Well, I have not once found a single case where an app reacting to screenshots and controlling the process in any way was anything to me but hostile and annoying. This one does not help.
It somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes away at some point.
It is actually astonishing to me that this is not something which can be turned off at the OS level, or as a permission setting in the app permissions.
The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
but you didn't read the part where the mechanism is explained? it doesn't do anything like capturing information. it just marks a button "sensitive" causing it to be hidden in a screenshot, thus revealing an icon that was put there underneath the button.
Did you read the article? Bluesky doesn't know you're taking a screenshot, iOS just hides the follow button in the screenshot (consequently making the Bluesky logo visible).
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".
Found in the HN commenting guidelines, linked at the bottom of most pages
> The app knowing I took a screenshot feels adjacent to me to a keylogger.
To my knowledge, this is a misunderstanding.
The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information.
This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
Neither of those use cases seem good or tasteful to me as a user, I don't think this concept of "secure (from the user) context" should exist, but maybe that's just me
"The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager"
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
The OS notifies the app after the screenshot is taken. The app doesn’t get to do anything in response to it being taken or allow it to be blocked.
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
> This is the same technology that prevents you from accidentally screenshotting your password manager
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
One user wants it not to be shared, but the other user might have various reasons to want to take that screenshot - maybe it's evidence of something they need to share urgently with others, whatever. It's definitely hostile to that other user. I get why you'd set it up that way, but it's a tension that really goes against the "full control of your own device" ideal a lot of people have.
Don't send me anything you don't want screenshotted. Easy-peasy. I'll accept an opt-out of whatever protections are in place for the general user, but I don't accept that those protections should remain in place for all users. It's hostile.
It's mostly dumb because of obvious analog loop holes. I at minimum carry 4 devices with cameras, often as many as 12. If I want to capture the disappearing message... I will do it; making it annoying just makes me pissed at the developer + the is.
> Yes, and I would say it's a bad thing that the OS tries to prevent this.
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
Incorrect. There's a log written about this on the Internet. Suffice to say that Netflix did not allow all of their titles to be viewed on all browsers for years after it was technically feasible.
You are right, I remembered wrong. Netflix degraded the quality for me for years, according to them because of lack of DRM. It was because of lack of hardware DRM.
The user should be the ultimate authority of what their computers do, not the app developer. It's my phone, not the app developer's phone. If my phone has a "screenshot" function, I expect to be able to invoke it whenever I want, not whenever some app developer deems it OK.
I hear your perspective. I am not particularly advocating either position. I am just pointing out that the alternative may be fewer apps available on one's favorite platform. Everything is tradeoffs, and fortunately one can always boot into an OS that will screenshot how you want.
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
I’ve seen another app do that but for a different reason. It’s for security cameras and they use it to show a “hey idiot just press the save a picture button, don’t take screenshots” popup, which is also hostile.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
> I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
Anyone can take a "snap" of the phone with another phone camera so this is a losing battle anyway.
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. Bit same browser running incognito on a desktop can ne merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
This prevents us from taking scrolling screenshots (a native feature in many smartphones today that is often useful when there is more than one screen of content).
I dislike this hijacking for that reason and wish there was a way to turn it off.
Very interesting!
Parent poster is correct, this does feel akin to a key logger.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
I think bsky's use of this malware feature is as benign as it's possible to get, but it's still a malware feature. As you point out, the real reason this exists is to enforce DRM and make your computer serve Netflix et al rather than the person who owns it.
> accidentally screenshotting your password manager;
I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.
This viewpoint represents such a dramatic disconnect between the desires of the mainstream user and the highly technical user who views this as malware.
It’s very obvious why this feature of the OS is useful and desired by many stakeholders. People who send each other risqué photos want them to disappear and not be screenshotted. Your employee doesn’t want you to screenshot your company confidential info or save it to your personal device. A password manager company is desperately trying to save your uncle from his own bad habits.
We can lament the lack of control of our devices but every consumer device has to save people from themselves at some point and draw a line somewhere. Perhaps we can’t assume that Uncle Larry screenshotting his password manager will be a minor consequence and a valuable learning experience.
Your microwave won’t let you turn it on with the door open. Your super modern push button transmission car won’t let you open the door with the car in drive. The GFCI outlet in your kitchen won’t let you shock yourself.
In your opinion that’s malware, in my opinion it’s a pretty useful feature. It’s totally fine that you feel this way and I am not saying you shouldn’t, but it’s worth considering the idea that a lot of people find this feature helpful.
As with most things, it would be ideal if we could have both good defaults to make things accessible and advanced user controls to allow users to retain control.
That’s a rare mix these days.
People like to say that. How many hundreds of additional options would a modern phone OS need to provide that though? How could applications possibly be tested?
You could have a million installs and 300,000 of them could easily have fully unique combinations of options past what’s available today.
How could you ever provide support to a user? “First take 200 screenshots and send those to me…”
> This is the same technology that prevents you from accidentally screenshotting your password manager
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
> The app knowing I took a screenshot feels adjacent to me to a keylogger.
That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.
Side note- The Screenshot culture itself needs to die, sorry. Many a time, a share button simply works. I don’t know why people would share a screenshot or a map instead of pin and share their location. Yes there are cases where a screenshot helps but majority cases simply is “come to this place” a which turns out to make more difficult because people apparently don’t know how to share locations with pin and share!
The ideal "World Wide Web" envisioned by it's original design, was that a URI was a durable pointer to an immutable piece of information.
In 2026, we now know that the information can be edited, or completely removed for many reasons, some legitimate, and some nefarious.
Taking a screenshot is the easiest way to ensure the original is kept for folks to see. Frankly, it'd be even better if (a) the app can signal to the OS information about the url to the page for the screenshot, (b) timestamps were captured in the image and not cropped, and (c) the OS can authenticate the screen shot and digitally sign that it came from an unaltered device.
