The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
To my knowledge, this is a misunderstanding. The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
Android does it too: https://developer.android.com/about/versions/14/features/scr...
I dislike this hijacking for that reason and wish there was a way to turn it off.
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. But same browser running incognito on a desktop can be merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
Though I don’t see how this is anything like a keylogger.
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.
If you send it, it is no longer yours to control.
If it is my phone, it should be mine to control. Too often it really isn't my phone...
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
Not a marketing logo.
https://developer.apple.com/documentation/uikit/uiapplicatio...
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.
RIP rational.
>To my knowledge, this is a misunderstanding.
re: an OS informing an app of a user action (but didn’t downvote ya)
> accidentally screenshotting your password manager;
I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.
How could you ever provide support to a user? “First take 200 screenshots and send those to me…”
That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.
Isn’t that what everyone is talking about?
Otherwise userDidTakeScreenshotNotification only fires for your own app
https://developer.apple.com/documentation/uikit/uiapplicatio...
Found in the HN commenting guidelines, linked at the bottom of most pages
If someone from Google Maps or LinkedIn team is here, please, when I take a screenshot it's because I want to a screenshot, not share the friggin location/post.
Not sure who got the idea that it was useful, it isn't.
If I'm sending a screenshot it's because I want to send exactly what I see on my screen and not have my recipient's gmaps instance happily recompute a route it thinks is better or leave out the routing information I included, or switch from biking to driving directions, or whatever else.
Ah... to imagine a world where you could just share a coordinate string and people could open it in whatever map app/page they wanted. Geo URI is probably the closest we have today but I don't think much of anything outside the OS Geo community accepts it.
A lat/lon/zoom/start?/dest? is kind of what a Google Maps share currently is, but it's neither an interoperable standard nor a reliable capture of the current state, so really the worst of both worlds.
(Also, hi AB! Nice to see you on here)
[1]: https://www.alltrails.com/trail/canada/ontario/harrison-trai...
I believe it was their response to what3words. It's not as good at the "communicating by text" use case as what3words.
It's not clear who it is protecting against, it does not seem to be effective at protecting against anything at all, it is actively annoying to the user, and has no way to disable. Perfect example of the usual "security theater" feature.
I don't have an iOS device handy to compare against, but it surprises me that Apple wouldn't also recognize that Wi-Fi passwords in particular are extremely common things to share.
Unsecure: open Shortcuts, tap Gallery, search “Adjust Clipboard”. Add to Action Button folder and run from Action Button. - Or add “Dismiss Siri and Continue” action after “Get Clipboard” so you can say “Siri, Adjust Clipboard”.
Type in the still-unreasonably small window, tap Done, paste password. (Then clear clipboard I suppose and consider privacy implication if your clipboard syncs to Mac.)
Could write my own phone operating system to not be subject to the iOS WiFi password field display settings though!
Oh wait it absolutely does.
Just like their iCloud Keychain API that lets apps secretly track users across app reinstalls and device resets.
Do you use the same password on every site? How do you deal with data breaches?
> Do you use the same password on every site?
I use a password I can reconstruct in memory for sites I care about logging in by hand. If I don't, or don't mind resetting my password each time, I just use random garbage + whatever platform password manager is the one active today, with vague hopes that it'll still be there the next time I need to log in.
> How do you deal with data breaches?
Who ever cares about those? I'm yet to hear about anything impactful being released on those. It only matters if you actually do reuse the same e-mail/login and password combinations on both important sites and garbage sites. Which is something you should not. But 2FA and magic links tend to solve that vendor-side, these days.
A physical notebook is so easily lost I wouldn’t even consider it.
Just search for keepass in the app store (Keepassium, KeePass Touch, Strongbox, ...)
Frank Dux was a fraud! :)
And I prefer to see and choose the data an app stores on my fucking ICLOUD ACCOUNT. And fucking DELETE it when I want.
There's no way to do that from an iOS device.
But this one looks like you actually mean it? Yikes.
Hijacking the screenshot process is a privilege that you ought to be able to revoke, it's insane to allow software to be given more control.
And don't tell me it's anything to do with security when it can be circumvented in any number of ways.
It should not exist as a control in the first place.
I know it may sound absolutist, but the way I see it: if you allow this as a user-revocable permission, then the very apps that need to be screenshotted by users most often will be the first to refuse to work at all unless you grant this permission.
Screenshotting is an system operations level feature. Apps should be neither aware of, nor able to interfere with, a screen capture being taken.
The toast shows up after the screenshot, but my phones's long screenshot feature captures the top part a second time, so the top part of the chat becomes unreadable.
It works! Unless:
- the person you’re linking it to doesn’t have an account on that platform
- you’re posting it in a chat, and the site doesn’t implement unfurls correctly
- the site shows a thumbnail on the link, but clicking on it gets hijacked by the “mAkE an aCcOuNt/ login here” shenanigans.
- you’re trying to link to something in context and the sites linking doesn’t support it
- the site is riddled with ads.
- the site is slow to load.
- you’re trying to save something and don’t want to have to load the site every single time in order to refer to it.
- any combination of the above.
Screenshots allows you to get a point in time reference to what you are sharing.
Screenshots are clunky and unideal, but at least they're fast and I know that they don't fail or break or send the wrong info to my contact.
If it were a one off message, this wouldn't be an issue, but if you zoom out on the issue and see you're sending up to a hundred messages a day, points of failure become major life frictions and you're trained out of using things like links in messaging apps.
In 2026, we now know that the information can be edited, or completely removed for many reasons, some legitimate, and some nefarious.
Taking a screenshot is the easiest way to ensure the original is kept for folks to see. Frankly, it'd be even better if (a) the app can signal to the OS information about the url to the page for the screenshot, (b) timestamps were captured in the image and not cropped, and (c) the OS can authenticate the screen shot and digitally sign that it came from an unaltered device.
and then when it does send I have no control over the presentation on the other side. Sites love to add some cringe "I love this app SOOOO much hearteyesemoji fire fire fire... sent from my iPhone, made with love in san cupertino" nonsense in my own voice - literally sending their words into my chats using my account, as though I had written their marketing dreck
Of course this is doable on open source OSes like GrapheneOS, it just sucks that you have to keep modifying the OS every time they release a new version
At least it's open source, so maybe one can add root access and screenshot blocking to it.
You don't have to wish, in this scenario. Bluesky supports third-party clients, you can use one that has a more minimal featureset if you prefer.
Android and iOS should not let apps do this, because it can be (ab)used by apps that you can’t really choose not to use.
I know there’s a popular bank in my country that completely blocks screenshots and screen recordings on Android somehow.