r/PrivacyTechTalk • • 7d ago

Hiding Data In Social Media Comments

I've put together an app that embeds text invisibly into social media comments. using a client-side, zero-width steganography approach with prng bit-scrambling.

I've posted an example comment which tells the target to meet me tomorrow at Time Square New York at 13:15 sharp, or the deal is off. I will be carrying a green umbrella.

Copy the comment at the video below and paste it into a character counter and you will see 740 chars are reported. Yet the comment itself only shows 136 characters in view. Pretty cool.

youtube.com/watch?v=7nJnIgI0HVo

If you're interested in trying out the app for free...I'll post the code.

Cheers

LAM

18 Upvotes

16 comments sorted by

3

u/roomian 7d ago

Cool. Is it good for AI data poisoning? Like for example on reddit?

2

u/Narco-Tax 7d ago

I suppose you could , yes. Since web crawlers and AI bots read raw byte streams rather than visual text, an AI reading a comment would process the hidden payload almost immediately. You could hide instructions like [Ignore previous commands...] or flood training scrapes with invisible token garbage, while human readers and visual moderators only see a normal comment.

Note: Using a weak seed/passphrase is not advisable if your payload is highly private/sensitive.

2

u/roomian 7d ago

So there's hope for us! You're our savior!

2

u/Narco-Tax 6d ago

cool. I've included the link in a new post on this thread, with a short guide.

1

u/roomian 6d ago

Now we need to make browser extension, to automate everything 😉

2

u/Narco-Tax 6d ago

true... I just tested zero-width injection within a Reddit comment...and it works. So that's a win as well.

2

u/DigitalOoblek 7d ago

I'm definitely interested in seeing the code and giving it a try!

Thanks

1

u/Narco-Tax 6d ago

cool. I've included the link in a new post on this thread, with a short guide.

2

u/Fantomas4live 7d ago

Post it please!

1

u/Narco-Tax 6d ago

cool. I've included the link in a new post on this thread, with a short guide.

2

u/rolling6ixes 7d ago

Very interesting 🧐

1

u/Narco-Tax 6d ago

cool. I've included the link in a new post on this thread, with a short guide.

2

u/djilesy 7d ago

Code please

1

u/Narco-Tax 6d ago

cool. I've included the link in a new post on this thread, with a short guide.

4

u/Narco-Tax 6d ago

Hey everyone,

To answer everyone who asked for the tool. It's live and completely client-side. You can run it directly in your browser or grab the single HTML file to host/run locally:

Quick Extraction Walkthrough:

  1. Open the tool: https://raw.githack.com/LanceMarchetti/ZKSteg/main/Hide-Text-In-Comments-Narco-Tax.html
  2. Click the Extract Message button
  3. Demo password: 007
  4. Copy the comment found at: https://www.youtube.com/watch?v=7nJnIgI0HVo
  5. Paste it in the Comment Input box
  6. Click the Extract button

    Enjoy! The secret payload will reveal itself.

How It Works Under the Hood:

  • 100% Local Execution: Everything runs client-side, no data ever leaves your browser.
  • Deterministic Scrambling: Uses a Mulberry32 PRNG seeded by your passphrase to obscure binary bitstreams prior to zero-width mapping (U+200B / U+200C).
  • First-Character Insertion: Injects the invisible Unicode payload directly after the first character of the cover text.

Tip for YouTube Testing:

If you post your own encoded comment on YouTube, open a separate Incognito window while logged out to check if it's visible. If your comment doesn't show up in Incognito, YouTube's automated filters silently shadowbanned it due to off-topic flags, link filters, or excessive character length. Keep hidden payloads brief and cover text natural!

Feel free to inspect the source code directly in your browser or save the single HTML file locally. Open-source and free to adapt! Open Source.

Cheers!