frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Text AI watermarks will always be trivial to remove

https://www.seangoedecke.com/text-ai-watermarks/
19•pseudolus•1h ago

Comments

ch_sm•55m ago
here‘s what i don‘t get about this whole discussion. AI companies already store all prompts and responses for future training.

just make an API that returns the string distance between a previously generated paragraph and the query?

that would sidestep this whole problem class.

regulators could even specify how that has to work.

what am i missing?

dpoloncsak•51m ago
Local models?
dTal•37m ago
Local models enable:

- watermark-free generation

- the stripping of watermarking from the output of SAAS models

Any discussion of watermarking is dead in the water in a world where we are permitted to have these things. I fear for the future.

thisoneworks•25m ago
Chill my dude. This is just a sane default which will catch normies copy pasting stuff from claude and chatgpt. It's good enough.
mirashii•7m ago
> AI companies already store all prompts and responses for future training.

They store some prompts and responses, not all, that's what you're missing.

ramesh31•45m ago
Yeah but it's like saying "Masterlocks will always be easy to pop off with a hammer". Of course, but by doing so you are actively engaging in fraud, which then puts the onus on you and whoever you are attempting to deceive.
buf•44m ago
Except this isn't like saying that at all. This isn't fraud, because it's legal in almost every circumstance.
ramesh31•41m ago
>almost every circumstance

Key phrase. And I'm not saying fraud in the legal liability sense. If you're not trying to hide the fact that something was LLM generated, then you have no reason to remove it. If you are trying to hide it, then there's probably a reason, i.e. you would face consequences for doing so, therefore it is fraud.

burnte•33m ago
Or, you simply edit the text the LLM generated ruining the hidden message. That's not even remotely fraud. There are legitimate reasons to edit text. There are fewer legit reasons to bash off someone else's lock with a hammer.
happytoexplain•38m ago
Yeah, but it's better than nothing.

People underestimate the value of rules that only take malice and a little knowledge to break.

JoshTriplett•17m ago
Exactly. If this works on pull requests, for instance, it'd be really useful for projects trying to do a first-pass filter to close slop spam.
firefoxd•36m ago
I feel like this is going to end up being like cookie laws. It sounds good, I don't know how any one benefits from it.

Currently I can recognize AI text because I read thousands of ai generated text. I know that 110% of yahoo finance news is generated. I don't want to read an AI generated personal blog, but if I do what's the problem really? Other than the companies distinguishing AI text for getting better training data, how do people benefit from watermarked text exactly?

andy_xor_andrew•32m ago
The article mentions you can always simply use a smaller, local, un-watermarked LLM to rephrase the original watermarked text. Which is true, sure.

But if we're talking about deterministically taking some watermarked LLM output and having a function removeWatermark(text), it won't necessarily be "trivial" to remove, because the watermark function itself need not be public. Only the API that tests for the watermark need be public, right?

Anthropic's magic watermark could be, like the article mentions, something like "every 7th semicolon has a N% chance to be a comma where N is the sum of the last X characters mod Y, and every character in the bit range q1...q2 has a Z% chance to..." etc etc etc. And if Anthropic controls those variables, it would be very difficult to determine the rule, even with some pretty advanced analysis (I would assume). And keep in mind, that example rule I mentioned is pretty naive, too. I expect the actual rule would be way more advanced and not so straightforward as "swap every <charX> for a <charY>"

cayleyh•29m ago
It could be, but common, we all know that Anthropic's watermark is the using "load bearing", "genuine", and "seam" 1000x more in the same paragraph than any human in history.
johnjwang•20m ago
There exist methods to detect what kind of watermarking tool that someone is using, and most of the big tools have specific signatures that you can look for.

For Anthropic, it’s highly likely that the watermark is a SynthID type mark similar to the one that Sean is talking about (I actually ran the analysis here https://johnjwang.com/post/2026/08/12/how-claude-watermarkin...). When we get confirmation of whether all models actually are watermarked, I think we’ll be even more confident.

Of course it’s always possible that Anthropic has come up with a proprietary scheme, but I think it’s definitely harder to implement.