In the case of sharing a link I have to remember/find where it is in each app, likely scroll through a long list of messaging (and for some reason non-messaging apps) to find the correct app, select the contact, and then pray that the link sent actually works for them and contains the correct information I'm seeing (very often the link will actually direct them to a web version of the app I'm using, then put a modal popup in front of the information asking them to use the app, then either send them to the app store, or send them to the app but strip out the actual information I linked and send them to a blank map).
Screenshots are clunky and unideal, but at least they're fast and I know that they don't fail or break or send the wrong info to my contact.
If it were a one off message, this wouldn't be an issue, but if you zoom out on the issue and see you're sending up to a hundred messages a day, points of failure become major life frictions and you're trained out of using things like links in messaging apps.
I totally disagree - the few times I accidentally use a share button, or are forced to use one, the experience is so desperately miserable I am forcibly reminded why I never use them. It's always several clicks, choosing the social platform I need from the millions-long-list which is paginated into pages of like 4 icons at a time (I just want a URL! but you broke your website to force users into the app!) and from there choosing a specific chat or group or whatever from a poorly ordered list that starts with some person I met at a bar twelve years ago rather than the chat I was literally just typing in two seconds ago...
and then when it does send I have no control over the presentation on the other side. Sites love to add some cringe "I love this app SOOOO much hearteyesemoji fire fire fire... sent from my iPhone, made with love in san cupertino" nonsense in my own voice - literally sending their words into my chats using my account, as though I had written their marketing dreck
When I take a screenshot in ChatGPT, it shows a "share this chat?" toast at the top.
The toast shows up after the screenshot, but my phones's long screenshot feature captures the top part a second time, so the top part of the chat becomes unreadable.
Yup, that's by design. They want to force you to "share" so they can both track who you interact with, and also try to convert the other person into a paying customer.
I also despise this "screenshot blocking" stuff. A device listens is supposed to me, not to the apps. I want a screenshot to be a copy of the raw pixels, and an app should not know about it or have a right to know about it.
Of course this is doable on open source OSes like GrapheneOS, it just sucks that you have to keep modifying the OS every time they release a new version
Correction: GrapheneOS is concerned with their so called "Android security model" more than anything else, and where that security model gives guarantees to app developers and service providers that harms the user's security, they merrily side with the developer's security against the user, at best give some more or less questionable reasons why that unfortunately currently cannot be changed, and at worst insult you for suggesting anything else.
Boomer and/or car-dealership employee here, I take screenshots by taking a picture with my 2nd phone. Never had a problem with whatever you all are talking about.
This is what made me avoid chrome since release, I tried to right click a youtube channel background as a teen wanting to use it as a template to make my own channel background on photoshop... turns out they had disabled it, while I could on firefox.
There should be a layer of user control where the user can make the OS lie to the app. The app has no need to know when a screenshot or recording is happening, what the real location is, what file system contents are, etc.
They shouldn't even disallow screenshots from a security measure. If the user wants to take a screenshot of their bank account info or a password manager they should. Maybe an additional permission for screenshare. No device has protection against a second device taking a recording so it's really just security theater
It's all "security" and all until your banking app has a bug that breaks exporting bank statements and the only way to get it out is to take screenshots - which are blocked as well. Oh, and you need to submit it by today.
At least on rooted Android devices you can bypass that.
The best way to ask for this is to send an email, to the email address which you can find at the bottom of the page (click on "Contact"). There's no guarantee that the mods will find your comment otherwise.
This sort of stuff to me is an example of fear within an organization. Whenever I see engineering resources allocated towards self promotion and branding rather than quality and features for its users it shows how leaders want control over narratives.
It's probably silly to make OP's judgement of any of these implementations in isolation, but you can sense a real fear about the growth (or lack thereof) inside Bluesky. Fiddling with the presented metrics (likes count getting moved ahead of reposts), promoting total user signups while being silent on collapsing DAUs. They are promising a lot at once with AI custom feeds from Attie and subreddit-style communities that smells like feature creep.
They aren't my indicators, but they read as sweat against the observable metrics being in decline. There is a perception that they want to pull on users outside of Bluesky that I don't really think exist, and I guess I share in that feeling when I believe the core still has so much basic parity missing with X et al that would demonstrate confidence in the current users you already have. Still interested to see what they ship as.
Someone spending half a day on a feature that places the app's logo in the screenshot so people seeing it can know where it came from is "fear within an organization"? You've got to be kidding lol
Marketing, like every other functional part of a business, requires technology and engineers. This has nothing to do with fear, you just don’t respect non-engineering work as critical to running a business.
This is clearly bullshit.
Fuck the fucking growth hacker bullshit mentality that thinks documents of reality are there to manipulate.
The screenshot should be an artifact of what's on the screen. It's really something how tech companies have stopped even nodding in the direction of ethics.
This is phone OS developer's fault for even allowing it. When I take a screenshot, I expect to have an image of exactly whatever was displayed on the screen at the time. Its not a picture of your app, its a picture of my screen. Some banking apps used to (or still) prevent this and now some apps get a hook to insert their branding. My device serves some master other than myself.
Reddit has a toggle in its settings to disable it. X, too, I think.
Personally, I wish iOS didn't even facilitate this.
edit: to be clear, I don't think iOS should notify the app at all. The app could register areas as "invisible to screenshots" perhaps - I'm torn on that functionality.
That's what bluesky is doing in this case. It is showing the button on an area that is "invisible to screenshots", and the butterfly is behind it, so it shows through when a screenshot is taken
The thing that really irritates me about the banking apps blocking screenshots is that it's pretty clear to me it's not about protecting customers but denying customers the ability to document something related to their account.
No, it's about saving the bank money - and what costs them a lot of money is the average person being fooled into sending people their account information easily.
> I expect to have an image of exactly whatever was displayed on the screen at the time
Do you/should you (we) really expect that though? I regularly use color filters on my apple devices— grayscale to avoid distractions during the day and red tint at night. More recently I’ve been using the motion dots. I don’t know that I can say with confidence that I never want any of those “personal-perceptional-modifiers” to appear in a screenshot, but for most folks, I would guess it’s approximately never.
