conv.

All stories
AIFading · day 2

Blog essay renames AI "watermarks" as "spymarks," HN debates the framing

A viral post argues hidden signals in Google's SynthID and similar tools can encode personal-identity data, prompting pushback and technical debate on Hacker News.

What to know

  • An essay reframes AI content watermarking (e.g. Google's SynthID) as "spymarking," arguing hidden signals can encode database identifiers traceable to a specific person.
  • Google's SynthID-Image paper is cited as being able to embed a 136-bit payload in a 512x512 image, enough for a 64-bit database ID plus error correction.
  • Hacker News discussion splits between those who see this as a genuine covert-tracking risk akin to steganography or printer tracking dots, and those who call the "spymark" label alarmist given legitimate uses like counterfeit detection.
  • One commenter says he built an open-source, independently verifiable watermarking tool as a transparent alternative to closed systems like SynthID.

The dispute Whether "spymark" accurately describes a genuine privacy threat or is an alarmist rebranding of a technology with legitimate, benign applications. · positions read across 38 posts and comments

many voices

Hidden watermarking is a real covert tracking capability, comparable to steganography and historical tracking methods like printer dots.

  • “Spymarks just seem like another word for steganography.”

    Retro_Dev · Hacker News ↗
some voices

"Spymark" is an unnecessarily negative rebrand; invisible watermarking has legitimate, non-sinister uses.

  • “I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.”

    pavo-etc · Hacker News ↗
some voices

The specific encoding schemes described (like text word-choice substitution) may not work reliably in practice.

  • “I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.”

    Morromist · Hacker News ↗

Google Developer of SynthIDOpenAI Developer of similar tracking/watermarking systemspossibilistic Hacker News submitter of the essayminimaxir HN commenter, tool developer

How it unfolded 4 developments, newest first · click a bar or a number to jump articlespostscomments

Peak 6 pieces in one hour at Sep 21, 6 PM; 41 pieces over 2 days (2 articles · 5 posts · 34 comments) Sep 21, 6 PM — 6 pieces · 2 articles · 2 posts · 2 comments — Hacker News 3, Newswires 2, Mastodon 1Sep 21, 7 PM — 3 pieces · 3 comments — Hacker News 3Sep 21, 8 PM — 1 piece · 1 comment — Hacker News 1Sep 21, 9 PM — 3 pieces · 3 comments — Hacker News 3Sep 21, 10 PM — quietSep 21, 11 PM — 2 pieces · 1 post · 1 comment — Hacker News 1, Mastodon 1Sep 22, 12 AM — 5 pieces · 1 post · 4 comments — Hacker News 4, Mastodon 1Sep 22, 1 AM — 3 pieces · 3 comments — Hacker News 3Sep 22, 2 AM — 4 pieces · 4 comments — Hacker News 4Sep 22, 3 AM — 2 pieces · 2 comments — Hacker News 2Sep 22, 4 AM — 1 piece · 1 comment — Hacker News 1Sep 22, 5 AM — 2 pieces · 2 comments — Hacker News 2Sep 22, 6 AM — quietSep 22, 7 AM — 1 piece · 1 post — Mastodon 1Sep 22, 8 AM — quietSep 22, 9 AM — 1 piece · 1 comment — Hacker News 1Sep 22, 10 AM — 2 pieces · 2 comments — Hacker News 2Sep 22, 11 AM — 2 pieces · 2 comments — Hacker News 2Sep 22, 12 PM — quietSep 22, 1 PM — quietSep 22, 2 PM — quietSep 22, 3 PM — quietSep 22, 4 PM — quietSep 22, 5 PM — quietSep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — quietYesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quiet 1–34
Sep 22yesterdaynow · 12:59 AM ET
  1. 4

    Thread links spymarking to past printer-tracking exposure

    Commenters draw parallels to steganography and cite a historical case of a leaker identified via hidden printer tracking dots, broadening the discussion beyond AI-specific tools to tracking technology generally.

    • I feel like there’s some security engineering calculus that would be useful here?You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?There must be value in having a visible vs an…

      gorgoilerHacker News1d agoview on Hacker News ↗
    2 more of the top 3 · 31 posts in this stretch
    • newsyc500@toot.community

      Spymarks, Not Watermarks: https:// brand.io/article/spymarks/ Discussion: http:// news.ycombinator.com/item?id=4 9794615

      newsyc500@toot.communityMastodon1d agoview on Mastodon ↗
    • Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't…

      Retro_DevHacker News2d agoview on Hacker News ↗
    all of them →
  2. 3

    Developer says he built an open alternative to SynthID

    A commenter describes creating an imperceptible, tamper-resistant watermarking tool intended to be open-sourced, positioned as a transparent, independently-decodable alternative to closed systems like SynthID.

    “I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be hidden.”
    — minimaxir
    • These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.First the low-end laptops and…

      xp84Hacker News2d agoview on Hacker News ↗
    2 more of the top 3 · 4 posts in this stretch
    • The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be…

      MorromistHacker News2d agoview on Hacker News ↗
    • Out of frustration with SynthID being closed-source with weird dubious ways to verify if an image has the watermark, I created an imperceptible tamper-resistent watermarking tool intended to be open-sourced, where the watermark can be decoded independently and steganographic aspects are impossible as the algorithm is transparent so nothing can be…

      minimaxirHacker News2d agoview on Hacker News ↗
    all of them →
  3. 2

    Commenters call the "spymark" label alarmist

    Early Hacker News replies push back on the terminology itself, arguing invisible watermarking is not inherently malicious and citing benign precedents like counterfeit-note detection.

    “I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to sound very negative when invisible watermarks are not always negative…”
    — pavo-etc
    • I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.Tech like SynthID I see a net positive especially since it doesn't degrade text quality. I dream about a browser extension…

      pavo-etcHacker News2d agoview on Hacker News ↗
    2 more of the top 3 · 3 posts in this stretch
    • hkrn@mstdn.social

      Spymarks, Not Watermarks L: https:// brand.io/article/spymarks/ C: https:// news.ycombinator.com/item?id=4 9794615 posted on 2026.09.21 at 19:03:49 (c=1, p=5)

      hkrn@mstdn.socialMastodon2d agoview on Mastodon ↗
    • Weirdly the article doesn’t mention steganography. Arguably it isn’t quite the same, because the aim of steganography isn’t typically to add an identification, but something like “steganomark” would seem to be fitting.

      layer8Hacker News2d agoview on Hacker News ↗
    all of them →
  4. 1

    Essay coins "spymark" for hidden AI tracking watermarks

    An anonymous brand.io essay argues Google's SynthID and similar systems from OpenAI and others embed imperceptible signals in images, audio, text and video that can encode database identifiers tying content back to a user's identity, and proposes renaming them "spymarks" to foreground the privacy risk.

    “A spymark is a hidden signal that makes your work traceable without your knowledge or consent.”
    — brand.io essay
    1. first by HN Best, 2d ago · also HN Frontpage

What people are saying 16 voices from 1 site · best of 38 · verbatim