Rendered at 20:53:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jjcm 22 hours ago [-]
If it's between this and a perpetual logo, I'll take this any day.
I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content.
There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people are dogmatically opposed to intent being modified, but I think you need to balance nuance. I actually enjoy having an attributable source in shared elements, and I think this is a low-impact way of achieving that.
blauditore 13 hours ago [-]
I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily.
It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
TeMPOraL 13 hours ago [-]
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.
fluoridation 13 hours ago [-]
On a similar note in terms of frustration, my bank ended up getting me to memorize my randomly-generated passwords twice because it blocked pasting. I guess it's to discourage writing them down in plaintext files, but I bet it just makes most people choose meaningful (and therefore weak and guessable) passwords.
garbagepatch 5 hours ago [-]
Same here. Luckily you can show two apps at the same time in Android so I just put the password manager above the bank's app.
squigz 5 hours ago [-]
I just ran into a signup/login flow that allows pasting of passwords to register but not to login.
Very frustrating.
lostlogin 11 hours ago [-]
> much sekhurity
This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.
account42 7 hours ago [-]
So did the airport and companies selling you overpriced water beyond the security screening.
joquarky 2 hours ago [-]
The terrorists and the large corporations are looking very similar these days.
Perz1val 13 hours ago [-]
Then they deserve you taking a photo with a second phone
TeMPOraL 12 hours ago [-]
Well, I did, after the fact, but it's only because I had a work phone on me (that doesn't yet actively block sharing to non-work devices).
I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.
setopt 8 hours ago [-]
There might be a market for a USB-C camera to take phone screen photos to immediately upload back into the phone.
TeMPOraL 8 hours ago [-]
Yeah, few moments ago it hit me there could be a market for a phone case with in-built camera(s) that photograph your screen at a shallow angle on demand, and transform that into a screenshot automatically.
However, my idea happens to hit a very new limitation: for some reason, "privacy filters" are suddenly a thing. New phones have them built-in as some new magic display function, and for everyone else, there's this mad marketing push to get people to buy and use privacy foils in place of glass/foil screen protectors.
IDK what's up with those. Since when "shoulder surfing" with smartphones is a real problem, and why do marketers and product designers bet there's so much latent demand for it?
flir 11 hours ago [-]
We're heading for two devices, IMO. A useful one and one for communicating with bureaucracies.
GuB-42 8 hours ago [-]
That's exactly my idea. My phone is a lost cause, not really "mine" anymore. The good thing is that I stopped caring about the device. I take what's cheap and well supported (Samsung "A" series is the right kind of boring to me), no more expensive flagships.
The "useful device" is a laptop.
rplnt 10 hours ago [-]
And a third one for membership apps.
fc417fc802 5 hours ago [-]
> before pausing and realizing that this would only cause even more problems with those apps,
In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
TeMPOraL 5 hours ago [-]
I feel that too, but the practical reality is, many services happily exploit the leverage they have over me - I need them more than they need me.
Banks are the canonical example - changing one is a huge hurdle, with consequences that can drag on for years. One by one, they're all ditching their websites (if they had one in the first place) in favor of apps. Even those with full-featured websites increasingly force you to use their app as the second factor to log in, confirm transactions, even confirm viewing some data. Some offer physical tokens, most don't advertise that, and it's only a matter of time before they convince regulators that Attested Phones are Safer and Everyone Has One, and that option will disappear. And because they want their app to be the second factor, they can argue it needs to be secure, creating demand for remote attestation, and boom - there goes your option to work around any other bullshit limitation they throw at you.
The day has only 24 hours, I don't want to spend them clearing bushes by walking off the beaten path wrt. every single important service - payment services, government services, IM services, ${whatever bullshit SaaS app I need right now because you're using it for the thing you just shared with me, and I need to view that}, etc. So I submit. So does everyone.
It's why I put blame on platforms here. Features protecting the device from the user should not be built in the first place - they always start justified by some legitimate security reason, and always end up broadly abused to serve business reasons.
ryandrake 5 hours ago [-]
Banks are the stereotypical example, but they are really not that hard to change, especially now that many decently reputable ones are entirely online. I've changed my bank in an afternoon.
Zambyte 12 hours ago [-]
Software that intentionally subverts the intent of the user is malware. We now live in a world where most financial institutions literally ship malware as their primary or only interference to access their systems.
V__ 12 hours ago [-]
I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.
QuantumNomad_ 12 hours ago [-]
People also take pictures of their government IDs (passports, drivers license, etc) and utility bills.
Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?
I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.
It’s my phone, I want to decide what I take photos and screenshots of.
TeMPOraL 12 hours ago [-]
> especially if the bank might be partially at fault if a scam happens
That's the crux.
Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).
Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.
j1elo 10 hours ago [-]
Add a system setting to ON/OFF this feature. Add a recommendation to set this as ON in the "Security Checkup" section which all modern systems have as of lately, that pops-up a couple times a year for suggesting good defaults to the user.
Done.
Jtarii 12 hours ago [-]
This just reinforces the notion that apple is the one that actually owns the phone and they generously let you use it.
Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".
dspillett 11 hours ago [-]
Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.
Jtarii 9 hours ago [-]
Well, it sounds like those people are just too stupid to own phones at all then.
account42 6 hours ago [-]
And worst of all, it doesn't matter if you are one of those people or not, for some reason all software you get to use must be designed for the lowest common denominator.
miki123211 9 hours ago [-]
"are you sure" checks work if you force deliberate effort on the part of the user.
Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.
5 hours ago [-]
hahn-kev 9 hours ago [-]
The number of times I've seen people blow though prompts which directly refer to the issue they are coming to me about... SMH
TeMPOraL 8 hours ago [-]
Trained by the many more prompts that are irrelevant in practice, and merely stand between a person and the task they're trying to accomplish.
It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later <tinyprint>0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry</tinyprint> ;-)" anyway.
Most of the time, people are given only two options: give up on their task, or ignore the popup. No point in reading the message in such cases, it brings zero value.
hahn-kev 7 hours ago [-]
I'd say the problem is that delete usually has a popup. Sure you don't really want to delete without any kind of confirmation, way too many people would click something on accident and if there's not a way to undo it (which has it's own issues), then a popup is a simple solution, but it does result in this unfortunate behavior.
TeMPOraL 5 hours ago [-]
Honestly, if I were to dig, then for my generation[0], I'd blame save and close popups more, but even more than that, flaky component-based software. At some point in the Windows 98/NT and then 2000/XP era, you'd often see software throwing "fatal errors" and then continuing to happily chug along, possibly with subtly broken features, and ready to throw more inconsequential "fatal errors" if you moved your mouse the wrong way.
Repeated exposure built immunity.
You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.
The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.
Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.
We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:
Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.
--
[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.
[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.
blauditore 4 hours ago [-]
Well, then make it harder to accidentally make a screenshot. E.g. make the user confirm (and then memorize whatevr setting).
miki123211 9 hours ago [-]
People also get scammed using accessibility services, so some banks deliberately make their app inaccessible unless you're running a whitelisted screen reader. If you are running a non-whitelisted screen reader...
Perseids 12 hours ago [-]
Hoping to not sound like a broken record, this is why having full ownership of your device and OS is important. My stock Pixel Android recently told me something along the line of "A security policy blocks screenshots for this app. Talk to your administrator if you want to change the policy". I looked in the mirror and my administrator said "time for a policy change, we're moving to GrapheneOS".
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
kllrnohj 9 hours ago [-]
The remote tech support scam using screen sharing apps like team viewer is unfortunately very common and is basically why this exists.
It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed
rixed 8 hours ago [-]
The use case they have in mind may be screenshots triggered by another app, not by the user.
kotaKat 12 hours ago [-]
I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog.
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
fc417fc802 5 hours ago [-]
It warns you but it doesn't block or redact the screenshot? Also why are they sharing photos in the first place if they don't want them to be public?
kotaKat 4 hours ago [-]
Warned me but did not block or redact the screenshot at all. Absolutely funny. Of course, then I had to screenshot the warning...
So yeah, I have a screenshot of the generic technician's ID photo, I guess.
Later on it did populate an actual name and photo when a human was assigned, but still, yeah, I don't get why they didn't just automatically redact it and just throw you the stupidest bullshit warning error ever on the honor system.
runtime_lens 12 hours ago [-]
[flagged]
TeMPOraL 12 hours ago [-]
> “Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge.
Very true.
> The right fix is selective redaction, not disabling screenshots everywhere.
That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".
ryandrake 4 hours ago [-]
The app developer shouldn't even get a vote. The user should be the one who decides what information is "sensitive" and what isn't.
whywhywhywhy 10 hours ago [-]
I get why it's the default but anyone who'd had to navigate an elderly relative around their banking app just via them describing the screen because iOS blanks it out when screen sharing definitely wishes there was a way to opt out of it.
subjectleft 13 hours ago [-]
It is strange how this spawned a 100+ comments discussion on HN.
TeMPOraL 13 hours ago [-]
It's not about the logo. It's about abusing a platform feature that arguably shouldn't exist in the first place.
pembrook 21 hours ago [-]
[flagged]
ramraj07 19 hours ago [-]
Consider the possibility that many HN users, who likely also constantly ask why mice are needed when vim/Emacs exist, are not the users who mostly use regular apps.
computably 20 hours ago [-]
Uh, no? I highly doubt that a non-occluding watermark on screenshots is even in the top 100 gripes most people have with X. And I don't use either platform. If anything your argument is an accusation of bias without any discussion of merits.
Petersipoi 18 hours ago [-]
Not sure why you think anyone is suggesting that non-occluding watermarks are a gripe people have with X.
GP is saying that BS gets a pass where X would not for a user hostile action.
saghm 17 hours ago [-]
From reading through a lot of comments on this thread, I'm honestly struggling to notice any super obvious pattern or bias other than the amount that people care about how screenshots work compared to the average person is a lot.
irishcoffee 18 hours ago [-]
Yeah, the dead comment really cements the bias of hn despite what people claim.
I don’t use either platform, I have no interest in the debate. As an outsider looking in, the bias has been proven.
Not that it matters much, I am left-of-center generally speaking.
saghm 17 hours ago [-]
I don't think this says a whole lot about the direction of people's political views here as much as there being a general disdain for arbitrary claims of political bias that aren't based on any discernible evidence. I feel pretty confident that if I jumped into a random thread about some feature in the Brave browser and accused someone of defending it only because they agreed with Brendan Eich on Prop 8, I would get flagged too.
alex1138 15 hours ago [-]
re: dead, I agree. I'm so tired of flags killing discussion. This site is highly regimented
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.
alex1138 13 hours ago [-]
You're not wrong and I do think that specific dead comment is dead for a reason. I just get a bit bristly when I do see legitimate comments buried under flags
alex1138 11 hours ago [-]
PS - sorry. I love a great many things about HN. I'm glad the site does sometimes insist on decorum
skiing_crawling 22 hours ago [-]
This is phone OS developer's fault for even allowing it. When I take a screenshot, I expect to have an image of exactly whatever was displayed on the screen at the time. Its not a picture of your app, its a picture of my screen. Some banking apps used to (or still) prevent this and now some apps get a hook to insert their branding. My device serves some master other than myself.
MBCook 18 hours ago [-]
This exists for a very good reason.
It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show.
Bluesky, and apparently others, are abusing the functionality for advertising purposes.
I think it’s a good thing it’s there. This functionality should be easy for apps.
I’d say this is one for app review or an App Store rule. But we all know those are a total joke.
no-name-here 15 hours ago [-]
I don't have an issue with BSky's use, but I regularly run into the functionality's abuse elsewhere, such as multiple of the biggest Thai banks' apps where every screen in the app entirely blocks screenshots (iOS). Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms for proof or a personal reminder? Blocked. It's even worse as multiple of the biggest brick-and-mortar Thai banks wholly dropped web access and are now smartphone-only. (Or more obscure, want to translate a single-language screen into another language? Blocked.) Etc.
high_na_euv 13 hours ago [-]
>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer?
Why not ask contact for data via text and just copy paste it with double check?
TeMPOraL 12 hours ago [-]
What if the app doesn't allow pasting? What if the communications app prevents copying?
For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!
--
[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, all text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.
no-name-here 12 hours ago [-]
1. On the pre-submit-button screen it shows the recipient's name to confirm, but as in the GP example, if the recipient's name is in a character set different than your own, it would be nice to be able to have someone who can confirm the recipient's name matches.
2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.
