Live data from Hacker News

How Bluesky draws its logo on screenshots

timmarinin.net

361–370 of 478 posts

Re: How Bluesky draws its logo on screenshots

#361

Earlier quoted context omitted.

I don't have an issue with BSky's use, but I regularly run into the functionality's abuse elsewhere, such as multiple of the biggest Thai banks' apps where every screen in the app entirely blocks screenshots (iOS). Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms…

>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Why not ask contact for data via text and just copy paste it with double check?

1. On the pre-submit-button screen it shows the recipient's name to confirm, but as in the GP example, if the recipient's name is in a character set different than your own, it would be nice to be able to have someone who can confirm the recipient's name matches.

2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.

Re: How Bluesky draws its logo on screenshots

#362
post #194

Earlier quoted context omitted.

This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…

The OS could draw an ugly censoring block over the sensitive information. That would protect the user's privacy when needed but also prevent apps mis-using the feature like this.

It could. But the root problem is, there is no such thing as unqualified "sensitive information". The information is sensitive to someone, for some reason. The problem with screenshots manifests when the app and the user disagrees about whether the information is sensitive and who has the right to control it.

The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.

The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.

Re: How Bluesky draws its logo on screenshots

#363
post #346

Earlier quoted context omitted.

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.

This just reinforces the notion that apple is the one that actually owns the phone and they generously let you use it.

Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".

Re: How Bluesky draws its logo on screenshots

#364
post #347

Earlier quoted context omitted.

Funny enough, that's what the big passkey folks want: https://github.com/keepassxreboot/keepassxc/issues/10407

Really glad open-source password managers are resisting the bullying and not implementing DRM.

For now: https://github.com/keepassxreboot/keepassxc/issues/10406

Or not: https://github.com/Kunzisoft/KeePassDX/issues/2321

They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.

Re: How Bluesky draws its logo on screenshots

#365
post #49

If it's between this and a perpetual logo, I'll take this any day. I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content. There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people…

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

Software that intentionally subverts the intent of the user is malware. We now live in a world where most financial institutions literally ship malware as their primary or only interference to access their systems.

Re: How Bluesky draws its logo on screenshots

#366

Earlier quoted context omitted.

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

[flagged]

> “Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge.

Very true.

> The right fix is selective redaction, not disabling screenshots everywhere.

That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".

Re: How Bluesky draws its logo on screenshots

#367
post #49

If it's between this and a perpetual logo, I'll take this any day. I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content. There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people…

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…

Hoping to not sound like a broken record, this is why having full ownership of your device and OS is important. My stock Pixel Android recently told me something along the line of "A security policy blocks screenshots for this app. Talk to your administrator if you want to change the policy". I looked in the mirror and my administrator said "time for a policy change, we're moving to GrapheneOS".

And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.

Re: How Bluesky draws its logo on screenshots

#368

Earlier quoted context omitted.

I don't have an issue with BSky's use, but I regularly run into the functionality's abuse elsewhere, such as multiple of the biggest Thai banks' apps where every screen in the app entirely blocks screenshots (iOS). Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms…

>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Why not ask contact for data via text and just copy paste it with double check?

What if the app doesn't allow pasting? What if the communications app prevents copying?

For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!

--

[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, all text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.

Re: How Bluesky draws its logo on screenshots

#369
post #10
post #2

Well, I have not once found a single case where an app reacting to screenshots and controlling the process in any way was anything to me but hostile and annoying. This one does not help. It somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes aw…

> hostile and annoying If someone from Google Maps or LinkedIn team is here, please, when I take a screenshot it's because I want to a screenshot, not share the friggin location/post. Not sure who got the idea that it was useful, it isn't.

It's not about what you want. It's about increasing engagement with the Google platform

Re: How Bluesky draws its logo on screenshots

#370
post #240
post #194

Earlier quoted context omitted.

This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…

I don't think they're abusing functionality at all. I don't think screenshotting a skeet should, by default, leak the follow state of the user taking the screenshot, which is what would happen without the secure input swap "Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way

One person's "sensitive input" is another's "key information".

Follow state is a useful bit of information. There's argument to be made for both hiding and preserving it.

Post reply on HN