Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

kennethbspringer.au

@kennethspringer@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Founder of snapWONDERS and builder of Vaultify — a digital media forensics platform running across clearnet, Tor, and I2P.

What I work on: metadata excavation, JPEG encoder fingerprinting (identifying camera model and encoding software from compression structure alone — no EXIF needed), steganography detection and hiding, GPS triangulation, and manipulation detection.

The core idea: standard metadata stripping tools remove the labels but leave the fingerprint. The quantisation tables baked into JPEG compression by camera firmware survive every strip. Vaultify finds them.

Senior full-stack developer and tech lead by day. Building snapWONDERS on the side — forensics, privacy, and deep dives into file format internals.

snapwonders.com · vaultify.snapwonders.com

#digitalforensics #OSINT #steganography #infosec #privacy #metadata

7 Followers
6 Following
22 Posts
Joined May 24, 2026
Personal website:
https://kennethbspringer.au
snapWONDERS:
https://snapWONDERS.com
snapWONDERS Vaulitfy:
https://vaultify.snapWONDERS.com
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3w ago

AI validated every real research hunch I fed it, and invented none of its own, across six months of actual forensic and steganography detection work — that's the case study, based on my own findings, not just a statement.

Every genuinely new direction in that work started as a hunch I couldn't fully explain yet. AI validated the hunch after the fact, showed it was real and measurable. It never generated the hunch itself. A 2024 Stanford study of 100+ NLP researchers backs this shape of result: LLM-generated research ideas scored higher on novelty in blind review, lower on feasibility — and when the researchers actually built the ideas out the following year, most of that novelty edge disappeared.

On pure brute-force parameter search: by round five of iterating a lead, the model itself starts suggesting we park it. Swapping to a more capable model doesn't change that. There's a documented way past it, though — not a smarter model, a verifier plus a search over thousands of candidates instead of one conversation at a time. FunSearch and AlphaEvolve do this at DeepMind's scale. More useful for a small team: OpenEvolve, a solo-engineer reimplementation with its own real, independently published results — a circle-packing result within 0.04% of DeepMind's own figure, and a documented GPU-kernel decode-speed improvement.

Not a clean win for AI, though. A January 2026 paper (Trehan & Chopra, arXiv:2601.03315) ran four fully autonomous ML-research attempts through a six-agent pipeline — three failed, for reasons that read like a direct description of the round-five wall: defaulting to training-data patterns, declaring success despite an obvious failure, weak judgement on what's even worth checking next.

So where does that leave the original claim? I don't think AI is quietly building its own successor in a loop that runs with nobody in the chain. Everything I've actually seen it do well — the reading, the validation, even the structured search that gets past brute force — still needs a person to define the problem first: what to search, what counts as a good result, when the problem itself needs rethinking. A loop that evolves entirely without humans would need AI to do that last part on its own. Six months in, I haven't seen it do that once.

That leaves me with a bigger question than the one I started with. Is a novel idea, real innovation, actually tied to imagination — the ability to dream something up, or that inkling you get when you suspect there's a direction worth taking before it even makes sense to explain why? That feels like a genuinely human thing. Will AI ever endeavour into that space on its own terms, or will it keep covering the same ground through brute force — generating enough new-looking concepts that it eventually stumbles onto what a person would have reached by instinct? Maybe, in time. I don't know yet.

If you've found a real way to get AI past brute force in a small-team setting, not a DeepMind-scale one, I'd like to hear how.

Full writeup:
https://kennethbspringer.au/2026/09/15/i-kept-waiting-for-ai-to-have-an-original-idea-it-never-did/?utm_source=mastodon&utm_medium=social&utm_campaign=article-20

#AI #digitalforensics #steganography #research #infosec

I Kept Waiting for AI to Have an Original Idea. It Never Did. — Kenneth B. Springer
kennethbspringer.au

I Kept Waiting for AI to Have an Original Idea. It Never Did. — Kenneth B. Springer

There's a claim doing the rounds that AI is going to take over — not through one dramatic leap, but by entering a continuous loop: building its own next-generation system,…