CrimsonRain 17 hours ago [-]
I want to take a screen shot of the transaction I just did. Can't because some ahole decided for me that it's too sensitive information and blacks out the whole screen. this API is stupid without control in settings of the os
ralferoo 13 hours ago [-]
Yeah, I used to have this issue a lot. If I use my personal card for a business expense, I used to like to keep a screenshot of the transaction on the card as well as the invoice. As it's an app-only challenger bank, this is the only way short of exporting transactions as a PDF and that includes other transactions for the day. For a long time I used to use another phone to take a photo of my phone screen. Eventually, I just stopped bothering taking that photo because of the extra hassle, but it never stopped annoying me that I couldn't keep the records I wanted easily.
smelendez 17 hours ago [-]
Yeah, I would rather see a warning in that case that the screenshot could contain sensitive information, with options to take a redacted screenshot or a normal one.
subjectleft 13 hours ago [-]
[flagged]
j16sdiz 16 hours ago [-]
Lots of people here exposing their single sign on approve code because a scammer ask them to send them a screenshot.
jrockway 16 hours ago [-]
I mean... "please read me the code you get via text" or "this really Bank of America, please type your OTP" seems to work well enough. We really don't need OS-level controls for stuff on the screen. People can just tell you what's on the screen.
squigz 15 hours ago [-]
So that means this change will result in a noticeable decline in such scams, right?
Right??
SkyBelow 9 hours ago [-]
Potentially worse than nothing, it allows for someone to claim they have a fix even if the fix does nothing to stop someone from becoming a victim, thus allowing for even stronger victim blaming.
monegator 14 hours ago [-]
you don't have a share button tha generates a PDF and shares it with whomever?
TeMPOraL 13 hours ago [-]
Often, you don't, because the same developers of the bank app decided it's an unnecessary power user feature that doesn't fit in the MVP or something.
Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose is to be a share target and dump the information to file (and being apps on an app store, chances are top 10 are just thinly veiled malware).
GlumWoodpecker 10 hours ago [-]
Here's an open source solution on F-Droid, presumably malware-free:
Yeah I wondered why anyone would ever install such a simple utility app from the app store. It's something that needs to be developed once and then only receive minimal maintenance which means the usual individual maintainer scratching his itch and sharing the result model works well but it also processes intentionally sensitive data meaning developers might be tempted to monetize that in some way. The curated open source distribution model of F-Droid is the perfect solution to this.
monegator 13 hours ago [-]
really? I'm not suprised by shitty developers developing shitty apps but i'm still baffled. Surely the bank would be getting tons of angry emails from customers if it happened in europe
TeMPOraL 13 hours ago [-]
Would they care?
They probably support proper export for business accounts. Business customers have leverage. Regular people? They're an annoying but necessary nuisance.
bryanrasmussen 12 hours ago [-]
>This exists for a very good reason.
This exists for a very bad reason.
>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.
and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.
>I think it’s a good thing it’s there. This functionality should be easy for apps.
I think it's a bad thing it's there. The functionality should be easy for me.
WhyNotHugo 14 hours ago [-]
OTOH, I might very well want to take a screenshot of my own bank details, transactions, or other sensitive information. It's annoying that my information is being protected from myself.
alibarber 13 hours ago [-]
You might have amazing operational security but lots of other people don't, and they make noise, which means governments write laws meaning that banks have to refund them for fraud.
So as much as a bank might agree with your stance on freedom of compute - they probably don't want to pay for it with actual money.
TeMPOraL 12 hours ago [-]
Banks have managed to externalize the costs of their own security onto people by inventing the concept of "identity theft", and pinning the blame for poor security practices on regular people.
They really shouldn't be allowed to double down on it.
And arguably, half of it isn't even really security, it's about keeping you in their app. Application interface is the ultimate sales platform, and banks are making extensive use of that fact.
account42 5 hours ago [-]
So in other words, we should make even more noise so that governments make laws requiring banking apps to support basic OS features including screenshots.
have_faith 12 hours ago [-]
Then it's a bad solution to a real problem. A better solution would be exposing a hook that apps can call when a screenshot is initiated that tells the OS to warn the user before saving the screenshot. This way the user is actually educated on the risk while still respecting their right to control the outcome.
underwater 18 hours ago [-]
The OS could draw an ugly censoring block over the sensitive information. That would protect the user's privacy when needed but also prevent apps mis-using the feature like this.
TeMPOraL 12 hours ago [-]
It could. But the root problem is, there is no such thing as unqualified "sensitive information". The information is sensitive to someone, for some reason. The problem with screenshots manifests when the app and the user disagrees about whether the information is sensitive and who has the right to control it.
The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.
The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.
account42 5 hours ago [-]
And a more basic technical problem is that OSes prevent users from modifying the apps running on their devices.
Gigachad 16 hours ago [-]
I don't think Apple cares about apps replacing the follow button with an icon. It's a weird use of the api, but it's not abusing the user or a security/privacy risk.
MBCook 17 hours ago [-]
Yeah. I wonder if Apple does something to change this.
This is a failure of imagination for Apple, but it’s hard to blame them.
Who would think someone would put a button inside a “secure” text field and change the masked appearance to a logo?
If I was proposing this feature, I would never imagine someone would come up with something like that.
geocar 13 hours ago [-]
> it doesn’t accidentally end up in a screenshot
Your banking app probably has an option to disable that because it's a legal requirement in so many places: People who can't see need to use assistive tools, and that includes screenshots and friends. If you are using a tiny/stupid bank in the US, file a ADA claim and get some money. In the EU check your Ombudsman.
No, it's so you can't screen-record Netflix. The bank doesn't care about that because it's not a liability issue to them, just fetishism; no way they pay Apple and Google for this capability.
Apple and Google should step in and allow users to remove these shenanigans with a little button on the screenshot preview screen, but resist this because of Netflix et al.
MBCook 8 hours ago [-]
iOS and MacOS have a large number of built-in accessibility features. Taking a screenshot of the screen is not necessary.
sschueller 15 hours ago [-]
It's MY phone that I paid over $1000 for. Let me choose what is exposed and what is not.
dbdr 13 hours ago [-]
This shows hardware won't be yours unless the software running on it is open source. Asking a company to modify its closed source software might work occasionally, but it's a band-aid and a never-ending battle.
weird-eye-issue 15 hours ago [-]
Account numbers appear on checks. They are not exactly secret, and if I want to take a screenshot of one, I should be able to.
nerdsniper 18 hours ago [-]
But how can I take a screenshot that intentionally shows the password or whatever?
saghm 17 hours ago [-]
Use a device with an operating system that doesn't think it knows better than you what you want.
thaumasiotes 15 hours ago [-]
You're not that unlikely to leave that feature in place if you have such an operating system. What you really want is two controls: one for "safe screenshot", and another for "raw screenshot".
userbinator 14 hours ago [-]
"accidentally end up in a screenshot" --- how often do you even take a screenshot on a phone, much less accidentally?
Y-bar 12 hours ago [-]
Almost daily on my iPhone.
The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.
And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.
That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.
MBCook 8 hours ago [-]
I believe Apple added an entire section to the photos app to show screenshots that were taken.
I don’t accidentally take screenshots very often, though it does happen.
I know multiple people who seem to take them constantly. It’s crazy. You and I may not do it, but I promise you there are people who do. LOTS of them.
tuoret 13 hours ago [-]
Consider that people use their phones differently than you. I take screenshots on a daily basis, accidental ones at least once a week. Usually it's just the lock screen though.
I take them constantly. Not even sure how. I think it means I am “of a certain age” these days.
Now get off my lawn.
monegator 14 hours ago [-]
i take many screenshots, but about half of them are accidental (somehow it recognizes the "tap three times" gesture whenever it feels about it)
account42 5 hours ago [-]
Preventing accidental screenshotting is all well and good but these security measures all seem to forget the part where they should still allow intentional screenshotting.
jvuygbbkuurx 15 hours ago [-]
If it's to prevent accidents, it should just prompt user to confirm saving the screenshot with sensitive information.
As it is, it is just an annoyance that requires you to do stupid workarounds like taking a photo of your screen.
Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.
...and it characteristic the level of patronising arrogance in the issue thread
"This is normal. It is not recommended to copy passwords to the clipboard in any case, this mitigates this behavior and complies with new Web Authentication standards."
This does not even invite a discussion. Maybe some people run tight, safe systems and know what they are doing? Maybe some people never rely on a single password being the only thing between them an an account compromise? Nope. Some patronising guy knows it all, and will override what people want to do on their machines.
TeMPOraL 13 hours ago [-]
> Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
... have you heard of passkeys?
Yes, it's as stupid as it sounds. And works about as well.
poink 17 hours ago [-]
I don't think they're abusing functionality at all. I don't think screenshotting a skeet should, by default, leak the follow state of the user taking the screenshot, which is what would happen without the secure input swap
"Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way
TeMPOraL 12 hours ago [-]
One person's "sensitive input" is another's "key information".
Follow state is a useful bit of information. There's argument to be made for both hiding and preserving it.
conductr 17 hours ago [-]
If a dev forgot to obfuscate the password and rendered it as plain text on the screen, then what are the chances they remember to program the blur into this screenshot api hook. Or why not add an alert, “what me to blur sensitive info? Yes/No”
MBCook 8 hours ago [-]
Doing it correctly requires setting a single Boolean. That’s it. The OS will do everything else for you if you don’t override it.
There’s no need to implement a custom blur.
TeMPOraL 13 hours ago [-]
Unfortunately there's platform-level features for marking surfaces as sensitive/secure. So your dev would typically just mark the whole app as such, and be proud of their proactive problem solving.
like_any_other 6 hours ago [-]
> This exists for a very good reason.
They find a good reason for every little piece of control or privacy they take from you.
bio_hacker 15 hours ago [-]
I can always just pull out my second phone to bypass all this shit.
seany 18 hours ago [-]
Which is why everyone should root the their phone to turn this kind of shit off.
csomar 9 hours ago [-]
You know you could declare your app screen sensitive and then a screenshot requires a face id?
Whatsapp also does this shit. You can’t screenshot a conversation (it comes back black). I am going Chinese for my next phone.
huflungdung 11 hours ago [-]
[dead]
kashnote 19 hours ago [-]
1000%. Apps should not even be able to know that I've taken a screenshot - let alone change the contents of it.
nine_k 19 hours ago [-]
The app doesn't know. It just produces a widget tree, and the OS-provided renderer renders it this way or that way. In particular, it chooses not to render controls marked as "security-sensitive" when the rendering is intended for a screenshot; it could instead put empty boxes in their place, etc. The app has no idea and no control, AFAIK.
Open the amazon app. Take a screenshot. See a toast message informing you that the amazon app has detected you've taken a screenshot. Fucking used for fucking profiling.
kashnote 18 hours ago [-]
Don't apps like Snapchat notify the other person if you take a screenshot of your messages?
woadwarrior01 17 hours ago [-]
Yes, iOS has userDidTakeScreenshotNotification for that.
I think at least in snap it makes sense, the communications are suppose to be ethereal and disappear after reading, I like to know when someone screenshots something and its no longer ethereal
Petersipoi 18 hours ago [-]
Yes, Snapchat does this. Apps absolutely have the ability to know when a screenshot is taken.
thaumasiotes 14 hours ago [-]
Snapchat advertises that they detect screenshots. They try. But they're well aware that they can't actually know.
For example, their bug bounty program policy helpfully informs you that "screenshot detection avoidance" is not considered a vulnerability: https://hackerone.com/snapchat . That's because it's always possible.
nemosaltat 18 hours ago [-]
The apps definitely know. Horsemen example: If you screenshot on Amazon (and Business version) iOS apps, it “helpfully” pops its own share sheet.
blensor 14 hours ago [-]
I wonder if this is the expectation of the majority or just the expectation of us tech people.
Because I assume most people want to take a screenshot because they want to capture something they are seeing in the app, most people probably are even annoyed to have the system indicators visible there.
asaddhamani 14 hours ago [-]
Bank apps black out the whole screen when I take a screenshot and it’s super annoying. As a user, I should be able to take a screenshot of my screen. I can use a camera or another phone to do it anyway.
spike021 22 hours ago [-]
iOS allows something similar. twitter (X) will also add a logo. I believe reddit did the same but i stopped using their app a while ago.
mh- 19 hours ago [-]
Reddit has a toggle in its settings to disable it. X, too, I think.
