Live data from Hacker News

How Bluesky draws its logo on screenshots

timmarinin.net

341–350 of 478 posts

Re: How Bluesky draws its logo on screenshots

#341
post #194

Earlier quoted context omitted.

This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…

I don't have an issue with BSky's use, but I regularly run into the functionality's abuse elsewhere, such as multiple of the biggest Thai banks' apps where every screen in the app entirely blocks screenshots (iOS). Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms…

>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer?

Why not ask contact for data via text and just copy paste it with double check?

Re: How Bluesky draws its logo on screenshots

#342

Earlier quoted context omitted.

That's what a username and password are for. I'd rather not be forcibly tracked.

I have 200+ different passwords stored in iCloud Keychain, each 20+ characters long. How am I supposed to remember all of those? Do you use the same password on every site? How do you deal with data breaches?

Major reason I don't use password managers that much.

> Do you use the same password on every site?

I use a password I can reconstruct in memory for sites I care about logging in by hand. If I don't, or don't mind resetting my password each time, I just use random garbage + whatever platform password manager is the one active today, with vague hopes that it'll still be there the next time I need to log in.

> How do you deal with data breaches?

Who ever cares about those? I'm yet to hear about anything impactful being released on those. It only matters if you actually do reuse the same e-mail/login and password combinations on both important sites and garbage sites. Which is something you should not. But 2FA and magic links tend to solve that vendor-side, these days.

Re: How Bluesky draws its logo on screenshots

#343

Earlier quoted context omitted.

> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing. Yes, this. Payment apps, government apps, IM communications. The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".…

Then they deserve you taking a photo with a second phone

Well, I did, after the fact, but it's only because I had a work phone on me (that doesn't yet actively block sharing to non-work devices).

I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.

Re: How Bluesky draws its logo on screenshots

#344
post #197

Earlier quoted context omitted.

Spotify uses this and it annoys me all the time. If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Sp…

I’ve seen another app do that but for a different reason. It’s for security cameras and they use it to show a “hey idiot just press the save a picture button, don’t take screenshots” popup, which is also hostile. I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.

Yeah it’s Snapchat. If you take a screenshot of a (potentially extremely private, intended to be ephemeral) image, it notifies the person who sent it.

Re: How Bluesky draws its logo on screenshots

#345
post #33

This is in fact a watermark to promote the application, which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app. I didn't know that Sam literally named the file GrowthHack.tsx, which is pretty funny.

I mean, X does the exact same thing

Re: How Bluesky draws its logo on screenshots

#346
post #49

If it's between this and a perpetual logo, I'll take this any day. I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content. There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people…

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.

Re: How Bluesky draws its logo on screenshots

#347

Earlier quoted context omitted.

If it's to prevent accidents, it should just prompt user to confirm saving the screenshot with sensitive information. As it is, it is just an annoyance that requires you to do stupid workarounds like taking a photo of your screen. Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.

Funny enough, that's what the big passkey folks want: https://github.com/keepassxreboot/keepassxc/issues/10407

Really glad open-source password managers are resisting the bullying and not implementing DRM.

Re: How Bluesky draws its logo on screenshots

#348
post #346

Earlier quoted context omitted.

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.

> especially if the bank might be partially at fault if a scam happens

That's the crux.

Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).

Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.

Re: How Bluesky draws its logo on screenshots

#349
post #194

Earlier quoted context omitted.

This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…

"accidentally end up in a screenshot" --- how often do you even take a screenshot on a phone, much less accidentally?

Almost daily on my iPhone.

The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.

And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.

That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.

Re: How Bluesky draws its logo on screenshots

#350
post #194

This is phone OS developer's fault for even allowing it. When I take a screenshot, I expect to have an image of exactly whatever was displayed on the screen at the time. Its not a picture of your app, its a picture of my screen. Some banking apps used to (or still) prevent this and now some apps get a hook to insert their branding. My device serves some master other than myself.

This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…

>This exists for a very good reason.

This exists for a very bad reason.

>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.

and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.

>I think it’s a good thing it’s there. This functionality should be easy for apps.

I think it's a bad thing it's there. The functionality should be easy for me.

Post reply on HN