Unlimited Data Storage Using Image Steganography and Cat GIFs
minimaxir.com
minimaxir.com
I wrote a program[0] a few years ago that does exactly this "steganography" without encoding it in as pixels. It just prints a tiny png and then concatenates your data on to the back of it. Even my script could be way simpler if I was a better programmer at the time =]. To image sites, etc it's all the same. I thought it was pretty cool when I did it. Simple concept. Worked well. All you need is to encrypt your data first, since stego is hand wavy mumbo jumbo. Here[1] is an example
Uh, nope. The file is small because the frames are non random, and thus heavily compressed. If you wanted to store arbitrary data, the frames would be far more random, and therefore take up more space.
(The above was written halfway through the article)
I disagree that you need "deep knowledge of how image compression works". I have very little idea how the actual compression works, the only thing I needed to know was that images are compressed and random/arbitrary data doesn't compress as well for fundamental algorithmic reasons. It's obvious that changing images can make them larger even without any knowledge of the particular compression used.
There's the issue with image compression admist noise, but there's a second issue with GIF animation compression specifically which makes the math I provide a complete sleight of hand.
I dicuss the GIF file size issue and the quest to minimize it in my original GIF post (http://minimaxir.com/2015/08/gif-to-video-osx/), which is why I think mechanics of GIF file size are interesting and why I will write a followup.
Now you flood the web with images that have had data added to them, and it creates potentially millions of false positives. That then actually enables using the channel for covert conversations because so many images are now carrying data, they no longer stand out.
Anyway, given that a 2TB drive is like $90, so you can create a dual parity raid set of 6 for less than $600, that seems like way more storage than you'll probably use and if you amortize it over 3 years its way less than the cost of your Internet connection over that same time.
Another issue I am looking into is "could an image steganography SaaS startup exist today?" I believe the answer is no because web services are inconsistent about how they modify the picture in transit. (e.g. Twitter lossly compresses the photo with no way to retrieve the original.)
Wouldn't encrypting the data to be hidden, and then hiding it within random data (say, the low bits of image bytes) be perfectly indetectable? I'm assuming that the low bits of image bytes are uniformly random, but even if they're not then one could still hide data in them, it's just trickier.
In gifs you have a separate "color map" that stores at most 256 colors. So by modifying the LSB of each color you get at most 256 bits aka 32 bytes.
More info: http://half-life.wikia.com/wiki/Portal_ARG
That's Glitch Art 101: https://www.reddit.com/r/glitch_art/
One of my actual obfuscations a long time ago against casual users. Except it worked the other way around to hide midi's and mp3's as broken executables, etc. :)
In regards to the original challenge, you could convert a gif to wav a number of ways, the simplest being just copying image data as raw PCM.
Of course you can make it even more interesting.
Imagine turn each color channel into notes (dark red = C, blue = D, etc...). Better yet, what if remapped each byte value of a color into a table of chord progressions. What if you only allowed harmonized chord progressions and made it in a 4/4 rhythm. You just turned a gif into a song.
If you wanted to go even more ambitious, use something like OpenCV to identify shapes, objects, people/animals. Take what you find and create a sound mixer that generates a cacophony of sounds.
Use your imagination; code can be beautiful.
It won't matter given my use case of non-technical people snooping on computers or half-assed educators finding what I stashed on barely maintained PC's. I'm not speculating: they were fooled to the point they gave up trying far as I know.
"Of course you can make it even more interesting."
This is true. Your ideas are interesting. My brief foray into this sort of thing brought in a problem: compression passes applied at different points in apps and services. Your file might get modified at some point by a cheap storage service.
Also, the readers are lossy by design. So, these two things must be considered in any of these stego designs using multimedia formats disguised as actual multimedia. Plenty of methods still left.