How Claude’s text watermark works 
anthropic.com

All major LLM providers will be required, by the AI Act of the European Union, to add watermarks to the generated content, including text. Anthropic, owner of Claude, explained its method:

Large language models like Claude work by generating one word at a time. Each time the model decides on the next word, it chooses among a list of potential candidates, ultimately selecting the most sensible or likely based on the preceding text. Take the sentence “The weather today was cold and…”. The next word is very unlikely to be “sugary.” But it is quite likely to be “overcast” or “grey.” Under most circumstances, it doesn’t matter much to the reader which of these latter two words the model ultimately chooses—the meaning of the sentence is largely the same either way. In cases like this, the choice is settled by a random number.

Watermarking uses low-stakes choices like these—which occur many times over a piece of generated text—to leave a pattern in Claude’s responses. That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different. Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick. That is, the words that Claude picks are still random, but now, one can check the sequence of words and see if it’s consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude.

The solution is the same one Google created and has used since 2024 in Gemini, called SynthID-Text.

Some people are freaking out over this change. As I’ve been saying for a while now, it doesn’t matter.

Besides, simple systems that swap out some words for synonyms are likely to show up (if they don’t exist already), which (in theory? someone correct me if that’s the case) would break SynthID-Text’s digital signature. Still in the realm of guesswork, I’d imagine that feeding the text into another LLM and asking it to swap out some words and structures would already do the trick.

Regardless of all that, isn’t it about time people who use generative AI to write text started owning up to their choices?

I think the first thing that comes to mind when this topic comes up is using the watermark to point fingers and shame whoever uses it. It’s possible to imagine other uses, though, such as helping triage requests sent to public agencies, which, as Ronaldo Lemos pointed out [pt_BR] in his column in Folha de S.Paulo this past Sunday (the 16th), are already swamping governments and courts in several countries.

These tacky men with ridiculous glasses want you to wear them too

Meta — the same company that declared in 2021 that by now you’d be living in the “metaverse” — sold a few million camera glasses for pervs and, all of a sudden, the next future envisioned by Mark Zuckerberg’s unhinged mind is one where we all walk around wearing camera glasses powered by “artificial intelligence.”

Yes, Silicon Valley CEOs believe the best way to curb screen addiction at 20 cm from your face is to strap screens 20 mm from your eyes.

(more…)

Google will remove the last traces of Manifest v2, the feature that enabled robust ad-blocking extensions like uBlock Origin, in Chrome versions 150 and 151. Chromium forks — Edge and Opera — have signaled they will follow Google’s lead, though no firm deadlines have been set. Manifest v3-compliant ad blockers work, albeit with limitations.

Firefox (and its derivatives) and Safari will continue to support Manifest v2.

How AI chatbots manipulate you and undermine your privacy

At the risk of being among the first victims of artificial intelligence in a potential machine uprising, I keep my interactions with today’s generative AIs (or AI chatbots) strictly transactional.

I open the site, ask or request what I need, get the answer, close the site. No names, no pleases, no thank-yous, no small talk. I avoid anthropomorphizing them as much as possible. I treat them for what they are: statistical machines churning out words that make sense, not a new form of sentient life — at least, not yet.

Keeping a transactional relationship with AI chatbots is, for me, a way of keeping the line between us clearly drawn, to ward off an unlikely — but not impossible — “AI psychosis,” the kind of spiral where someone genuinely believes the AI is alive.

A newly published report by the Center for Democracy and Technology (CDT), authored by researchers Ruchika Joshi, Adinawa Adjagbodjou and Michal Luria, gave me further reasons to stand by that approach.

(more…)

Still thinking about Google I/O

Google presented “AI agents” capable of doing people’s work in countless scenarios, none of them very believable for real people. (Who needs AI to organize a neighborhood block party?) At TechCrunch, Sarah Perez writes a solid critique of this questionable utopia that Google is trying to sell us.

On my end, I think we’re living a “Groundhog Day” moment of that Google Now feature from ~2012, which would notify you via push notification that your flight’s gate had changed. As if that information wasn’t already on your face the whole time at the airport. For 15 years Google has been using different technologies, each increasingly complex and expensive, to try to solve problems that no human being has ever actually had.

Google wants to be the interface for the web

The opening of Google I/O this year (35-minute video recap) showed a Google less shy about transforming the web into raw material for its AIs.