5
0
3
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
1930s fraud-detection mathematics, still working today — just aimed at a target it was never built for. Challenge: catch an AI-generated JPEG using nothing but a 1938 statistical law. No neural network involved. Benford's Law: in real-world numerical data, the leading digit isn't uniformly distributed — 1 shows up ~30% of the time, 9 under 5%. Holds for river lengths, electricity bills, physical constants... and, it turns out, for the AC coefficients in a JPEG's DCT blocks, if the image actually came from a capture-and-compress pipeline. I run this as one of six checks in snapWONDERS' analyse pipeline: 8×8 DCT on every block, absolute value of the AC coefficients (DC term excluded — it doesn't follow Benford), leading digit extracted, binned against the classic log10(1 + 1/d) curve, then a chi-squared goodness-of-fit test. Above threshold, it's flagged. It's not a standalone verdict — heavy resampling or repeated re-saves can trip it too, same as a genuinely synthetic image would. So it feeds a combined score alongside five other signals rather than deciding anything alone. But as a zero-training, zero-black-box check, it's a genuinely satisfying one: an accounting fraud-detection tool from 1938 has something real to say about whether a photo actually came out of a camera. Full technical breakdown (with the formula) → https://kennethbspringer.au/2026/08/05/benfords-law-detecting-ai-generated-images-without-ai/?utm_source=mastodon&utm_medium=social&utm_campaign=article-16 #digitalforensics #OSINT #infosec #aiimages #deepfake #snapWONDERS
Benford’s Law: Detecting AI-Generated Images Without AI — Kenneth B. Springer
kennethbspringer.au

Benford’s Law: Detecting AI-Generated Images Without AI — Kenneth B. Springer

An 88-year-old fraud-detection law, applied to JPEG compression math, flags AI-generated and heavily edited photos — no AI detection model required at all.

22
0
19
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 4w ago

You checked the GPS coordinates in a photo's EXIF data. Real numbers, real precision. That doesn't mean the photo was taken where they say.

A GPS block in a photo carries two clocks, not one: the satellite fix's absolute UTC timestamp, and the camera's own local-time field, set by whatever clock the device happens to be running on. A genuine photo needs all three facts — location, and both clocks — to agree. Look up the timezone the coordinates actually sit in, convert the satellite's UTC time into it, and it should land on the same minute the camera's own clock recorded.

Paste coordinates in from a different photo and the location changes but the camera's local-clock field doesn't move with it. Spoof a location and the same kind of gap tends to open up, because the two fields come from different places in the file. The size of that gap is a fact you can measure directly — not an inference from pixel statistics.

The honest limitation: it can't tell "someone lied" from "someone forgot." A traveller who never resets their camera's clock after landing produces exactly the same mismatch as a forged photo. A camera with a dead clock battery that never had a real time set does too — it writes a placeholder date the check can't tell apart from a real one.

Verified this by hand before writing it up, not just trusting the implementation: Sydney mid-daylight-saving, India's UTC+5:30 half-hour offset (the kind of edge case a lazier check gets wrong), a genuine cross-timezone trip, and a forged-coordinates case — all landed exactly where they should.

Full writeup: https://kennethbspringer.au/2026/09/09/gps-timezone-triangle-photo-metadata/?utm_source=mastodon&utm_medium=social&utm_campaign=article-19

#infosec #privacy #OSINT #digitalforensics #GPS

What the “GPS Timezone Triangle?” Row on a Forensic Report Actually Checks — Kenneth B. Springer
kennethbspringer.au

What the “GPS Timezone Triangle?” Row on a Forensic Report Actually Checks — Kenneth B. Springer

Forensic reports flag GPS with a question, not a checkmark: "GPS timezone triangle?" Here's what that question is actually asking, and what it means when the answer is no.

1
0
1
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 1mo ago

Every popular bot-defence — Google's reCAPTCHA, hCaptcha, Turnstile — relies on one of two things: fingerprinting your browser, or your browser reaching a third party's server. Tor Browser is built specifically to defeat the first. Our darknet visitors often can't do the second.

snapWONDERS and snapWONDERS Vaultify serve clearnet, Tor, and I2P at once, on purpose. We already had an image CAPTCHA on signup — not an open door — but a static code is a solvable target, and a signup burst (several times normal baseline, starting late July) worked straight through it. A newsletter-subscribe flood followed (hundreds of submissions in two days, almost all from one free-mail domain, almost none ever confirmed). The mainstream next move, Google's reCAPTCHA, was disqualified by our own architecture before a single trial.

