352 comments

[ 0.24 ms ] story [ 44.5 ms ] thread
AI-generated text warning (I submitted - but did not author - the piece), but it seems MS Paint and MS Photos add both a visible (can be turned off) and invisible watermarks to photos that have been AI-manipulated, even when using a local model to perform the action. It's not clear if this applies to even things like using AI-enhanced background delete/remove, but the invisible watermark is embedded in both the image pixels and the image metadata, both containing a GUID that can be linked to the exact prompt that was used and the originating device/user (on Microsoft's end).

Obvious next step is to explore if you can replace watermarker.dll with a (signed) no-op shim or MITM the API call to at least use your own (nil?) GUID that isn't linked to your device/account.

I don’t understand the warning.
They're saying that the blogpost is at least partially AI-generated.
I'd like to know more about the GUID part and how easy is it so deanonymize yeah.

But if it's only on ai generation and not on all images it seems easy enough to work around that part? Still better than printers doing it no matter what you're printing.

The article says that once converted to BMP all the metadata gets removed....so on linux:

convert file.jpg file.bmp; convert file.bmp file.jpg

It says that about the C2PA content credentials metadata, but not about the modified image pixels.
Conversion from jpg to bmp to jpg is a lossy process, so it may obscure the watermarked pixels.
Sounds better to do postprocess filtering explicitly? For example, adding random noise with amplitude 1/255 (which should be as invisible as the watermark), followed by a smart blur that blurs more in directions where the colors are more similar (making the blur less obvious to humans).

But this is all moot really, if MS Paint is watermarking shit, it’s better to just use something else. Nothing from Microsoft is trustworthy.

or maybe add 3 lsb noise, then let local diffusion model denoise the image. (is there something like convolutional diffusion denoiser?)
If it works anything like synthid, it is more resilient than that.
> AI-generated text warning

This seems incorrect to me. Are you basing that on the use of bullet points?

There are several paragraphs where output looks very AI-like (and Claude flavored one at that), e.g.

> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.

> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.

> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.

Personally it didn't bother me too much.

I have some better options. Stop using computers, or if you use a computer, use Linux.

Everything is spying on us now. Literally everything. I recently downgraded my MacBook M1 to Sonoma to avoid all this AI privacy invading BS.

Some people are suggesting systemd is spying on you because of /etc/machine-id
Don't use it then, there's at least three other init systems...
> AI-generated text warning (I submitted - but did not author - the piece)

Took me a moment to realize you're saying someone else generated it, rather than you did.

How do they add a watermark to local llm content?
Interesting. I really didn't think watermarks would end up going anywhere, but maybe with enough adoption we can have easy ai generated content flagging after all?
Not every generative AI model will watermark. Especially not adversarial and disinformation models.
It actually might make the new horrible world even worse. Imagine the populace getting used to a AI image detector flagging things as fake using this fairly easily defeated GUID marker system. Most people are just making memes or cat videos and don't even try to remove this so eventually the populace starts to believe these things actually work.

Now some one slightly more sophisticated starts creating deepfakes of a woman and uploading them or fabricating video of an political event without this marker. The subject protests it's fake and AI generated but a loud majority of ignorants feed it into Microsoft AI detector and call you a liar and say it's confirmed real. Most people don't know any better and eat it up because a computer said so.

> the populace starts to believe

US Social Security Numbers are a useful analogy: The designers knew they weren't something anyone could securely depend on, and told people not to do it... but companies did it anyway, for their own convenience and cheap security-theater. Ultimately a lot of individual victims suffered for it.

It would have almost been better if one big incident blew the "knowing an SSN means something" myth apart early on.

Or puts the marker on real footage of, say, Elon doing a Hitler salute, then starts pointing how that actually didn't happen and was AI.
I think it would be nice if all cameras digitally signed pictures. You could prove the photo was real.
The hard part is deciding how much post processing is acceptable with these images. Feels like a lot of phone cameras optimize images and curious how much of it is considered “AI”
I was thinking any photo created with a camera should be signed. Why we don't have that in 2026 is beyond me.

