me recently

b5n 10 hours ago

Why have you linked a bug report for a niche userland application that may be causing disk corruption as evidence against linux reliability? That seems like a pretty uninformed conclusion.

1970-01-01 10 hours ago

This isn't a one-off niche user. Just look for more of these. You will find them.

https://www.reddit.com/r/archlinux/comments/1cvwo93/arch_run...

b5n 9 hours ago

This supports my initial reply. This was an f2fs bug in a bleeding edge kernel released only seven days earlier. The thread suggests perfectly reasonable mitigations, especially for an arch user: use the lts kernel or downgrade to 6.8.9.

If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.

I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.

1970-01-01 9 hours ago

Ok fair point, here's plenty more of the same on stable. My point is Linux is always fine right until it isn't. Then you're back to a day of debugging your update.

https://bugzilla.kernel.org/show_bug.cgi?id=218770

https://lore.kernel.org/linux-f2fs-devel/20240409203411.1885...

https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07280.html

https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07260.html

https://bugzilla.suse.com/show_bug.cgi?id=1226043

https://lists.opensuse.org/archives/list/[email protected]...

https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/15478...

https://bugs.launchpad.net/bugs/63175

b5n 8 hours ago

Most of these links weaken your claim rather than support it. The lkml links are patch submissions in a _development_ discussion, not ordinary users running a stable distro. The f2fs bugzilla links are the same issue we already discussed, a regression in the brand-new 6.9 kernel released only days earlier, with the fix landing in 6.9.3. The suse bug is an upstream e2fsprogs issue. This is precisely the kind of issue distro package maintainers can catch, patch, or avoid before it reaches ordinary users on a stable release. The launchpad link is another development discussion, not an example of ordinary users experiencing a bug in a stable release.

Linux does experience regressions, but your argument conflates upstream development, bleeding edge releases, and stable distro releases. Those distinctions are fundamental to how linux distributions work, and these links don't support the claim you're making.

frig57 10 hours ago

Anyone got tips or guides to starting a linux OS that protects privacy without sacrificing utility?

Considering putting linux on a 2nd PC

Yiin 9 hours ago

omarchy.org

delecti 8 hours ago

Essentially any Linux distro protects privacy. You'd kinda have to go out of your way to find one that doesn't, because there's no online account connected to your install for any of them.

If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.

Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.

dismalaf 4 hours ago

Pretty much all of them. None require online accounts or anything like that. Browser choice is probably more important.

For something that just works I recommend Fedora or Ubuntu. It's what I'd put on my mom or wife's PC.

Currently using Omarchy on my laptop though which is a tad more exotic, it's Arch + Hyprland and is pretty polished for that stack (at least the current version, 4.0) but still a tiny bit of jank.

RobotToaster 10 hours ago

Genuine question: does Linux have an AI image editor as easy to use as the win11 paint/photos?

matheusmoreira 9 hours ago

> Some say "i do nothing illegal" "have nothing to hide".

I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.

adventured 9 hours ago

The best response is always:

"That's not up to you."

When people claim they have nothing to hide, always point out that's not up to their determination. That freaks them out, it disarms their shrink-from-confrontation move.

And you can point it out super fast, in a plain six word statement. No need to launch into a deep discussion unless prompted.

Alternatively, simply respond with: yes you do. When they reply: "what?" - "every single thing you have ever done wrong across your entire life." Everybody has done something they would prefer to keep hidden, the cowards just lie about it.

unselect5917 8 hours ago

Just because I have nothing to hide doesn't mean I have anything I want you to see.

People are entitled to privacy because they enjoy it. No further justification is needed.

allthetime 9 hours ago

many games work flawlessly on Linux now. enough to make the switch anyways. a lot more than on mac.

seriocomic 4 hours ago

"inivisibly"? for 9 hours this was invisible...

two_handfuls 9 hours ago

This is not ok.