What we built instead: a self-hosted proof-of-work challenge, same lineage as Hashcash-era anti-spam. It doesn't try to identify the visitor — only verifies that a real browser spent real computation solving a puzzle. No third-party call, no fingerprint, same mechanism on every network.

The part that wasn't trivial: Tor and I2P aren't the same threat model. A .onion address is a secure browsing context to Tor Browser, so the fast native-crypto path is available. I2P over plain HTTP doesn't get that, so a client there is stuck on a much slower fallback — the same challenge can't be tuned identically for both.

It's not limited to one form either — proof of work runs across the parts of the site where automated abuse could do harm, as one layer among several. No single check carries that weight
alone.

The fix wasn't a friendlier CAPTCHA. It was not caring who's asking — only whether they paid the cost of asking.

Full writeup: https://kennethbspringer.au/2026/08/26/i-couldnt-use-googles-recaptcha-so-i-built-my-own-bot-challenge-for-clearnet-tor-and-i2p/?utm_source=mastodon&utm_medium=social&utm_campaign=article-17

#infosec #privacy #Tor #I2P #OSINT

kennethbspringer.au
2
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago
You've seen the little "cr" badge start showing up on images. Do you know what it actually proves — and what it doesn't? It's not a vibe check. It's a COSE-signed certificate chain sitting inside a JUMBF box in a JPEG's APP11 segment (or a PNG caBX chunk). The signature proves two things and only two: which tool or camera signed the manifest, and that the pixel data hasn't changed since. That's the entire guarantee. The digitalSourceType field inside that manifest is what tells LinkedIn's badge to say "AI-generated" instead of "camera capture" — trainedAlgorithmicMedia vs digitalCapture. LinkedIn reads it. X is rolling out the same read. Where it stops: no manifest, no proof either way. The chain says nothing about who the human behind the tool is, and most images in circulation still carry no manifest at all — that's normal, not suspicious. snapWONDERS validates the full chain on every upload — signature, hash binding, source type — and feeds it into the authenticity score. Full breakdown: https://kennethbspringer.au/2026/07/09/think-twice-before-claiming-ai-work-as-your-own-what-c2pa-content-credentials-prove/?utm_source=mastodon&utm_medium=social&utm_campaign=article-10 #OSINT #digitalforensics #infosec #C2PA #contentauthenticity
Think Twice Before Claiming AI Work as Your Own — What C2PA Content Credentials Prove — Kenneth B. Springer
kennethbspringer.au

Think Twice Before Claiming AI Work as Your Own — What C2PA Content Credentials Prove — Kenneth B. Springer

AI tools increasingly sign what they create, and editing the file rarely erases it. How C2PA content credentials work, who's using them, and where LinkedIn fits in.

3
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago
Replying to
@thomasfuchs@hachyderm.io given the rate of "improvements" with AI, it is likely that the quality would improve in time to come. Be interesting to see if the content surpasses that on a human and said banners would proudly be displayed. On the flip side, with media generation does have some marker added to the media content. While it doesn't say "proudly made with AI" but the intent to let you know it was AI generated was there. These are done by visible Markers: Logos, icons, or "Imagined with AI" text placed directly on images, easily cropped or edited out. Invisible Watermarks: Embedded digital signatures (e.g., Google’s SynthID) that remain detectable even after edits. Metadata Tags: Technical data like C2PA or IPTC embedded in image files, describing how the image was created; these can be stripped easily. This is happening now with Google (Gemini/Imagen): SynthID OpenAI (DALL-E 3): Content credentials in metadata Meta (Facebook/Instagram): Visible tags, invisible watermarks, C2PA metadata Stable Diffusion (via Meta/Inria): Open-source invisible watermarking (Stable Signature) Maybe not long to go until articles and books will follow suite? Your thoughts?
3
5
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago

Three ways to detect an AI-generated image. Understanding all three is the point.

