Blog essay renames AI "watermarks" as "spymarks," HN debates the framing
A viral post argues hidden signals in Google's SynthID and similar tools can encode personal-identity data, prompting pushback and technical debate on Hacker News.
What to know
- An essay reframes AI content watermarking (e.g. Google's SynthID) as "spymarking," arguing hidden signals can encode database identifiers traceable to a specific person.
- Google's SynthID-Image paper is cited as being able to embed a 136-bit payload in a 512x512 image, enough for a 64-bit database ID plus error correction.
- Hacker News discussion splits between those who see this as a genuine covert-tracking risk akin to steganography or printer tracking dots, and those who call the "spymark" label alarmist given legitimate uses like counterfeit detection.
- One commenter says he built an open-source, independently verifiable watermarking tool as a transparent alternative to closed systems like SynthID.
The dispute Whether "spymark" accurately describes a genuine privacy threat or is an alarmist rebranding of a technology with legitimate, benign applications. · positions read across 38 posts and comments
Hidden watermarking is a real covert tracking capability, comparable to steganography and historical tracking methods like printer dots.
-
“Spymarks just seem like another word for steganography.”
Retro_Dev · Hacker News ↗
"Spymark" is an unnecessarily negative rebrand; invisible watermarking has legitimate, non-sinister uses.
-
“I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.”
pavo-etc · Hacker News ↗
The specific encoding schemes described (like text word-choice substitution) may not work reliably in practice.
-
“I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.”
Morromist · Hacker News ↗
Google Developer of SynthIDOpenAI Developer of similar tracking/watermarking systemspossibilistic Hacker News submitter of the essayminimaxir HN commenter, tool developer
How it unfolded 4 developments, newest first · click a bar or a number to jump articlespostscomments
-
4
Thread links spymarking to past printer-tracking exposure
Commenters draw parallels to steganography and cite a historical case of a leaker identified via hidden printer tracking dots, broadening the discussion beyond AI-specific tools to tracking technology generally.
-
I feel like there’s some security engineering calculus that would be useful here?You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?There must be value in having a visible vs an…
2 more of the top 3 · 31 posts in this stretch
-
N
Spymarks, Not Watermarks: https:// brand.io/article/spymarks/ Discussion: http:// news.ycombinator.com/item?id=4 9794615
-
Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't…
-
-
3
Developer says he built an open alternative to SynthID
A commenter describes creating an imperceptible, tamper-resistant watermarking tool intended to be open-sourced, positioned as a transparent, independently-decodable alternative to closed systems like SynthID.
“I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be hidden.”
— minimaxir -
These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.First the low-end laptops and…
2 more of the top 3 · 4 posts in this stretch
-
The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be…
-
Out of frustration with SynthID being closed-source with weird dubious ways to verify if an image has the watermark, I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be…
-
-
2
Commenters call the "spymark" label alarmist
Early Hacker News replies push back on the terminology itself, arguing invisible watermarking is not inherently malicious and citing benign precedents like counterfeit-note detection.
“I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to sound very negative when invisible watermarks are not always negative…”
— pavo-etc -
I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.Tech like SynthID I see a net positive especially since it doesn't degrade text quality. I dream about a browser extension…
2 more of the top 3 · 3 posts in this stretch
-
H
Spymarks, Not Watermarks L: https:// brand.io/article/spymarks/ C: https:// news.ycombinator.com/item?id=4 9794615 posted on 2026.09.21 at 19:03:49 (c=1, p=5)
-
Weirdly the article doesn’t mention steganography. Arguably it isn’t quite the same, because the aim of steganography isn’t typically to add an identification, but something like “steganomark” would seem to be fitting.
-
-
1
Essay coins "spymark" for hidden AI tracking watermarks
An anonymous brand.io essay argues Google's SynthID and similar systems from OpenAI and others embed imperceptible signals in images, audio, text and video that can encode database identifiers tying content back to a user's identity, and proposes renaming them "spymarks" to foreground the privacy risk.
