Researcher Wants To Protect Whistleblowers Against Hidden Printer Dots (bleepingcomputer.com)
An anonymous reader writes: "Gabor Szathmari, a security researcher for CryptoAUSTRALIA, is working on a method of improving the security of leaked documents by removing hidden dots left behind by laser printers, which are usually used to watermark documents and track down leakers," reports Bleeping Computer. "Szathmari's work was inspired by the case of a 25-year-old woman, Reality Leigh Winner, who was recently charged with leaking top-secret NSA documents to a news outlet." According to several researchers, Winner might have been caught after The Intercept had shared some of the leaked documents with the NSA. These documents had the invisible markings left behind by laser printers, which included the printer's serial number and the date and time when the document was printed. This allowed the NSA to track down Winner and arrest her even before she was able to publish the leaked documents. Now, Szatmari has submitted a pull request to the PDF Redact Tools, a project for securely redacting and stripping metadata from documents before publishing. Szathmari's pull request adds a code routine to the PDF Redact Tools project that would allow app operators to convert documents to black and white before publishing. "The black and white conversion will convert colors like the faded yellow dots to white," Szathmari said in an interview. Ironically, the project is managed by First Look Media, the parent company behind The Intercept news outlet.
So no one wonders how a person named "Reality Winner" was able to get TS clearance?
even black and white laser printers can watermark the document. The pixels are small enough that you won't notice them and at normal 300dpi scanning they won't transfer, just like the yellow dots, but if you get hold of the originals, there's data on there that can be used to track back to the printer in question. Inkjets do it too, both black and color models.
Turns colored dots into black ones. Problem solved.
excitingthingstodo.blogspot.com
I'd operate under the assumption that the NSA has hacked their hardware and software to put document tracking information into things like font rendering and image dithering artifacts.
OCR into a plain text file and strip out any formatting. It's the only way to be even remotely sure.
Log in or piss off.
I suspect you wont have this problem with a 1986 dot-matrix epson.
"This is useful to detect whistle blowers in the US."
Again, we are sacrificing billions around the world to dictatorships who will just use the exact same products to clamp down on their own people.
If 1984 were to be rewritten, it should have been from the point of view of many billions living in grinding dictatorship, being spied on by their governments simply using commercial products sold to them by some hundreds of millions living in relative freedom, embedding spying tech in those products to catch mundane crooks in their own society.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
scan to grayscale
filter to remove fine dots
mild blur fliter
reduce unnecessary resolution
threshold to B&W
the dots are created by the printer itself, not in the file.
by removing hidden dots left behind by laser printers, which are usually used to watermark documents and track down leakers,
This is incorrect. The purpose of the dots and why they are limited to color printouts is because they are intended to be used to identify currency counterfeiters.
wiki
During the 1990s Xerox and other companies sought to reassure governments that their printers would not be used for forgery.
Anons need not reply. Questions end with a question mark.
Is it just me, or does the part about "...working on a method of improving the security of leaked documents..." sound rather ironic considering that the ones in question were secure documents that shouldn't be released in the first place?
Beware of Sales Reps bearing gifts.
A color printer will print faint yellow dots for a water mark. Simply print the documents on yellow paper, then photocopy them on to white paper (and a low quality scan setting to be safe).
+jpg compression + OCR.
Most of the time you just want the text not images so scan it as text (if your scanner has that option), lower the contrast so only black text is picked up, scan at a lower dpi so any small dots won't even get picked up or will just result in a giant blur, compress the image even further to blur out any possible remaining dots and if possible just OCR it.
Then do a quick invert colors to see if there are anything left because your eyes will pick up lighter areas in pure black far easier than slightly darker areas of pure white.
And if all that is too much effort then you don't deserve the privileged of releasing such documents. You are responsible for protecting your source from having their life ruined by trying to do what is right for the people the government is supposed to serve.
Buy 5 printers. Printbthe doc then run it thru the other printers running a print job for a text file with the only content being a space. Dots will overlay and throw off the system.
I want my leakers to pass an idiot test first.
... use yellow paper?
There is no XUL, only WebExtensions...
It is much harder to prove authenticity in this case. Like rewriting the text by hand — it just is not as convincing.
That said, when it comes to accusing Trump, authenticity obviously yields to outrageousness in importance...
In Soviet Washington the swamp drains you.
Ironically, the author of this story has misused "ironically".
There's nothing ironic about THE INTERCEPT trying to protect sources by providing a means for them to pass important documents to them in the public interest without ending up in jail. Perhaps the word "appropriately" would have been more... appropriate.