But what you're talking about is the generative aspect of these photos likely expanding over time. We're seeing that today with the ultra zoom features on some cameras regenerating objects (and especially text). Without the user doing anything the phone will generatively fill in detail, most worryingly text and people. Then there's the Samsung moon issue - taking a photo of a pixelated printout of the moon caused Samsung phones to generate a new image of the moon.

Signing doesn't really achieve anything when an attacker can manipulate the device into signing arbitrary pixels.

Nobody knows how to make a camera that can distinguish honest vs deceptive photons.

What would prevent someone from applying the same algorithm on a computer to sign arbitrary images?
Or, you know, using the totally-real-picture camera to take a photo of an AI-generated scene?
If C2PA and similar signature systems ever become a meaningful authenticity signal, they will create huge incentives for someone (potentially a state actor) to hack at least one camera in order to sign images of arbitrary provenance with its private keys. This will in turn inevitably lead to the same game of cat-and-mouse we have seen play out with video DRM schemes, where keys are regularly extracted from exploitable devices and used to decrypt as much content as possible before the device gets blacklisted entirely (harming all legitimate owners in the process).
I don't think that that's a good idea, because it implies trust when there actually isn't any.

Being signed with something just means that whoever has that key could've done that. That might be the owner of a specific camera, but it might also be the camera manufacturer, anyone else in the supply chain, or anyone who dumped the key.

Imagine fake evidence signed with the same key as your camera uses being used in court against you. And the court believes it because it has this signature attached and those computers are very secure and all.

Exactly that will happen. Not widespread, of course, but it will.

When I was in photography class in college, I created backplates in photoshop for still life portraits of small trinkets I was photographing. The photos were taken on black and white film and developed in the campus dark room. Led to some impressive photos. In our class's critiques, I explained how it was done. A lot of peers went from impressed to meh'd. The point: the black and white film laundered the new-age manipulation, and a digitally signed photo from a modern camera remains vulnerable to the same premise.
"I think it would be nice if all pens added a unique isotopic tracer signature to their ink. You could tell exactly who wrote everything."

"I think it would be nice if all typewriters had their unique fine-detail type artifacts registered with the government. You could tell exactly who authored a given document."

I think it would be nice if you took these ideas back to Stalinist Russia where they belong.

Stalinist Russia? Stalin would be absolutely dumbfounded by the level of tracking common in the west today.
He would love the image editing though.
> You could prove the photo was real.

No. You'd only ever be able to show that key material belonging to $specific_camera was used to sign/mark the image.

Was the camera manufacturer breached? Did somebody on the factory floor steal some keys during the provisioning step? Or did somebody build their own photo-sensor simulator and plug _that_ in to the camera's motherboard to feed it a "real" image? Before going _that_ far, just point the unmodified camera at a sufficiently high resolution display...

do you believe this should be mandated by regulation, or voluntarily offered by manufacturers as a value-add feature? ("all" implies the former.)
How exactly would this work?

People take RAW photos. Load it up in a RAW editing tool. Manipulate it. Then load it in Gimp. Manipulate some more.

Will the final result have the signature?

And if it does, what use would it be?

In the imaginary dream world that Adobe, Google et al live in, the final file does indeed have a signature.

Each piece of software in the chain must use TPM-like technologies (yes, even GIMP) to make sure it's running a "legitimate" build of the software, on "legitimate" hardware, and re-sign the file at each step along the way (using keys provisioned during some flavour of remote attestation flow, or using a RA-authenticated remote-signing oracle).

The final file embeds every preceding manifest, so you can "verify" all the way back to the original.

If this all sounds patently unworkable, that's because it is.