“A spymark is a hidden signal that makes your work traceable without your knowledge or consent.”
— brand.io essay -
2 outlets Spymarks, Not Watermarks
first by HN Best, 2d ago · also HN Frontpage
-
What people are saying 16 voices from 1 site · best of 38 · verbatim
- Yesterday
-
Imagine these being used as DLP. Each service consuming/publishing content can scan for its spymark/watermark which reference parameters instructing the service on allowed use, revocation etc.Seems like a wet dream for DRM with lots of possible uses that may be considered bad, but there's also some potential to have it be used to better control…
- Sep 22
-
I actually wrote a library to do stego with LLM outputs last year and it turned out to be an almost exact implementation of the Anthropic watermark algo.Repo here https://github.com/sutt/innocuous. It works with last year's llama.cpp. Check out the "Use Cases" and "How it works" sections in the readme if you're interested.
-
"A spymark is a hidden signal that makes your work traceable"Not a single example provided of anything that could be honestly called "your work", just a bizarre attempt to stigmatize accurate detection of genAI output.What was that PG bit about "submarining"?
-
This is a straightforward example of how the positive or negative valence of a piece of tech depends entirely on how it's used.You just need to address three questions:- who controls what information is going in? (that is, what is the process by which the tech companies who control all the tech are using it)- who controls what information is…
-
On the one hand, I 100% want AI-generated videos, images, text, etc to come with some kind of 'spymark'.On the other hand, no matter how robust that solution is, inevitably someone will come up with a way to bypass it, strip them out, etc - so would it really be useful in the long run?
-
Don't media companies do something like this to track which employee might have leaked films/TV shows/video game trailers/etc online?I recall they had separately watermarked versions of these to make it easier to figure out how things were being leaked.
-
They're the simplest way to be automatically able to track AI generated text and I very much love them being used for that, it would be pretty cool if _all_ AIs were forced from training to include these things into their output.The "tracking" bit is kind of nefarious, but that can be removed as a concern if the thing that is being tracked is…
-
Thanks for the article. I hadn't heard of SynthID before and it's good to.It's a shame however, how low quality and vibecoded the live examples are. The first example says "Toy example; not SynthID.", the second one is a generic spectrogram and the third one has an identification space too small to be useful (173 in decimal). I was hoping to see…
-
The vulnerability of steganography is that is has to pretend that signal is noise. Remove the noise - and the signal is gone. I'm pretty sure that the simplest gaussian blur will remove the spymark from any picture.Or... add some noise. Just align the last bit of every pixel channel with a random bit sequence - and Bob's your uncle.
-
Reminds me of Blizzard embedding data inside World of Warcraft screenshots (link goes to a small write-up from 2012 in a forum focused on video game cheats; sorry, could not find a better source):
-
A number of prominent corporations used to embed these in the background images of their internal webpages, so that leakers could be identified from the screenshots they shared. Caused a whole fun adversarial loop where journalists had to transcribed and/or redraw screenshots before publishing to avoid exposing the identity of leakers...
-
> ... particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open.This has been going on for a while with Facebook. They seem to embed custom metadata tags so that images shared outside…
-
> Spymarks are certainly not great for whistleblowers or anyone who doesn’t want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about.How do you spymark text that someone else wrote? You can't change the words or they'd notice
-
Spooky stuff. This will take surveillance to a whole new level. This is basically email read-receipt tracker, but for all of the digital content. They will know the whole trail - from originator to how it spread. Who read what and when. Big brother will always be watching.
-
Spymarks an application of steganography, not a different name for it.> On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have producedThat doesn't help with things like the typical use of SynthID where the spymarking is done by the same process…
- Sep 21
-
> A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership.We also recently had this with LG spy-TVs. Cars here in the EU also spy on people, allegedly to show how alert they are. Perhaps they sneakily upload that information somewhere ... Facebook also has the spy-glasses now. People…