Earlier quoted context omitted.
Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.
Well, it sounds like those people are just too stupid to own phones at all then.
How Bluesky draws its logo on screenshots
431–440 of 478 posts
Re: How Bluesky draws its logo on screenshots
#432Earlier quoted context omitted.
I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing. Yes, this. Payment apps, government apps, IM communications. The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".…
In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
Re: How Bluesky draws its logo on screenshots
#433Earlier quoted context omitted.
Trained by the many more prompts that are irrelevant in practice, and merely stand between a person and the task they're trying to accomplish. It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later 0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry ;-)"…
I'd say the problem is that delete usually has a popup. Sure you don't really want to delete without any kind of confirmation, way too many people would click something on accident and if there's not a way to undo it (which has it's own issues), then a popup is a simple solution, but it does result in this unfortunate behavior.
Repeated exposure built immunity.
You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.
The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.
Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.
We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:
Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.
--
[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.
[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.
Re: How Bluesky draws its logo on screenshots
#434Earlier quoted context omitted.
I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily. It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring abo…
I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog. WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device. ... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no…
Re: How Bluesky draws its logo on screenshots
#435Earlier quoted context omitted.
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing. Yes, this. Payment apps, government apps, IM communications. The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".…
> before pausing and realizing that this would only cause even more problems with those apps, In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
Banks are the canonical example - changing one is a huge hurdle, with consequences that can drag on for years. One by one, they're all ditching their websites (if they had one in the first place) in favor of apps. Even those with full-featured websites increasingly force you to use their app as the second factor to log in, confirm transactions, even confirm viewing some data. Some offer physical tokens, most don't advertise that, and it's only a matter of time before they convince regulators that Attested Phones are Safer and Everyone Has One, and that option will disappear. And because they want their app to be the second factor, they can argue it needs to be secure, creating demand for remote attestation, and boom - there goes your option to work around any other bullshit limitation they throw at you.
The day has only 24 hours, I don't want to spend them clearing bushes by walking off the beaten path wrt. every single important service - payment services, government services, IM services, ${whatever bullshit SaaS app I need right now because you're using it for the thing you just shared with me, and I need to view that}, etc. So I submit. So does everyone.
It's why I put blame on platforms here. Features protecting the device from the user should not be built in the first place - they always start justified by some legitimate security reason, and always end up broadly abused to serve business reasons.
Re: How Bluesky draws its logo on screenshots
#436This is phone OS developer's fault for even allowing it. When I take a screenshot, I expect to have an image of exactly whatever was displayed on the screen at the time. Its not a picture of your app, its a picture of my screen. Some banking apps used to (or still) prevent this and now some apps get a hook to insert their branding. My device serves some master other than myself.
This exists for a very good reason. It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show. Bluesky, and apparently others, are abusing the functionality for advertising purposes. I think it’s a good thing it’s there. This functionality should be easy for apps…
Re: How Bluesky draws its logo on screenshots
#437Earlier quoted context omitted.
Well damn, I would have thought rooting would have been a basic feature of GrapheneOS. At least it's open source, so maybe one can add root access and screenshot blocking to it.
GrapheneOS is concerned with security more than anything else, to which rooting is completely counterproductive
1. I need to be able to monitor what's inside the memory and communications of every process running if I want to
2. I need to be able to pin a different root certificate, install a MITM SSL proxy and see what every app is sending about me, if I want to
Re: How Bluesky draws its logo on screenshots
#438Earlier quoted context omitted.
Did you read the post? Nothing is hijacked, but its a trick where they render the normal button in a ui element for secret data, which is blanked by the system on screenshot, revealing the logo underneath. Its a reasonable feature, so its hard for apple to control it better or remove this.
No, it’s not a reasonable feature. If I take a screenshot, I want the image to include what is displayed on my fucking screen, period. What is so difficult about this?
Re: How Bluesky draws its logo on screenshots
#439Earlier quoted context omitted.
Did you read the post? Nothing is hijacked, but its a trick where they render the normal button in a ui element for secret data, which is blanked by the system on screenshot, revealing the logo underneath. Its a reasonable feature, so its hard for apple to control it better or remove this.
That is a lot of words just to make it sound reasonable that a page can be exempt from the underlying screenshot functionality. It isn't. Not without asking the user.
Re: How Bluesky draws its logo on screenshots
#440Earlier quoted context omitted.
Often, you don't, because the same developers of the bank app decided it's an unnecessary power user feature that doesn't fit in the MVP or something. Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose i…
Here's an open source solution on F-Droid, presumably malware-free: https://f-droid.org/packages/com.mateusrodcosta.apps.share2s... https://github.com/MateusRodCosta/SaveLocally