Personally, I wish iOS didn't even facilitate this.
edit: to be clear, I don't think iOS should notify the app at all. The app could register areas as "invisible to screenshots" perhaps - I'm torn on that functionality.
voidUpdate 14 hours ago [-]
That's what bluesky is doing in this case. It is showing the button on an area that is "invisible to screenshots", and the butterfly is behind it, so it shows through when a screenshot is taken
Chinjut 19 hours ago [-]
iOS allows something similar because this is iOS. iOS allows something exactly the same because this article is about iOS.
ErigmolCt 15 hours ago [-]
Bluesky trick exposes how strange the abstraction is
thaumasiotes 15 hours ago [-]
So...
> and now some apps get a hook to insert their branding.
No, apps can already insert their branding anywhere they want. They're writing the app. If they want their logo to be visible in screenshots, they have infinite ways to do that.
This particular way seems basically prosocial. It's much more useful to me as a consumer of the screenshot to see that it came from Bluesky than to see that there was a "Follow" button. It's not what the feature they're using was intended for, but I can't call it an abuse of the feature. What they're actually doing is good.
The fact that you're getting unexpected behavior isn't good. Sometimes you want to create a picture of sensitive information. You should be able to override the app developer's security settings.
KennyBlanken 19 hours ago [-]
The thing that really irritates me about the banking apps blocking screenshots is that it's pretty clear to me it's not about protecting customers but denying customers the ability to document something related to their account.
devmor 18 hours ago [-]
No, it's about saving the bank money - and what costs them a lot of money is the average person being fooled into sending people their account information easily.
ruszki 17 hours ago [-]
But every bank app which I used had a button to copy all of those directly.
isodev 17 hours ago [-]
if only there was some kind of app review process... but Apple doesn't care.
I guess the Bluesky bros got inspired by Threads, again.
nemosaltat 19 hours ago [-]
> I expect to have an image of exactly whatever was displayed on the screen at the time
Do you/should you (we) really expect that though? I regularly use color filters on my apple devices— grayscale to avoid distractions during the day and red tint at night. More recently I’ve been using the motion dots. I don’t know that I can say with confidence that I never want any of those “personal-perceptional-modifiers” to appear in a screenshot, but for most folks, I would guess it’s approximately never.
smelendez 17 hours ago [-]
I want those things included, at least by default. A screenshot normally captures the user’s screen size, brightness, zoom level, font choices, etc.
It is often important to people that the screenshot is an accurate record of what was on the screen.
tmp10423288442 16 hours ago [-]
It doesn’t copy the brightness AFAIK
15 hours ago [-]
zamadatix 18 hours ago [-]
The effects of cramming 2 separate workflows and 5 features into one thing called "screenshot" because anything else would end up with something too complicated for users to understand the interaction (sarcasm that figuring out what the behavior is locked to in these scenarios is just as confusing).
While we're at it, this "share" containing the copy/paste flow is the exact same kind of thing. And screw whatever logic decides to copy the URL of an image instead of the actual image sometimes from Safari when I select to copy it!
nemosaltat 17 hours ago [-]
And whatever’s worse than screw for copying presumable pngs as .webp or whatever that format is
pfraze 22 hours ago [-]
This is in fact a watermark to promote the application, which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app. I didn't know that Sam literally named the file GrowthHack.tsx, which is pretty funny.
red_hare 21 hours ago [-]
I can't help but respect the dev's self-awareness
yjftsjthsd-h 14 hours ago [-]
> which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app.
The text at the top of the screenshot is
> Eric Roston
> @eroston.bsky.social
So it's pretty easy to tell IMHO.
radicalriddler 14 hours ago [-]
what happens when it’s a custom handle like @example.com?
yjftsjthsd-h 14 hours ago [-]
Honestly I didn't know that was a possibility. In that case yes, it's probably harder in when that's in play.
dbbk 12 hours ago [-]
I mean, X does the exact same thing
inigyou 10 hours ago [-]
In X's case, the advertising is just the close button.
YesThatTom2 10 hours ago [-]
Can they do something similar so that caps include the full date/time? I hate when caps are perpetually “1 hour ago”.
fiatpandas 6 hours ago [-]
Great idea.
3form 22 hours ago [-]
Well, I have not once found a single case where an app reacting to screenshots and controlling the process in any way was anything to me but hostile and annoying. This one does not help.
It somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes away at some point.
thepasswordis 22 hours ago [-]
It is actually astonishing to me that this is not something which can be turned off at the OS level, or as a permission setting in the app permissions.
The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
CircuitSeuss 22 hours ago [-]
> The app knowing I took a screenshot feels adjacent to me to a keylogger.
To my knowledge, this is a misunderstanding.
The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information.
This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
This prevents us from taking scrolling screenshots (a native feature in many smartphones today that is often useful when there is more than one screen of content).
I dislike this hijacking for that reason and wish there was a way to turn it off.
snailmailman 20 hours ago [-]
Spotify uses this and it annoys me all the time.
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
MBCook 18 hours ago [-]
I’ve seen another app do that but for a different reason. It’s for security cameras and they use it to show a “hey idiot just press the save a picture button, don’t take screenshots” popup, which is also hostile.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
bspammer 12 hours ago [-]
Yeah it’s Snapchat. If you take a screenshot of a (potentially extremely private, intended to be ephemeral) image, it notifies the person who sent it.
albert_e 12 hours ago [-]
Anyone can take a "snap" of the phone screen with another phone's camera so this is a losing battle anyway.
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. But same browser running incognito on a desktop can be merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
MBCook 8 hours ago [-]
Actually I was referring to the Eufy app. How nice there are others.
TeMPOraL 13 hours ago [-]
> I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
MBCook 8 hours ago [-]
No, that feature long predates Snapchat. In fact, I think it predates iOS, but I don’t remember for sure.
smelendez 17 hours ago [-]
Yes, it is very annoying. But I think they are already tracking you.
They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.
CircuitSeuss 19 hours ago [-]
Very interesting!
Parent poster is correct, that notification does feel akin to a key logger… although I’m not sure that it applies to this bluesky feature.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
MBCook 18 hours ago [-]
Correct.
Though I don’t see how this is anything like a keylogger.
chrsstrm 21 hours ago [-]
"The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager"
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
MBCook 18 hours ago [-]
The OS notifies the app after the screenshot is taken. The app doesn’t get to do anything in response to it being taken or allow it to be blocked.
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
> This is the same technology that prevents you from accidentally screenshotting your password manager
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
EGreg 19 hours ago [-]
Why is this feature bad?
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
nemomarx 18 hours ago [-]
One user wants it not to be shared, but the other user might have various reasons to want to take that screenshot - maybe it's evidence of something they need to share urgently with others, whatever. It's definitely hostile to that other user. I get why you'd set it up that way, but it's a tension that really goes against the "full control of your own device" ideal a lot of people have.
stronglikedan 18 hours ago [-]
Don't send me anything you don't want screenshotted. Easy-peasy. I'll accept an opt-out of whatever protections are in place for the general user, but I don't accept that those protections should remain in place for all users. It's hostile.
_carbyau_ 18 hours ago [-]
Honestly, even schoolkids know to have another phone/camera(usually a friends) take a picture of their phone screen.
In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.
If you send it, it is no longer yours to control.
If it is my phone, it should be mine to control. Too often it really isn't my phone...
zahlman 3 hours ago [-]
If you can't trust the intended recipient, a secure communication channel is pointless.
seany 18 hours ago [-]
It's mostly dumb because of obvious analog loop holes. I at minimum carry 4 devices with cameras, often as many as 12. If I want to capture the disappearing message... I will do it; making it annoying just makes me pissed at the developer + the is.
runako 18 hours ago [-]
> Yes, and I would say it's a bad thing that the OS tries to prevent this.
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
ryandrake 4 hours ago [-]
The user should be the ultimate authority of what their computers do, not the app developer. It's my phone, not the app developer's phone. If my phone has a "screenshot" function, I expect to be able to invoke it whenever I want, not whenever some app developer deems it OK.
runako 1 hours ago [-]
I hear your perspective. I am not particularly advocating either position. I am just pointing out that the alternative may be fewer apps available on one's favorite platform. Everything is tradeoffs, and fortunately one can always boot into an OS that will screenshot how you want.
ruszki 16 hours ago [-]
But… but they allowed. For a long time. Netflix didn’t need that.
runako 6 hours ago [-]
Incorrect. There's a log written about this on the Internet. Suffice to say that Netflix did not allow all of their titles to be viewed on all browsers for years after it was technically feasible.
akersten 21 hours ago [-]
Neither of those use cases seem good or tasteful to me as a user, I don't think this concept of "secure (from the user) context" should exist, but maybe that's just me
stronglikedan 18 hours ago [-]
> This is the same technology that prevents you from accidentally screenshotting your password manager
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
Barbing 21 hours ago [-]
Can Snapchat no longer inform the other user when a screenshot was taken?
jambalaya8 20 hours ago [-]
can someone just take a picture of the phone with another phone, or use a screen recorder?
computably 20 hours ago [-]
Security is never absolute, it always "merely" raises barriers.
jambalaya8 19 hours ago [-]
lol. downvoting on this is quite dumb.
pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.
RIP rational.
Barbing 19 hours ago [-]
mmm on average we’ve probably considered the photograph of a screen, and we were focused on:
>To my knowledge, this is a misunderstanding.
re: an OS informing an app of a user action (but didn’t downvote ya)
jambalaya8 19 hours ago [-]
the other device then likely indexes it after a brief once-over by its own ai-enabled os. any crossover interactions, and it may as well be the same device. maybe some of you have not experimented enough with the theshold to have noticed yet.
Barbing 18 hours ago [-]
Able to elaborate for me?
applfanboysbgon 20 hours ago [-]
I think bsky's use of this malware feature is as benign as it's possible to get, but it's still a malware feature. As you point out, the real reason this exists is to enforce DRM and make your computer serve Netflix et al rather than the person who owns it.
> accidentally screenshotting your password manager;
I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.
19 hours ago [-]
CircuitSeuss 19 hours ago [-]
As with most things, it would be ideal if we could have both good defaults to make things accessible and advanced user controls to allow users to retain control.
That’s a rare mix these days.
MBCook 18 hours ago [-]
People like to say that. How many hundreds of additional options would a modern phone OS need to provide that though? How could applications possibly be tested?
You could have a million installs and 300,000 of them could easily have fully unique combinations of options past what’s available today.
How could you ever provide support to a user? “First take 200 screenshots and send those to me…”
raincole 21 hours ago [-]
> The app knowing I took a screenshot feels adjacent to me to a keylogger.
That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.
echoangle 21 hours ago [-]
But for completeness, iOS apps can detect screenshots. That’s what allows them to show annoying popups with a share option when you take a screenshot.
edoceo 21 hours ago [-]
What? App-B on iOS knows when I'm taking a screenshot from App-Y? I don't have iOS to check but that seems crazy.
echoangle 20 hours ago [-]
No, I was talking about App Y knowing about a screenshot you take of App Y.
Isn’t that what everyone is talking about?
albedoa 19 hours ago [-]
Yes, that commenter is lost.
efskap 21 hours ago [-]
I guess it would need permissions, but you can monitor the photo library with PHPhotoLibraryChangeObserver and check if a new item's subtype is photoScreenshot.
Otherwise userDidTakeScreenshotNotification only fires for your own app
but you didn't read the part where the mechanism is explained? it doesn't do anything like capturing information. it just marks a button "sensitive" causing it to be hidden in a screenshot, thus revealing an icon that was put there underneath the button.
araeyn 22 hours ago [-]
Did you read the article? Bluesky doesn't know you're taking a screenshot, iOS just hides the follow button in the screenshot (consequently making the Bluesky logo visible).
LPisGood 21 hours ago [-]
iOS does tell the app that a screenshot was taken though
verdverm 21 hours ago [-]
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".
Found in the HN commenting guidelines, linked at the bottom of most pages
araeyn 15 hours ago [-]
Noted, I'll keep that in mind when commenting in the future.
fer 22 hours ago [-]
> hostile and annoying
If someone from Google Maps or LinkedIn team is here, please, when I take a screenshot it's because I want to a screenshot, not share the friggin location/post.
Not sure who got the idea that it was useful, it isn't.
mikepurvis 22 hours ago [-]
I would happily use the Google Maps "share" feature, but I've yet to encounter any but the simplest of scenarios where it actually preserves the entire context of what I'm trying to share: the viewport, the start and destination, stops along the way, route choice, the time of day, all of it.
If I'm sending a screenshot it's because I want to send exactly what I see on my screen and not have my recipient's gmaps instance happily recompute a route it thinks is better or leave out the routing information I included, or switch from biking to driving directions, or whatever else.
