“Program and program settings: When preparing the letter, WordPad for Windows is most likely used. Default settings for font, line spacing and paragraph are used. The page layout has been Letter.”
That, I think, can be inferred with good confidence from precisely measuring various font measurements, looking at how lines got broken, etc, and comparing that with a database of program defaults for a large set of OSes and programs.
“Device, operating system and video card : When designing the threat letter, a Windows PC has been used, with an operating system Windows 10 or 8.”
I guess either WordPad or the font got tweaked somewhat in that Windows version. Maybe WordPad started using ligatures more aggressively, its page width got a tiny bit wider, or, in the font, some letter shape or spacing table changed a tiny bit, or a character was added.
“The PC has had an integrated video card, Intel HD Graphics 630.”
That, for me, is the most intriguing part. Does Windows use the GPU to render fonts even if they get printed, and are there subtle differences between GPUs and their software rendering that, statistically, can be recovered from the somewhat noisy print?
Most cheaper printers (esp. on Windows) use the GDI protocol for printing. These printers only know how to print rasterised images, so the document is rasterised by the OS/Print driver and only this final rasterised image is sent to the printer. This is different from higher end PCL/PS printers where the document is translated into a page description language and the printer is (partially) responsible for rasterising the final document for print.
Since Windows uses the GPU to render fonts I wouldn't be surprised if the same code is used to rasterise the fonts for GDI printing.
That being said I'm very surprised they can identify the GPU just from that, unless there is some specific bug in the driver for the card which produces an obvious font rendering artefact.
Gaussian blur is your friend if you wanna send a death note, I guess.
Could also be by design, similar to printer identification dots. Have the artifacting vary every so slightly from one GPU to another. Then again, I feel (emotional statement, not of fact) that this would be known by now if it was a thing.
So...evidently from a sample of me, I can tell from which monitor a screenshot was taken...
Edit: Specifically, what about printers that only print black and white?
I'm not sure these days when most GPUs are IEEE-754-compliant. But back in the mid to late 2000's I worked on a GPU renderer for video editing and we had a few filters that gave noticeably different results on different GPUs. One filter did a hard black and white threshold, then blurred the result, did another hard threshold, etc., in a loop. Because of differences in precision of the floating point values (24-bit on AMD at the time, if I recall correctly), the thresholds could produce minor differences that got magnified by the blurring, and then created new thresholds with minor differences, etc.
Even if all the GPUs are using IEEE-754 floats, there are driver differences that can cause the results to be slightly different, too. Like a simple GLSL mix() function could be implemented as result = x * a + y * (1 - a) (where x and y are 2 input pixels and a is the alpha of x). Or it could be implemented more efficiently as result = a * (x - y) + y. Doing the same math in a slightly different way can sometimes lead to slight differences in intermediate results which compound in the final result. So yeah, it may be possible to tease out some of these things by examining something like font rendering.
Becomes extremely easy for malicious actors (out or inside the police) to fake evidence and frame anyone they'd like.
Bite mark identification was used forever until blown up by particularly shameless grifting, and has never been shown to work as practiced. [1]
Tennessee still uses dowsing rods. [2]
Fingerprinting as practiced is a bundle of folk practice, guesses, and some science. Quality varies wildly. [3]
Fiber analysis, lie detectors, spatter analysis and many more techniques are all crap. When one bogus method is finally found legally unreliable, cops and prosecutors find a new one.
[1] https://innocenceproject.olemiss.edu/radley-balko-reports-on...
[2] https://www.themarshallproject.org/2022/03/17/witching-dowsi...
[3] https://www.aaas.org/resources/latent-fingerprint-examinatio...
And I'm wondering about that, because we know the criminal must have been a pretty hard-core cryptocurrency nut. There aren't THAT many of them in Norway (they've already concluded they are a fluent Norwegian speaker).
As for malicious actors, wouldn't that be a risk for most forms of evidence? Likewise, wouldn't many of the techniques used to establish the validity of other forms of physical evidence be applicable when these techniques are used?
Ah yes, I see they’re using the default formatting options. That narrows down our search to 99.9999% of the population.
That narrows it down to coming from 10s of millions of computer perhaps?
