Printing (even text) is also a risk: It's very likely your printer is secretly adding marks to the page that contain its serial number and the current timestamp. [0]
Meanwhile Microsoft (and Apple) have "telemetry" harvesting those serial numbers of all internal and external devices you've ever had connected or reachable. Then they link them to your MS/Apple account, IP addresses, and the extended social-graph of all computers that were ever in the same room or shared the same bluetooth speaker.
In short, your "anonymous" flyer critiquing The Regime and depicting Dear Leader as a clown could lead thugs straight to your door. Or to the door of whomever you're staying with.
Essentially all of that country's businesses that are close to the regime need to be considered hostile.
We don't need to wait a few years, the revolution already happened; the insurrectionists were freed. These companies paid their tributes, in dollars, to the regime.
Maybe next ML will be integrated into software suites to enforce that regime's lies? Most Western governments use such software, the distributers of which have already shown they'll act in the regimes interests against supposed allies...
It's most likely how the FBI caught NSA leaker Reality Winner:
> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.
https://w2.eff.org/Privacy/printers/docucolor/
Seems like the algorithm is simple enough that they did it just by looking at some prints
Did it get revealed that Apple did that? This is news to me
Also, C2PA, another technology mentioned in the article, means tampering is easily detected.
So? Still the weapon worked.
Obviously Paint could have been watermarking prior to AI though, but this specific AI watermarking appears to be only that.
Why not just mod the app to not call this API?
Besides, you need to sign-in and pay to use that feature. It's very obvious that's not local.
I don't have a Copilot PC, but if you still need to pay MS to run the model on your own hardware it's laughable.
Provided you bent the knee and created a Microsoft account.
Some servers allow joining without a Microsoft account even these days, but probably can't play on any of the servers you regularly play on, if you don't have a Microsoft account.
*with the help of AI*. Does in fact make a difference.
I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.
I am not willing to pay the price of sending every bit I create to some megacorporation's server or stamp it with my only identity so the computer can tell me what's AI and what isn't. Especially not while the average quality settles into an uncanny valley that's often discernible with the naked eye, both for text and images.
Their images? I don't know how they'll be able to prove that.
Do not tell Microsoft where you sleep. IANAL but they are not a government or financial institution and do not have a right to that information.
Make sure you register mailing addresses with your credit card institutions in addition to your residential addresses, and make your mailing address your billing address so that you aren't forced to tell a thousand businesses like Microsoft where you sleep.
It takes zero effort to bypass that with Rufus, if you set up your own pc.
While it's definitely a dark pattern that I 100% do not agree with, Pro editions still allow you to do a local account. No need for the oobe /bypass command, still can be done through the OOBE GUI setup by selecting a Work/School account option then selecting Sign in options to then specify a local account to create.
No it's not. Sign up for a virtual mailbox for $15-$25/month.
> A scalable solution would be to make this sort of thing illegal.
I'm posting this in the genuine interest of people being able to maintain anonymity from data leaks, privacy leaks, and in general not needing to tell businesses more personal information than is necessary to render services. This is in a country that has no protection of personal safety whatsoever, and any business data leak could mean life or death to average citizens who are being threatened by criminals, stalkers, and more.
It seems every time I post something of this flavor the same handful of you come out of the woods and want to make privacy illegal, and I'm not sure who you are trying to support.
or make it illegal to ask for address, etc. definitely a little more effective than mailboxes
I fully agree that businesses should not be asking for addresses. Non-financial businesses don't need to KYC in the first place, and financial institutions can KYC without needing to know where you sleep.
I got triggered because people seem to always want to come out of the woods and say "addresses should be public record" or things of that sort and I vehemently disagree in the interest of privacy, in a country where a stalker can just look you up, terrorize you, and the police will do nothing about it.
Did you notice that it's an affordability crisis out there? An absolutely enormous number of people are skipping bills, taking on credit, and using predatory lenders to make end meets, and your recommendation is to add another fee on top of things.
It's not practical or useful guidance for the vast majority of people. I strongly agree with supporting privacy, but this sort of behaviour (adding trackers, etc) to normal functions without a full disclosure and opt-out mechanism must be made illegal, otherwise we are just creating markets for "privacy preserving" technologies that are increasingly less likely to actually be effective for that purpose but sure do put on a good theatre of seeming that way.
https://transparency.ky.gov/search/Pages/SalarySearch.aspx#/...
> and work underground for cash
My sister was a member of Scientology for 2 decades and she was encouraged to do this. As a result, she has almost no Social Security earnings and her Social Security check is about 1/4 of what she would be getting if she reported (and paid taxes to the government instead of to her "church") her income.
> decide to vote? Your information again is publicly available
I ran for elected office in the past. When I asked the voter registration office for a "walking list", they only checked that I did get on the ballot and I was provided with a list of every registered voter in the district I was running for. It had names, addresses, phone numbers, political party and a list of what elections you voted in (I think it went back 8 years). Some people were rather upset that I had access to that information when I knocked on their door and asked them to vote for me.
You are out of touch.
That isn't going to stop Microsoft from collecting your address by collecting your wifi info, or from the data you enter into websites or documents. When the maker of your OS is the enemy you will always lose.
As soon as you purchase something from Microsoft - e.g. your Office 365 subscription - they have at the very least your billing address on file for the credit card.
Even in places with strong privacy regulations requiring businesses not to collect data they don’t need, businesses apparently get away with asking this.
And as soon as you connect with telephony systems (e.g. VoIP numbers) or rent out servers, some countries' telecom KYC laws apply that also force MS to collect validated address data.
Because handling that PII is not only cheap, it’s profitable!
Because of the volume of stolen credit card numbers. If you have the address, you are much less likely to be someone using stolen CCs. Seriously, most of the crooks are that lazy. So the real reason is the credit card processing companies.
Also, post 911, there is this thing called "know your customer". It was set up to fight money laundering and financing terrorists.
Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.
Presumably USA are complicit in this spying on allied countries - did the countries know, is it a Five Eyes thing?
At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."
Inserting a tracker that can personally identify me without my explicit opt-in consent is a GDPR breach. I'm surprised you do not not this.
The whole EU vision is they know what the little people do all the time, think all the time, and spend their money on all the time. For the children, obviously.
In the meantime, the GDPR is your friend. The amount of FUD spread about it on here by those working in Adtech (and whose very salaries are dependent on invading peoples privacy) is insane.
I genuinely wish you were right, but you are so naive it is frightening.
> The amount of FUD spread about it on here by those working in Adtech
You are confused. You are arguing with people that want to protect privacy. The EU demonstrably is not doing that, as WhatsApp gets ever more de facto mandated by the day.
Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239
"I haven’t read enough to understand". Oh, now I know the answer to my question
so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.
to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.
Personally I think there is a good argument for being able to distinguish AI generated image and video...
Neat but that's not what's being built here. What's being built is "we can trace back this content to who made it" which is bad. Doesn't matter if today that it's limited to AI generated content. Won't be tomorrow. Your devices should not act against your best interests. No cop in my pocket please.