frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Text AI watermarks will always be trivial to remove

https://www.seangoedecke.com/text-ai-watermarks/
18•pseudolus•1h ago

Comments

ch_sm•43m ago
here‘s what i don‘t get about this whole discussion. AI companies already store all prompts and responses for future training.

just make an API that returns the string distance between a previously generated paragraph and the query?

that would sidestep this whole problem class.

regulators could even specify how that has to work.

what am i missing?

dpoloncsak•38m ago
Local models?
dTal•24m ago
Local models enable:

- watermark-free generation

- the stripping of watermarking from the output of SAAS models

Any discussion of watermarking is dead in the water in a world where we are permitted to have these things. I fear for the future.

thisoneworks•12m ago
Chill my dude. This is just a sane default which will catch normies copy pasting stuff from claude and chatgpt. It's good enough.
ramesh31•32m ago
Yeah but it's like saying "Masterlocks will always be easy to pop off with a hammer". Of course, but by doing so you are actively engaging in fraud, which then puts the onus on you and whoever you are attempting to deceive.
buf•31m ago
Except this isn't like saying that at all. This isn't fraud, because it's legal in almost every circumstance.
ramesh31•28m ago
>almost every circumstance

Key phrase. And I'm not saying fraud in the legal liability sense. If you're not trying to hide the fact that something was LLM generated, then you have no reason to remove it. If you are trying to hide it, then there's probably a reason, i.e. you would face consequences for doing so, therefore it is fraud.

burnte•20m ago
Or, you simply edit the text the LLM generated ruining the hidden message. That's not even remotely fraud. There are legitimate reasons to edit text. There are fewer legit reasons to bash off someone else's lock with a hammer.
happytoexplain•25m ago
Yeah, but it's better than nothing.

People underestimate the value of rules that only take malice and a little knowledge to break.

JoshTriplett•4m ago
Exactly. If this works on pull requests, for instance, it'd be really useful for projects trying to do a first-pass filter to close slop spam.
firefoxd•23m ago
I feel like this is going to end up being like cookie laws. It sounds good, I don't know how any one benefits from it.

Currently I can recognize AI text because I read thousands of ai generated text. I know that 110% of yahoo finance news is generated. I don't want to read an AI generated personal blog, but if I do what's the problem really? Other than the companies distinguishing AI text for getting better training data, how do people benefit from watermarked text exactly?

andy_xor_andrew•19m ago
The article mentions you can always simply use a smaller, local, un-watermarked LLM to rephrase the original watermarked text. Which is true, sure.

But if we're talking about deterministically taking some watermarked LLM output and having a function removeWatermark(text), it won't necessarily be "trivial" to remove, because the watermark function itself need not be public. Only the API that tests for the watermark need be public, right?

Anthropic's magic watermark could be, like the article mentions, something like "every 7th semicolon has a N% chance to be a comma where N is the sum of the last X characters mod Y, and every character in the bit range q1...q2 has a Z% chance to..." etc etc etc. And if Anthropic controls those variables, it would be very difficult to determine the rule, even with some pretty advanced analysis (I would assume). And keep in mind, that example rule I mentioned is pretty naive, too. I expect the actual rule would be way more advanced and not so straightforward as "swap every <charX> for a <charY>"

cayleyh•16m ago
It could be, but common, we all know that Anthropic's watermark is the using "load bearing", "genuine", and "seam" 1000x more in the same paragraph than any human in history.
johnjwang•7m ago
There exist methods to detect what kind of watermarking tool that someone is using, and most of the big tools have specific signatures that you can look for.

For Anthropic, it’s highly likely that the watermark is a SynthID type mark similar to the one that Sean is talking about (I actually ran the analysis here https://johnjwang.com/post/2026/08/12/how-claude-watermarkin...). When we get confirmation of whether all models actually are watermarked, I think we’ll be even more confident.

Of course it’s always possible that Anthropic has come up with a proprietary scheme, but I think it’s definitely harder to implement.