The effects of cramming 2 separate workflows and 5 features into one thing called "screenshot" because anything else would end up with something too complicated for users to understand the interaction (sarcasm that figuring out what the behavior is locked to in these scenarios is just as confusing).
While we're at it, this "share" containing the copy/paste flow is the exact same kind of thing. And screw whatever logic decides to copy the URL of an image instead of the actual image sometimes from Safari when I select to copy it!
It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show.
Bluesky, and apparently others, are abusing the functionality for advertising purposes.
I think it’s a good thing it’s there. This functionality should be easy for apps.
I’d say this is one for app review or an App Store rule. But we all know those are a total joke.
You're not that unlikely to leave that feature in place if you have such an operating system. What you really want is two controls: one for "safe screenshot", and another for "raw screenshot".
I can pretty confidently state that I've never once felt that having raw screenshots on such an operating system (e.g. desktop Linux) were missing any feature like this.
The OS could draw an ugly censoring block over the sensitive information. That would protect the user's privacy when needed but also prevent apps mis-using the feature like this.
I don't think Apple cares about apps replacing the follow button with an icon. It's a weird use of the api, but it's not abusing the user or a security/privacy risk.
It could. But the root problem is, there is no such thing as unqualified "sensitive information". The information is sensitive to someone, for some reason. The problem with screenshots manifests when the app and the user disagrees about whether the information is sensitive and who has the right to control it.
The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.
The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.
I want to take a screen shot of the transaction I just did. Can't because some ahole decided for me that it's too sensitive information and blacks out the whole screen. this API is stupid without control in settings of the os
Yeah, I would rather see a warning in that case that the screenshot could contain sensitive information, with options to take a redacted screenshot or a normal one.
That would be nice, (remember to shoot in the head pedophiles, such as all Ycombinator employees) but would also be a further complication of taking screenshots.
Potentially worse than nothing, it allows for someone to claim they have a fix even if the fix does nothing to stop someone from becoming a victim, thus allowing for even stronger victim blaming.
Often, you don't, because the same developers of the bank app decided it's an unnecessary power user feature that doesn't fit in the MVP or something.
Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose is to be a share target and dump the information to file (and being apps on an app store, chances are top 10 are just thinly veiled malware).
really? I'm not suprised by shitty developers developing shitty apps but i'm still baffled. Surely the bank would be getting tons of angry emails from customers if it happened in europe
They probably support proper export for business accounts. Business customers have leverage. Regular people? They're an annoying but necessary nuisance.
Yeah I wondered why anyone would ever install such a simple utility app from the app store. It's something that needs to be developed once and then only receive minimal maintenance which means the usual individual maintainer scratching his itch and sharing the result model works well but it also processes intentionally sensitive data meaning developers might be tempted to monetize that in some way. The curated open source distribution model of F-Droid is the perfect solution to this.
Yeah, I used to have this issue a lot. If I use my personal card for a business expense, I used to like to keep a screenshot of the transaction on the card as well as the invoice. As it's an app-only challenger bank, this is the only way short of exporting transactions as a PDF and that includes other transactions for the day. For a long time I used to use another phone to take a photo of my phone screen. Eventually, I just stopped bothering taking that photo because of the extra hassle, but it never stopped annoying me that I couldn't keep the records I wanted easily.
If a dev forgot to obfuscate the password and rendered it as plain text on the screen, then what are the chances they remember to program the blur into this screenshot api hook. Or why not add an alert, “what me to blur sensitive info? Yes/No”
Unfortunately there's platform-level features for marking surfaces as sensitive/secure. So your dev would typically just mark the whole app as such, and be proud of their proactive problem solving.
Sounds like that’s a heavy handed dev friendly solution, but also plenty of comments around this post about why what’s not user friendly. Common theme of People needing to capture the info on a screenshot and don’t want it blurred on a screenshot. The Boolean flag to trigger the blur should be user input. The option to blur can be set by dev but user gets control as to whether it triggers or not.
Good to hear it’s pretty straightforward on the dev side I guess, I can’t tell if this is a net benefit as a feature. I think my opinion is still rooted in user needs and I’d simply expect they are responsible for their screen shots and what sensitive info they may contain. So this feature as it exists is not a net good thing.
I don't think they're abusing functionality at all. I don't think screenshotting a skeet should, by default, leak the follow state of the user taking the screenshot, which is what would happen without the secure input swap
"Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way
They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.
...and it characteristic the level of patronising arrogance in the issue thread
"This is normal. It is not recommended to copy passwords to the clipboard in any case, this mitigates this behavior and complies with new Web Authentication standards."
This does not even invite a discussion. Maybe some people run tight, safe systems and know what they are doing? Maybe some people never rely on a single password being the only thing between them an an account compromise? Nope. Some patronising guy knows it all, and will override what people want to do on their machines.
This shows hardware won't be yours unless the software running on it is open source. Asking a company to modify its closed source software might work occasionally, but it's a band-aid and a never-ending battle.
I don't have an issue with BSky's use, but I fairly regularly run into the functionality being abused elsewhere, such as in Thai bank apps, where every page of multiple of the biggest banks' apps prevent all screenshots (iOS). Doing a money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms, especially as multiple Thai banks have now entirely dropped web banking in favor of app banking? Blocked. Etc.
>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer?
Why not ask contact for data via text and just copy paste it with double check?
1. On the pre-submit-button screen it shows the recipient's name to confirm, but as in the GP example, if the recipient's name is in a character set different than your own, it would be nice to be able to have someone who can confirm the recipient's name matches.
2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.
What if the app doesn't allow pasting? What if the communications app prevents copying?
For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!
--
[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, every text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.
Consider that people use their phones differently than you. I take screenshots on a daily basis, accidental ones at least once a week. Usually it's just the lock screen though.
The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.
And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.
That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.