Waterluvian 22 hours ago [-]
It's of course about lock-in. In the early Web-GIS era there were a few competing but popular notation standards for sharing lat/lon/zoom/<sometimes more> that was meant to be human readable and compatible with any WMS or similar.
Ah... to imagine a world where you could just share a coordinate string and people could open it in whatever map app/page they wanted. Geo URI is probably the closest we have today but I don't think much of anything outside the OS Geo community accepts it.
mikepurvis 21 hours ago [-]
I think that's actually a separate issue. What I specifically want from a Google Maps share URL is for it to be something I can send over text that will reproduce for my recipient exactly what I see.
A lat/lon/zoom/start?/dest? is kind of what a Google Maps share currently is, but it's neither an interoperable standard nor a reliable capture of the current state, so really the worst of both worlds.
(Also, hi AB! Nice to see you on here)
Waterluvian 21 hours ago [-]
Hi! I think I’m on the same page (give or take a zoom level) now. That is hard to do between separate geodatabases (hence CRS, placenames, geocoding, etc.) but Google isn’t even doing it within their own. And the only way I can obtain a link is to first place a pin, which wants to snap to nearby features. If I try to link a nice trail near my home it snaps to the quarry instead, making me look like a maniac with a terrible idea of what a “quiet walk” looks like.
mikepurvis 17 hours ago [-]
I've noticed similar things with off-road biking as well. Hydrocut generally does an okay job of snapping to the trails there since Google knows about them, but I was at Rondeau this weekend, and Google kept insisting I was on the adjacent Lakeshore Rd rather than the Harrison trail [1] that I was actually on. And this had real consequences because my youngest and I had become separated from the rest of our group and were trying to use a "share my location" through Signal, but the Android system-supplied location used was the one that had been unhelpfully snapped to the road.
The other reason someone might want a screenshot specifically isn't to share a location, but to share a route. For instance, I might want to text a friend a screenshot of my driving route. Maps can sometimes route weirdly, so this is definitely a use-case I've needed before.
I believe it was their response to what3words. It's not as good at the "communicating by text" use case as what3words.
20 hours ago [-]
KennyBlanken 19 hours ago [-]
I have a seething hatred for google maps links people send on mobile because Google no longer shows you the map in your mobile browser. It has for at least a year or twoo required Google Maps be installed to show you what the person linked to.
umeshunni 22 hours ago [-]
Today I noticed that Amazon Pharmacy decided to blank out my prescription info that I was screenshotting to send to my doctor. WTF.
AshamedCaptain 22 hours ago [-]
From the same lunacy that forces me to write my 30-something character Wi-Fi password on a "secure password field" that only shows me the last character, almost ensuring that I will make an unlimited number of typos and spend way too much time for something that should only take 30 seconds.
It's not clear who it is protecting against, it does not seem to be effective at protecting against anything at all, it is actively annoying to the user, and has no way to disable. Perfect example of the usual "security theater" feature.
zrobotics 19 hours ago [-]
That seems oddly user hostile for apple. Especially for Wi-Fi passwords, which are a very common thing to share. Android has had a feature for years that generates the password as a plaintext-encoded QR code so you can share a wifi password without the other party even needing to type it in. And at least on my pixel 9, I have a toggle on the password entry field to toggle visibility.
I don't have an iOS device handy to compare against, but it surprises me that Apple wouldn't also recognize that Wi-Fi passwords in particular are extremely common things to share.
Barbing 21 hours ago [-]
Super secure!!1one
Unsecure: open Shortcuts, tap Gallery, search “Adjust Clipboard”. Add to Action Button folder and run from Action Button. - Or add “Dismiss Siri and Continue” action after “Get Clipboard” so you can say “Siri, Adjust Clipboard”.
Type in the still-unreasonably small window, tap Done, paste password. (Then clear clipboard I suppose and consider privacy implication if your clipboard syncs to Mac.)
doc_ick 21 hours ago [-]
.
Barbing 21 hours ago [-]
Was referring to the other point.
Could write my own phone operating system to not be subject to the iOS WiFi password field display settings though!
doc_ick 20 hours ago [-]
.
Barbing 20 hours ago [-]
Just need some help mining the ore to make sure it’s conflict free (OK would actually really like that if it were possible!)
20 hours ago [-]
Barbing 21 hours ago [-]
Apple gave too much power to iOS developers. They can use DRM strong enough that when your iPhone is open in iPhone Mirroring on your Mac, and you record your Mac screen with a third-party tool, the iPhone screen is blacked out.
wolvoleo 22 hours ago [-]
And if you take a screenshot of a product in the Amazon app it hijacks that and copies a link instead.
jerezzprime 20 hours ago [-]
I bet this is the inverse problem. Someone thought "oh a prescription is definitely privacy sensitive information, I should ensure the OS does the right thing" not realizing this counter productive behavior.
smelendez 17 hours ago [-]
Yeah, health information is interesting in general because it needs to be kept strictly secret from unauthorized people, but people also often need or want to share their own information and have every legal and moral right to do so.
duskdozer 12 hours ago [-]
It's not about what you want. It's about increasing engagement with the Google platform
Barbing 22 hours ago [-]
Good thing if you have GMaps open to the directions list while driving and tell Siri to take a screenshot, it doesn’t throw up a full page of nonsense over your directions that only Voice Control (not Siri alone) or a [potentially nonexistent] passenger could close.
Oh wait it absolutely does.
Razengan 22 hours ago [-]
Blame Apple for even allowing apps to be aware of the user taking a screenshot.
Just like their iCloud Keychain API that lets apps secretly track users across app reinstalls and device resets.
bethekidyouwant 22 hours ago [-]
Getting your account back on reinstall is good
sfdlkj3jk342a 21 hours ago [-]
That's what a username and password are for. I'd rather not be forcibly tracked.
chongli 19 hours ago [-]
I have 200+ different passwords stored in iCloud Keychain, each 20+ characters long. How am I supposed to remember all of those?
Do you use the same password on every site? How do you deal with data breaches?
TeMPOraL 12 hours ago [-]
Major reason I don't use password managers that much.
> Do you use the same password on every site?
I use a password I can reconstruct in memory for sites I care about logging in by hand. If I don't, or don't mind resetting my password each time, I just use random garbage + whatever platform password manager is the one active today, with vague hopes that it'll still be there the next time I need to log in.
> How do you deal with data breaches?
Who ever cares about those? I'm yet to hear about anything impactful being released on those. It only matters if you actually do reuse the same e-mail/login and password combinations on both important sites and garbage sites. Which is something you should not. But 2FA and magic links tend to solve that vendor-side, these days.
nemomarx 18 hours ago [-]
You can just use your own password manager and it wouldn't automatically do anything to apps on reinstall, right? Or a physical notebook, maybe.
chongli 18 hours ago [-]
I’d love to have my own password manager that syncs between all my devices without relying on a third party server, but I don’t know of one. Do you?
A physical notebook is so easily lost I wouldn’t even consider it.
daleswanson 18 hours ago [-]
I use KeepassXC and Syncthing. It's not a single password manager doing both the managing and syncing, but it works very well, and I sync between phone/laptop/desktop without any third parties.
chongli 17 hours ago [-]
Do they work on iOS?
clort 13 hours ago [-]
Keepass database is an openly documented format, and there are several apps available on iOS that use it and can store the database in your iCloud (ie syncthing is not required, unless you need to sync to non-iOS devices)
Just search for keepass in the app store (Keepassium, KeePass Touch, Strongbox, ...)
chongli 10 hours ago [-]
I see there are a lot of Keepass apps in the App Store. How do I trust the developers not to steal my credentials though?
clort 4 hours ago [-]
I don't know about iOS but if it saves it to your Files and lets iOS deal with the synchronisation then it should not have any network permissions?
(I use KeePassDX from F-droid it does not have network permissions)
esseph 17 hours ago [-]
Great name.
Frank Dux was a fraud! :)
singpolyma3 21 hours ago [-]
It's massively confusing to users though.
OneLeggedCat 21 hours ago [-]
Maybe, so long as it's optional.
Razengan 22 hours ago [-]
I can fucking type my username and password, thank you.
And I prefer to see and choose the data an app stores on my fucking ICLOUD ACCOUNT. And fucking DELETE it when I want.
There's no way to do that from an iOS device.
doc_ick 21 hours ago [-]
.
Dylan16807 20 hours ago [-]
I thought your other comments about writing your own were sarcasm about how that's such a terrible situation if that's the kind of thing it would take.
But this one looks like you actually mean it? Yikes.
20 hours ago [-]
Razengan 20 hours ago [-]
Someone should follow you around saying that to you every time you complain about anything
19 hours ago [-]
water-drummer 16 hours ago [-]
How else are they gonna track you? Think of the big tech
shiandow 22 hours ago [-]
It still baffles me that it has become normal for an OS to place the wishes of an app above those of the user.
Hijacking the screenshot process is a privilege that you ought to be able to revoke, it's insane to allow software to be given more control.
And don't tell me it's anything to do with security when it can be circumvented in any number of ways.
TeMPOraL 12 hours ago [-]
> Hijacking the screenshot process is a privilege that you ought to be able to revoke, it's insane to allow software to be given more control.
It should not exist as a control in the first place.
I know it may sound absolutist, but the way I see it: if you allow this as a user-revocable permission, then the very apps that need to be screenshotted by users most often will be the first to refuse to work at all unless you grant this permission.
Screenshotting is an system operations level feature. Apps should be neither aware of, nor able to interfere with, a screen capture being taken.
javier2 22 hours ago [-]
Did you read the post? Nothing is hijacked, but its a trick where they render the normal button in a ui element for secret data, which is blanked by the system on screenshot, revealing the logo underneath. Its a reasonable feature, so its hard for apple to control it better or remove this.
xorcist 22 hours ago [-]
That is a lot of words just to make it sound reasonable that a page can be exempt from the underlying screenshot functionality. It isn't. Not without asking the user.
javier2 5 hours ago [-]
it isnt really. Im saying the feature is reasonable from Apple's UI elements, i wasnt saying the way Bluesky is using it is reasonable...
nemomarx 22 hours ago [-]
users should have some way to control if screenshots have secret data in them or not, really. what if I do actually need to preserve it?
edoceo 21 hours ago [-]
I like your idea. When the screenshot is taken a user can have an option: Include Secrets? And the Apps can only hint at what to hide.
Analemma_ 22 hours ago [-]
No, it’s not a reasonable feature. If I take a screenshot, I want the image to include what is displayed on my fucking screen, period. What is so difficult about this?
javier2 5 hours ago [-]
Im saying the feature is reasonable from Apple's UI elements, i wasnt saying the way Bluesky is using it is reasonable...
21 hours ago [-]
andai 22 hours ago [-]
When I take a screenshot in ChatGPT, it shows a "share this chat?" toast at the top.
The toast shows up after the screenshot, but my phones's long screenshot feature captures the top part a second time, so the top part of the chat becomes unreadable.
KennyBlanken 19 hours ago [-]
Yup, that's by design. They want to force you to "share" so they can both track who you interact with, and also try to convert the other person into a paying customer.
xnx 20 hours ago [-]
There should be a layer of user control where the user can make the OS lie to the app. The app has no need to know when a screenshot or recording is happening, what the real location is, what file system contents are, etc.
tchalla 22 hours ago [-]
Side note- The Screenshot culture itself needs to die, sorry. Many a time, a share button simply works. I don’t know why people would share a screenshot or a map instead of pin and share their location. Yes there are cases where a screenshot helps but majority cases simply is “come to this place” a which turns out to make more difficult because people apparently don’t know how to share locations with pin and share!
FridgeSeal 16 hours ago [-]
> Many a time, a share button simply works
It works! Unless:
- the person you’re linking it to doesn’t have an account on that platform
- you’re posting it in a chat, and the site doesn’t implement unfurls correctly
- the site shows a thumbnail on the link, but clicking on it gets hijacked by the “mAkE an aCcOuNt/ login here” shenanigans.
- you’re trying to link to something in context and the sites linking doesn’t support it
- the site is riddled with ads.
- the site is slow to load.
- you’re trying to save something and don’t want to have to load the site every single time in order to refer to it.
- any combination of the above.
dhruvrrp 21 hours ago [-]
Screenshots are much better for archival. So many times you go back to a url/link you shared, and poof it's gone or the content has changed from when you sent it.
Screenshots allows you to get a point in time reference to what you are sharing.
