Police claims to have fingerprinted computer based on printed document
nrk.no
nrk.no
“Program and program settings: When preparing the letter, WordPad for Windows is most likely used. Default settings for font, line spacing and paragraph are used. The page layout has been Letter.”
That, I think, can be inferred with good confidence from precisely measuring various font measurements, looking at how lines got broken, etc, and comparing that with a database of program defaults for a large set of OSes and programs.
“Device, operating system and video card : When designing the threat letter, a Windows PC has been used, with an operating system Windows 10 or 8.”
I guess either WordPad or the font got tweaked somewhat in that Windows version. Maybe WordPad started using ligatures more aggressively, its page width got a tiny bit wider, or, in the font, some letter shape or spacing table changed a tiny bit, or a character was added.
“The PC has had an integrated video card, Intel HD Graphics 630.”
That, for me, is the most intriguing part. Does Windows use the GPU to render fonts even if they get printed, and are there subtle differences between GPUs and their software rendering that, statistically, can be recovered from the somewhat noisy print?
Most cheaper printers (esp. on Windows) use the GDI protocol for printing. These printers only know how to print rasterised images, so the document is rasterised by the OS/Print driver and only this final rasterised image is sent to the printer. This is different from higher end PCL/PS printers where the document is translated into a page description language and the printer is (partially) responsible for rasterising the final document for print.
Since Windows uses the GPU to render fonts I wouldn't be surprised if the same code is used to rasterise the fonts for GDI printing.
That being said I'm very surprised they can identify the GPU just from that, unless there is some specific bug in the driver for the card which produces an obvious font rendering artefact.
Gaussian blur is your friend if you wanna send a death note, I guess.
Also, I doubt you can get conclusive evidence from a single letter. Luckily, your average random note has lot of them, even duplicated ones. I would carefully align and average out as many capital A’s as I had, and work with that.
You missed the explanation above why you're wrong, at least on consumer non-PostScript printers. Most cheap printers nowadays passes the buck of rasterisation to Windows (and its horrible, security headache spooler). You can even check if which is which: in Windows 10, open Settings, then Devices, select Printers & scanners, select [your name of printer], press Manage, press Printer Options (not Printing options), open the Advanced tab and then click on the Print Processor... button. If it says "winprint" then Windows handles the rasteriser.
I think they meant something like "ink smears".
Pinpointing a version of Windows, if it was printed from a stock OS font, could be as simple as comparing tiny differences in the vector files and knowing if one pixel would rasterize at 60% black versus 50%. To the extent that the rip goes through a graphics card, it would be knowing whether that card rendered the 60% as 58% or 62%.
I'm pretty sure if you scale it down, the printer driver will do an extra layer of downsampling and add its own anti-aliasing; but the printer hardware doesn't do that, it just sprays the dots it's told to spray, and in general the drivers replicate the pixels that are sent from Photoshop or in this case, MS Word, which uses something like QuickDraw used to be on a Mac, an embedded system process, to rasterize the fonts.
Prior to this it had never occurred to me. But yeah, more randomness. Noise filter and blur, then a bit more noise, then photograph it, print the photo, scan it on another device, put it in the washing machine, leave it on the porch for a week and repeat.
Could also be by design, similar to printer identification dots. Have the artifacting vary every so slightly from one GPU to another. Then again, I feel (emotional statement, not of fact) that this would be known by now if it was a thing.
So...evidently from a sample of me, I can tell from which monitor a screenshot was taken...
https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
Edit: Specifically, what about printers that only print black and white?
https://www.eff.org/press/archives/2005/10/16
The implication is that only color printers are affected.
"The U.S. Secret Service admitted that the tracking information is part of a deal struck with selected color laser printer manufacturers, ostensibly to identify counterfeiters."
https://upload.wikimedia.org/wikipedia/commons/7/7b/Obverse_...
Probably just idiots playing around with the copier rather than dedicated gangs, but if it worked they might be tempted to say "Well ..."
https://old.reddit.com/r/mildlyinteresting/comments/1s8rl9/i...
