I guess they’ve optimized their workforce to just keep making changes so they get promoted rather than just creating really good software.
MS Paint and Photos inivisibly watermark even locally generated output with GUID (xusheng.dev)
clickety_clack 8 hours ago
SideQuark 8 hours ago
trickypr 8 hours ago
buzer 2 hours ago
It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.
SilasX 8 hours ago
If I wanted all of that, I would have used a different app!
pxoe 7 hours ago
drdexebtjl 7 hours ago
They also started rendering and preserving Unix-style line endings (LF).
Very welcome breaking changes :)
pxoe 6 hours ago
bananaboy 6 hours ago
travoc 5 hours ago
jamesfinlayson 4 hours ago
Rohansi 4 hours ago
bigstrat2003 an hour ago
mook 4 hours ago
I don't understand why they didn't just stuff all the AI things and new features in Write, where it belongs…
titzer 4 hours ago
pxoe 7 hours ago
Unfortunately, some of the regular paint tools like eraser don't erase in a smooth antialiased way and just end up looking jagged (also only a square shape for eraser...no eraser brush mode unfortunately), so it ends up being a better looking option (well, when it works properly, which it does often enough to be useful). For whatever reason a bunch of tools and transforms (scaling, rotating), just produce such garbage jagged looking results, it's not serviceable even for those basics.
cj 6 hours ago
But yea, I guess it’s a bug in 2026.
pxoe 6 hours ago
cj 6 hours ago
Otherwise you might as well use photoshop.
(But no I’m not kidding myself, I realize the days of using Paint to actually Paint are over)
pxoe 6 hours ago
cj 5 hours ago
> It seems like they could have left it as a pure “paint” app and added the fancy stuff to some new image editor or something.
Apple Text Edit vs Pages.
razster 6 hours ago
pxoe 6 hours ago
vunderba 6 hours ago
alterom 5 hours ago
It's a pixel-perfect modern clone (with some actually useful extras that won't get in the way unless you look for them), and yes, you can clone the repo and run it locally.
a-dub 2 hours ago
Aerroon 2 hours ago
Other image editing applications can do all of that, but they take 10 years to launch (during which they will ask for focus) and 2 GB of RAM.
opan an hour ago
fchicken 12 minutes ago
"Cannot run local AI model, no network connection".
The more you think about it, the more it really is the same: https://en.wikipedia.org/wiki/Printer_tracking_dots?useskin=...
weberer 13 hours ago
nemomarx 13 hours ago
Someone1234 12 hours ago
Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
londons_explore 12 hours ago
Why not just mod the app to not call this API?
nvme0n1p1 11 hours ago
autoexec 8 hours ago
szatkus 7 hours ago
Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.
iririririr 7 hours ago
szatkus 7 hours ago
I don't have a Copilot PC, but if you still need to pay MS to run the model on your own hardware it's laughable.
qurren 13 hours ago
Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.
Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.
BitwiseFool 13 hours ago
clear0250 11 hours ago
It takes zero effort to bypass that with Rufus, if you set up your own pc.
BitwiseFool 11 hours ago
0cf8612b2e1e 10 hours ago
AngryData 10 hours ago
jborean93 11 hours ago
While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.
rexpop 13 hours ago
qurren 12 hours ago
No it's not. Sign up for a virtual mailbox for $15-$25/month.
> A scalable solution would be to make this sort of thing illegal.
I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.
It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.
nemomarx 12 hours ago
or make it illegal to ask for address, etc. definitely a little more effective than mailboxes
qurren 12 hours ago
I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.
I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.
ygjb 11 hours ago
Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.
It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.