OK, but given that GIMP is a general purpose tool, what use is the signature if all of them verify it, when I can drastically change the image to whatever I want it to be?
I can't wait for poking memory of applications running on my computer to become a felony.
It already is.
No it isn't, cheatengine exists, Q.E.D.
If you use cheat engine to inject child porn into an image viewer is it legal?
And then some incriminating photo is made with your forged signature. "Not like that, not like that!"
(comment deleted)
I had this trigger the other day incorrectly and went and installed Paint.net. I pasted in a screenshot I took and just wanted to resize it. I got a banner saying it was made with AI and would be updated to reflect that.
I get the privacy concerns, and we are right to expect Microsoft to say that this is what their tool may be doing. However, I fear that one day we will look back and wonder why we didn't do more to sign and preserve human authenticity. Having a stamp saying "AI manipulated" should be a part of digital lineage tooling.
You can watermark AI without leaking who did it. That's just using AI to add yet another layer of user tracking.
If an adversary knows how the watermark is embedded they can replace it with noise so its not like you can rely on these watermarks anyway.
Yeah you can do that, and it's a crime
Thanks Microsoft, for adding my signature so I won't have to claim authorship when it ends up in a museum in 200 years, and the NSA archives are declassified for art historians filing a FOIA in 2226, who find out, "yep, it was from his PC."
Ms paint slop being hung in a museum? Now that's a dystopian future!
No, I wasn't suggesting that. I was saying that if there was digital art (human made) aesthetically significant that a curator would want to display it in a museum, Microsoft's GUID supplied to a data collection agency would make it possible to retrieve if ever/whenever that data were declassified (assuming it isn't purged)
According to It's FOSS,

"View company: It's FOSS It's FOSS

3h •

Microsoft quietly embeds a hidden tracking identifier in every AI-generated image you create using Paint or Photos on Windows.

A researcher discovered that these apps embed a server-issued GUID (a globally unique identifier) as an invisible watermark in locally generated AI images.

The watermark is tied to the prompts you type. And since those prompts are associated with your Microsoft account, Microsoft could "theoretically" trace any watermarked image back to the user who created it.

This is recycling an idea from the 80s. Back then, laser printer manufacturers added tiny yellow dot patterns to every printed page. With this, they could identify the printer.

Now Microsoft has brought the same idea to AI image generation, and added it to two of the most widely used default Windows apps.

Microsoft had disclosed its AI safety measures in official documentation, but the practical implication, that your output image file carries an invisible fingerprint linked to your identity, was never clearly mentioned, of course.

The researcher found this by reading Microsoft's own published documentation and analyzing the watermarking mechanics.

AI watermarking is a requirement by law in the EU. But "this image was generated by AI" is different than "this image was generated by AI by Mr. Winston Smith".

For anyone who values privacy, this is something to worry about. If you generate an image locally, on your own device, why should it carry a tag that can identify you to the company whose software you used?

But then, anyone who values their privacy won't be using Microsoft Windows anyway."

Since the cat is out of the bag, I wouldn't be surprised if Microsoft generates an invisible watermark for ALL files and not just AI generated ones. The real story is that since AI watermarks are possible, there is no technical barrier to them adding personal EXIF metadata to a file where it can't be seen, removed, or decrypted, whether it is media, a document or other file.

The AI aspect of this is a red herring. The real problem is that they're secretly adding in a unique identifier into every image you create. If somebody does not like your meme, they can just send a copyright subpoena to Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account. Just like age verification, this is another weapon in the war against internet anonymity.
This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.
> This really needs to be hit with the GDPR hammer. Microsoft have not obtained consent for this.

At best they'd just disable it for EU... assuming they didn't successfully argue "it was in the ToS ..."

But the EU mandates watermarking of AI content.
As the article explained, the EU does not mandate a prompt-specific GUID, only the ability to identify the content as AI-generated. The highly privacy-invasive level of provenance tracking which Microsoft has added goes beyond the EU’s new mandates.
Why would the EU possibly object to this? It is exactly what they want.
Ummmmmmmm. No.

Inserting a tracker that can personally identify me without my explicit opt-in consent is a GDPR breach. I'm surprised you do not not this.

So you will defeat chat control by sitting there going “but you don’t have muh gdpr consent for that!”?

The whole EU vision is they know what the little people do all the time, think all the time, and spend their money on all the time. For the children, obviously.

If you think "chat control" is going to pass, I've a bridge to sell you.

In the meantime, the GDPR is your friend. The amount of FUD spread about it on here by those working in Adtech (and whose very salaries are dependent on invading peoples privacy) is insane.

> If you think "chat control" is going to pass, I've a bridge to sell you.