[1] https://www.eff.org/pages/list-printers-which-do-or-do-not-d... [2] https://en.m.wikipedia.org/wiki/Machine_Identification_Code
I'm not sure these days when most GPUs are IEEE-754-compliant. But back in the mid to late 2000's I worked on a GPU renderer for video editing and we had a few filters that gave noticeably different results on different GPUs. One filter did a hard black and white threshold, then blurred the result, did another hard threshold, etc., in a loop. Because of differences in precision of the floating point values (24-bit on AMD at the time, if I recall correctly), the thresholds could produce minor differences that got magnified by the blurring, and then created new thresholds with minor differences, etc.
Even if all the GPUs are using IEEE-754 floats, there are driver differences that can cause the results to be slightly different, too. Like a simple GLSL mix() function could be implemented as result = x * a + y * (1 - a) (where x and y are 2 input pixels and a is the alpha of x). Or it could be implemented more efficiently as result = a * (x - y) + y. Doing the same math in a slightly different way can sometimes lead to slight differences in intermediate results which compound in the final result. So yeah, it may be possible to tease out some of these things by examining something like font rendering.
Becomes extremely easy for malicious actors (out or inside the police) to fake evidence and frame anyone they'd like.
Bite mark identification was used forever until blown up by particularly shameless grifting, and has never been shown to work as practiced. [1]
Tennessee still uses dowsing rods. [2]
Fingerprinting as practiced is a bundle of folk practice, guesses, and some science. Quality varies wildly. [3]
Fiber analysis, lie detectors, spatter analysis and many more techniques are all crap. When one bogus method is finally found legally unreliable, cops and prosecutors find a new one.
[1] https://innocenceproject.olemiss.edu/radley-balko-reports-on...
[2] https://www.themarshallproject.org/2022/03/17/witching-dowsi...
[3] https://www.aaas.org/resources/latent-fingerprint-examinatio...
And I'm wondering about that, because we know the criminal must have been a pretty hard-core cryptocurrency nut. There aren't THAT many of them in Norway (they've already concluded they are a fluent Norwegian speaker).
Instead of facing it just as a lead, it might influence investigators to, consciously or not, build confidence in framing a (wrong) person and and end up building a compelling case against them.
The person who wrote the ransom they believe to be fluent in Norwegian, there could easily be other people involved who're foreign.
Do we?
I was still under the impression everybody was blaming her husband for the disappearance.
As for malicious actors, wouldn't that be a risk for most forms of evidence? Likewise, wouldn't many of the techniques used to establish the validity of other forms of physical evidence be applicable when these techniques are used?
Ah yes, I see they’re using the default formatting options. That narrows down our search to 99.9999% of the population.
That narrows it down to coming from 10s of millions of computer perhaps?
⇒ I don’t think it’s fair to call this speculation, let alone pure speculation.
Seriously though, I thought printers have been using microdots as identifiers for years. Is this just an old wives tale?
Just make sure you pay with cash.
There's a number of encoding schemes [1], though most of those only identify the printer - they don't go far enough to identify the graphics card or OS where it originated. That's a new capability - if it's being accurately relayed here.
[0] https://en.m.wikipedia.org/wiki/Machine_Identification_Code
I believe it's only by some copiers and laser printers, not inkjets for example.
In that case, they may have the yellow watermark and just aren’t saying so.
Or do you mean light gray dots or so? Because I haven't heard of such a thing but find it hard to prove this negative.
They figured out it was Wordpad (presumably based on line breaking or similar) which narrows it down to Windows, and the graphics drivers probably subtly affect the font rendering in the same way that can be used for canvas fingerprinting.
That said, Windows 8 or 10 using Wordpad and Intel integrated graphics doesn't exactly narrow it down.