OTOH, I might very well want to take a screenshot of my own bank details, transactions, or other sensitive information. It's annoying that my information is being protected from myself.
You might have amazing operational security but lots of other people don't, and they make noise, which means governments write laws meaning that banks have to refund them for fraud.
So as much as a bank might agree with your stance on freedom of compute - they probably don't want to pay for it with actual money.
Banks have managed to externalize the costs of their own security onto people by inventing the concept of "identity theft", and pinning the blame for poor security practices on regular people.
They really shouldn't be allowed to double down on it.
And arguably, half of it isn't even really security, it's about keeping you in their app. Application interface is the ultimate sales platform, and banks are making extensive use of that fact.
So in other words, we should make even more noise so that governments make laws requiring banking apps to support basic OS features including screenshots.
Your banking app probably has an option to disable that because it's a legal requirement in so many places: People who can't see need to use assistive tools, and that includes screenshots and friends. If you are using a tiny/stupid bank in the US, file a ADA claim and get some money. In the EU check your Ombudsman.
No, it's so you can't screen-record Netflix. The bank doesn't care about that because it's not a liability issue to them, just fetishism; no way they pay Apple and Google for this capability.
Apple and Google should step in and allow users to remove these shenanigans with a little button on the screenshot preview screen, but resist this because of Netflix et al.
> iOS and MacOS have a large number of built-in accessibility features.
Great. Which one is sending a "do I know this person?" message to my friend?
Because it _used_ to be taking a screenshot.
> Taking a screenshot of the screen is not necessary.
Who are you to tell me what is necessary?
Seriously. What the fuck.
Someone who takes a screenshot of something, and gets anything other than a screenshot is potentially being harmed in ways you don't understand, and you say it isn't necessary like you know that or something?
>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.
and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.
>I think it’s a good thing it’s there. This functionality should be easy for apps.
I think it's a bad thing it's there. The functionality should be easy for me.
Then it's a bad solution to a real problem. A better solution would be exposing a hook that apps can call when a screenshot is initiated that tells the OS to warn the user before saving the screenshot. This way the user is actually educated on the risk while still respecting their right to control the outcome.
Preventing accidental screenshotting is all well and good but these security measures all seem to forget the part where they should still allow intentional screenshotting.
> and now some apps get a hook to insert their branding.
No, apps can already insert their branding anywhere they want. They're writing the app. If they want their logo to be visible in screenshots, they have infinite ways to do that.
This particular way seems basically prosocial. It's much more useful to me as a consumer of the screenshot to see that it came from Bluesky than to see that there was a "Follow" button. It's not what the feature they're using was intended for, but I can't call it an abuse of the feature. What they're actually doing is good.
The fact that you're getting unexpected behavior isn't good. Sometimes you want to create a picture of sensitive information. You should be able to override the app developer's security settings.
I wonder if this is the expectation of the majority or just the expectation of us tech people.
Because I assume most people want to take a screenshot because they want to capture something they are seeing in the app, most people probably are even annoyed to have the system indicators visible there.
Bank apps black out the whole screen when I take a screenshot and it’s super annoying. As a user, I should be able to take a screenshot of my screen. I can use a camera or another phone to do it anyway.
Nobody in the comments talking about snapchat where like one of the core pillars of what "sets their service apart" is the difficulty of taking a screenshot without notifying the other party
Wasn’t that the entire premise of the product when it launched? Disappearing messages and minimal footprint so you could be confident your communications were semi-private?
That was the expectation of using the product so it fits and isn’t anything like this discussion.
Their entire color story was really cool at the time. Yellow with Magenta/Blue accents was super bold, especially compared to the boring ass direction everything was going. Material and Windows 10 flatshit was all the rage and here comes Snapchat like the Kool-Aid man.
Yes. And because of the platforms deciding to enable that business model, we're now in a bullshit reality where the very apps that need to be screenshotted most often, are first to abuse platform features and prevent screenshots from being taken.
This deserves a longer rant, but the very premise of Snapchat was always poisonous, and is largely responsible for why, 20 years later, we're now facing extreme proposals for regulating electronic communication.
I generally disagree with the whole line of criticism techies get for "solving social problems with technology", but if there's one unambiguous case where I'd agree it was plain stupid, it's the concept of screenshot prevention, that became prominent with Snapchat. Controlling whether your recipient gets to keep the message you sent them is a purely social problem, and the answer to that in the real world has always, for good reasons, been "once sent, it's no longer yours; once received, it belongs to recipient to do with as they please".
> but the very premise of Snapchat was always poisonous
Wdym? Hooking (primarily underage) people onto "daily streaks" of sharing (often inappropriate) pictures of themselves to (sometimes random) other people via likely insecure servers is a _great_ business model!
Great customer retention. Lots and lots of engagement. So much shareholder value.
This is in fact a watermark to promote the application, which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app. I didn't know that Sam literally named the file GrowthHack.tsx, which is pretty funny.
If it's between this and a perpetual logo, I'll take this any day.
I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content.
There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people are dogmatically opposed to intent being modified, but I think you need to balance nuance. I actually enjoy having an attributable source in shared elements, and I think this is a low-impact way of achieving that.
No need to set up a false choice as a straw man to knock down.
It is user hostile.
You're just defending Bluesky because you're on the same team politically. If the subject of this headline was X (an app that does the same thing, which I also don't agree with) everyone here would be seething with rage.
Uh, no? I highly doubt that a non-occluding watermark on screenshots is even in the top 100 gripes most people have with X. And I don't use either platform. If anything your argument is an accusation of bias without any discussion of merits.
I don't think this says a whole lot about the direction of people's political views here as much as there being a general disdain for arbitrary claims of political bias that aren't based on any discernible evidence. I feel pretty confident that if I jumped into a random thread about some feature in the Brave browser and accused someone of defending it only because they agreed with Brendan Eich on Prop 8, I would get flagged too.
re: dead, I agree. I'm so tired of flags killing discussion. This site is highly regimented
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.