-0_0- 20 hours ago [-]
In the case of sharing a link I have to remember/find where it is in each app, likely scroll through a long list of messaging (and for some reason non-messaging apps) to find the correct app, select the contact, and then pray that the link sent actually works for them and contains the correct information I'm seeing (very often the link will actually direct them to a web version of the app I'm using, then put a modal popup in front of the information asking them to use the app, then either send them to the app store, or send them to the app but strip out the actual information I linked and send them to a blank map).
Screenshots are clunky and unideal, but at least they're fast and I know that they don't fail or break or send the wrong info to my contact.
If it were a one off message, this wouldn't be an issue, but if you zoom out on the issue and see you're sending up to a hundred messages a day, points of failure become major life frictions and you're trained out of using things like links in messaging apps.
jasonjayr 21 hours ago [-]
The ideal "World Wide Web" envisioned by it's original design, was that a URI was a durable pointer to an immutable piece of information.
In 2026, we now know that the information can be edited, or completely removed for many reasons, some legitimate, and some nefarious.
Taking a screenshot is the easiest way to ensure the original is kept for folks to see. Frankly, it'd be even better if (a) the app can signal to the OS information about the url to the page for the screenshot, (b) timestamps were captured in the image and not cropped, and (c) the OS can authenticate the screen shot and digitally sign that it came from an unaltered device.
RugnirViking 12 hours ago [-]
I totally disagree - the few times I accidentally use a share button, or are forced to use one, the experience is so desperately miserable I am forcibly reminded why I never use them. It's always several clicks, choosing the social platform I need from the millions-long-list which is paginated into pages of like 4 icons at a time (I just want a URL! but you broke your website to force users into the app!) and from there choosing a specific chat or group or whatever from a poorly ordered list that starts with some person I met at a bar twelve years ago rather than the chat I was literally just typing in two seconds ago...
and then when it does send I have no control over the presentation on the other side. Sites love to add some cringe "I love this app SOOOO much hearteyesemoji fire fire fire... sent from my iPhone, made with love in san cupertino" nonsense in my own voice - literally sending their words into my chats using my account, as though I had written their marketing dreck
qurren 21 hours ago [-]
I also despise this "screenshot blocking" stuff. A device listens is supposed to me, not to the apps. I want a screenshot to be a copy of the raw pixels, and an app should not know about it or have a right to know about it.
Of course this is doable on open source OSes like GrapheneOS, it just sucks that you have to keep modifying the OS every time they release a new version
hod6654 19 hours ago [-]
GrapheneOS doesn't allow for it. You'd need a rooted device to bypass screenshot blocking
qurren 14 hours ago [-]
Well damn, I would have thought rooting would have been a basic feature of GrapheneOS.
At least it's open source, so maybe one can add root access and screenshot blocking to it.
broodbucket 13 hours ago [-]
GrapheneOS is concerned with security more than anything else, to which rooting is completely counterproductive
summm 7 hours ago [-]
Correction: GrapheneOS is concerned with their so called "Android security model" more than anything else, and where that security model gives guarantees to app developers and service providers that harms the user's security, they merrily side with the developer's security against the user, at best give some more or less questionable reasons why that unfortunately currently cannot be changed, and at worst insult you for suggesting anything else.
qurren 5 hours ago [-]
I would think that rooting is not counterproductive. In fact my personal security model requires root access.
1. I need to be able to monitor what's inside the memory and communications of every process running if I want to
2. I need to be able to pin a different root certificate, install a MITM SSL proxy and see what every app is sending about me, if I want to
dev1ycan 20 hours ago [-]
This is what made me avoid chrome since release, I tried to right click a youtube channel background as a teen wanting to use it as a template to make my own channel background on photoshop... turns out they had disabled it, while I could on firefox.
21 hours ago [-]
bigyabai 22 hours ago [-]
> I wish, and wish only I can, that this trend goes away at some point.
You don't have to wish, in this scenario. Bluesky supports third-party clients, you can use one that has a more minimal featureset if you prefer.
drdexebtjl 21 hours ago [-]
For Bluesky, sure. I think the comment was aimed at the trend.
Android and iOS should not let apps do this, because it can be (ab)used by apps that you can’t really choose not to use.
I know there’s a popular bank in my country that completely blocks screenshots and screen recordings on Android somehow.
In USA Wells Fargo blocks it, so I can't get a picture of the bugs I'm trying to report.
21 hours ago [-]
jambalaya8 20 hours ago [-]
agree with you.
alasano 21 hours ago [-]
I hate the ChatGPT app and Spotify the most for their screenshot behavior.
internetter 22 hours ago [-]
Nobody in the comments talking about snapchat where like one of the core pillars of what "sets their service apart" is the difficulty of taking a screenshot without notifying the other party
Mtinie 21 hours ago [-]
Wasn’t that the entire premise of the product when it launched? Disappearing messages and minimal footprint so you could be confident your communications were semi-private?
That was the expectation of using the product so it fits and isn’t anything like this discussion.
TeMPOraL 13 hours ago [-]
Yes. And because of the platforms deciding to enable that business model, we're now in a bullshit reality where the very apps that need to be screenshotted most often, are first to abuse platform features and prevent screenshots from being taken.
This deserves a longer rant, but the very premise of Snapchat was always poisonous, and is largely responsible for why, 20 years later, we're now facing extreme proposals for regulating electronic communication.
I generally disagree with the whole line of criticism techies get for "solving social problems with technology", but if there's one unambiguous case where I'd agree it was plain stupid, it's the concept of screenshot prevention, that became prominent with Snapchat. Controlling whether your recipient gets to keep the message you sent them is a purely social problem, and the answer to that in the real world has always, for good reasons, been "once sent, it's no longer yours; once received, it belongs to recipient to do with as they please".
hypfer 11 hours ago [-]
> but the very premise of Snapchat was always poisonous
Wdym? Hooking (primarily underage) people onto "daily streaks" of sharing (often inappropriate) pictures of themselves to (sometimes random) other people via likely insecure servers is a _great_ business model!
Great customer retention. Lots and lots of engagement. So much shareholder value.
Oh and just think about how vulnerable they are. _Perfect_ for ads.
BasicallyBluesk 21 hours ago [-]
That plus product design.
Yellow.
They fuckin did it. Not construction not a warning of some type. Not yellow pages. Yellow - cool looking yellow.
Is what I said to myself as a 20-something product designer
ryukoposting 17 hours ago [-]
Their entire color story was really cool at the time. Yellow with Magenta/Blue accents was super bold, especially compared to the boring ass direction everything was going. Material and Windows 10 flatshit was all the rage and here comes Snapchat like the Kool-Aid man.
imfemambocus 8 hours ago [-]
Snapchat is just on another level when it comes to screenshots.
"Forget watermarks, I'm just going to let the person know! Ha!"
c7b 10 hours ago [-]
If you're mad at Bluesky for doing this, I think you're mad at the wrong party. Modifying intent is problematic and can be abused (although I think there's nothing particularly problematic about this particular instance). The real problem is that you have next to no possibility of modifying the behavior. On an OS that respects user freedom, there would by a myriad ways of intercepting what the software is doing to get your desired result. On iOS, you're at the mercy of Apple. I think we should be mad at Apple for normalizing a computing culture that views user freedom as a security risk, potentially something that should be outlawed (thinking of age verification).
rmwaite 18 hours ago [-]
On iOS, if you swipe control center down and then back up but don’t lift your finger, the screenshot will not have the logo. I do this with Twitter so my screenshots don’t have the X logo.
red369 14 hours ago [-]
Interesting that this works. I know I have been frustrated recently when trying to take a screenshot of a bank transfer or something similar, but I couldn't find which app that was to test again. I tested on the iOS Passwords app, and I couldn't get the trick to work in that. I wonder if I'm doing something wrong, or it only works in specific apps.
Each time I tried to take a screenshot of a password, the password was missing from the screenshot - even when I kept the control centre pulled down far enough that the Password app was starting to look blurry.
wraptile 14 hours ago [-]
This is why pocket computers are still so unserious. My programs should not be aware let alone respond to my administrative actions like screenshots.
8-prime 11 hours ago [-]
Not only 'pocket computers' are an issue.
I was thoroughly shocked when I found out that websites can detect that the dev-tools are open. That is something that a website should never be able to know, yet here we are.
backwardsponcho 9 hours ago [-]
I ran into a government site that not only was aware of the devtools being open, but also stopped virtually all user actions if it did. And it worked quite well- to bypass it, I had to block the detection script from loading altogether since merely removing the event listener didn't work.
ShadowOfThePit 9 hours ago [-]
I ran into a different site where every single action had a debug breakpoint pausing everything if you had devtools open. Luckily, you can disable breakpoints.
voidUpdate 13 hours ago [-]
They don't respond to it. It simply says "this button is part of sensitive content", and the OS itself hides the sensitive content, revealing the image below it
RugnirViking 12 hours ago [-]
have you never encountered the plague of apps saying "don't screenshot, our content looks so much better when you share it, see:" and then displaying a picture of the stupidest looking thing youve ever seen in your life as though you would ever consider showing that to your friends instead of the most personal thing - literally showing them what youre seeing with your own eyes
voidUpdate 11 hours ago [-]
No, and that's not what bluesky is doing
Laurel1234 12 hours ago [-]
[dead]
_djo_ 22 hours ago [-]
X and Threads do this too. I wish they all wouldn't, messing with screenshots should only ever be done when preventing them as a security measure.
dvngnt_ 22 hours ago [-]
They shouldn't even disallow screenshots from a security measure. If the user wants to take a screenshot of their bank account info or a password manager they should. Maybe an additional permission for screenshare. No device has protection against a second device taking a recording so it's really just security theater
spaqin 16 hours ago [-]
It's all "security" and all until your banking app has a bug that breaks exporting bank statements and the only way to get it out is to take screenshots - which are blocked as well. Oh, and you need to submit it by today.
At least on rooted Android devices you can bypass that.
wolvoleo 22 hours ago [-]
Even preventing them shouldn't be possible. It's just security theater anyway. You can easily capture it with another camera.
kps 19 hours ago [-]
Until the big players agree on a watermark that their cameras will refuse to photograph.
FinnKuhn 22 hours ago [-]
Reddit as well. Although they let you disable it from what I remember.
chewbacha 10 hours ago [-]
Actually, I’m a little worried by what this post demonstrates but not the logo or the use of the api.
I’m worried that switching apps and screenshots _doesn’t_ put the logo in. If the point of the switch is privacy, isn’t that a bug? Shouldn’t it apply the privacy screen during any screenshot? What if there was sensitive information on there when you were switching and taking the screenshot?
godelski 20 hours ago [-]
I'm confused why people are mad at Bluesky for this. Everyone stating their issues seems more related to Apple than Bluesky. So why point the finger at them?
serial_dev 19 hours ago [-]
I don’t think a significant percent of real Bluesky users actually care.
Having a follow button on the screenshot brings nothing and a logo is helpful when sharing (“hey it’s not twitter, I know it looks like it but it’s bluesky”) and looks subtle.
It’s just it’s a forum so people say things for discussions sake and get outraged by anything that a platform they don’t like is doing.
whitenoise7 17 hours ago [-]
> a significant percent of Bluesky users
42 of their 56 active users might not care about a watermark but god dammit do they respect it
And so should you
saagarjha 18 hours ago [-]
Bluesky didn't have to use this API for this purpose.
godelski 15 hours ago [-]
Okay? Is the purpose bad? Leading to bad things? What's the problem
19 hours ago [-]
KeybordWarrior6 19 hours ago [-]
[flagged]
0xferruccio 22 hours ago [-]
To be fair this is useful for discovering bluesky from screenshots getting posted on other platforms.