Anyway, she could have simply RETYPED them, and e-mailed them, avoiding the whole printer dot problem in the first place. If you want to see whether or not your printer is doing this, refill your yellow (and red and blue just to be sure,) toner cartridges with BLACK toner, and print a mostly blank page, with maybe a letter or two, (not sure if it'll print the dots on a blank page) or perhaps a fun message like "FUCK THE SURVEILLANCE STATE!" or "QUIT FUCKING SPYING ON ME!"
If the dots are small, print several a day or two apart with the same message, then compare the sheets. Some of the dots will have moved, and these are the ones that betray you.
Perhaps it's a matter of making sure everyone knows this, and pressure manufacturers into NOT having these dots by NOT buying printers that have them, and not buying their overpriced goddamned toner cartridges.
Here's an almost certainly non-exhaustive list of printers KNOWN to help the government spy on you:
EFF List of printers you shouldn't buy.
I can certainly see, how the methods being researched could help the good guys. But to better publicize the project, a much more compelling poster-boy or girl is needed than Ms. Winner — a supporter of Iran, who sincerely believes, American President is the vilest person in the US (if not the world)...
In Soviet Washington the swamp drains you.
Build your own black and white printer/copier. Unless you put the watermarking in it'll never have it when used properly.
Every agency office should install a special "whistleblowers only" printer in a prominent location near the office entrance.
Don't use a color printer to leak shit.
#naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
Who besides old geezers use printers anymore?
Convert the data to a textfile.
Use TOR at a Starbucks coffeeshop with a beard, sunglasses and a Trump hat and send the fucker to the New York Times Leaker page.
Interesting work - too bad the government wouldn't ever allow software that does this to be installed on the computer. IDS SDS would detect if someone tried to install it.
Same with modifying the print drivers.
What you said hints at the big picture. Removing the means of identification would protect criminals, who are far more common than actual whistle blowers (of which Reality Winner is not). Forgery is just one crime, but there are a whole lot of other crimes where printer signature is significant. I'd argue that the majority of those happen to be white collar crimes.
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
Look, just throw the stupid document on a copier and they're gone.
This isn't rocket science. What sort of a moron would print a document IN THE NSA and then hand that original to a reporter?
She needs to go to prison for the maximum span.
I personally believe Snowden should be pardoned, and they should stop pursuing Assange, but not every leak is sacrosanct, nor is every leaker a saint.
She clearly did this as a political act, despite signing documents affirming she would keep information confidential.
Basically, leaking info is like using a legally-carried handgun: you should do it only if you accept that the consequences of not using it are worse than the punishment you'll receive, and be perfectly ok with that result.
-Styopa
Do B&W printers have another trick?
Contractors will always have a lot staff ready for any level of US security.
Look into the past of every staff member. Education, politics, languages, university, mil, gov, internet, protests, work, hobbies, interests.. walk the resume and interview everyone in person. Educators, friends. See what a person was like.
Learn from the issues the UK had from 1930-70's. Learn how the UK solved its internal security issues.
Learn why the USA was so good at security from the 1950's-80's.
Once a person has a job with security considerations keep on looking at their work and how they use the "internet", their politics, education, interests, hobbies, friends..
Keep looking, all year, every year.
Two contractors now working together is not a new security policy.
Create perfect bait projects and files just for staff given their politics, see if they respond.
Domestic spying is now "Benign Information Gathering"
The Ice Station Zebra option should add cartoons of Disney characters as faint yellow dots after stripping the original finger printing.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Some criminal wants to counterfeit money and they are using the naivety of geeks to do so.
It's clear that the staff at The Intercept are complete and utter imbeciles. It really seems that they didn't even know about the hidden printer dots which everyone (and I mean everyone) has known about for the last decades. Everyone at the Intercept should be fired and not ever work as a journalist again. This is just really really stupid. Even if you didn't know about the printer dots, sharing the documents with NSA is just mindboggling. Everyone should be fired.
*cough* *cough* Wite-Out® *cough*
by removing hidden dots left behind by laser printers, which are usually used to watermark documents and track down leakers,
This is incorrect. The purpose of the dots and why they are limited to color printouts is because they are intended to be used to identify currency counterfeiters.
1) They where originally designed to identify currency counterfeiters.
2) They are as well quite often used to track down leakers (both government and business).
If you want news from today, you have to come back tomorrow.
More liberals making a mockery of themselves. Today's example: Publicly white-knighting for a treasonous cunt and advocating for better privacy protection for secure documents by making it easier to leak them to the press. And he STILL won't get any fucking pussy!