I genuinely wish you were right, but you are so naive it is frightening.

> The amount of FUD spread about it on here by those working in Adtech

You are confused. You are arguing with people that want to protect privacy. The EU demonstrably is not doing that, as WhatsApp gets ever more de facto mandated by the day.

Watermarking ai generated stuff is mandated by EU
Do they require the watermark to be a unique token that can be associated with PII?
It doesn’t need to be a personally identifiable watermark.
This a variant of the provenance scheme: C2PA its implemented by all major Camera maker, and Google it seems, Apple support it with 3rd party apps on iPhone, but they have something called "Apple Reference Image" brewing.

Personally I think there is a good argument for being able to distinguish AI generated image and video...

No - there is a huge difference between "this AI created this image" and "this user did it" - the first we need more of, and the second is a big privacy concern. The article does not say anything about identifying a user.
Article literally says it adds a guid, not a binary field indicating that the image is ai generated.
a GUID isn't an indicator, it's a fingerprint.

so unless you want to draw a distinction between 'user' and 'machine' , yeah it is for identifying users.

to believe otherwise, especially with Microsoft involved, would be incredibly naive to their history.

Well yeah they know my John Doe info
add your IP, location, provider, computer specs, dimensions, screen info, nearby devices, etc etc etc

Ain't nobody anon anymore thanks to the image recording GPS radio in the pocket.

Exactly. Forget the AI aspect, this is entirely to identify users for any purposes they deem necessary. People are ignoring the surveillance state aspect of this. Reminds me of the device id debacle they have attached to their outbounds Windows network calls
> every image you create

*with the help of AI*. Does in fact make a difference.

While it does make a difference, their willingness to quietly integrate watermarking features into what people saw as simple apps for doing simple tasks is unnerving. It only takes a small change for them to start baking your identifiable information into all images they edit, or some government politely asking them to do that.

I wonder if in ten years we'll have a horrifying world where everything that leaves a machine is imprinted with its permanent identifier. Every file comes with a verifiable history of who created it, what computers it passed through, who made edits. We're closer to that world than we think.

There is a certain convergence of wills here: watermarking AI products on the one hand, and infusing AI into everything on the other hand. When you layer generative AI into Notepad, once just a raw text buffer, then you’re setting the stage for watermarking everything because AI touches everything.
AI watermarking is now the law.
[delayed]
We already live in that world, and the sky hasn't fallen so far. Even in the worst case scenario, the world isn't going to be as horrifying as the alternative, because people react to the proliferation of scams, they will not keep falling for fake impersonation for the 10000th time a row. In this scenario, we simply will stop taking factual-looking images at their word in the same way how you don't take any piece of writing on the internet as factual, verifiable truth. Journalism will rely on a person vouching for their images with their reputation, and images with unknown sources will be looked at with suspicion.

I am not willing to pay the price of sending every bit I create to some megacorporation's server or stamp it with my only identity so the computer can tell me what's AI and what isn't. Especially not while the average quality settles into an uncanny valley that's often discernible with the naked eye, both for text and images.

> Journalism will rely on a person vouching for their images with their reputation

Their images? I don't know how they'll be able to prove that.

meta comment: anyone else noticed this is a very classic text format of AI and it's the top comment as of now?? colours me impressed :)
I am a human and I upvoted the comment immediately. Do not underestimate the wide ranging hate for age verification. Even my normie friends are against it. Meta/etc have been buying those laws but at the cost of more and more people waking up to privacy activism. I predict in a couple years it'll backlash as people first fight against AV, and then fight for more broad privacy reform in the US. At least for myself, I had never been actively calling my reps until the AV laws.
[delayed]
and then in few years a new mono-mustachioed or mono-browed leader will emerge who declares memes a blasphemy punishable by death and will call up all the telemetry gathered to punish all involved.
You know a certain dictator denies access to the country they control based on whether visitors "like" them? They use a private militia, funded by stealing from taxpayers, in contravention to that country's laws, to target citizens who are not supporters of them. Some of those citizens get shipped abroad to foreign prisons by these militia. Others get shot in summary executions in the streets - the controlling regime covers it up with false media reports, and uses corrupt judges to evade scrutiny ... a certain software company support that regime, even acting against foreign scrutiny on their behalf.

