New Program Makes It Even Easier To Hide & Access Information In Flickr Photos

from the ban-flickr! dept

The practice of hiding data in images -- known as steganography -- is nothing new. People have talked about it for ages, and we've long heard reports of how nefarious organizations used it all the time. But, of course, it can also be used for perfectly good reasons as well -- and now it may have just become a lot easier to use. Glyn Moody points us to the news of a new steganography program that is designed to work easily via Flickr, with the goal of getting news reports to various countries that try to censor the internet. The program, called Collage, supposed makes it quite easy to both encrypt and decrypt information in Flickr photos, knowing that Flickr -- unlike many news sites -- isn't often blocked in countries that censor the internet.

Of course, once word of this program gets out, that could possibly change, but the programmers behind it say they can easily expand it to work with other photo sharing sites as well.

None of this is that surprising, really. In fact, my first reaction on hearing it was to think that this can't be new, as I'm pretty sure other offerings have already allowed such functionality with Flickr. However, it is a nice reminder that every time you try to censor the internet, there will be ways through, and that includes just masking the traffic you want blocked as legitimate traffic, such as Flickr photos.

Filed Under: collage, easy, flickr, steganography


Reader Comments

Subscribe: RSS

View by: Time | Thread


  1. icon
    chris (profile), 17 Aug 2010 @ 9:18am

    Re: Could still be dangerous if the steganography is detectable

    If a regime decides to continue to allow Flickr despite this, it sounds like they could use Collage themselves to detect and decode the hidden material.

    stego can be detected, all you have to do is look for extraneous data in an image file. the problem isn't that it's detectable, it's that services like flickr host billions of files that would have to be checked:

    http://www.citi.umich.edu/u/provos/stego/

    Once they know which pictures contain censored information they log any downloads of those images against the user's IP address and use that as information about who in their own population is reading it.

    the thing with steganography is that you have to know where to look and then apply a method for extraction. if you have the target and extraction method ahead of time it's just a layer of inconvenience, like crypto. if you are an outsider sweeping for steganographic data, you are looking for a needle in a haystack which is potentially sitting in a stack of haystacks.

    if you were to pair this tool with a bunch of compromised/colluding accounts, it would be very difficult to locate the party that is making these materials available. if these accounts are popular, it might also be difficult to locate the parties who are downloading these materials as well. a popular photographer may get thousands of hits per day on his/her photos, and if he/she has thousands of posted photos, it may not be apparent that a photo has been modified.

    I would want the program to need the right key to even be able to detect that there is hidden material present before I used something like this.

    stego isn't undetectable, nor is it unbreakable, but it does do a lot to obscure your activities. the point of stego is to put your payload out in the open. you are hiding your message in plain sight.

    stego also pairs up nicely with crypto: you can embed encrypted data inside an file using steganography, so even if you can find the suspicious image(s), you may not necessarily get the payload.

Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here



Subscribe to the Techdirt Daily newsletter




Comment Options:

  • Use markdown. Use plain text.
  • Remember name/email/url (set a cookie)

Follow Techdirt
Techdirt Gear
Show Now: Takedown
Advertisement
Report this ad  |  Hide Techdirt ads
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Chat
Advertisement
Report this ad  |  Hide Techdirt ads
Recent Stories
Advertisement
Report this ad  |  Hide Techdirt ads

Close

Email This

This feature is only available to registered users. Register or sign in to use it.