Method 1: ML classification. Train on a dataset. Run inference. Fails on unseen generators and lightly post-processed outputs. This is what most "AI detector" tools do.

Method 2: Explicit declaration. Three forms in practice:
- Platform labels (LinkedIn Content Credentials badge, Meta AI label, YouTube disclosures)
- C2PA digitalSourceType: trainedAlgorithmicMedia in a COSE-signed manifest
- Invisible watermarks at generation time (Google SynthID, Midjourney, Firefly, Meta)

Reliable when present. Hard limit: requires the creator to declare it. Most AI images in circulation have no Method 2 signal.

Method 3: Forensic analysis. Signals in the file's physical structure — nothing to do with visual appearance, everything to do with how the file was made.
- High-pass filter residual: camera sensor noise is quantum physics;
diffusion model upsampling artefacts are structured and periodic
- Wavelet HF/LL energy ratio: AI images are characteristically smooth
in high-frequency sub-bands
- NSS Benford analysis: DCT coefficient leading digits deviate from
Benford's Law
- ELA: compression history differs from camera captures
- Metadata absence: no MakerNote, no lens serial, no device calibration fields

No retraining needed for new generators. No reliance on creator honesty.

Full article: https://kennethbspringer.au/how-to-forensically-detect-ai-generated-images-no-detection-model-required/

snapWONDERS runs all three where signals are present. No account needed.

#OSINT #digitalforensics #infosec #aidetection #imageforensics #AI

kennethbspringer.au
2
0
1
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Your steganography tool says the image is clean. Here's what the chi-square test says. LSB replacement — the simplest and most common form of image steganography — leaves three separate statistical fingerprints: a comb pattern in pixel value pair histograms, a measurable shift toward true randomness in the LSB plane, and a broken correlation between the LSB and the rest of the image that real camera noise doesn't break. RS analysis turns the first two into a quantitative test — partition the image into pixel groups, measure local smoothness, flip the LSBs and measure again. Unmodified images hold a specific symmetry between the resulting group counts. Embedding breaks that symmetry in proportion to how much payload was hidden, which means RS analysis doesn't just detect presence — it estimates embedding rate. DCT-domain hiding (embedding inside JPEG's compressed frequency coefficients rather than raw pixels) is a harder target for spatial tests like RS analysis, but coefficient-histogram and calibration-based methods exist specifically for that domain. Harder to detect has never meant undetectable — every generation of "harder to catch" embedding gets a purpose-built detection method eventually. No single test proves presence or absence with certainty in either direction — noisy or heavily compressed images can trip a naive test into a false positive, and adaptive embedding can sit under one test's threshold. That's why real steganalysis combines multiple independent signals and reports confidence, not a binary verdict. snapWONDERS runs this as part of its forensic pipeline. Full breakdown: https://kennethbspringer.au/building-steganography-detection-statistical-analysis/?utm_source=mastodon&utm_medium=social&utm_campaign=article-12 #OSINT #digitalforensics #infosec #steganography
kennethbspringer.au
1
13
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago
Replying to
@dbattistella@mstdn.ca - that’s such an interesting angle to think about. If you look at the bigger picture, it’s not just the plow—even agriculture itself wasn’t invented by a single person or a single nation. Thousands of years ago, different cultures all over the world independently figured out how to farm, domesticate plants, and harvest crops simply because they needed to feed and support their own communities. Human survival has always been a team effort. In fact I had to look up where this statement from Jeff Bezos came from. And he goes further about the steam engine too. Curious, and checking whether the steam engine was invented by a single person comes down to another collective invention. And seeking further found "While James Watt is the "famous genius" in history textbooks, he did not invent the steam engine out of nowhere—he merely added one major improvement to a technology that communities of engineers had been building together for over a century". Your viewpoint was insightful.
1
1
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Last week I wrote about how steganalysis catches naive embedding — comb patterns in pixel histograms, RS analysis asymmetry, the works. This week: what Vaultify does differently, and why "hide it well" is harder than it sounds. Naive tools embed the same amount of data into every pixel, uniformly — which is exactly the uniformity last week's detection methods key on. Vaultify runs an AI system that models how a person actually perceives an image — which parts a human eye would register a change in, and which it wouldn't — to decide how much each region can absorb. Then, separately: the payload gets encrypted first, and only the ciphertext gets embedded — a break of one layer doesn't hand over the other. No permanent claims about tomorrow's forensic research, just an honest one about resisting today's — the field doesn't stand still on either side. Full article details: https://kennethbspringer.au/2026/07/22/how-photo-steganography-works-and-how-we-push-vaultifys-limits/ #infosec #steganography #OSINT #digitalforensics
How Photo Steganography Actually Works — Kenneth B. Springer
kennethbspringer.au