Essentially all of that country's businesses that are close to the regime need to be considered hostile.

We don't need to wait a few years, the revolution already happened; the insurrectionists were freed. These companies paid their tributes, in dollars, to the regime.

Maybe next ML will be integrated into software suites to enforce that regime's lies? Most Western governments use such software, the distributers of which have already shown they'll act in the regimes interests against supposed allies...

> It's very likely your printer is secretly adding marks to the page

It's most likely how the FBI caught NSA leaker Reality Winner:

> Both journalists and security experts have suggested that The Intercept's handling of the documents, which included publishing the documents unredacted and including the printer tracking dots, was used to identify Winner as the leaker.

https://en.wikipedia.org/wiki/Reality_Winner

Yeah - these criminal agencies use this to protect their billionaire buddies on top. The Epstein network must be really huge. I always wondered how one or two person can meta-coordinate +5000 underage girl and their +10000 customers. That never made any sense to me, yet suspiciously enough only Ghislaine is in prison. That does not add up.
There isn't just one Epstein network. There are many similar networks.
This seems like something that could be confirmed by reverse engineering a printer’s firmware? Surely someone has done that?
No need to reverse engineer, printers are required to do this for decades.
You'd still need to reverse engineer it to build a better firmware without this anti-feature.
And the reason why it refuses to print this B&W document when yellow is empty.
You don't need reverse engineering if it's publicly known fact for 20+ years, telemetry just identifies you. 20 years ago, you would need to find the printer.
(comment deleted)
Pro tip: when leaking documents, use a b/w printer or remove the yellow drum unit if that's possible.
So what you're saying is we should use linux?
Until it gets outlawed for not telling websites what age you are.
[delayed]
Can this also be weaponized? Get an innocuous image from someone you don't like, grab their GUID, add it to another image, sent it to the thin skinned politician in power.
No, because the GU in GUID stands for globally unique. Adding it to a second image would cause a detectable collision.

Also, C2PA, another technology mentioned in the article, means tampering is easily detected.

Collision only detectable when you have both messages. Detecting a forgery seems more likely.
That was largely my read of the situation too - it would be a colossal GDPR breech against every EU user, surely? That's got to be a €Billion fine??

Presumably USA are complicit in this spying on allied countries - did the countries know, is it a Five Eyes thing?

Why would they need to subpoena Microsoft and why will Microsoft hand them the data if someone doesn't like my meme? I understand what you are trying to say but it does not make a whole lot of sense even from Microsoft pov. They are not bound by law to hand over personal data to anyone without a warrant issued. If a warrant is issued then it is their lawful duty to give that data, the same would be done by you if you were in their shoes or your office or your family. Law is not optional to follow. But Microsoft doesn't need to do watermarking on memes to track you or to do this as a war against "internet anonymity".
Watermarking is just one puzzle piece in the surveillance state; the legislation around it another.
I would say the watermarking is not really a puzzle piece at all when it comes to the surveillance state, which was my point. They don't need watermarking to know who you are or to get information about you. So why would they work on this really visibile method if their intention was to progress the survelliance state? Microsoft with all their resources (and assuming it is an evil corporation purely acting from the state's interest to spy on you) will use this to track you?
You can incentivize cooperation without having to compel action with a warrant. This sort of corrupt quid pro quo is quite common, in other countries at least...
It's like Snowden said (paraphrasing): "If privacy comes from policy, the policy can be changed on a whim, and in effect you have no privacy at all"
Indeed. This also means I can no longer use Microsoft apps, because they spy on me.
> Microsoft to instantly get your full name, address, email, phone number, and any other data associated with your Microsoft account.

Provided you bent the knee and created a Microsoft account.