I think the game will be a cat and mouse game similar to LinkedIn and other websites trying to block scrapers: each iteration makes it harder for someone to figure out the watermarking scheme, but likely not impossible

That's not SOC 2 compliant

https://ampcode.com/notes/thats-not-soc-2-compliant
2•tosh•2m ago•0 comments

Samsung is using Claude to verify chip designs. It's not going smoothly

https://www.neowin.net/news/samsung-is-using-claude-to-verify-chip-designs-and-its-not-going-smoo...
2•bundie•3m ago•0 comments

Codex Blocks Fast Mode with an API Key on Desktop

https://denta.co/p/codex-blocks-fast-mode-with-an-api-key
1•adenta•4m ago•1 comments

What happens when a GPU reads memory?

https://blog.doubleword.ai/what-happens-when-a-gpu-reads-memory
3•somnial•4m ago•0 comments

Show HN: Virtual Private LLM, fixed fee with no usage or token limits

https://solheim.ai
1•CodingPanda42•4m ago•0 comments

Employees are replacing themselves with AI faster than management does it

https://www.geekbeard.dev/p/nobody-pays-100k-for-curation
1•drunx•4m ago•0 comments

Brave improves protections against GPU fingerprinting

https://brave.com/privacy-updates/38-webgl-webgpu-fingerprinting-protections/
2•w0ts0n•4m ago•0 comments

Aarhus Denmark eliminating single use coffee cup with "reverse vending machines"

https://reasonstobecheerful.world/can-this-city-banish-single-use-coffee-cups/
1•Geekette•5m ago•0 comments

Frontier LLMs know more facts than they can recall

https://research.google/blog/empty-shelves-or-lost-keys-recall-is-the-bottleneck-for-parametric-f...
3•MarcoDewey•5m ago•0 comments

ApplyWise – AI tools for tailoring your CV to a specific job

https://applywise.eu/
1•peter_nemec•8m ago•0 comments

GNU Parallel

https://www.gnu.org/software/parallel/
1•thunderbong•8m ago•0 comments

Show HN: My Grok Voice Mode System Prompt

1•nomilk•9m ago•0 comments

I found moderation endpoint in JavaScript

https://nadleer.github.io/posts/flagging_post_bug/
1•adminez•9m ago•0 comments

MiniMax-Music3

https://huggingface.co/MiniMaxAI/MiniMax-Music3
2•Philpax•9m ago•0 comments

Ordinary Abundance

1•jxmorris12•9m ago•0 comments

You're Not Ready to Compete with Self Disruptive Companies

https://julienreszka.com/blog/you-re-not-ready-to-compete-with-self-disruptive-companies/
1•julienreszka•10m ago•0 comments

Decision Records

https://github.com/DecisionRecordsORG/DecisionRecords
1•ntatenyakiso•11m ago•0 comments

Getting Real

https://elijahpotter.dev/articles/getting-real
1•chilipepperhott•11m ago•0 comments

Show HN: A open-source AI-native coding agent

https://github.com/missingstudio/eva
1•missingstack•13m ago•0 comments

DeepSeek up to 1000% price hike is live

https://xcancel.com/deepseek_ai/status/2087864589895798968
5•krlx•14m ago•1 comments

Who Cares about the Shrimp?

https://joinreboot.org/p/who-cares-about-the-shrimp
1•alexwennerberg•15m ago•0 comments

An Ice Island as Big as Manhattan Just Broke Off Greenland

https://nautil.us/an-ice-island-as-big-as-manhattan-just-broke-off-greenland-1283725
1•Brajeshwar•16m ago•0 comments

Pediatricians document e-scooter injuries, deaths in children, teens

https://www.cbc.ca/news/health/e-scooters-pediatrician-survey-9.7305210
1•Teever•16m ago•0 comments

Toasted Pitta Thermodynamics

https://chatgpt.com/share/6a7de7a3-f60c-83ed-9b5b-2be08758a56c
1•quasiuna•16m ago•1 comments

How Localhost Sharing Works: Nat, Tunnels, P2P, and Relays

https://medium.com/@Koukyosyumei/how-localhost-sharing-actually-works-nat-tunnels-p2p-and-relays-...
2•syumei•17m ago•0 comments

DeepSeek Harness: Everything Is a Plugin

https://www.x-cmd.com/install/deepseek-harness/
1•Zhengqbbb•18m ago•0 comments

Announcing JCT-1

https://chatjct.com/announcing-jct-1/
4•iamacyborg•19m ago•1 comments

Turning static interfaces into interactive AI experiences

https://wzrd.to
1•maryamwnna•20m ago•0 comments

Norway in a Nutshell

https://donmoynihan.substack.com/p/norway-in-a-nutshell
1•toomuchtodo•21m ago•0 comments

AROS for Raspberry Pi 3

https://amiga-news.de/en/news/AN-2026-08-00076-EN.html
4•doener•22m ago•1 comments