I think the game will be a cat and mouse game similar to LinkedIn and other websites trying to block scrapers: each iteration makes it harder for someone to figure out the watermarking scheme, but likely not impossible

clemlesne•9m ago
I done a C2PA implementation for raw text, if that can ease someone’s life: https://github.com/dualeai/c2patxt

DeepSeek Harness

https://github.com/deepseek-ai/deepseek-harness
339•bjin•3h ago•154 comments

Gloomberb

https://gloom.sh/
179•rbanffy•2h ago•67 comments

Deutsche Bank becomes first foreign yuan clearing bank in Europe

https://tradersunion.com/news/central-banks/show/2973571-deutsche-bank-becomes/
276•Markoff•4h ago•298 comments

Spaghettifying DRAM

https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
169•matt_d•2h ago•45 comments

Come for ENIAC, Stay for UNIVAC and Skeduflo

https://uniqueatpenn.wordpress.com/2026/08/05/come-for-eniac-stay-for-univac-and-skeduflo/
30•cainxinth•2d ago•3 comments

Kubernetes on Oxide: How customer needs shaped our integrations

https://oxide.computer/blog/kubernetes-on-oxide
51•stevehipwell•1h ago•8 comments

I built a 500k-domain search engine for makers in a weekend for $10

https://alexmorleyfinch.github.io/marlin/history/v1/article/the_birth.html
49•dreamforever•2h ago•31 comments

We eliminated 1,400 CVEs in NanoClaw's container images

https://www.echo.ai/blog/echo-xnanoclaw-under-the-hood
26•omrimaya•2h ago•8 comments

Show HN: MCP Memory – Fast Agent Memory Using Google's OKF and SQLite FTS5

https://github.com/fellowgeek/mcp-memory
34•pcbmaker20•2h ago•16 comments

Flock updates privacy, accountability, security, and transparency safeguards

https://www.flocksafety.com/blog/flock-guardrails-address-lpr-privacy-concerns-and-police-transpa...
22•LazyMans•1h ago•32 comments

Time to Move On: Querying Without Nulls and Bags

https://arxiv.org/abs/2608.10863
32•Jimmc414•2h ago•4 comments

Graduate Student Proves a Quantum Uncertainty Principle for Fractals

https://www.quantamagazine.org/graduate-student-proves-the-fractal-uncertainty-principle-20260812/
17•bookofjoe•1h ago•1 comments

Heart aerospace completes first flight of largest electric aircraft

https://www.heartaerospace.com/newsroom/heart-aerospace-completes-first-flight-of-world-s-largest...
79•chha•2h ago•64 comments

Picking berries is my meditation

https://www.tsoon.com/posts/picking-berries-meditation/
82•mooreds•4d ago•59 comments

ATG (YC F25) Is Hiring Member of Technical Staff (Data Platform)

https://atg.science/careers
1•dkobran•4h ago

Codex in ChatGPT desktop app for Linux is now in preview

https://community.openai.com/t/codex-in-chatgpt-desktop-app-for-linux-is-now-in-preview/1390027
357•allanrbo•11h ago•249 comments

I requested a copy of my data from McDonald’s loyalty program

https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave/
60•thehoff•1h ago•56 comments

Launch HN: Bullet (YC S26) – A Faster Coding Agent

https://www.codewithbullet.com
10•adi1•8h ago•4 comments

The mathematical physics of rainbows and glories (2001) [pdf]

https://tlakoba.w3.uvm.edu/AppliedUGMath/auxpaper_rainbow_glory_review.pdf
9•num42•2d ago•0 comments

Choosing an AI model: one prompt, 11 models, different results

https://www.netlify.com/blog/one-prompt-11-models-very-different-results/
96•toddmorey•3h ago•49 comments

Better Gaussian Splatting in Julia

https://pxl-th.github.io/blog/better-gs-julia/
65•pxl-th•4d ago•6 comments

Ordinary Abundance

https://ordinaryabundance.com/
17•yen223•2h ago•1 comments

The lattice of sets of natural numbers is rich (2021)

https://jdh.hamkins.org/the-lattice-of-sets-of-natural-numbers-is-rich/
90•benmandrew•3d ago•18 comments

Nine PBS could lose 70 years of archives after cloud vendor goes defunct

https://www.tomshardware.com/software/cloud-storage/nine-pbs-loses-access-to-70-years-of-data-aft...
83•vinayakborkar•3h ago•40 comments

Delta

https://zed.dev/blog/introducing-delta
635•khy•22h ago•232 comments

What garbage collection actually costs

https://shivanshuag.com/blog/what-garbage-collection-actually-costs/
20•shivanshuag•3d ago•32 comments

Text AI watermarks will always be trivial to remove

https://www.seangoedecke.com/text-ai-watermarks/
23•pseudolus•1h ago•17 comments

Principia Mathematica is modern and insightful

https://okmij.org/ftp/Computation/Impressions/PrincipiaMathematica.html
245•matt_d•16h ago•131 comments

DeepSeek API Pricing Update

https://twitter.com/deepseek_ai/status/2087864589895798968
84•mfiguiere•3h ago•30 comments

Build a Stratum 1 PTP Grandmaster on a Budget

https://opscode.io/posts/ptp-grandmaster-cm4-sr1723u10/
7•malcolmfrazier•2h ago•1 comments