WHAT THE SCANNER SEES
EXHIBIT 09
IMPLEMENTATION TRACES
Standards leave room for different legal choices.
Generate one payload with two independent browser encoders. Compare their version, error correction, mask, segments, padding, codewords, and modules without assuming either output is suspicious.
TWO LIVE ENCODERS / FIVE STORED CONTROLLED PROFILES
LIVE COMPARISON
Same payload, different defaults
HideAndSeen currently encodes one byte segment by default. node-qrcode optimizes segmentation and uses its own mask scoring.
CONTROLLED SAMPLE
Five observed profiles
Ranges below summarize five held-out payloads per encoder from the corrected experiment. They are not universal signatures.
| Encoder | Version | ECC | Mask | Segments | Leading 00 |
|---|
THE FOUR QUESTIONS
Ask four questions of an innocent symbol.
WHAT CHANGED UNDERNEATH
WHAT A SECOND READER CAN RECOVER
HOW AN ANALYST CAN NOTICE
FINDING
Implementations can leave behavioral traces. Traces are not necessarily identities.
Version, ECC boosting, mask selection, segmentation, and padding behavior can differ among valid implementations. Those features may support a hypothesis about provenance, but overlap, configuration, and payload effects prevent strong identification.
Read the methods and limitations