AbsurdCensor 9 hours ago
Modified3019 8 hours ago
You are out of touch.
autoexec 8 hours ago
That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.
qurren 7 hours ago
mschuster91 12 hours ago
As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.
sellmesoap 7 hours ago
drdexebtjl 7 hours ago
Even in places with strong privacy regulations requiring businesses not to collect data they don’t need, businesses apparently get away with asking this.
pjc50 12 hours ago
baby_souffle 12 hours ago
At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."
red_admiral 11 hours ago
jkaplowitz 11 hours ago
mosura 11 hours ago
TiredOfLife 11 hours ago
thayne 10 hours ago
drdexebtjl 7 hours ago
dagaci 12 hours ago
Personally I think there is a good argument for being able to distinguish AI generated image and video...
akersten 12 hours ago
Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.
herf 12 hours ago
dmantis 12 hours ago
refulgentis 12 hours ago
themaninthedark 12 hours ago
Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239
dylan604 11 hours ago
"I haven’t read enough to understand". Oh, now I know the answer to my question
serf 12 hours ago
so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.
to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.
frollogaston 12 hours ago
pizzafeelsright 11 hours ago
Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.
fishfasell 12 hours ago
red_admiral 11 hours ago
*with the help of AI*. Does in fact make a difference.
tavavex 8 hours ago
I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.
Terr_ 11 hours ago
Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]
Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.
In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.
varispeed 9 hours ago
Terr_ 8 hours ago
pbhjpbhj 5 hours ago
Essentially all of that country's businesses that are close to the regime need to be considered hostile.
We don't need to wait a few years, the revolution already happened; the insurrectionists were freed. These companies paid their tributes, in dollars, to the regime.
Maybe next ML will be integrated into software suites to enforce that regime's lies? Most Western governments use such software, the distributers of which have already shown they'll act in the regimes interests against supposed allies...
Terr_ 4 hours ago
Rendello 8 hours ago
It's most likely how the FBI caught NSA leaker Reality Winner:
> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.
hiccuphippo 9 hours ago
dbmnt 4 hours ago
Also, C2PA, another technology mentioned in the article, means tampering is easily detected.
pbhjpbhj 6 hours ago
Presumably USA are complicit in this spying on allied countries - did the countries know, is it a Five Eyes thing?
altmanaltman an hour ago
adrianN 23 minutes ago
fchicken 14 minutes ago
ComputerGuru 14 hours ago
Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.
In case it's not obvious, my bigger concern isn't "this image can be identified to have been generated with/by AI" so much as it is "digital yellow printer dots have been forced upon us, except they can identify and retrieve the exact user/device/time/place/document/etc", completely destroying any and all illusions of privacy left.
stronglikedan 13 hours ago
This seems incorrect to me. Are you basing that on the use of bullet points?
buzer an hour ago
> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.
> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.
> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.
Personally it didn't bother me too much.
Noaidi 12 hours ago
Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.
furyofantares 11 hours ago
Took me a moment to realize you're saying someone else generated it, rather than you did.
frig57 10 hours ago
aucisson_masque 23 minutes ago
Anyone disturbed about that ? It's your computer, running locally, but Microsoft can tell you 'no'.
It's like you want to open a folder and it asks permission to Microsoft.
zdragnar 16 minutes ago
Anyone not deep in tech will accept the "think of the children" defense without much worry, and anyone who is deep in tech already knows that if you really want an OS that doesn't spy on you, you need to go to a *nix of some flavor.
fchicken 15 minutes ago
Prompt moderation, GUID insertion, watermark insertion; track anything and everything, probably done in the name of "protect the children".
VCFundedGenYer 13 hours ago
A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.
MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.
JoeBOFH 13 hours ago
initramfs 13 hours ago
aqfamnzc 13 hours ago
erk__ 13 hours ago
a1o 13 hours ago
Ajedi32 12 hours ago
JoeBOFH 11 hours ago
dagaci 13 hours ago
Delphiza 13 hours ago
jacquesm 12 hours ago
andai 9 hours ago
cupantae 11 hours ago
userbinator 5 hours ago
The request is JSON and contains at least these fields:..."prompt": "..."
