Google's SynthID hides secret tracking IDs in your images and audio

Spymarks, Not Watermarks

Google's SynthID hides secret tracking IDs in your images and audio

Google's SynthID embeds hidden signals, called spymarks, into images, audio, text, and video. A 512x512 image can carry a 136-bit payload, enough for a 64-bit database ID linked to your personal records. Unlike visible watermarks, these signals are imperceptible, survive edits, and track you without consent. OpenAI and others are developing similar systems, raising serious privacy concerns.

Spymarks are a form of metadata you have limited knowledge of and control over, and their purpose is entirely antagonistic to you.
  1. Retro_Dev

    Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't watermark, an image compressor we are certain can't watermark, etc). One vector that I am particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open. They might rationalize it (if discovered/announced) by saying that our memes won't be reposted, images or work stolen, etc... but honestly I'd rather my work be stolen than tracking information inserted in there. Oh, we also have stuff which is way more secure, like time-stamped cryptographic signatures.

  2. xp84

    These are going to be very popular for intercepting images on their way to a display. Think of the advertising possibilities. Ad attribution can be 'vastly improved' when both the ad and every step in the funnel are all spymarked and all of them are reliably reported on by virtue of their pixels hitting your screen.

    First the low-end laptops and phones (and probably later, most of them) will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home. I assume this is something Apple will, to their credit, refuse to do[1] but I don't think other OEMs will have any qualms based on what they already do with their TVs.

    [1] (though they don't do this kind of thing out of altruism, but because their cash cow is app store rents and fat hardware margins, not third-party advertising.)

  3. paweladamczuk

    It increasingly seems to me like the only way to prevent value to be extracted from myself is to stop engaging with new tech altogether.

  4. swiftcoder

    A number of prominent corporations used to embed these in the background images of their internal webpages, so that leakers could be identified from the screenshots they shared. Caused a whole fun adversarial loop where journalists had to transcribed and/or redraw screenshots before publishing to avoid exposing the identity of leakers...

  5. Morromist

    The word choice example is cool. I wonder if it really works dependably. I'm sure many many exerpts in posts and books have those same 8 bits - you'd need a lot more bits - but the more you add the more strange your writing style might become.

    Like it choose between "winding" and "curving" but there are many uses of curving that probably can't be replaced with "winding" like "her gently curving thighs" with "her gently winding thighs"

    But I'm sure there are some intricacies I don't understand. Anyway, very cool website, thanks for sharing it~!

  6. encrypted_void

    Spooky stuff. This will take surveillance to a whole new level. This is basically email read-receipt tracker, but for all of the digital content. They will know the whole trail - from originator to how it spread. Who read what and when. Big brother will always be watching.

  7. gorgoiler

    I feel like there’s some security engineering calculus that would be useful here?

    You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?

    There must be value in having a visible vs an invisible watermark, or in declaring that a work is watermarked without revealing the hidden mark, or having two marks — one that is publicly verifiable and another that is hidden?

    If the process itself can be defeated through adding entropy (or more generally by revealing the watermark algorithm) then is that not security through obscurity, which is to say it is a one-shot rather than a general system that is doomed to become obsolete over time?

    Something feels off about a technology based on being hidden but whose only value is in being revealed but I feel dumb for not being able to be more specific about what feels wrong! It could simply be that anyone who can verify the presence of the watermark also now has a tool to tell them when they’ve successfully scrubbed the watermark off the work, so the verify tool has to be kept secret which in turn limits its usefulness.

  8. Ennea

    Reminds me of Blizzard embedding data inside World of Warcraft screenshots (link goes to a small write-up from 2012 in a forum focused on video game cheats; sorry, could not find a better source): https://www.ownedcore.com/forums/world-of-warcraft/world-of-...

More from this day

2026-09-22