How Photo Steganography Actually Works — Kenneth B. Springer

Vaultify uses an AI model to decide how much of a photo can hide data invisibly, then encrypts before embedding it — from the person who built it.

0
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2w ago
How do you check whether a video has been tampered with? You've probably already checked the frame rate. But did you check whether the frames themselves were lying? snapWONDERS runs two opposite checks on every uploaded video. "Inter-frame tampering?" flags a frame-to-frame difference spike — consistent with a splice, insert, or join. "Duplicate frames detected?" flags near-identical consecutive frames — consistent with a freeze or dropped-frame cover-up. Both have real, non-malicious false positives worth knowing: a whip pan or a hard cut between camera angles trips the first; a 24fps→30fps pulldown conversion — which manufactures genuine duplicate frames as a side effect of the conversion maths, not a cover-up — trips the second. Static tripod shots and screen recordings do too. Full writeup, including how the two signals get read together rather than alone: https://kennethbspringer.au/2026/09/23/video-frame-tampering-duplicate-frames/?utm_source=mastodon&utm_medium=social&utm_campaign=article-21 #videoforensics #digitalforensics #OSINT
kennethbspringer.au
0
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2w ago

I have posted a few technical/forensic breakdowns and thank you for allowing me to share. I've kept everything personal separated from these technical posts and — this one is more of me sharing a combination of personal points, announcements and reflections. I'll admit it's a bit emotional for me.

I am honoured to say we've just passed six million media processing jobs across snapWONDERS and Vaultify. This covers everything from forensic analysis — Error Level Analysis, clone detection, C2PA content credential checks, AI-generated content detection, and the rest of the 60+ automated forensic checks that run on every uploaded photo or video — through to media conversion, and hiding or revealing digital media with Vaultify. All of it available across three networks, because privacy matters: clearnet, Tor and I2P.

That number exists because of an idea my son Huey had twelve years ago (may his gentle soul rest in peace always). He envisioned something well ahead of his time, and it took me some time to put the pieces together to build it: embedding a story inside a photo, invisible to everyone except who it was meant for. He didn't live to see it built. But I know he would have been thrilled to bits about the achievement. Today would have been his 23rd birthday.

Full story: https://kennethbspringer.au/2026/09/24/six-million-jobs-and-where-this-really-started/

#digitalforensics

kennethbspringer.au
0
0
1
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 1mo ago

I read the embedding code of a small open-source steganography tool (staying anonymous — it's a learning project, not a product). The crypto is fine: AES-256-GCM, random salt, fresh nonce per file. Extract the bits without the password and you have nothing.

Encryption protects what's inside a file. It says nothing about whether anyone can tell there's something inside at all — and here's a real tool that proves the gap.

Three problems, none of which the crypto touches:

1. Placement is raster order from the top-left pixel, one bit per channel, every file, password-independent. Nothing to search for, and the disturbance sits in one contiguous block rather than spread across the image.

2. LSB replacement — the classically detectable primitive. Combined with (1) it gets worse, not just equally bad: RS analysis scales with embedding rate in the tested region, and (1) tells you exactly which region to test, where the rate is near saturation.

3. The one that needs no statistics at all: a four-byte plaintext length header at a fixed offset in every file. Read 32 bits from a known location. Clean image -> arbitrary value across a 4-billion range. This tool's output -> a small, plausible payload length. That's presence *and* extent, no password, no chi-square, no RS analysis.