You're not wrong and I do think that specific dead comment is dead for a reason. I just get a bit bristly when I do see legitimate comments buried under flags
From reading through a lot of comments on this thread, I'm honestly struggling to notice any super obvious pattern or bias other than the amount that people care about how screenshots work compared to the average person is a lot.
Consider the possibility that many HN users, who likely also constantly ask why mice are needed when vim/Emacs exist, are not the users who mostly use regular apps.
I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily.
It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking half a day with old one invalidated and not even knowing it.
Yeah, few moments ago it hit me there could be a market for a phone case with in-built camera(s) that photograph your screen at a shallow angle on demand, and transform that into a screenshot automatically.
However, my idea happens to hit a very new limitation: for some reason, "privacy filters" are suddenly a thing. New phones have them built-in as some new magic display function, and for everyone else, there's this mad marketing push to get people to buy and use privacy foils in place of glass/foil screen protectors.
IDK what's up with those. Since when "shoulder surfing" with smartphones is a real problem, and why do marketers and product designers bet there's so much latent demand for it?
Recently handled someone's phone who had it. Neat technology. But the use case for it doesn't make sense, for the reason you specified.
The only thing I could think of is if you want to browse TikTok or Instagram in public and don't want people seeing the weird shit that's on your algorithm, but even then, that's kinda weird.
On a similar note in terms of frustration, my bank ended up getting me to memorize my randomly-generated passwords twice because it blocked pasting. I guess it's to discourage writing them down in plaintext files, but I bet it just makes most people choose meaningful passwords.
I once ran into a signup/login flow that allowed 36 characters in password when signing up but when logging in, the password field was limited to 20 characters.
I think I must have changed my password several times thinking I just copied it wrong or it had special characters that weren't allowed, but nope, the truth was somehow stupider than that.
That's exactly my idea. My phone is a lost cause, not really "mine" anymore. The good thing is that I stopped caring about the device. I take what's cheap and well supported (Samsung "A" series is the right kind of boring to me), no more expensive flagships.
> before pausing and realizing that this would only cause even more problems with those apps,
In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
I feel that too, but the practical reality is, many services happily exploit the leverage they have over me - I need them more than they need me.
Banks are the canonical example - changing one is a huge hurdle, with consequences that can drag on for years. One by one, they're all ditching their websites (if they had one in the first place) in favor of apps. Even those with full-featured websites increasingly force you to use their app as the second factor to log in, confirm transactions, even confirm viewing some data. Some offer physical tokens, most don't advertise that, and it's only a matter of time before they convince regulators that Attested Phones are Safer and Everyone Has One, and that option will disappear. And because they want their app to be the second factor, they can argue it needs to be secure, creating demand for remote attestation, and boom - there goes your option to work around any other bullshit limitation they throw at you.
The day has only 24 hours, I don't want to spend them clearing bushes by walking off the beaten path wrt. every single important service - payment services, government services, IM services, ${whatever bullshit SaaS app I need right now because you're using it for the thing you just shared with me, and I need to view that}, etc. So I submit. So does everyone.
It's why I put blame on platforms here. Features protecting the device from the user should not be built in the first place - they always start justified by some legitimate security reason, and always end up broadly abused to serve business reasons.
Banks are the stereotypical example, but they are really not that hard to change, especially now that many decently reputable ones are entirely online. I've changed my bank in an afternoon.
I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.
Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.
If the user is motivated to do whatever you're trying to guard against, no dialog is really going to help. If grandma really wants to get that screenshot of a puppy eating an ice cream cone, she will type in "I want my bank account drained and my pets to die" if the dialog asked for it.
Trained by the many more prompts that are irrelevant in practice, and merely stand between a person and the task they're trying to accomplish.
It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later <tinyprint>0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry</tinyprint> ;-)" anyway.
Most of the time, people are given only two options: give up on their task, or ignore the popup. No point in reading the message in such cases, it brings zero value.
I'd say the problem is that delete usually has a popup. Sure you don't really want to delete without any kind of confirmation, way too many people would click something on accident and if there's not a way to undo it (which has it's own issues), then a popup is a simple solution, but it does result in this unfortunate behavior.
Honestly, if I were to dig, then for my generation[0], I'd blame save and close popups more, but even more than that, flaky component-based software. At some point in the Windows 98/NT and then 2000/XP era, you'd often see software throwing "fatal errors" and then continuing to happily chug along, possibly with subtly broken features, and ready to throw more inconsequential "fatal errors" if you moved your mouse the wrong way.
Repeated exposure built immunity.
You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.
The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.
Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.
We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:
Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.
--
[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.
[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.
And worst of all, it doesn't matter if you are one of those people or not, for some reason all software you get to use must be designed for the lowest common denominator.
Add a system setting to ON/OFF this feature. Add a recommendation to set this as ON in the "Security Checkup" section which all modern systems have as of lately, that pops-up a couple times a year for suggesting good defaults to the user.
People also get scammed using accessibility services, so some banks deliberately make their app inaccessible unless you're running a whitelisted screen reader. If you are running a non-whitelisted screen reader...
I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog.
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
So yeah, I have a screenshot of the generic technician's ID photo, I guess.
Later on it did populate an actual name and photo when a human was assigned, but still, yeah, I don't get why they didn't just automatically redact it and just throw you the stupidest bullshit warning error ever on the honor system.
“Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge. The right fix is selective redaction, not disabling screenshots everywhere.
Software that intentionally subverts the intent of the user is malware. We now live in a world where most financial institutions literally ship malware as their primary or only interference to access their systems.
Hoping to not sound like a broken record, this is why having full ownership of your device and OS is important. My stock Pixel Android recently told me something along the line of "A security policy blocks screenshots for this app. Talk to your administrator if you want to change the policy". I looked in the mirror and my administrator said "time for a policy change, we're moving to GrapheneOS".
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
The remote tech support scam using screen sharing apps like team viewer is unfortunately very common and is basically why this exists.