I was forced to create multiple as part of the mojang migration - truly a nightmarish experience to use their AuthN, haven’t seen something quite as bad since
Maybe you were "tricked into", but probably not forced. We are free to refuse, at cost, but free.
The cost is that you can never play Minecraft again
It might be small cost in retrospect.
Including old pre-enshittified versions.
Never play online
They used dark patterns to trick me into signing up. I do not know how anyone can trust them, at all, ever.
Assuming you are on windows, you probably have
Not even. They log the IP and your ISP (or VPN provider!) knows the name/address of the person using that ip at that time.
How can they send a copyright subpoena for work which cannot be copyrighted? There is a contradiction here between "no it's FAIR USE" and copyright.
Keep an eye on this.

A few months back, MS incorrectly tried to stamp a Copilot "watermark" (just an auto-added note) to any and all Azure DevOps commits, regardless of whether an LLM was actually involved. They removed it after a lot of github issues were submitted to the source of the issue which was a VS Code Copilot extension.

MS has been very sloppy in their implementations. I would recommend against using Paint or any other LLM enabled app they use as a result. Things may be getting incorrectly stamped.

I would avoid junk from Microsoft entirely.
[dead]
I'm honestly surprised they don't upload the entire image to apply the watermark server-side, to the point that I'd like someone else to repeat this investigation and confirm it's not happening.

Shipping the watermark generator on user's machine would make it very easy for someone motivated to find how it works and write a "watermark remover".

It is already fairly trivial to write a universal watermark remover, an LLM can do it for you.
awesome breakdown of the process you took. reverse-engineering is crazy now with AI. IP is dead

this also reminds me of what got me hooked on CS in the first place: a simple java steganography app in cmsc150

How resistant is it to dithering? Can you just add +-1 randomly to each pixel r,g and b values and throw it off?
This reminds me that in the USSR they had typewriters that added an identifier somehow that could be traced back to that particular typewriter (and who it was sold to)
You have no idea how deep this rabbit hole goes. Search for EFF printers secret tracking.

Virtually all commercial printers embed an invisible identifier on every page printed.

Now I need to see if agentic reverse engineering of printer firmware can actually remove that "feature" for good.
Virtually all color laser printers and copiers.
This muddle of an article makes it totally unclear to me if this GUID is attached by the AI generation call or every image I edit in MS Paint. I'm going to assume the former unless they release a clarification.

Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.

> Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save.

Did it?

Assuming the watermark works like the upcoming AI watermark for text, then it uses the content's entropy to embed the information. An all-black image doesn't have much entropy, so it's unlikely you'd find anything.
the GUID is the giveaway that it's not about protecting artists, it's about being able to prove provenance later. nobody embeds a unique id in a local file for the user's benefit.
Misleading title: the watermark applies to AI generated/edited images. That includes local models.

Whether it applies to non-AI generated images is a question for the reverse engineers (or ironically, a suitable AI). My bet is on "no".

Of course, the pre-AI versions of paint and notepad can still be installed with a bit of trickery, and it's worth it just for the UX.

Don’t care.

There is no reason to assign a GGUID except to identify the person, not that the photo is generated. This is nothing more than surveillance.

These days i cant recommend Windows to anybody. Even gamers should move to linux.

Some say "i do nothing illegal" "have nothing to hide". You dont do anything illegal in your point of view. AI tracking you might think otherwise.

A sudden knock on your door might happen because of an ambigious search/propmt.

There's a huge number of gamers moving to things like CachyOS. Some are stuck because of Valorant, LoL or Battlefield DRM, but it's a big move lately.
I'd never play one of those games but the excuse for the kernel modules spying on you is usually anti-cheat not DRM as they are online games.

There are droves of people petitioning Valve to add kernel anti–cheat to CS2.

It's both and the main reason why anti-cheat is needed is the central matchmaking model, which is itself a form of DRM. If people were still hosting smaller community-moderated servers there would not be a need for invasive anti-cheat but people could also pay on cracked servers without paying.
Others say

"I need it to work on a random Thursday, not wait for fsck after ever reboot"

https://github.com/IceWhaleTech/CasaOS/issues/1104

I have the same issue on Windows 11. It's been bugging me to press a button or "check my drive" on every startup for at least half a year, no matter how often I let it run the check...
Why have you linked a bug report for a niche userland application that may be causing disk corruption as evidence against linux reliability? That seems like a pretty uninformed conclusion.
This isn't a one-off niche user. Just look for more of these. You will find them.

https://www.reddit.com/r/archlinux/comments/1cvwo93/arch_run...