Seriously though, I thought printers have been using microdots as identifiers for years. Is this just an old wives tale?
There's a number of encoding schemes [1], though most of those only identify the printer - they don't go far enough to identify the graphics card or OS where it originated. That's a new capability - if it's being accurately relayed here.
[0] https://en.m.wikipedia.org/wiki/Machine_Identification_Code
I believe it's only by some copiers and laser printers, not inkjets for example.
They figured out it was Wordpad (presumably based on line breaking or similar) which narrows it down to Windows, and the graphics drivers probably subtly affect the font rendering in the same way that can be used for canvas fingerprinting.
That said, Windows 8 or 10 using Wordpad and Intel integrated graphics doesn't exactly narrow it down.
‘It’s a Hewlett-Packard laser. They can tell by the toner chemistry. Can’t tell which model, because all their black-and-white lasers use the same basic toner powder. The typeface is Times New Roman, from Microsoft Works 4.5 for Windows 95, fourteen point, printed bold.’
’Typefaces tend to change very subtly between different word processors. The software writers fiddle with the kerning, which is the spacing between individual letters, as opposed to the spacing between words. If you look long enough, you can kind of sense it. Then you can measure it and identify the program. ...’
(Edit: Limited the amount of quoted text a bit; I believe a few lines is fine/fair use. Loving the series re-read after the TV show, and that I bought them on Kindle originally!).
If you're in a highly secure environment, it's even possible the content itself may be a unique identifier. I could imagine a sensitive document having grammatical alterations unique to each recipient.
Journalists should consider this before publishing unredacted copies of leaked documents.
Well, that the typewriters and today the printers are unique, sure.
But here they seem to claim(I do not speak the articles language) that they could identify the computer that send the document. Which is a very bold and new claim, I think.
1) Printers leave a unique "invisible" watermark; similar to the way you can hide an image within an image. The naked eye can see it, but it's there.
2) Aside from that the printer itself has a unique fingerprint, similar to how keyboards do (i.e., AI can pick the difference in the sound of each key and with that audio can translate your typing into letters / words).
3) Networked printers phone home; with snippets. Again, similar to the way some smart TVs send screenshots.
Perhaps not every printer does all of the above, and some not at all, but enough do or might.
Finally, law enforcement explanations like the article's to me are suspect. For example, how often do we hear that a random-y car stop led to a sizable drug bust? So of all the thousands of car going up Rt 95 the police randomly picked one with loads of drugs? What are the odds?
Moral of the story, if (federal) law enforcement has "insider information" they're not going to share that with the public.
I agree: all I've learned is to make a doc on my oldest laptop, multi-paged and-fonted, have it printed at different public (paid or library) sources and then cobble them together and post them from a random place (not taking my phone there, either).
From what I've anec-heard, those 'rando' car stop/ mega busts are politely arranged so the cops get their bust, but the real mega-shipments sail on by, untouched. Everybody gets a payday, even the Prison system!
*the captured mules get to live rent free for a whilem so there's that, for them.
Wtf! Just when I thought I'd heard it all.
- Are there certain rendering artifacts that can be seen on printed glyphs that give clues to the GPU?
- Or, are they going by heuristics here? (I.e. it was XYZ GPU, because it was a common machine that at the time that would be running Win 8 or 10)
Most printers will do their own rendering, it's not often that a text document gets pre-rendered by the OS.
If it was printed straight from WordPad without being converted to an image, there's no artefact from the host OS, there.
What does intrigue me is how they managed to determine the graphics card.
Anyone?
It's more likely the printer driver have encoded information about the gpu into the yellow microdots [1] that many color printers use to trace pages.
But if they have microdots, then they really should have more information.
[1] https://en.wikipedia.org/wiki/Machine_Identification_Code
Cheap GDI printers use the PC for rendering. I find it a bit surprising that would give enough to identify a specific card from a printed sample, but it certainly seems plausible.
There's quite a lot required for them to credibly show that the letter could only have been produced on a pc with "Intel HD Graphics 630". I suspect the argument is on the level of "we tried to duplicate it with some random PCs and the one with Intel HD graphics looked most similar".
But even if it is true, integrated intel GPUs are in (maybe?) a third of all windows PCs.