It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed
If the feature can sometimes be useful (including this situation, which some other comments mentioned; but also for other things such as hiding actual secure data), then perhaps it should be made as a setting which can be changed in the setting menu (e.g. "Exclude secure data from screenshots"; it should also mention which apps use this feature), so prevent abuse. (This would also make it clear what the feature is, as well as being able to disable it.)
No because per default the input is not cleared when screenshotting. If you‘d implement this yourself for security reasons you'd most likely blur / overlay the whole screen when the app enters background state.
Probably, but to the extent that was at all a problem to begin with, multiply it by another 0.0001 or whatever for the threat of the screenshot being taken mid switch away!
Related: Airplay Screen Mirroring being too damn cleaver for its own good. Yes, I want to mirror my screen, and no I don't want the app to enforce it's own controls/blocks on what is being displayed on the external screen (Looking at all the streaming apps).
It's bad UX all around:
- iOS claims it mirrors my screen (It does not)
- Except when it does mirror my screen (Depending on the app!)
To be clear, I do think it's nice to beam the video directly to the target device for better quality, but that's not what screen mirroring is!
Tangentially, I see a lot of people here upset that apps can react to your screenshot before it is captured. I think it is helpful to think about it as a tradeoff between freedoms:
(a) the freedom to screenshot any content on your own device
(b) the freedom to share content with others that cannot be screenshotted
It can be annoying when DRM or privacy features block a screenshot, but I think it can also benefit the platform ecosystem that you participate in as a user too. Idk!
The logo is actually decentralized, we just host it on our centralized “relay”. It’s basically open tho.
We use “Zero Knowledge Pixels” so no images can be leaked onto the dark web where all the criminals live.
The way it works is, as long as our content is so moderated to hell, most dark web hosts avoid crawling us entirely. It’s just not that interesting of content. Which means it’s safe content. Safety first, I always say.
So we listened to the feedback from our dozens of users and put all watermark images on the blockchain so it’s instantly federated and backed up in a vault in Antarctica. We call it the “Waterhose”. When an image reaches the vault, it becomes “frozen” and only an admin can “thaw” the data.
It’s all backed up with proofs. By people way smarter than you lol
348 comments
[ 0.20 ms ] story [ 39.7 ms ] threadIt somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes away at some point.
The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
Found in the HN commenting guidelines, linked at the bottom of most pages
To my knowledge, this is a misunderstanding. The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.
RIP rational.
>To my knowledge, this is a misunderstanding.
re: an OS informing an app of a user action (but didn’t downvote ya)
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
https://developer.apple.com/documentation/uikit/uiapplicatio...
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
Not a marketing logo.
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.
If you send it, it is no longer yours to control.
If it is my phone, it should be mine to control. Too often it really isn't my phone...
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
Android does it too: https://developer.android.com/about/versions/14/features/scr...
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. Bit same browser running incognito on a desktop can ne merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.
I dislike this hijacking for that reason and wish there was a way to turn it off.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
Though I don’t see how this is anything like a keylogger.
> accidentally screenshotting your password manager;
I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.
It’s very obvious why this feature of the OS is useful and desired by many stakeholders. People who send each other risqué photos want them to disappear and not be screenshotted. Your employee doesn’t want you to screenshot your company confidential info or save it to your personal device. A password manager company is desperately trying to save your uncle from his own bad habits.
We can lament the lack of control of our devices but every consumer device has to save people from themselves at some point and draw a line somewhere. Perhaps we can’t assume that Uncle Larry screenshotting his password manager will be a minor consequence and a valuable learning experience.
Your microwave won’t let you turn it on with the door open. Your super modern push button transmission car won’t let you open the door with the car in drive. The GFCI outlet in your kitchen won’t let you shock yourself.
In your opinion that’s malware, in my opinion it’s a pretty useful feature. It’s totally fine that you feel this way and I am not saying you shouldn’t, but it’s worth considering the idea that a lot of people find this feature helpful.
How could you ever provide support to a user? “First take 200 screenshots and send those to me…”
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.
In 2026, we now know that the information can be edited, or completely removed for many reasons, some legitimate, and some nefarious.
Taking a screenshot is the easiest way to ensure the original is kept for folks to see. Frankly, it'd be even better if (a) the app can signal to the OS information about the url to the page for the screenshot, (b) timestamps were captured in the image and not cropped, and (c) the OS can authenticate the screen shot and digitally sign that it came from an unaltered device.
Screenshots are clunky and unideal, but at least they're fast and I know that they don't fail or break or send the wrong info to my contact.
If it were a one off message, this wouldn't be an issue, but if you zoom out on the issue and see you're sending up to a hundred messages a day, points of failure become major life frictions and you're trained out of using things like links in messaging apps.
It works! Unless:
- the person you’re linking it to doesn’t have an account on that platform
- you’re posting it in a chat, and the site doesn’t implement unfurls correctly
- the site shows a thumbnail on the link, but clicking on it gets hijacked by the “mAkE an aCcOuNt/ login here” shenanigans.
- you’re trying to link to something in context and the sites linking doesn’t support it
- the site is riddled with ads.
- the site is slow to load.
- you’re trying to save something and don’t want to have to load the site every single time in order to refer to it.
- any combination of the above.
and then when it does send I have no control over the presentation on the other side. Sites love to add some cringe "I love this app SOOOO much hearteyesemoji fire fire fire... sent from my iPhone, made with love in san cupertino" nonsense in my own voice - literally sending their words into my chats using my account, as though I had written their marketing dreck
The toast shows up after the screenshot, but my phones's long screenshot feature captures the top part a second time, so the top part of the chat becomes unreadable.
Of course this is doable on open source OSes like GrapheneOS, it just sucks that you have to keep modifying the OS every time they release a new version
At least it's open source, so maybe one can add root access and screenshot blocking to it.
1. I need to be able to monitor what's inside the memory and communications of every process running if I want to
2. I need to be able to pin a different root certificate, install a MITM SSL proxy and see what every app is sending about me, if I want to
At least on rooted Android devices you can bypass that.