‘It’s a Hewlett-Packard laser. They can tell by the toner chemistry. Can’t tell which model, because all their black-and-white lasers use the same basic toner powder. The typeface is Times New Roman, from Microsoft Works 4.5 for Windows 95, fourteen point, printed bold.’
’Typefaces tend to change very subtly between different word processors. The software writers fiddle with the kerning, which is the spacing between individual letters, as opposed to the spacing between words. If you look long enough, you can kind of sense it. Then you can measure it and identify the program. ...’
(Edit: Limited the amount of quoted text a bit; I believe a few lines is fine/fair use. Loving the series re-read after the TV show, and that I bought them on Kindle originally!).
If you're in a highly secure environment, it's even possible the content itself may be a unique identifier. I could imagine a sensitive document having grammatical alterations unique to each recipient.
Journalists should consider this before publishing unredacted copies of leaked documents.
https://support.zoom.us/hc/en-us/articles/360021839031-Addin...
I wonder how well the audio fingerprint works over telephone. On one hand, it certainly won't have the same frequency range as a laptop speaker, but on the other hand so few people join by dialing in, it may end up obvious who the leaker is.
Well, that the typewriters and today the printers are unique, sure.
But here they seem to claim(I do not speak the articles language) that they could identify the computer that send the document. Which is a very bold and new claim, I think.
1) Printers leave a unique "invisible" watermark; similar to the way you can hide an image within an image. The naked eye can see it, but it's there.
2) Aside from that the printer itself has a unique fingerprint, similar to how keyboards do (i.e., AI can pick the difference in the sound of each key and with that audio can translate your typing into letters / words).
3) Networked printers phone home; with snippets. Again, similar to the way some smart TVs send screenshots.
Perhaps not every printer does all of the above, and some not at all, but enough do or might.
Finally, law enforcement explanations like the article's to me are suspect. For example, how often do we hear that a random-y car stop led to a sizable drug bust? So of all the thousands of car going up Rt 95 the police randomly picked one with loads of drugs? What are the odds?
Moral of the story, if (federal) law enforcement has "insider information" they're not going to share that with the public.
I agree: all I've learned is to make a doc on my oldest laptop, multi-paged and-fonted, have it printed at different public (paid or library) sources and then cobble them together and post them from a random place (not taking my phone there, either).
From what I've anec-heard, those 'rando' car stop/ mega busts are politely arranged so the cops get their bust, but the real mega-shipments sail on by, untouched. Everybody gets a payday, even the Prison system!
*the captured mules get to live rent free for a whilem so there's that, for them.
That feels like it exposes your attack surface enormously! More witnesses, more cameras, more data to cross reference, etc.
Buy a cheap laptop and printer at Goodwill or a garage sale, print, destroy them, then mail your manifesto or whatever.
Just be sure not to get DNA or fingerprints on the stamp :)
Wtf! Just when I thought I'd heard it all.
If you want to take the deep dive read "The Age of Surveillance Capitalism."
- Are there certain rendering artifacts that can be seen on printed glyphs that give clues to the GPU?
- Or, are they going by heuristics here? (I.e. it was XYZ GPU, because it was a common machine that at the time that would be running Win 8 or 10)
Even if there were subtle GDI rendering differences -- which I doubt -- it is hard to believe that a printout would let them positively identify Intel HD Graphics 630 specifically, as opposed to say HD Graphics 610 or 615 which are slightly slower clocked versions of the same GPU released at the same time and which almost definitely use the same drivers and GDI rendering system.
But if the information comes from elsewhere, as in already having a suspect and knowing what computer they used -- they should reasonably have given more information from the same source -- CPU model, etc.
I can't imagine a possible way to leak only GPU info -- unless GDI or the Intel drivers has some secret mechanism for intentionally rendering some sort of subtle identification code onto printer output.
It's just really hard to understand.
If you only knew how much the Norwegian police are blasted these days for over-stepping boundaries in searches of persons, and their interpretation of reasonable cause for home searches, and their ties to the private drug cop association NNPF (and reluctance to release membership details)
Like, the "State Attorney" (Riksadvokatsembetet) had to issue a clarification that busting someone with a joint in the street is NOT reasonable cause to search their home for more, please stop doing that you morons, also don't lift people's testicles to see if they have hidden something there thank you.
