Social engineering attack using simple HTML <img> tags. Is it possible?

Let’s say the user is visiting sensitive.com and uploads some sensitive image sensitive.com/private.png. This image can be read with a GET request but requires authentication via a session cookie.
Now, the user visits another site evil.com… Continue reading Social engineering attack using simple HTML <img> tags. Is it possible?

What are the acceptable ranges of MSE, MAE, and PSNR values in the context of image encryption?

In my research on image encryption, I use the metrics below to evaluate the level of distortion between the original image ( I ) and its encrypted version ( I’ ):

MSE (Mean Squared Error)
MAE (Mean Absolute Error)
PSNR (Peak Signal-to-Noi… Continue reading What are the acceptable ranges of MSE, MAE, and PSNR values in the context of image encryption?

Is Error Level Analysis (ELA) in image forensics a reliable indicator for detecting digital modifications?

I’m reading about Error Level Analysis (ELA) in image forensics as means to detect if modifications were made to a photo. ELA is nicely described here: https://fotoforensics.com/tutorial.php?tt=ela. Also below examples are from that site.
Continue reading Is Error Level Analysis (ELA) in image forensics a reliable indicator for detecting digital modifications?

When viewing a hotlinked Google image preview, is the IP address of Google’s server recorded on the original site?

When I click on a Google image thumbnail to view a larger preview, I understand that the image is hotlinked from the hosting site.
In this case, when I view the hotlinked Google preview image, is my IP address recorded by the original site… Continue reading When viewing a hotlinked Google image preview, is the IP address of Google’s server recorded on the original site?