Their product UI kind of looks like X, so it's helpful to know the source of a post
grim_io 22 hours ago [-]
I don't think anyone doubts that it benefits the company.
mulmen 22 hours ago [-]
If only there was some uniform way to identify a resource. But it might lead people out of the walled garden so best not to risk it.
pastel8739 19 hours ago [-]
Or, in the case of X, into the outside of the wall of the garden with no way through
shepherdjerred 17 hours ago [-]
This is a pretty cool, harmless hack honestly. I don’t see how you could be mad at it.
expedited123 15 hours ago [-]
It feels restrictive, especially since it’s part of a broader pattern of limiting user freedom on platforms. For instance, on PC you can't simply right click on a video and save it on bluesky. They add some frontend bullshit to prevent you from doing that. On "new" Reddit I remember when you saved an image it would always have a watermark on it. On PC, you can't preview the raw image/video either. On Instagram you can't save images at all easily. Cant view content without being logged in, etc.. Now contrast this with platforms like Mastodon where I can do whatever I want with the uploaded media there and there are barely any such restrictions.
demux 4 hours ago [-]
The data is publicly stored on [publicly accessible servers](https://atproto.wiki/en/wiki/reference/core-architecture/pds) so you can indeed do whatever you want with the uploaded media on BlueSky as well. Not to mention that if you care enough about this issue, there are numerous alternate clients to access BlueSky.
p0w3n3d 14 hours ago [-]
First - it's great that people can't take screenshots of their sensitive data by accident
Second - I hate when my device keeps me from anything. I'm used to have control over my computer, and this is outrageous that I can't take screenshots of anything I want. There should be a god mode or something like that.
bouncycastle 15 hours ago [-]
Dear app developers: please do not detect screenshots, and do not change behavior. It is my phone and I should have the right to save anything on my screen for my own purposes and you should not know that I do that.
wraptile 14 hours ago [-]
This complaint should be aimed at operating system developers who should have never allow such infringement to begin with.
wmichelin 18 hours ago [-]
I know of social media sites who have kept an untracked version of the link in the dom of the A tag, but replace it with their in-house link tracker copy of it as you're clicking, that way the destination looks correct when you hover over the link.
tgv 15 hours ago [-]
A simple call to get a list of sensitive screen areas would suffice. Add a bunch of options to make everybody happy, but don't allow replacement with different content.
thomasnowhere 10 hours ago [-]
[dead]
asdfsa32 19 hours ago [-]
This is an interesting case of "Good use" of a "bad feature". This feature is bad because it works against the user and device owner, but this use case like hiding your password when sharing your screen is a good use case.
47282847 7 hours ago [-]
I am not a Bluesky user, but it looks like it actually serves a privacy-preserving purpose here - whether the person is following the account or not. Were it not for the name of the module, I wouldn’t see any nefarious action here.
That said, operating systems should turn this into a user choice, and present a dialog to select the “protected” version or not.
motbus3 14 hours ago [-]
Unfortunately way more applications inject some sort of info into the image using noise of alpha channels when you take a screenshot...
Ofc you shouldn't be doing anything wrong, but let's say you join a court and provide some evidence in confidence, you can be found if that evidence is shared with both lawyers
ErigmolCt 15 hours ago [-]
Once apps can present one thing to the user and another thing to the captured image, there are some pretty weird possibilities
radicalriddler 15 hours ago [-]
LinkedIn’s job screen in the app is a good example of this different presentation.
I’ve noticed a certain AI recruitment company gets “highlighted” (darkened white background of the screen, but their logo is pure white and REALLY stands out), but when I screenshot it, it reverts to normal, like there’s no blatant special advertising.
CGamesPlay 14 hours ago [-]
Different underlying mechanism. The LinkedIn one (and almost all ads on Instagram/Facebook these days) use a gain map to increase the brightness of the image. Here's a site demoing the tasteful application of this [0], you can see the difference viewing it live versus taking a screenshot of the result.
Like adding some nice fingerprinting. I really feel my devices work against me. Nothing works for me.
Insanity 4 hours ago [-]
That's smart, I quite like that approach. And it's a subtle enough logo that it wouldn't bother me on screenshots either.
zzo38computer 21 hours ago [-]
If the feature can sometimes be useful (including this situation, which some other comments mentioned; but also for other things such as hiding actual secure data), then perhaps it should be made as a setting which can be changed in the setting menu (e.g. "Exclude secure data from screenshots"; it should also mention which apps use this feature), so prevent abuse. (This would also make it clear what the feature is, as well as being able to disable it.)
akersten 21 hours ago [-]
That such a setting does not exist suggests the feature's true purpose is not for the end user's own benefit!
hk1337 7 hours ago [-]
The overall sentiment is that everyone is okay with Bluesky adding a watermark while a few days ago they were up in arms about Claude adding a watermark?
It seems more appropriate for Claude to do it seeing as it generated the image, all Bluesky did is provide the platform to post it.
This sort of stuff to me is an example of fear within an organization. Whenever I see engineering resources allocated towards self promotion and branding rather than quality and features for its users it shows how leaders want control over narratives.
skupig 22 hours ago [-]
It's equally possible there was one engineer with some free time who thought it would be cool.
AlexAplin 21 hours ago [-]
It's probably silly to make OP's judgement of any of these implementations in isolation, but you can sense a real fear about the growth (or lack thereof) inside Bluesky. Fiddling with the presented metrics (likes count getting moved ahead of reposts), promoting total user signups while being silent on collapsing DAUs. They are promising a lot at once with AI custom feeds from Attie and subreddit-style communities that smells like feature creep.
pfraze 21 hours ago [-]
Your indicators that we're afraid about growth is that we're shipping features and experimental new products?
AlexAplin 20 hours ago [-]
They aren't my indicators, but they read as sweat against the observable metrics being in decline. There is a perception that they want to pull on users outside of Bluesky that I don't really think exist, and I guess I share in that feeling when I believe the core still has so much basic parity missing with X et al that would demonstrate confidence in the current users you already have. Still interested to see what they ship as.
21 hours ago [-]
mozzius 15 hours ago [-]
This is correct. I was tired of Bluesky screenshots looking bland, no culture of fear needed
armadyl 3 hours ago [-]
I agree with you. It’s a nice touch.
I also have no issue with the API, people here are definitely overreacting to it’s existence.
Larrikin 22 hours ago [-]
Implementing a watermark isn't a thing anyone thinks is a cool feature they want to try out.
paimapi 22 hours ago [-]
what do you mean, it's a very normal cool thing that everyone loves
Sent from my Ryobi Riding Lawnmower
singpolyma3 21 hours ago [-]
I mean. I read this and immediately thought it was a cool thing I'd like to try out
Larrikin 21 hours ago [-]
By the end of your first year in CS you will have hopefully learned enough to place an image on something, that's about as cool as it gets.
398642258909 21 hours ago [-]
Adding a watermark, how radical, dude
hmokiguess 22 hours ago [-]
And such engineer would have enough organizational clout to just ship it without going through anyone?
rbaudibert 22 hours ago [-]
That's how a modern organization works. You trust your colleagues will do good work, and will ship something useful and there's not really "someone to go through".
I agree this can be defined as cool and very very likely someone did this on their free time/prompted Claude on the side.
hmokiguess 22 hours ago [-]
It's a Series B company, it needs to make money, and they have to answer to a board and provide information to investors. They have a roadmap, direction, and leadership. Yes, trust and good intentions is an awesome thing and I hope they have that indeed, but I would think reality lies in the middle of both sides.
rbaudibert 22 hours ago [-]
I've worked at a Series B company and reality is this is too minor for investors to care on its own, and it's also very hard to correlate this change to new revenue, so not something that's likely to have been done with that intention
hmokiguess 20 hours ago [-]
I guess we had very different experiences. Maybe it’s the B2C industry or these free apps
Bluesky has <100 employees so it could be possible
hmokiguess 22 hours ago [-]
I agree that having less people to manage means easier to build trust relationships and culture, though I believe some form of management and control must exist.
pfraze 22 hours ago [-]
I'm sure this wasn't even in the top 10 of things that we made sam implement out of fear
whyrusleeping 21 hours ago [-]
Yes actually Sam often ships random fun things he feels like doing.
Slurpee99 22 hours ago [-]
You're fun
jdgoesmarching 18 hours ago [-]
Marketing, like every other functional part of a business, requires technology and engineers. This has nothing to do with fear, you just don’t respect non-engineering work as critical to running a business.
haileyok 22 hours ago [-]
Someone spending half a day on a feature that places the app's logo in the screenshot so people seeing it can know where it came from is "fear within an organization"? You've got to be kidding lol
> The “Follow” button is visible when I take the screenshot mid-switch.
Does this indicate that the privacy feature has a gap, where you could reveal the length of your password if you take a screenshot mid app switch?
tom1337 21 hours ago [-]
No because per default the input is not cleared when screenshotting. If you‘d implement this yourself for security reasons you'd most likely blur / overlay the whole screen when the app enters background state.
OJFord 21 hours ago [-]
Probably, but to the extent that was at all a problem to begin with, multiply it by another 0.0001 or whatever for the threat of the screenshot being taken mid switch away!
TeMPOraL 13 hours ago [-]
Reading between the lines:
Oh, so you can take screenshots of the content that tries to avoid it if you do it mid-switch?
If it's reliable and WONTFIX, that's almost enough to get me to switch away from Android.
Screenshot taking prevention is harmful and should not have ever been allowed to become a platform-level feature in the first place. Because if there's one rule of platform/client interaction, is that if you add a feature that can be abused against customers for stupid reasons, it will be. There's a number of apps I have on my Android phone that block screenshots for dubious reasons, that can be maaaybe charitably explained by calling them "growth hacking pretending to be a security feature", but in some cases even that's a stretch.
This feature should never have existed in the first place.
(At least Bluesky is open about it, both by being Open Source and calling out the "growth hack" by name in source code.)
phillipseamore 21 hours ago [-]
If not for the function being named "GrowthHack" I would have thought that hiding following status for screenshots to be a good privacy measure. They don't use it to hide anything else and since I'm not a user of the app I don't know if there is more extraneous information that could be used to infer or track down who screenshotted and they don't hide.
kimos 22 hours ago [-]
Perplexity does this on web by adding a logo in response to key combos for normal screenshot shortcuts.
This trick was almost certainly invented by Nikita Bier when he joined X.
ebbi 22 hours ago [-]
X does the same thing.
Jonovono 22 hours ago [-]
Just since Nikita joined (altho now he's gone, doubt they will remove it tho)
thn-gap 13 hours ago [-]
I only ever used bluesky/twitter via web app on my phone, and stuff like this affirms that it's the right decision.
vachina 20 hours ago [-]
This is why I use the browser version for anything. I’m using an actual user agent.
HelloUsername 14 hours ago [-]
I was wondering about this as well; did they only test with the official iOS app? Or also through a mobile webbrowser?
socalgal2 19 hours ago [-]
They're just following Apple's lead.
When iPhone shipped, any time you emailed a photo it would append "Sent from my iPhone" to try to virally market. Same or at least similar slimey tactics
doublepg23 19 hours ago [-]
There was at least a fig leaf of “I’m typing on a mobile keyboard” excuse my typos”.
rmwaite 18 hours ago [-]
That’s just an email signature, configurable (or removable, if you prefer) by the user. This is completely different, in my opinion.
The-Bus 6 hours ago [-]
Uber is another example of an app that is actively hostile when I want to take a screenshot. Let's say I'm calling a call for someone and want them to know what car it is, driver's info, etc. Uber doesn't let me do that, I have to "share" the result with someone.
The workaround is letting that person take a photo of my phone, which is lower quality.
21 hours ago [-]
ahoka 13 hours ago [-]
This technique would be devious if applied to a QR code.
Does anyone know a way to do this for a computer? I built a p2ppoker website the protects the shuffle from the server but I would like to blank the cards on screenshots to prevent huds and AIs from making the game unplayable.
mwmiller 17 hours ago [-]
I’m interested in reading more about this. how does p2ppoker work out?
whalesalad 21 hours ago [-]
I’ve noticed that if you screenshot a thread in the threads app an “@threads” logo appears in the upper right corner
lukeholder 22 hours ago [-]
Tiktok has been watermarking videos since the beginning.
garyhasapoint 22 hours ago [-]
has this guy lived on a rock? reddit/twitter/etc every social media platform does this already.
mozzius 15 hours ago [-]
the difference is those apps aren’t open source so you can’t go explore how they work
wolvoleo 22 hours ago [-]
It's pretty likely that bluesky users aren't on other social media. Because it pretends to be better than them (this shows it isn't really, though)
pfraze 21 hours ago [-]
I know you don't think it's bluesky, but which app do you think is better at putting its logo on screenshots?
drbscl 11 hours ago [-]
That's not what the other commenter is saying. The other commenter is stating that by doing this logo trick, bsky is very similar to competing platforms
I think RevenueCat does the same thing. Smart way to exploit network effects!
globular-toast 15 hours ago [-]
> Thankfully, I remembered that Bluesky app is open source (or at least the code is available to look at).