This supports my initial reply. This was an f2fs bug in a bleeding edge kernel released only seven days earlier. The thread suggests perfectly reasonable mitigations, especially for an arch user: use the lts kernel or downgrade to 6.8.9.

If you're not familiar with linux and/or don't want to deal with trivial issues periodically, don't hang out at the bleeding edge. There are plenty of boring and/or beginner friendly choices out there.

I'm not saying linux is perfect, but your conclusions in this instance appear to be uninformed rather than supported by the facts.

[flagged]
>Most of these links weaken your claim rather than support it.

Yep. Good catch, I think you win the argument. These are all distros that are under development and their underlying issues should never be called-out as handing the user frustration as they willingly chose to become a victim of the kernel.

I don't know why you'd choose one of the smaller OSes, I'm required to use Ubuntu at work and it just works fine for me, every day.

It's also a bit rich especially to complain when Microsoft also suffers from forced autoupdates and the like.

Do those users use the OS that randomly takes hours to shut down because it desperately needs to install updates right now - and then it won't shut down at all and reboot instead. And even if it doesn't do that shutdown takes ages and you need to attend it and can't just walk away because the OS will drop you in a logged in desktop when some random application decides to interrupt the shutdown process.
Anyone got tips or guides to starting a linux OS that protects privacy without sacrificing utility?

Considering putting linux on a 2nd PC

omarchy.org
Essentially any Linux distro protects privacy. You'd kinda have to go out of your way to find one that doesn't, because there's no online account connected to your install for any of them.

If you're reasonably technical, you can make nearly any use-case work on nearly any distro, but if you have choice paralysis, my top recommendations would be CachyOS if you plan to play games, and Mint otherwise.

Personally I'm happy with EndeavourOS. I picked it to find a general purpose distro similar to the Steam Deck (KDE and arch based) but with a more user-friendly installer.

Pretty much all of them. None require online accounts or anything like that. Browser choice is probably more important.

For something that just works I recommend Fedora or Ubuntu. It's what I'd put on my mom or wife's PC.

Currently using Omarchy on my laptop though which is a tad more exotic, it's Arch + Hyprland and is pretty polished for that stack (at least the current version, 4.0) but still a tiny bit of jank.

Genuine question: does Linux have an AI image editor as easy to use as the win11 paint/photos?
> Some say "i do nothing illegal" "have nothing to hide".

I hate how pervasive this argument is. I'm so tired. Sometimes I wish they'd get the total panopticon they want so much. I'm sure the government will be able to find some crimes to hang them with.

many games work flawlessly on Linux now. enough to make the switch anyways. a lot more than on mac.
Solution: Don't AI generate images! I think this is a good way to discourage people from making slop.
Until proven otherwise via open-source audits and reproducible binaries, you should assume that all commercial photo editing software is embedding watermarks in any way they can get away with. This includes the professional software that you pay quite expensive licenses for. You should also assume that even if they're not today, they will eventually be coerced into doing so, in the same way that printers embed tracking dots.
You should however not accept this state of affairs even if you exclusively use open source software because the next step is that it become illegal to have photo editing software that doesn't include the tracking information needed to protect the children, fight terrorists or whatever the boogeyman of the day is.
It's already illegal to not watermark an AI image.
Oh I didn't know I was going to break the law today just using automatic1111 stable diffusion. I'll call my lawyer.
As a linux fan I just love all these changes Microsoft have been introducing
As another Linux fan, I don't. What Microsoft does to their users changes the overton window of what's acceptable in tech. Before you know it there will be a politician demanding that all software systems that don't implement such tracking will be outlawed and there will be no one left to speak up to you because they are all already used to the tracking so why should you get a pass.
Exactly. North Star linux was doing this 20yr ago. And now Microsoft thinks it's ok to do it.
With every new thing Microsoft goes trying so hard to come out as the good person, but they just cannot help themselves but to inject their evil. It had to be changed with Nadla coming, but their enshitification is just keeps getting worse and worse. What on Earth is this.