Remix.run Logo
blauditore an hour ago

I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily.

It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.

I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.

TeMPOraL an hour ago | parent | next [-]

> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.

Yes, this. Payment apps, government apps, IM communications.

The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".

My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".

--

[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...

[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.

fluoridation an hour ago | parent | next [-]

On a similar note in terms of frustration, my bank ended up getting me to memorize my randomly-generated passwords twice because it blocked pasting. I guess it's to discourage writing them down in plaintext files, but I bet it just makes most people choose meaningful passwords.

Perz1val an hour ago | parent | prev [-]

Then they deserve you taking a photo with a second phone

TeMPOraL 28 minutes ago | parent [-]

Well, I did, after the fact, but it's only because I had a work phone on me (that doesn't yet actively block sharing to non-work devices).

I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.

V__ 28 minutes ago | parent | prev | next [-]

I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.

TeMPOraL 24 minutes ago | parent | next [-]

> especially if the bank might be partially at fault if a scam happens

That's the crux.

Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).

Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.

QuantumNomad_ 16 minutes ago | parent | prev [-]

People also take pictures of their government IDs (passports, drivers license, etc) and utility bills.

Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?

I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.

It’s my phone, I want to decide what I take photos and screenshots of.

kotaKat 5 minutes ago | parent | prev [-]

I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog.

WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.

... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.