MS Paint and Photos inivisibly watermark even locally generated output with GUID(xusheng.dev)
850 points by ComputerGuru 17 days ago | 432 comments
tl;dr: Reverse engineering of Windows Paint and Photos reveals that even "locally generated" AI images send prompts to Microsoft's servers for moderation, which returns a per-generation GUID that gets invisibly embedded into the output pixels via an SVD-style watermark and also recorded in a signed C2PA manifest. The pixel watermark and file-level Content Credentials are two layers of the same provenance system, linking each image to its prompt moderation request. Microsoft discloses the C2PA metadata and content filtering, but not that the embedded GUID is server-issued and tied to prompt moderation.
HN Discussion:
  • Hidden GUIDs enable deanonymization and threaten internet anonymity beyond just AI concerns
  • This reflects Microsoft's broader pattern of user-hostile sloppy implementations, avoid their tools
  • Provides additional technical clarification and confirms the article's findings as the author
  • Signing and preserving AI-manipulation provenance is actually valuable for digital authenticity
  • Shares related anecdote of watermarking triggering incorrectly on non-AI content