All the while more violent and serious shit is being ignored.
ACAB, also here.
But the fact that they are complaining about these things shows they're not quite as unrestricted as police in other parts of the world. Lying is one of the areas there is a difference: Norwegian police aren't allowed to e.g. lie to a suspect that his friend has already confessed. Which isn't to say they won't, but cases can get thrown out over it.
So it's a stretch to think that the police are lying to the public about the positive evidence they have. Lying by omission, maybe, perhaps being wrong, hell yes, but making up things out of whole cloth in public in just to gather information would be new ground for Norwegian police.
Norway is a beautiful, modern country, and while the older generation is still fairly religious (and racist to some degree), overall it's pretty liberal. It's a really nice place, and I considered moving there more than once.
The Norwegian police may have some warts, but they are held to a much, much higher standard than police in the US.
Honestly, there is no comparison between US police and those in any part of Europe or Scandinavian - we don't have paramilitary-style police busting down doors with flashbangs and automatic weapons blazing, police officers regularly murdering people, or anything like the overt fabrication of "evidence" that some US PDs seem to think is a sport to see how much they can get away with.
I do agree that our police cannot be compared to the US "out of control" situation, where both its conduct and its excessive use of violence is extreme and avoids judicial oversight. But that's not to say it goes clear of criticism from a systemic perspective.
There are ongoing debates and investigations concerning effectively punitive cavity searches against persons suspected of having smoked a joint, using suspected drug use as a pretext for invasive home searches, immediate confiscation of drivers' licenses after reports of one-off marijuana use (no judicial process involved), involuntary commitment to somatic hospital followed by coerced drug testing in pregnant women after (flimsily) suspected drug use, punitive home searches against drug reform activists and more.
The most high-profile of the two latter cases were conducted against women who visibly participated in democratic debate for reforming our drug laws, and participation in said debate was documented in writing as probable cause for having the woman involuntarily committed by the police.
All but the very last example is strongly suspected to be systemic; it has happened with regularity. And the problems are so obvious that the conduct clearly has a high degree of political support, although "should we systematically jail marijuana smokers and degrade them by probing their vagina or rectum in the police station" has never featured in a debate preceding the elections for Parliament.
Also plenty of criticism regarding the democratic role of a private drug law activist organization (NNPF) that's effectively both part of the police force and a central partner in the bureaucratic process for determining what drug policy should be democratically enacted.
No. If this is the case from just before Christmas, the media reporting was extremely biased as the health services cannot comment due to privacy. However, the woman posted her letter on Twitter (now deleted but still available at the internet archive) and it was, in my opinion, justified. (1) The woman had a history of drug use, (2) her mother had reported concerns regarding the woman's drug use and asked the health services to consider involuntary treatment the same year as the woman became pregnant, (3) the woman did not meet her GP after becoming pregnant, (4) the woman did not respond when the health services approached her to evaluate her drug use voluntarily, (5) the woman moved to another municipality (which may have been interpreted as an attempt to "escape" from them), (6) the woman did not approach the health services in her new municipality to follow up her pregnancy.
In light of the two previous reports of concern and the use of drugs, [the woman]'s information about pregnancy, [her] lack of contact with her GP during pregnancy, [the authorities] found cause for concern. [...] The decision was made on the basis that she has orally informed [the authorities] and confirmed to [the authorities] that she is pregnant and the severity of which drugs (including cannabis, MDMA, LSD) that she has stated that she uses in the newspaper and Social Media. Use of these drugs is not compatible with pregnancy. There is no information on how far she has come in her pregnancy or that she has followed up regular pregnancy controls. [...] The municipality considers that it is overwhelmingly probable that the mother's drug intake will be harmful to the fetus
The national guidelines highlight that the fetus should have priority - "the care of the fetus takes precedence over the care of the woman" - and that Pregnant women with substance abuse problems are in a special position and the consequences for the fetus can be serious if the municipality spends too much time considering the use of coercion. The municipality must therefore not spend unnecessarily long time on assessment and testing of voluntary measures. The due diligence requirement requires quick clarifications to prevent the fetus from being exposed to an unnecessary risk of injury.