I also have no issue with the API, people here are definitely overreacting to it’s existence.
The screenshot should be an artifact of what's on the screen. It's really something how tech companies have stopped even nodding in the direction of ethics.
He smokes them
You’d have to smoke that shit to come up with the decentralized/centralized fuckware that is Bluesky
Their product UI kind of looks like X, so it's helpful to know the source of a post
Personally, I wish iOS didn't even facilitate this.
edit: to be clear, I don't think iOS should notify the app at all. The app could register areas as "invisible to screenshots" perhaps - I'm torn on that functionality.
Do you/should you (we) really expect that though? I regularly use color filters on my apple devices— grayscale to avoid distractions during the day and red tint at night. More recently I’ve been using the motion dots. I don’t know that I can say with confidence that I never want any of those “personal-perceptional-modifiers” to appear in a screenshot, but for most folks, I would guess it’s approximately never.
While we're at it, this "share" containing the copy/paste flow is the exact same kind of thing. And screw whatever logic decides to copy the URL of an image instead of the actual image sometimes from Safari when I select to copy it!
It is often important to people that the screenshot is an accurate record of what was on the screen.
Yes.
It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show.
Bluesky, and apparently others, are abusing the functionality for advertising purposes.
I think it’s a good thing it’s there. This functionality should be easy for apps.
I’d say this is one for app review or an App Store rule. But we all know those are a total joke.
This is a failure of imagination for Apple, but it’s hard to blame them.
Who would think someone would put a button inside a “secure” text field and change the masked appearance to a logo?
If I was proposing this feature, I would never imagine someone would come up with something like that.
The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.
The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.
Right??
Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose is to be a share target and dump the information to file (and being apps on an app store, chances are top 10 are just thinly veiled malware).
They probably support proper export for business accounts. Business customers have leverage. Regular people? They're an annoying but necessary nuisance.
https://f-droid.org/packages/com.mateusrodcosta.apps.share2s...
https://github.com/MateusRodCosta/SaveLocally
There’s no need to implement a custom blur.
Good to hear it’s pretty straightforward on the dev side I guess, I can’t tell if this is a net benefit as a feature. I think my opinion is still rooted in user needs and I’d simply expect they are responsible for their screen shots and what sensitive info they may contain. So this feature as it exists is not a net good thing.
"Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way
Follow state is a useful bit of information. There's argument to be made for both hiding and preserving it.
As it is, it is just an annoyance that requires you to do stupid workarounds like taking a photo of your screen.
Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
... have you heard of passkeys?
Yes, it's as stupid as it sounds. And works about as well.
Or not: https://github.com/Kunzisoft/KeePassDX/issues/2321
They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.
...and it characteristic the level of patronising arrogance in the issue thread
"This is normal. It is not recommended to copy passwords to the clipboard in any case, this mitigates this behavior and complies with new Web Authentication standards."
This does not even invite a discussion. Maybe some people run tight, safe systems and know what they are doing? Maybe some people never rely on a single password being the only thing between them an an account compromise? Nope. Some patronising guy knows it all, and will override what people want to do on their machines.
Why not ask contact for data via text and just copy paste it with double check?
2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.
For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!
--
[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, every text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.
Now get off my lawn.
The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.
And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.
That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.
I don’t accidentally take screenshots very often, though it does happen.
I know multiple people who seem to take them constantly. It’s crazy. You and I may not do it, but I promise you there are people who do. LOTS of them.
So as much as a bank might agree with your stance on freedom of compute - they probably don't want to pay for it with actual money.
They really shouldn't be allowed to double down on it.
And arguably, half of it isn't even really security, it's about keeping you in their app. Application interface is the ultimate sales platform, and banks are making extensive use of that fact.
Your banking app probably has an option to disable that because it's a legal requirement in so many places: People who can't see need to use assistive tools, and that includes screenshots and friends. If you are using a tiny/stupid bank in the US, file a ADA claim and get some money. In the EU check your Ombudsman.
No, it's so you can't screen-record Netflix. The bank doesn't care about that because it's not a liability issue to them, just fetishism; no way they pay Apple and Google for this capability.
Apple and Google should step in and allow users to remove these shenanigans with a little button on the screenshot preview screen, but resist this because of Netflix et al.
Great. Which one is sending a "do I know this person?" message to my friend?
Because it _used_ to be taking a screenshot.
> Taking a screenshot of the screen is not necessary.
Who are you to tell me what is necessary?
Seriously. What the fuck.
Someone who takes a screenshot of something, and gets anything other than a screenshot is potentially being harmed in ways you don't understand, and you say it isn't necessary like you know that or something?
This exists for a very bad reason.
>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.
and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.
>I think it’s a good thing it’s there. This functionality should be easy for apps.
I think it's a bad thing it's there. The functionality should be easy for me.
Whatsapp also does this shit. You can’t screenshot a conversation (it comes back black). I am going Chinese for my next phone.
They find a good reason for every little piece of control or privacy they take from you.
I guess the Bluesky bros got inspired by Threads, again.
> and now some apps get a hook to insert their branding.
No, apps can already insert their branding anywhere they want. They're writing the app. If they want their logo to be visible in screenshots, they have infinite ways to do that.
This particular way seems basically prosocial. It's much more useful to me as a consumer of the screenshot to see that it came from Bluesky than to see that there was a "Follow" button. It's not what the feature they're using was intended for, but I can't call it an abuse of the feature. What they're actually doing is good.
The fact that you're getting unexpected behavior isn't good. Sometimes you want to create a picture of sensitive information. You should be able to override the app developer's security settings.
Because I assume most people want to take a screenshot because they want to capture something they are seeing in the app, most people probably are even annoyed to have the system indicators visible there.
Singin H-I-T-L-E-R drive around town in a fancy car
Singin H-I-T-L-E-R drive around town in a fancy car
♫
That was the expectation of using the product so it fits and isn’t anything like this discussion.