Film at 11, jerking off in their parents basement after coming home from the "security researcher" job at the uni. (Emptying bins in the security research lab I guess counts these days!)
Well...
Being an "Intel Specialist", if she was worth her salt, she could have simply memorized bits of the content over a few days and recreated it at the library in a text document.
Or, if she was inventive, she could simply have made it all up and created a realistic document. I'm surprised this doesn't happen more often, if you know the format it's very easy to create believable stuff, and the formats and classification markings are documented in publicly available government regulations / instructions as a matter of public record.
If you want news from today, you have to come back tomorrow.
There is also the problem of secrets, i can imagine a newsoutlet to support this as it will increase their profots if something interesting is published. But these people sign a NDA, so they should not publish this information, it's more about sensationalism then anything else for the readers.. if someone really leaks something important which is in the interest of general public because it is malicious behaviour then they are protected by law, but all i've seen so far on wikileaks or these newsoutlets it's all about sensationalism..
My HP printers would complain if the color cartridges were low, even when I was printing black-on-white text.
Was this done to ensure NSA can trace printouts?
If instead of yellow dots, individual black and white pixels were psudorandomly embedded in the document. Knowing the "key", and using sparse matrices and signal processing techniques, this pattern could be extracted to reveal a document's origin. If we can extract a radio signal at picowatt power levels from 8 billion kilometers away, we can extract a clever "hidden" invisible pixel pattern from a printed document.
These watermarks were added was to aid in catching counterfeiter when color laser printers became available. Their use in tracking confidential documents not withstanding, of f course.
The dots demonstrate authenticity as in she didn't just make this shit up. Had this been known at the time, The Intercept probably wouldn't have contacted the NSA. Everybody knows about them dots now.
Couldn't this whole problem be solved by converting images to black and white TIFF format and then inverting the colors to check for dot patterns? Going white to black and black to white should force any stray white pixels to show up like stars against the black background. It would then be easy to black those out before reversing back to the original document.
Don't leak raw documents - digitize and run them though any OCR.
Don't trust The Intercept with your leaked documents--those fuckers will rat you out to the NSA.
Journalists have a moral responsibility to protect their sources when necessary, and The Intercept fails.
The Intercept wants everyone to know: "We won't break your story. We'll turn you in."
When I was in high-school in the early 1980s, I had a few teachers who refused to accept term papers that came off a dot-matrix printer because as everyone should know, the quality of the content is far less important than the appearance. So, a couple of us nerds bought a nifty little gadget called a Dynatyper. http://www.computerhistory.org...
Problem solved.
But seriously, any parent that would name their kid "reality" a) has a screw loose and b) is setting the kid up to have a vastly over-inflated ego.
According to the Daily Mail, the leaker that this posting is motivated by was fascinated with Islamic jihad and wanted to live in Afghanistan or Pakistan.
http://www.dailymail.co.uk/new...
Leaking to expose corruption is great. Leaking that gets Westerners killed and attempts to take subvert the democratic system is still treason.
"An F.B.I. affidavit said a visible crease mark on the file, a scan of which The Intercept provided to the government while trying to authenticate it, prompted investigators to surmise it was a printout. Audit trails showed six people had printed copies, but only one — Ms. Winner — had also used a work computer to exchange emails with The Intercept. A search warrant application said she had found the report by plugging keywords into the N.S.A.’s system that fell outside her normal work duties — and had printed no other files."
Source: https://www.nytimes.com/2017/06/06/us/politics/reality-leigh-winner-leak-nsa.html
How can I read the information stored in the yellow dot? It would be very neat if you could access this information.
Leaking 101. Never send originals. Always use a public copier, not near home, and copy to black and white. Then recopy copy to same. Put in new brown envelope with minimal hand contact. Never lick or use tape. A DNA and hair|finger print thing.
In case not evident - turn all recording device off: phone, car GPS system.
Print on carbon paper, then run it through a mimeograph.
Track that leak bitches!!
If you work for a government agency they should be able to detect installations. Which should result in an instant termination and a thorough investigation.
The flat out denial of facts makes it pretty easy to spot the progressive/SJW/leftard/commie (all pretty interchangeable in the US at this point). Winner didn't try to use the chain of command to no avail, and leaked inconsequential information which at best could be used as "politically embarrassing" (according to even the far left media).
The only people applauding her are the same ones applauding all of the Stalinist tactics being used to smear the current President and his administration. More and more people are seeing those tactics for what they are, and see the useful idiots for who they are.
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.