and that coercision should be considered if "the pregnant woman deliveres a positive urine sample, fails to take a urine sample or fails to make an appointment"However, it is mentioned several times in that letter that she had been positive to drug use in her public writing and admitted to using several illegal drugs in social media. That was probably not okay, but the decision was not - by far - based on that fact alone.
I sort of doubt we can find agreement, since we appear to have quite different views on what basis is required for the authorities to perform this kind of incredibly invasive use of force against a citizen that isn't even suspected of having broken a law. This is not suspicion in the legal sense -- it's a possibility or a worry.
I'm not able to draw the conclusions you are from the part of the letter you've quoted. None of what is mentioned there is evidence -- she has publicly stated that she's been using certain illegal drugs on numerous occasions, that she's advocated for legal reform regarding drug use and that she is pregnant. She has declined seeing a publicly-provided doctor wrt. the pregnancy.
None of this is an indication of drug use!!
Related side note. If you ask other Europeans, e.g. someone from Germany, they might tell you that Norway's system of having regular, public-sector scheduled pregnancy inspections where declining will make alarms go off...is actually pretty creepy from a privacy perspective. At least that's what my left-voting German friends told me when they had kids a few years ago. Not that the service is a bad thing, but that declining or arranging your own is considered grounds for suspicion.
There is a difference between the Norwegian (Scandinavian?) and Western mindset here that our discussion illustrates splendidly. Our society is in some ways more collectivist; there are numerous situations where the rights of the individual are put last which contrast quite markedly to other Western societies. And these rules are enforced with strict social penalties.
The same contrast can be seen in the 13 (and counting) cases where the Norwegian Child Protective Services, supported by the Norwegian Supreme Court (and obviously the laws enacted in Parliament), have had rulings against them in the Human Rights court in Strasbourg.
It's a constant fight to make sure Norwegian police doesn't drift closer to UK/US style police, and in many ways we are losing.
Most printers will do their own rendering, it's not often that a text document gets pre-rendered by the OS.
If it was printed straight from WordPad without being converted to an image, there's no artefact from the host OS, there.
Without surveying the industry, I doubt that's accurate. Most inexpensive home printers sold to purchasers of Windows PCs are GDI printers. Part of the cost savings associated with those comes from using the PC to render the document.
What does intrigue me is how they managed to determine the graphics card.
Anyone?
It's more likely the printer driver have encoded information about the gpu into the yellow microdots [1] that many color printers use to trace pages.
But if they have microdots, then they really should have more information.
[1] https://en.wikipedia.org/wiki/Machine_Identification_Code
And you can't really use a b&w laser to print convincing notes.
Cheap GDI printers use the PC for rendering. I find it a bit surprising that would give enough to identify a specific card from a printed sample, but it certainly seems plausible.
I'd expect they would, as you, know the exact model and make of the printer if it was microdots.
They can also have libraries of things printed with lots of printers to analyse the quality of print etc., and then get an estimate for example by a neural network examining artefacts. in such a case, it would never be 100% certain, but maybe 95-99% range somewhere if they do it good.
I can _imagine_ such techniques might even also get to the point where they can somewhat certainly identify other aspects of the pc like graphics cards, even though they don't know exactly how the network will draw these conclusions.
There's quite a lot required for them to credibly show that the letter could only have been produced on a pc with "Intel HD Graphics 630". I suspect the argument is on the level of "we tried to duplicate it with some random PCs and the one with Intel HD graphics looked most similar".
But even if it is true, integrated intel GPUs are in (maybe?) a third of all windows PCs.