Yellow.
They fuckin did it. Not construction not a warning of some type. Not yellow pages. Yellow - cool looking yellow.
Is what I said to myself as a 20-something product designer
This deserves a longer rant, but the very premise of Snapchat was always poisonous, and is largely responsible for why, 20 years later, we're now facing extreme proposals for regulating electronic communication.
I generally disagree with the whole line of criticism techies get for "solving social problems with technology", but if there's one unambiguous case where I'd agree it was plain stupid, it's the concept of screenshot prevention, that became prominent with Snapchat. Controlling whether your recipient gets to keep the message you sent them is a purely social problem, and the answer to that in the real world has always, for good reasons, been "once sent, it's no longer yours; once received, it belongs to recipient to do with as they please".
Wdym? Hooking (primarily underage) people onto "daily streaks" of sharing (often inappropriate) pictures of themselves to (sometimes random) other people via likely insecure servers is a _great_ business model!
Great customer retention. Lots and lots of engagement. So much shareholder value.
"Forget watermarks, I'm just going to let the person know! Ha!"
The text at the top of the screenshot is
> Eric Roston
> @eroston.bsky.social
So it's pretty easy to tell IMHO.
https://github.com/mozzius/expo-privacy-sensitive/blob/main/...
I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content.
There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people are dogmatically opposed to intent being modified, but I think you need to balance nuance. I actually enjoy having an attributable source in shared elements, and I think this is a low-impact way of achieving that.
It is user hostile.
You're just defending Bluesky because you're on the same team politically. If the subject of this headline was X (an app that does the same thing, which I also don't agree with) everyone here would be seething with rage.
GP is saying that BS gets a pass where X would not for a user hostile action.
I don’t use either platform, I have no interest in the debate. As an outsider looking in, the bias has been proven.
Not that it matters much, I am left-of-center generally speaking.
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
> "You're posting too fast. Please slow down. Thanks." = censorship. Unaccountable [flag] = censorship.
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.
It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking half a day with old one invalidated and not even knowing it.
I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.
However, my idea happens to hit a very new limitation: for some reason, "privacy filters" are suddenly a thing. New phones have them built-in as some new magic display function, and for everyone else, there's this mad marketing push to get people to buy and use privacy foils in place of glass/foil screen protectors.
IDK what's up with those. Since when "shoulder surfing" with smartphones is a real problem, and why do marketers and product designers bet there's so much latent demand for it?
The only thing I could think of is if you want to browse TikTok or Instagram in public and don't want people seeing the weird shit that's on your algorithm, but even then, that's kinda weird.
Very frustrating.
I think I must have changed my password several times thinking I just copied it wrong or it had special characters that weren't allowed, but nope, the truth was somehow stupider than that.
The "useful device" is a laptop.
This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.
In my view that's a feature, not a bug. I refuse to use services that break under "reasonable" conditions (non-chrome, ublock, no widevine, rooted, etc, etc).
Banks are the canonical example - changing one is a huge hurdle, with consequences that can drag on for years. One by one, they're all ditching their websites (if they had one in the first place) in favor of apps. Even those with full-featured websites increasingly force you to use their app as the second factor to log in, confirm transactions, even confirm viewing some data. Some offer physical tokens, most don't advertise that, and it's only a matter of time before they convince regulators that Attested Phones are Safer and Everyone Has One, and that option will disappear. And because they want their app to be the second factor, they can argue it needs to be secure, creating demand for remote attestation, and boom - there goes your option to work around any other bullshit limitation they throw at you.
The day has only 24 hours, I don't want to spend them clearing bushes by walking off the beaten path wrt. every single important service - payment services, government services, IM services, ${whatever bullshit SaaS app I need right now because you're using it for the thing you just shared with me, and I need to view that}, etc. So I submit. So does everyone.
It's why I put blame on platforms here. Features protecting the device from the user should not be built in the first place - they always start justified by some legitimate security reason, and always end up broadly abused to serve business reasons.
Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".
Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.
It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later <tinyprint>0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry</tinyprint> ;-)" anyway.
Most of the time, people are given only two options: give up on their task, or ignore the popup. No point in reading the message in such cases, it brings zero value.
Repeated exposure built immunity.
You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.
The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.
Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.
We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:
Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.
--
[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.
[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.
The same can be said wrt people being too careless to have their car/bike/etc. Or powertools.
In any of those cases, just try take them away and see how that goes…
Done.
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
https://i.ibb.co/hRnn4ssF/2026-08-18-12-48-25.jpg
So yeah, I have a screenshot of the generic technician's ID photo, I guess.
Later on it did populate an actual name and photo when a human was assigned, but still, yeah, I don't get why they didn't just automatically redact it and just throw you the stupidest bullshit warning error ever on the honor system.
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed
Does this indicate that the privacy feature has a gap, where you could reveal the length of your password if you take a screenshot mid app switch?
It's bad UX all around:
- iOS claims it mirrors my screen (It does not)
- Except when it does mirror my screen (Depending on the app!)
To be clear, I do think it's nice to beam the video directly to the target device for better quality, but that's not what screen mirroring is!
(a) the freedom to screenshot any content on your own device (b) the freedom to share content with others that cannot be screenshotted
It can be annoying when DRM or privacy features block a screenshot, but I think it can also benefit the platform ecosystem that you participate in as a user too. Idk!
We use “Zero Knowledge Pixels” so no images can be leaked onto the dark web where all the criminals live.
The way it works is, as long as our content is so moderated to hell, most dark web hosts avoid crawling us entirely. It’s just not that interesting of content. Which means it’s safe content. Safety first, I always say.
So we listened to the feedback from our dozens of users and put all watermark images on the blockchain so it’s instantly federated and backed up in a vault in Antarctica. We call it the “Waterhose”. When an image reaches the vault, it becomes “frozen” and only an admin can “thaw” the data.
It’s all backed up with proofs. By people way smarter than you lol
Use our app