What does the author mean by this? I checked the repo and the project seems to be MIT licensed, which makes it open source.
amelius 10 hours ago [-]
Another reminder that you don't own your phone.
mrdoe 11 hours ago [-]
Why would someone use Bluesky? Isn't that a cesspool of the same midwit scolds, purity spirals, and performative outrage that made Twitter unbearable before the great migration?
zyvop1 11 hours ago [-]
I use bluesky for cross posting my blogs
22 hours ago [-]
adolph 22 hours ago [-]
Example n+1 of why I only use web and not download an app
ctdinjeu9 17 hours ago [-]
[flagged]
shevy-java 15 hours ago [-]
Companies always want to slop-spam their logos onto everything. It is a very annoying habit. On youtube videos this is even more annoying; several use floating logos.
Razengan 22 hours ago [-]
As Spring inevitably leads to Winter, and Night follows Day,
Thus the Inevitable Enshittification of all Centralized Platforms
Healer_0 7 hours ago [-]
[flagged]
jocelyner 15 hours ago [-]
[dead]
PrimeAli 17 hours ago [-]
[flagged]
winterqt 22 hours ago [-]
This is arguably missing the "how" from the title -- can someone fix?
CaliforniaKarl 22 hours ago [-]
The best way to ask for this is to send an email, to the email address which you can find at the bottom of the page (click on "Contact"). There's no guarantee that the mods will find your comment otherwise.
FinnKuhn 22 hours ago [-]
@Dang: I would like to report an innocent victim to the automatic "How"-Removal.
altairprime 22 hours ago [-]
Saying @dang has no effect; it does not activate a batsignal or any other mechanism of mod summoning. The only way to be sure a mod see this is to email them; see the contact link in the footer and include a link to the comment.
madhu_ghalame 14 hours ago [-]
[dead]
pranav_tech26 16 hours ago [-]
[dead]
pranav_tech26 21 hours ago [-]
[dead]
hn2crljhhy 10 hours ago [-]
[dead]
winningChild 22 hours ago [-]
[dead]
jheriko 19 hours ago [-]
[dead]
yesyoudo 20 hours ago [-]
[flagged]
KeybordWarrior6 16 hours ago [-]
[flagged]
BasicallyBluesk 21 hours ago [-]
[flagged]
pfraze 21 hours ago [-]
We really need better haters
yesyoudo 20 hours ago [-]
Really, can’t find any on a network as vast and populated as Bluesky??
Where anyone can say anything?
Maybe it’s so decentralized there is a dark web within BlueSky now! DarkSky
yesyoudo 20 hours ago [-]
Firehose -> Shadowhose
Now anyone can access the decentralized shadowhose from our server
whyrusleeping 20 hours ago [-]
“ and another thing: im not mad. please dont put in the newspaper that i got mad.”
yesyoudo 19 hours ago [-]
I’m not mad, Paul frazee is fucking MADD
Mothers Against Decentralized Development
He’s a madd mother, fucker
violetthreads 17 hours ago [-]
Shill News
jadengeller 21 hours ago [-]
Tangentially, I see a lot of people here upset that apps can react to your screenshot before it is captured. I think it is helpful to think about it as a tradeoff between freedoms:
(a) the freedom to screenshot any content on your own device
(b) the freedom to share content with others that cannot be screenshotted
It can be annoying when DRM or privacy features block a screenshot, but I think it can also benefit the platform ecosystem that you participate in as a user too. Idk!
Dylan16807 20 hours ago [-]
B is an illusion, and it seems like about 90% of the time it's used for dumb or bad purposes even if it did work.
nxc18 19 hours ago [-]
Locks can be picked. We still make and use locks.
Dylan16807 19 hours ago [-]
If a type of lock was overwhelmingly used for bad reasons, and only worked when someone didn't cover their hands (analog pictures), I'd be arguing against that type of lock too.
nxc18 19 hours ago [-]
Is it a “bad reason”? Millions of people chose to use Snapchat specifically because of how it handles screenshots. It is a feature even if you don’t like it.
Many people would find it inconvenient to find another device to take a picture with. And that manual picture would then have baked-in evidence that it was taken surreptitiously.
Locks keep honest people honest, as long as the app is up front about it and lets users make the choice, I don’t mind.
Dylan16807 19 hours ago [-]
I said 90% and not a higher number because of Snapchat. It's not the example of bad reasons.
Nobody deliberately opted in to random information hiding in a more general purpose app, or watermarking, or DRM.
nxc18 15 hours ago [-]
Another view of it is that’s just a creative use of the medium. An interactive button doesn’t serve any purpose in the screenshot, so why not find a better use for that space.
When I’m in Safari, taking a screenshot can turn into a totally separate operation (full page scrolling screenshot) and that’s a good feature.
Others complain about Google Maps showing a popup telling the user about location sharing upon screenshot - I think that makes a lot of sense, considering it doesn’t show up in the screenshot and dismisses easily.
I’m very harsh on user hostile choices, in fact I spend a lot of time ranting and raving about it, but I just don’t see that here.
Dylan16807 15 hours ago [-]
The ability to show exactly what you had on your screen is one of the biggest uses of screenshots. The ability for apps to do this kind of thing breaks that use.
Offering something better can be valuable (sometimes) but don't alter the screenshot itself.
I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content.
There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people are dogmatically opposed to intent being modified, but I think you need to balance nuance. I actually enjoy having an attributable source in shared elements, and I think this is a low-impact way of achieving that.
It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.
Very frustrating.
This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.
I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.
However, my idea happens to hit a very new limitation: for some reason, "privacy filters" are suddenly a thing. New phones have them built-in as some new magic display function, and for everyone else, there's this mad marketing push to get people to buy and use privacy foils in place of glass/foil screen protectors.
IDK what's up with those. Since when "shoulder surfing" with smartphones is a real problem, and why do marketers and product designers bet there's so much latent demand for it?
The "useful device" is a laptop.
In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
Banks are the canonical example - changing one is a huge hurdle, with consequences that can drag on for years. One by one, they're all ditching their websites (if they had one in the first place) in favor of apps. Even those with full-featured websites increasingly force you to use their app as the second factor to log in, confirm transactions, even confirm viewing some data. Some offer physical tokens, most don't advertise that, and it's only a matter of time before they convince regulators that Attested Phones are Safer and Everyone Has One, and that option will disappear. And because they want their app to be the second factor, they can argue it needs to be secure, creating demand for remote attestation, and boom - there goes your option to work around any other bullshit limitation they throw at you.
The day has only 24 hours, I don't want to spend them clearing bushes by walking off the beaten path wrt. every single important service - payment services, government services, IM services, ${whatever bullshit SaaS app I need right now because you're using it for the thing you just shared with me, and I need to view that}, etc. So I submit. So does everyone.
It's why I put blame on platforms here. Features protecting the device from the user should not be built in the first place - they always start justified by some legitimate security reason, and always end up broadly abused to serve business reasons.
Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?
I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.
It’s my phone, I want to decide what I take photos and screenshots of.
That's the crux.
Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).
Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.
Done.
Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".
Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.
It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later <tinyprint>0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry</tinyprint> ;-)" anyway.
Most of the time, people are given only two options: give up on their task, or ignore the popup. No point in reading the message in such cases, it brings zero value.
Repeated exposure built immunity.
You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.
The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.
Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.
We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:
Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.
--
[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.
[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
https://i.ibb.co/hRnn4ssF/2026-08-18-12-48-25.jpg
So yeah, I have a screenshot of the generic technician's ID photo, I guess.
Later on it did populate an actual name and photo when a human was assigned, but still, yeah, I don't get why they didn't just automatically redact it and just throw you the stupidest bullshit warning error ever on the honor system.
Very true.
> The right fix is selective redaction, not disabling screenshots everywhere.
That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".
GP is saying that BS gets a pass where X would not for a user hostile action.
I don’t use either platform, I have no interest in the debate. As an outsider looking in, the bias has been proven.
Not that it matters much, I am left-of-center generally speaking.
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
> "You're posting too fast. Please slow down. Thanks." = censorship. Unaccountable [flag] = censorship.
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.
It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show.
Bluesky, and apparently others, are abusing the functionality for advertising purposes.
I think it’s a good thing it’s there. This functionality should be easy for apps.
I’d say this is one for app review or an App Store rule. But we all know those are a total joke.
Why not ask contact for data via text and just copy paste it with double check?
For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!
--
[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, all text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.
2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.
Right??
Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose is to be a share target and dump the information to file (and being apps on an app store, chances are top 10 are just thinly veiled malware).
https://f-droid.org/packages/com.mateusrodcosta.apps.share2s...
https://github.com/MateusRodCosta/SaveLocally
They probably support proper export for business accounts. Business customers have leverage. Regular people? They're an annoying but necessary nuisance.
This exists for a very bad reason.
>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.
and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.
>I think it’s a good thing it’s there. This functionality should be easy for apps.
I think it's a bad thing it's there. The functionality should be easy for me.
So as much as a bank might agree with your stance on freedom of compute - they probably don't want to pay for it with actual money.
They really shouldn't be allowed to double down on it.
And arguably, half of it isn't even really security, it's about keeping you in their app. Application interface is the ultimate sales platform, and banks are making extensive use of that fact.
The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.
The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.
This is a failure of imagination for Apple, but it’s hard to blame them.
Who would think someone would put a button inside a “secure” text field and change the masked appearance to a logo?
If I was proposing this feature, I would never imagine someone would come up with something like that.
Your banking app probably has an option to disable that because it's a legal requirement in so many places: People who can't see need to use assistive tools, and that includes screenshots and friends. If you are using a tiny/stupid bank in the US, file a ADA claim and get some money. In the EU check your Ombudsman.
No, it's so you can't screen-record Netflix. The bank doesn't care about that because it's not a liability issue to them, just fetishism; no way they pay Apple and Google for this capability.
Apple and Google should step in and allow users to remove these shenanigans with a little button on the screenshot preview screen, but resist this because of Netflix et al.
The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.
And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.
That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.
I don’t accidentally take screenshots very often, though it does happen.
I know multiple people who seem to take them constantly. It’s crazy. You and I may not do it, but I promise you there are people who do. LOTS of them.
Now get off my lawn.
As it is, it is just an annoyance that requires you to do stupid workarounds like taking a photo of your screen.
Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
Or not: https://github.com/Kunzisoft/KeePassDX/issues/2321
They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.
...and it characteristic the level of patronising arrogance in the issue thread
"This is normal. It is not recommended to copy passwords to the clipboard in any case, this mitigates this behavior and complies with new Web Authentication standards."
This does not even invite a discussion. Maybe some people run tight, safe systems and know what they are doing? Maybe some people never rely on a single password being the only thing between them an an account compromise? Nope. Some patronising guy knows it all, and will override what people want to do on their machines.
... have you heard of passkeys?
Yes, it's as stupid as it sounds. And works about as well.
"Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way
Follow state is a useful bit of information. There's argument to be made for both hiding and preserving it.
There’s no need to implement a custom blur.
They find a good reason for every little piece of control or privacy they take from you.
Whatsapp also does this shit. You can’t screenshot a conversation (it comes back black). I am going Chinese for my next phone.
https://developer.apple.com/documentation/uikit/uiapplicatio...
For example, their bug bounty program policy helpfully informs you that "screenshot detection avoidance" is not considered a vulnerability: https://hackerone.com/snapchat . That's because it's always possible.
Because I assume most people want to take a screenshot because they want to capture something they are seeing in the app, most people probably are even annoyed to have the system indicators visible there.
Personally, I wish iOS didn't even facilitate this.
edit: to be clear, I don't think iOS should notify the app at all. The app could register areas as "invisible to screenshots" perhaps - I'm torn on that functionality.
> and now some apps get a hook to insert their branding.
No, apps can already insert their branding anywhere they want. They're writing the app. If they want their logo to be visible in screenshots, they have infinite ways to do that.
This particular way seems basically prosocial. It's much more useful to me as a consumer of the screenshot to see that it came from Bluesky than to see that there was a "Follow" button. It's not what the feature they're using was intended for, but I can't call it an abuse of the feature. What they're actually doing is good.
The fact that you're getting unexpected behavior isn't good. Sometimes you want to create a picture of sensitive information. You should be able to override the app developer's security settings.
I guess the Bluesky bros got inspired by Threads, again.
Do you/should you (we) really expect that though? I regularly use color filters on my apple devices— grayscale to avoid distractions during the day and red tint at night. More recently I’ve been using the motion dots. I don’t know that I can say with confidence that I never want any of those “personal-perceptional-modifiers” to appear in a screenshot, but for most folks, I would guess it’s approximately never.
It is often important to people that the screenshot is an accurate record of what was on the screen.
