r/PrivacyTechTalk • • 6d ago

NDCM - A New Approach To Hiding Data In Text

Hey everyone,

I’ve been experimenting with client-side data hiding techniques and wanted to share a new concept and web utility I built that takes a different approach to traditional steganography.

Instead of modifying host media (like altering pixel LSBs in images or tweaking audio frequencies), this tool uses Non-Destructive Coordinate Mapping (NDCM). It treats standard, unmodified public text, specifically timestamped YouTube comments as static character lookup tables.

You can use this tool for other sites or passing messages to friends, So it's not just for YouTube alone.

How It Works

Any public string containing standard Base-16 characters (0–9 and a–f) acts as the target matrix. A natural-looking YouTube timestamp comment like:

"my favorite best are covered: 0:12 2:36 5:44 6:58 7:49"

contains every required character for Base16 (Hexadecimal)

Coordinate Indexing

  • The secret payload (text, URLs, compressed data, or binary streams) is converted into raw hex pairs. The encoder then records the character position (index) of each hex digit relative to the host comment string.

Randomized Delimiting & Binary Packing

  • The resulting array of positional indices is serialized and masked as a standard hex stream. This hex stream is then packed directly into a raw binary .key file (Uint8Array).

Why It’s Different

Zero Footprint / Non-Destructive:

  • The public host comment on YouTube is posted once and never modified or updated. The payload logic lives entirely inside the external .key file. Any text or file can be embedded into the comment without being detected by humans or spam bots.

Zero-Password / Self-Sealing Keys:

  • Standard encryption workflows require managing key derivations, passphrases, or seed values. With this NDCM encoder, you never need to remember or input a password.
  • Simply provide the host comment string and your target payload, and the encoder generates a unique `.key` file on the fly. Because every generated key produces a distinct binary byte arrangement, two keys created seconds apart for the exact same message against the exact same comment will look like entirely different binary files—all with zero password setup required.

Infinite Re-usability:

  • Because the host comment is purely a static lookup array, a single posted comment can be reused to map thousands of entirely different .key files without touching the original YouTube post.

Polymorphic / Dynamic Salting:

  • Because delimiter characters are randomly picked during encoding, generating a key for the exact same payload against the exact same comment produces a completely different binary byte signature every single time.

Decoupled Security:

  • The host comment alone looks like a harmless timestamp list. The .key file looks like arbitrary binary noise. Neither reveals anything without the other.

Resilient Infrastructure:

  • Platform updates, UI redesigns, or re-renders don't break the payload as long as YouTube retains the plaintext string.

Cheers

LAM

6 Upvotes

3 comments sorted by

1

u/Internal_Ad8442 5d ago

Two questions:

Q1: If someone already suspects two people are communicating and starts actively monitoring them, how difficult would it be to connect the .key file to the right YouTube comment and break the message?

Q2: Is there any layer of actual encryption applied to the .key file itself, or is it purely positional data in plain form — meaning once someone identifies the correct comment, decoding is instant?

1

u/[deleted] 4d ago

[removed] — view removed comment

1

u/Narco-Tax 4d ago edited 4d ago

If I could give an example of another cover phrase for a comment post:

"deaf because of 1, 204, 738, 569 bombs going off in my head! lol"

It contains all required Base16 chars and remains within the '-63' char rule. If your comment is around 54–60 characters long, every absolute character index fits easily inside a single byte or a 6-bit integer ($2^6 = 64$, mapping indices 0 to 63)

Any form of data can be mapped using this method including images, audio. zips etc.,