deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

DEDA: open-source toolkit decodes and strips printer tracking dots

An open-source Python toolkit called DEDA extracts and decodes the yellow tracking dots that colour laser printers quietly print on every page, and can scrub or mask them to stop devices being traced.

DEDA: open-source toolkit decodes and strips printer tracking dots

An open-source toolkit named DEDA, which can read, decode and remove the hidden tracking dots that colour laser printers place on printed pages, has drawn attention after reaching the Hacker News front page via its GitHub repository. The project turns an obscure forensic artefact into something anyone with a scanner and Python can inspect — and, if they choose, neutralise.

What the dots are

According to the project's documentation, document colour tracking dots — commonly called yellow dots — are tiny marks laid down in a systematic pattern that carry data about the printer or the printout itself. The mechanism is built into nearly all commercial colour laser printers, so most colour printouts contain coded information about the device that produced them, including its serial number. Because the dots are printed in yellow, they are easy to miss under normal reading conditions.

DEDA — short for Tracking Dots Extraction, Decoding and Anonymisation — has a research pedigree: the README asks users to cite a 2018 paper, "Forensic Analysis and Anonymisation of Printed Documents", presented at the ACM IH&MMSec workshop by Timo Richter, Stephan Escher, Dagmar Schönfeld and Thorsten Strufe.

What the toolkit can do

The package installs from PyPI with pip3 install --user deda and requires Python 3. A graphical interface is available through deda_gui, but the core functionality lives in the command-line tools:

  • deda_parse_print reads and, where the scheme is recognised, decodes tracking data from a scanned page.
  • deda_compare_prints compares several scans to determine whether any of them came from a different printer.
  • deda_extract_yd pulls the raw dot pattern out of a scan when the tracking scheme is unknown, so it can be analysed further.
  • deda_create_dots generates a tracking-dot matrix of your own and adds it to a PDF.
  • deda_clean_document removes tracking data from a scanned image, which the README cautions works only "mostly".

Reading dots reliably depends on scanning conditions. The documentation recommends 300 dpi resolution, lossless compression such as PNG, and neutral contrast settings. Scan software that smooths away paper texture or applies aggressive thresholds can erase the dots before the tool ever sees them.

Anonymising documents before printing

A more elaborate workflow prepares documents for anonymous printing on a specific device. First, deda_anonmask_create -w generates a calibration page, which must be printed with no page margin and scanned back at 300 dpi in a lossless format. From that scan, deda_anonmask_create -r derives mask., an anonymisation mask tailored to the individual printer. Applying it with deda_anonmask_apply produces a masked.pdf designed to neutralise what the printer will add, again printed with zero margins. The project suggests verifying coverage under a microscope and notes that the mask's dot radius and x/y offsets can be tuned.

One detail stands out: a printer that genuinely emits no tracking dots can be identified by that very absence. DEDA covers this case too — a user can print the calibration page on another device and reuse that mask, or copy another printer's dots, so pages from a dotless printer don't stand out.

Known limitations

White or light-coloured areas inside graphics can only be masked if the optional Wand library is installed; without it, those regions stay exposed. The README also notes that monochrome pages and inkjet prints may not contain tracking dots at all, pointing to a simpler mitigation for some workflows. Installation can be fiddly: the GUI's eel dependency may need Linux build tools such as build-essential, and ImageMagick's security policy can block Wand from handling PDFs unless the policy file is adjusted or Wand is removed.

Why it matters

Tracking dots are a rare example of pervasive, largely undisclosed identification infrastructure embedded in consumer hardware — most buyers have no idea their printer tags every page with its serial number. The practice has had real consequences: in the 2017 prosecution of NSA contractor Reality Winner, court filings described how such dots on a printed classified document helped investigators trace it to her workplace printer. DEDA cuts in both directions. The same code that lets a privacy-minded user scrub or mask dots also gives journalists, researchers and forensic analysts an accessible way to read them. By making the mechanism legible — and fixable — the project shifts an obscure industry practice from secret to inspectable.

  • #privacy
  • #open-source
  • #python
  • #printing
  • #forensics

Related posts