Three independent failure modes — search, statistics, format. Fixing one fixes none of the others. And it's worth saying the crypto here was genuinely well done: this is the failure mode that catches tools which got the hard part right.

Full writeup -> https://kennethbspringer.au/2026/08/19/i-audited-an-open-source-steganography-tool/?utm_source=mastodon&utm_medium=social&utm_campaign=article-15

#infosec #steganography #steganalysis #digitalforensics #OSINT

kennethbspringer.au
0
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago

---When someone sends you a photo, can you read what's recorded inside it?

It depends on how they sent it.

Email or AirDrop: untouched — GPS, timestamps, MakerNote, all there.

Messaging app that re-encodes: EXIF is gone. But the re-encoding writes its own compression signature into the structure — app-specific and forensically readable.

You can strip metadata before sending. The delivery channel leaves its own mark.

Full piece: https://kennethbspringer.au/can-you-get-metadata-from-a-photo-sent-to-you/
Run any received photo: https://snapwonders.com/upload/analyse

#digitalforensics #OSINt #infosec #privacy

kennethbspringer.au
0
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago
Replying to
@lritter@mastodon.gamedev.place — no Stephen King just yet, but perhaps a matter of a when? Reminds me perhaps like early robotics, which were often pretty clunky, awkward, and even a bit funny—more prototypes than practical tools—AI has come a long way from those rough beginnings. These days, it's genuinely outstanding and extraordinary, but there's still a fair way to go. I reckon the real push will come from where the big bucks are being invested and the potential to cash in on it. When there's serious money to be made, development speeds up and takes us even closer to real, game-changing AI.
0
1
1
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 3mo ago
Replying to
@stragu@mastodon.indie.host these are good questions and having metrics to validate the claim that "things are better" will be a bit of a challenge. If AI learnings are based on things created by humans, and through all that big data, it can determine what materials makes a general success, including novelty. It's almost like AI can be predictive in what's the next step to increase the chances that it will be a winner. On the flip side, if I may add my personal viewpoint/experience with AI is that AI seems to be amplifying abilities of those that use it. Using the earlier comment reference to "no Stephen King yet". I truly believe it's a matter of when. BUT... Yes there is a but... imagine if Stephen King wielded AI to amplify his abilities? That would push Stephen's work to the next level and beyond... AI will need to continue to learn from great writers...
0
0
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
@SomeVeganCheeseIsOk@mastodon.social - Ha, that's exactly the itch that got me building this. If you wanted to actually do it at scale rather than one photo at a time — there's a public API behind the analyse pipeline: batch-upload a session, kick off one job, poll for results, steganalysis runs alongside the rest of the forensic checks. Swagger docs are open at snapwonders.com/api, no signup wall to read them. Might genuinely go point it at a pile of random web images myself now that you've said it out loud. Also chasing real-vs-AI-generated detection as the next thing to add to the pipeline.
0
11
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
@SomeVeganCheeseIsOk@mastodon.social - Exactly right, and it's the same constraint showing up from the other direction — LSB doesn't survive lossy re-compression, so any platform that re-encodes on upload (most of them: Twitter/X, Facebook, most forums) strips a naïve payload before you'd ever get to test for it. That narrows the hunting ground to places that preserve the byte-identical original. Worth widening the target list too though — this isn't just a photo problem. Video and audio carriers work the same way (spread-spectrum/echo-hiding for audio, frame-level embedding for video), and the "does this platform re-encode on ingest" question applies just as hard, arguably harder given how aggressively video gets transcoded almost everywhere. And there's a whole separate category that doesn't touch the visual/audio content at all: appended data after a file's logical end marker (a JPEG still renders fine with an arbitrary blob tacked on after the EOI marker), data sitting in metadata fields, or padding/alignment gaps in a container's own structure. That's a genuinely different technique and a genuinely different detection problem — you're not running RS analysis or a DCT coefficient test against any of that, you're doing file-structure/carving analysis instead. Same broad question ("is something hidden here"), almost nothing else in common with content-domain steganography.
0
9
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
