“And your credentials in steganography are...?”
Meh, it doesn’t take “credentials in steganography” to confirm there is no hidden zip file in this picture. The pkzip file format is public, anyone with a decent knowledge of computing can examine the file in question and verify for themselves that it does not contain anything resembling a pkzip file header or signature. Don’t take my word for it, go do it yourself and confirm it.
“I mean: the whole point of hiding a file in a picture is its not obvious that youre hiding a file in a picture.”
Obviously, but if you do hide a file in a picture in a certain way (which is what the posters in the original 4chan thread were claiming they found), then it is easy to verify if such a file is there or not.
“Did you examine the least significant bits in the color data?”
Unnecessary to disprove the claim.
“Did you confirm all data is used by the image, and none is extraneous nor errors?”
Unnecessary to disprove the claim. Remember the claim is not “there might be some data hidden in this file”. The claim was “there is a pkzip file hidden in this file because we found the bits corresponding to a pkzip header”. To disprove a more nonspecific claim, yes you would need to do a lot more analysis, but to disprove the specific claim, all one needs to do is compare the bits in the file to the pkzip file format.
Image staganography uses the lower value bits to hide a message. If you use a stego detector, it may pick up a stego’d but unencrypted zip header, with the person hiding the zip relying on the zip crypto to hide the contents. Examination of the jpeg code itself would not reveal the header, you’d need to know the type of steganography to uncover the header.
I have a steganography detector plugin for my browser that will detect but not necessarily decrypt a stegged file. R-click an image, select “Check selected image/text for stego” and it says yes/no and what type of steganography was used. A different plugin will take an image or text file and stuff it.
Using stego on a music file is similar and is better for large images because .wav music files are large.