While we're at it, this "share" containing the copy/paste flow is the exact same kind of thing. And screw whatever logic decides to copy the URL of an image instead of the actual image sometimes from Safari when I select to copy it!
The text at the top of the screenshot is
> Eric Roston
> @eroston.bsky.social
So it's pretty easy to tell IMHO.
It somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes away at some point.
The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
To my knowledge, this is a misunderstanding. The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
Android does it too: https://developer.android.com/about/versions/14/features/scr...
I dislike this hijacking for that reason and wish there was a way to turn it off.
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. But same browser running incognito on a desktop can be merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
Though I don’t see how this is anything like a keylogger.
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
Not a marketing logo.
https://developer.apple.com/documentation/uikit/uiapplicatio...
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.
If you send it, it is no longer yours to control.
If it is my phone, it should be mine to control. Too often it really isn't my phone...
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.
RIP rational.
>To my knowledge, this is a misunderstanding.
re: an OS informing an app of a user action (but didn’t downvote ya)
> accidentally screenshotting your password manager;
I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.
How could you ever provide support to a user? “First take 200 screenshots and send those to me…”
That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.
Isn’t that what everyone is talking about?
Otherwise userDidTakeScreenshotNotification only fires for your own app
https://developer.apple.com/documentation/uikit/uiapplicatio...
Found in the HN commenting guidelines, linked at the bottom of most pages
If someone from Google Maps or LinkedIn team is here, please, when I take a screenshot it's because I want to a screenshot, not share the friggin location/post.
Not sure who got the idea that it was useful, it isn't.
If I'm sending a screenshot it's because I want to send exactly what I see on my screen and not have my recipient's gmaps instance happily recompute a route it thinks is better or leave out the routing information I included, or switch from biking to driving directions, or whatever else.
Ah... to imagine a world where you could just share a coordinate string and people could open it in whatever map app/page they wanted. Geo URI is probably the closest we have today but I don't think much of anything outside the OS Geo community accepts it.
A lat/lon/zoom/start?/dest? is kind of what a Google Maps share currently is, but it's neither an interoperable standard nor a reliable capture of the current state, so really the worst of both worlds.
(Also, hi AB! Nice to see you on here)
[1]: https://www.alltrails.com/trail/canada/ontario/harrison-trai...
I believe it was their response to what3words. It's not as good at the "communicating by text" use case as what3words.
It's not clear who it is protecting against, it does not seem to be effective at protecting against anything at all, it is actively annoying to the user, and has no way to disable. Perfect example of the usual "security theater" feature.
I don't have an iOS device handy to compare against, but it surprises me that Apple wouldn't also recognize that Wi-Fi passwords in particular are extremely common things to share.
Unsecure: open Shortcuts, tap Gallery, search “Adjust Clipboard”. Add to Action Button folder and run from Action Button. - Or add “Dismiss Siri and Continue” action after “Get Clipboard” so you can say “Siri, Adjust Clipboard”.
Type in the still-unreasonably small window, tap Done, paste password. (Then clear clipboard I suppose and consider privacy implication if your clipboard syncs to Mac.)
Could write my own phone operating system to not be subject to the iOS WiFi password field display settings though!
Oh wait it absolutely does.
Just like their iCloud Keychain API that lets apps secretly track users across app reinstalls and device resets.
Do you use the same password on every site? How do you deal with data breaches?
> Do you use the same password on every site?
I use a password I can reconstruct in memory for sites I care about logging in by hand. If I don't, or don't mind resetting my password each time, I just use random garbage + whatever platform password manager is the one active today, with vague hopes that it'll still be there the next time I need to log in.
> How do you deal with data breaches?
Who ever cares about those? I'm yet to hear about anything impactful being released on those. It only matters if you actually do reuse the same e-mail/login and password combinations on both important sites and garbage sites. Which is something you should not. But 2FA and magic links tend to solve that vendor-side, these days.
A physical notebook is so easily lost I wouldn’t even consider it.
Just search for keepass in the app store (Keepassium, KeePass Touch, Strongbox, ...)
(I use KeePassDX from F-droid it does not have network permissions)
Frank Dux was a fraud! :)
And I prefer to see and choose the data an app stores on my fucking ICLOUD ACCOUNT. And fucking DELETE it when I want.
There's no way to do that from an iOS device.
But this one looks like you actually mean it? Yikes.
Hijacking the screenshot process is a privilege that you ought to be able to revoke, it's insane to allow software to be given more control.
And don't tell me it's anything to do with security when it can be circumvented in any number of ways.
It should not exist as a control in the first place.
I know it may sound absolutist, but the way I see it: if you allow this as a user-revocable permission, then the very apps that need to be screenshotted by users most often will be the first to refuse to work at all unless you grant this permission.
Screenshotting is an system operations level feature. Apps should be neither aware of, nor able to interfere with, a screen capture being taken.
The toast shows up after the screenshot, but my phones's long screenshot feature captures the top part a second time, so the top part of the chat becomes unreadable.
It works! Unless:
- the person you’re linking it to doesn’t have an account on that platform
- you’re posting it in a chat, and the site doesn’t implement unfurls correctly
- the site shows a thumbnail on the link, but clicking on it gets hijacked by the “mAkE an aCcOuNt/ login here” shenanigans.
- you’re trying to link to something in context and the sites linking doesn’t support it
- the site is riddled with ads.
- the site is slow to load.
- you’re trying to save something and don’t want to have to load the site every single time in order to refer to it.
- any combination of the above.
Screenshots allows you to get a point in time reference to what you are sharing.
Screenshots are clunky and unideal, but at least they're fast and I know that they don't fail or break or send the wrong info to my contact.
If it were a one off message, this wouldn't be an issue, but if you zoom out on the issue and see you're sending up to a hundred messages a day, points of failure become major life frictions and you're trained out of using things like links in messaging apps.
In 2026, we now know that the information can be edited, or completely removed for many reasons, some legitimate, and some nefarious.
Taking a screenshot is the easiest way to ensure the original is kept for folks to see. Frankly, it'd be even better if (a) the app can signal to the OS information about the url to the page for the screenshot, (b) timestamps were captured in the image and not cropped, and (c) the OS can authenticate the screen shot and digitally sign that it came from an unaltered device.
and then when it does send I have no control over the presentation on the other side. Sites love to add some cringe "I love this app SOOOO much hearteyesemoji fire fire fire... sent from my iPhone, made with love in san cupertino" nonsense in my own voice - literally sending their words into my chats using my account, as though I had written their marketing dreck
Of course this is doable on open source OSes like GrapheneOS, it just sucks that you have to keep modifying the OS every time they release a new version
At least it's open source, so maybe one can add root access and screenshot blocking to it.
1. I need to be able to monitor what's inside the memory and communications of every process running if I want to
2. I need to be able to pin a different root certificate, install a MITM SSL proxy and see what every app is sending about me, if I want to
You don't have to wish, in this scenario. Bluesky supports third-party clients, you can use one that has a more minimal featureset if you prefer.
Android and iOS should not let apps do this, because it can be (ab)used by apps that you can’t really choose not to use.
I know there’s a popular bank in my country that completely blocks screenshots and screen recordings on Android somehow.
This is absolutely hostile to users.
That was the expectation of using the product so it fits and isn’t anything like this discussion.
This deserves a longer rant, but the very premise of Snapchat was always poisonous, and is largely responsible for why, 20 years later, we're now facing extreme proposals for regulating electronic communication.
I generally disagree with the whole line of criticism techies get for "solving social problems with technology", but if there's one unambiguous case where I'd agree it was plain stupid, it's the concept of screenshot prevention, that became prominent with Snapchat. Controlling whether your recipient gets to keep the message you sent them is a purely social problem, and the answer to that in the real world has always, for good reasons, been "once sent, it's no longer yours; once received, it belongs to recipient to do with as they please".
Wdym? Hooking (primarily underage) people onto "daily streaks" of sharing (often inappropriate) pictures of themselves to (sometimes random) other people via likely insecure servers is a _great_ business model!
Great customer retention. Lots and lots of engagement. So much shareholder value.
Oh and just think about how vulnerable they are. _Perfect_ for ads.
Yellow.
They fuckin did it. Not construction not a warning of some type. Not yellow pages. Yellow - cool looking yellow.
Is what I said to myself as a 20-something product designer
"Forget watermarks, I'm just going to let the person know! Ha!"
Each time I tried to take a screenshot of a password, the password was missing from the screenshot - even when I kept the control centre pulled down far enough that the Password app was starting to look blurry.
At least on rooted Android devices you can bypass that.
I’m worried that switching apps and screenshots _doesn’t_ put the logo in. If the point of the switch is privacy, isn’t that a bug? Shouldn’t it apply the privacy screen during any screenshot? What if there was sensitive information on there when you were switching and taking the screenshot?
Having a follow button on the screenshot brings nothing and a logo is helpful when sharing (“hey it’s not twitter, I know it looks like it but it’s bluesky”) and looks subtle.
It’s just it’s a forum so people say things for discussions sake and get outraged by anything that a platform they don’t like is doing.
42 of their 56 active users might not care about a watermark but god dammit do they respect it
And so should you
Their product UI kind of looks like X, so it's helpful to know the source of a post
Second - I hate when my device keeps me from anything. I'm used to have control over my computer, and this is outrageous that I can't take screenshots of anything I want. There should be a god mode or something like that.
That said, operating systems should turn this into a user choice, and present a dialog to select the “protected” version or not.
I’ve noticed a certain AI recruitment company gets “highlighted” (darkened white background of the screen, but their logo is pure white and REALLY stands out), but when I screenshot it, it reverts to normal, like there’s no blatant special advertising.
[0]: https://gregbenzphotography.com/hdr-gain-map-gallery/
It seems more appropriate for Claude to do it seeing as it generated the image, all Bluesky did is provide the platform to post it.
https://github.com/GrapheneOS/os-issue-tracker/issues/664
Upvote the issue if so.
I also have no issue with the API, people here are definitely overreacting to it’s existence.
Sent from my Ryobi Riding Lawnmower
I agree this can be defined as cool and very very likely someone did this on their free time/prompted Claude on the side.
Does this indicate that the privacy feature has a gap, where you could reveal the length of your password if you take a screenshot mid app switch?
Oh, so you can take screenshots of the content that tries to avoid it if you do it mid-switch?
If it's reliable and WONTFIX, that's almost enough to get me to switch away from Android.
Screenshot taking prevention is harmful and should not have ever been allowed to become a platform-level feature in the first place. Because if there's one rule of platform/client interaction, is that if you add a feature that can be abused against customers for stupid reasons, it will be. There's a number of apps I have on my Android phone that block screenshots for dubious reasons, that can be maaaybe charitably explained by calling them "growth hacking pretending to be a security feature", but in some cases even that's a stretch.
This feature should never have existed in the first place.
(At least Bluesky is open about it, both by being Open Source and calling out the "growth hack" by name in source code.)
When iPhone shipped, any time you emailed a photo it would append "Sent from my iPhone" to try to virally market. Same or at least similar slimey tactics
The workaround is letting that person take a photo of my phone, which is lower quality.
https://github.com/mozzius/expo-privacy-sensitive/blob/main/...
What does the author mean by this? I checked the repo and the project seems to be MIT licensed, which makes it open source.
Where anyone can say anything?
Maybe it’s so decentralized there is a dark web within BlueSky now! DarkSky
Now anyone can access the decentralized shadowhose from our server
Mothers Against Decentralized Development
He’s a madd mother, fucker
(a) the freedom to screenshot any content on your own device (b) the freedom to share content with others that cannot be screenshotted
It can be annoying when DRM or privacy features block a screenshot, but I think it can also benefit the platform ecosystem that you participate in as a user too. Idk!
Many people would find it inconvenient to find another device to take a picture with. And that manual picture would then have baked-in evidence that it was taken surreptitiously.
Locks keep honest people honest, as long as the app is up front about it and lets users make the choice, I don’t mind.
Nobody deliberately opted in to random information hiding in a more general purpose app, or watermarking, or DRM.
When I’m in Safari, taking a screenshot can turn into a totally separate operation (full page scrolling screenshot) and that’s a good feature.
Others complain about Google Maps showing a popup telling the user about location sharing upon screenshot - I think that makes a lot of sense, considering it doesn’t show up in the screenshot and dismisses easily.
I’m very harsh on user hostile choices, in fact I spend a lot of time ranting and raving about it, but I just don’t see that here.
Offering something better can be valuable (sometimes) but don't alter the screenshot itself.