Search will become (even more) a souped-up ChatGPT, and also the checkout counter for every online store, and YouTube will use video clips to create answer pages.

Notice that in all these announcements, Google/YouTube transforms itself into a curator and interface for web content, without attribution or with minimal credit given. You won’t visit websites anymore; you’ll visit Google — and you’ll stay there. On the flip side, whoever calls themselves a “content creator” is actually a content supplier for platforms. It’s always been that way for Meta (Instagram), TikTok, and YouTube; now it’s also the case for Google, even if unintentionally (myself included!).

All of this amounts to a complete betrayal of everything Google once stood for (and was) back then. Maybe people like this new incarnation because the web, poor thing, has long suffered from the pernicious incentives and destructive influence of Google itself, but nothing is so bad that it can’t get worse.

By the way: Manual do Usuário project offers an instance of SearxNG, a metasearch engine that displays ten (or more) blue links to actual websites. It’s free. Use it and spread the word.

RCS, SMS via the internet, is good, but that doesn’t matter

In 2024, Apple made a gesture of goodwill to European regulators and opened iOS 18 to RCS, the evolution of the old SMS. Great, but too late.

RCS, which stands for Rich Communication Services, is SMS via the internet with all the benefits that come with this improvement, such as support for high-quality images, read receipts, typing indicators, and audio messages.

In other words, it is the “WhatsApp version” of SMS.

(more…)

The new version of Nova Launcher, a popular launcher for Android, brought an unwanted new feature: advertising trackers from Meta and Google. On Exodus, a non-profit app auditing platform, you can see the changes from the previous version (8.1.6) to the new one (8.2.4).

Nova Launcher was purchased by Sweden's Instabridge a few months after the launcher's creator left Branch, the company that bought the app in 2022 and promised to open its code — which never happened. Instabridge has confirmed that it is testing ads in Nova Launcher and that it will not display ads to those who have Nova Prime (paid version).

Once again, Google threatens the 3 billion (!) Gmail users with Gemini (AI) features. This time, the change is dramatic: the inbox will be “smart”, which would be tempting if AI models were capable of summarizing correctly (they are not) and were not prone to mistakes (“hallucination” is an euphemism for mistakes). For now, the new Gmail is being released to Americans who pay for Google's expensive AI plans. The prophylactic measure is to disable all AI features in Gmail: in the settings, General tab, uncheck the option Enable smart features in Gmail, Chat, and Meet. You're welcome!

A few months ago, youtubers reported unsolicited interventions by Google to “improve” their videos with generative AI. It appeared to be a test; now it’s official.

Channel owners can disable this feature in Studio: go to Settings, Channel, Advanced settings and uncheck the two options under Video quality enhancements. For viewers, Google’s suggested workaround is to change the resolution in the player’s settings.

About the password leak of 183 million Gmail accounts

In the same vein as the “phones that will stop running WhatsApp” beat, Brazilian news sites seem to have found a new evergreen click source for tech desks imported from Forbes’: millions of leaked Gmail passwords.

There is, in fact, a database of that type circulating online, created by an undergraduate student in the United States. Troy Hunt, who runs Have I Been Pwned, a breach repository, analyzed the data and found that “only” 8% of the passwords — about 14 million — are new. That makes sense, given the database was glued together by aggregating entries from multiple sources and prior breaches.

The main takeaway from a story like this isn’t “your Gmail password may have leaked,” but rather that “any of your passwords could leak at any time.” Not to spread alarm, but to encourage awareness of good digital security practices.

Which ones? For this situation, mostly these two:

  1. Use a password manager. It makes easy creating and retrieving strong, unique passwords for each service.
  2. Enable two‑factor authentication (or two‑step verification). It can be integrated with the very same password manager for easier adoption. In a breach, the second factor blocks unauthorized access even if someone has your password.

You can check whether your passwords have leaked by entering your email at Have I Been Pwned. If it shows up, there’s no need to panic: change the password and enable a second authentication factor. Google explains how to do this for Gmail.

Sideloading is fundamental to Android and it is not going away. Our new developer identity requirements are designed to protect users and developers from bad actors, not to limit choice. We want to make sure that if you download an app, it’s truly from the developer it claims to be published from, regardless of where you get the app. Verified developers will have the same freedom to distribute their apps directly to users through sideloading or through any app store they prefer.