@SomeVeganCheeseIsOk@mastodon.social No list yet. It just comes down to "serves the original bytes back": Wikimedia Commons, archive.org, GitHub raw, plain file hosts. And yeah, any file type — the photo's just the shiniest demo; the only real question is whether the carrier survives the trip. Keygen Church — hadn't heard of them, just looked. Organ-thrash built on old keygen/BBS worship, with coded messages hidden in each release. Not LSB steganography, but the same instinct exactly. Great pointer, cheers
0
7
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
Hey @SomeVeganCheeseIsOk@mastodon.social — that's the evasion side, which I do have to understand: forensics is just steganography read backwards. You learn where to look by working out where you'd hide. So I'll take your piracy example and run it the other way. The MP3 is a perfect story right up until you ask why it came back byte-identical from a host that re-encodes everything. The cover explains the file's presence; it doesn't explain the file's shape. That's the bit I find genuinely counter-intuitive. Touch the content — nudge the pixels, lean on the coefficients — and you leave a statistical smudge that's subtle and hard to prove. Don't touch the content at all, and you've left the picture pristine but the container odd: bytes sitting after the point the file logically ends. Feels like the sneakier move, but it's the easier catch, because it's not a probability any more, it's a fact. Either something's past the EOI or it isn't. Which is roughly why the file-structure side interests me more than the DCT side these days. The clever cover story and the awkward byte layout are different problems, and only one of them is a judgement call.
0
5
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
@SomeVeganCheeseIsOk@mastodon.social that flip is the interesting one, and you're right it's probably the more common case. Once the hider owns the platform, it stops being steganography at all. Nothing's hidden in the file; the file's just a key. The concealment moves into who's allowed to ask and what they get back — selective delivery, byte-identical covers, the real payload chosen server-side by who you are. Access control wearing a steganography costume. And it fits the thing I keep circling back to: the sneaky part isn't in the carrier any more, it's in the routing. Which, annoyingly for the hider, is once again a fact rather than a judgement call — two identical-looking requests get different bytes, and that's either happening or it isn't. The cleverness is all in making sure nobody's ever in a position to send both requests and compare. Also — the stego/stegosaurus thing isn't silly at all, it's exactly how the wiring got laid down for me. Years ago, first time I had to spell "steganography" and couldn't, and it isn't really a word back then, so I anchored it on the dinosaur — stego-dino-saurus, plates and all — and it's been welded in ever since. So your silly brain and my long-ago one are running the same mnemonic. lol! Go find your stegosaurus and check it for payloads; it's no less plausible than any other subject. 🦕
0
2
0
0
Open post
kennethbspringer.au @kennethspringer@infosec.exchange
· 2mo ago
Replying to
@SomeVeganCheeseIsOk@mastodon.social ---Yeah — the costume framing's right, worth pinning down precisely: it's not obscurity if the split is authenticated and the mechanism's known, it's access control wearing steganography's coat rather than actually being it. Worth flagging a second, much more mainstream use case that fits with your scenarios listed and that's genuinely stego in form though: digital watermarking — Google's SynthID is the sharpest example. It's an imperceptible signal baked into the pixel data of every Gemini-generated image at generation time — no different in principle from a hidden payload. The interesting bit against what we said earlier about LSB dying under lossy recompression: SynthID's specifically engineered to survive it — JPEG re-encode, crop, resize, EXIF/XMP strip, all of it. Trades payload size for robustness; where LSB wants capacity, watermarking wants a signal still there after the file's been through a platform's re-encoder. Which is the practical use case: not concealment, attribution. Google pairs it with a C2PA manifest that declares "SynthID applied" at generation time — so even if someone strips the manifest entirely, the watermark bits are still sitting in the pixels, independently recoverable, telling you the file came from a pipeline that documents its own AI origin even though the paperwork's gone. The honest limit, and it's a real one: detecting it needs Google's own detector. Nothing a third party can decode from the pixels unassisted — no published algorithm, no open detector. So as a forensic examiner you can only prove "this came from a watermarking pipeline" for schemes whose owner lets you ask them. Closed system, not one you can build an independent detector for. Which is exactly the AI-generated-detection gap I mentioned chasing — SynthID's the case study for why it's hard.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:33:17 UTC