When a Picture Export Becomes a Device Fingerprint

The newest privacy boundary may be hiding inside the Save button. A technical investigation suggests that Microsoft Paint and Photos can attach an invisible, machine-linked identifier to exported images, including files created without generative AI. If confirmed across normal installations, the finding turns a familiar editing workflow into something more consequential: a system capable of making unrelated pictures traceable to the same endpoint. Provenance slips into the everyday workflow According to [the technical investigation by Xusheng](https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/), files produced by current Microsoft image applications may contain a GUID that persists across outputs from one machine. A GUID is simply a large identifier; by itself, it does not reveal a name, address, or serial number. The privacy significance depends on whether it remains stable, where it is stored, which export paths include it, and who can extract it. Those qualifications matter. A pseudonymous value is not automatically a real-world identity. Yet stable pseudonyms are powerful because they enable correlation. If an anonymous forum image, a work document illust