Nahrajte obrázek pro zobrazení jeho kapacity.
(Dokumentace v angličtině)
What it does
The Image Steganography tool hides a secret message inside an ordinary PNG image - and reads one back out. It uses least-significant-bit (LSB) encoding: every pixel’s red, green and blue channels keep their values except the final bit, which stores one bit of your message. A 1000 × 1000 image can carry about 375 KB this way while looking pixel-for-pixel identical to the original, because a ±1 change in a channel value is invisible to the eye.
Optionally the message is encrypted first with AES-256-GCM (password-derived via PBKDF2, 100k iterations), so even someone who knows the image carries data cannot read it without the password. The tool runs 100% client-side: your image, message and password never leave the browser.
How to use it
- Pick a mode with the Hide / Extract toggle (top left).
- Hide: drag & drop (or click to choose) a carrier PNG. The tool shows its size and capacity - “this image can hold up to N characters”.
- Type your secret message and, optionally, a password (AES-256-GCM). The capacity line tracks how many bytes you have used.
- Press Hide message in image. The stego PNG downloads automatically, with a before/after comparison showing the two are visually identical.
- Extract: switch modes, drop the stego PNG, enter the password if one was used, press Extract hidden message. The message appears with a Copy button.
Examples
Hide a message
Carrier: photo.png (800 × 600) · message: Meet me at the airlock at 21:00 · no password
Capacity: 179,996 characters → downloads photo-stego.png
Pixels changed: 244 of 1.44M channels, each by exactly 1
Hide the same message with a password
Message: Meet me at the airlock at 21:00 · password: reactor-key
Extract without a password →
"This image contains an encrypted message - a password is required"
Extract with reactor-key → "Meet me at the airlock at 21:00"
Extract with wrong-key →
"Decryption failed - wrong password or corrupted data"
Extract from a clean image
Drop a PNG that carries no hidden data:
"No hidden message found in this image"
Good to know
- Why PNG: steganography needs a lossless format. PNG stores exact pixel values, so the LSBs survive saving, copying and re-uploading. JPEG is lossy - its recompression rewrites pixel data and destroys the hidden message. Always share the stego image as PNG.
- Capacity: floor(width × height × 3 / 8) bytes, minus a 4-byte header (and 44 bytes of
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
+ IV + GCM tag when you use a password). Photos and noisy images hide data more convincingly than flat graphics, where LSB noise can be statistically detected. - Encryption is authenticated: AES-GCM detects a wrong password and tampered pixels instead of returning garbage.
- Not a substitute for encryption alone: LSB steganography hides the existence of a message; statistical analysis can still flag suspicious images. For strong secrecy, use a password - then even a discovered payload is unreadable.
- Private: runs 100% client-side - safe for secrets.
- Related tools: Text Encryptor (plain message encryption), File Encryptor (whole-file AES-256-GCM), EXIF Stripper.