Local SD (especially the earlier versions) is already uncensored, so they're effectively crippling it with additional spyware that phones home to tell Microsoft what you're doing and asking whether they approve of it. IMHO the invisible watermark isn't the worst part, but rather the fact that MS is logging every interaction you have with the model, which doesn't ever need to leave your machine.
petjuh 12 hours ago
srean 12 hours ago
I wonder whether Arthur Conan Doyle had the idea before the police started using typewriter typeface wear and tear for forensics.
kvuj 11 hours ago
Virtually all commercial printers embed an invisible identifier on every page printed.
esafak 11 hours ago
SV_BubbleTime 11 hours ago
imhoguy 10 hours ago
kube-system 8 hours ago
testing22321 10 hours ago
angry_octet 8 hours ago
If you want to stay anonymous, don't share images you can't verify at the byte level. Apply filtering to decrease the low bit noise that could hide cryptographic signatures. Don't trust complex container formats.
See e.g. PPM format: https://www.cs.swarthmore.edu/~soni/cs35/f13/Labs/extras/01/...
These days entire scenes can be tweaked by AI to add unimportant but identifying marks, at a level far above signal processing tricks, like moving objects in the scene. Verify from multiple sources.
threecheese 7 hours ago
red_admiral 11 hours ago
Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no".
Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.
SV_BubbleTime 11 hours ago
There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.
phendrenad2 5 hours ago
fchicken 16 minutes ago
Soon it'll literally be "you need a license to use this technology" if we're not there in some form or another already.
luciana1u 12 hours ago
emsign 19 minutes ago
Why? What needs tobe moderated locally?
imnotr0b0t 9 hours ago
claiir 8 hours ago
tgsovlerkhgsel 6 hours ago
That sounds like a privacy violation that the DPAs should look into.
Edit: Apparently it's disclosed somewhere. Still, that defeats the entire point of local generation...
LeBit 6 hours ago
saejox 11 hours ago
Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise.
A sudden knock on your door might happen because of an ambigious search/propmt.
tapland 11 hours ago
avadodin 6 hours ago
There are droves of people petitioning Valve to add kernel anti–cheat to CS2.
1970-01-01 10 hours ago
"I need it to work on a random Thursday, not wait for fsck after ever reboot"
toilet 10 hours ago
quik95 10 hours ago
b5n 10 hours ago
1970-01-01 10 hours ago
https://www.reddit.com/r/archlinux/comments/1cvwo93/arch_run...
b5n 9 hours ago
If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.
I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.
1970-01-01 9 hours ago
https://bugzilla.kernel.org/show_bug.cgi?id=218770
https://lore.kernel.org/linux-f2fs-devel/20240409203411.1885...
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07280.html
https://lkml.iu.edu/hypermail/linux/kernel/2511.2/07260.html
https://bugzilla.suse.com/show_bug.cgi?id=1226043
https://lists.opensuse.org/archives/list/[email protected]...
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/15478...
b5n 8 hours ago
Linux does experience regressions, but your argument conflates upstream development, bleeding edge releases, and stable distro releases. Those distinctions are fundamental to how linux distributions work, and these links don't support the claim you're making.
frig57 10 hours ago
Considering putting linux on a 2nd PC
Yiin 9 hours ago
delecti 8 hours ago
If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.
Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.
dismalaf 4 hours ago
For something that just works I recommend Fedora or Ubuntu. It's what I'd put on my mom or wife's PC.
Currently using Omarchy on my laptop though which is a tad more exotic, it's Arch + Hyprland and is pretty polished for that stack (at least the current version, 4.0) but still a tiny bit of jank.
RobotToaster 10 hours ago
matheusmoreira 9 hours ago
I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.
adventured 9 hours ago
"That's not up to you."
When people claim they have nothing to hide, always point out that's not up to their determination. That freaks them out, it disarms their shrink-from-confrontation move.
And you can point it out super fast, in a plain six word statement. No need to launch into a deep discussion unless prompted.
Alternatively, simply respond with: yes you do. When they reply: "what?" - "every single thing you have ever done wrong across your entire life." Everybody has done something they would prefer to keep hidden, the cowards just lie about it.
unselect5917 8 hours ago
People are entitled to privacy because they enjoy it. No further justification is needed.
allthetime 9 hours ago
seriocomic 4 hours ago
two_handfuls 9 hours ago