upvote
> The app knowing I took a screenshot feels adjacent to me to a keylogger.

To my knowledge, this is a misunderstanding. The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.

There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.

reply
reply
This prevents us from taking scrolling screenshots (a native feature in many smartphones today that is often useful when there is more than one screen of content).

I dislike this hijacking for that reason and wish there was a way to turn it off.

reply
Spotify uses this and it annoys me all the time.

If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.

reply
I’ve seen another app do that but for a different reason. It’s for security cameras and they use it to show a “hey idiot just press the save a picture button, don’t take screenshots” popup, which is also hostile.

I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.

reply
Yeah it’s Snapchat. If you take a screenshot of a (potentially extremely private, intended to be ephemeral) image, it notifies the person who sent it.
reply
Anyone can take a "snap" of the phone screen with another phone's camera so this is a losing battle anyway.

It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. But same browser running incognito on a desktop can be merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.

reply
Actually I was referring to the Eufy app. How nice there are others.
reply
> I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.

My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".

reply
No, that feature long predates Snapchat. In fact, I think it predates iOS, but I don’t remember for sure.
reply
Yes, it is very annoying. But I think they are already tracking you.

They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.

reply
Very interesting! Parent poster is correct, that notification does feel akin to a key logger… although I’m not sure that it applies to this bluesky feature.

So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?

reply
Correct.

Though I don’t see how this is anything like a keylogger.

reply
> This is the same technology that prevents you from accidentally screenshotting your password manager

Yes, and I would say it's a bad thing that the OS tries to prevent this.

> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.

I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.

reply
Why is this feature bad?

As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.

Same for example with disappearing audio messages on whatsapp

What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.

reply
One user wants it not to be shared, but the other user might have various reasons to want to take that screenshot - maybe it's evidence of something they need to share urgently with others, whatever. It's definitely hostile to that other user. I get why you'd set it up that way, but it's a tension that really goes against the "full control of your own device" ideal a lot of people have.
reply
Don't send me anything you don't want screenshotted. Easy-peasy. I'll accept an opt-out of whatever protections are in place for the general user, but I don't accept that those protections should remain in place for all users. It's hostile.
reply
Honestly, even schoolkids know to have another phone/camera(usually a friends) take a picture of their phone screen.

In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.

If you send it, it is no longer yours to control.

If it is my phone, it should be mine to control. Too often it really isn't my phone...

reply
It's mostly dumb because of obvious analog loop holes. I at minimum carry 4 devices with cameras, often as many as 12. If I want to capture the disappearing message... I will do it; making it annoying just makes me pissed at the developer + the is.
reply
> Yes, and I would say it's a bad thing that the OS tries to prevent this.

Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).

Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.

reply
But… but they allowed. For a long time. Netflix didn’t need that.
reply
"The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager"

And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.

reply
The OS notifies the app after the screenshot is taken. The app doesn’t get to do anything in response to it being taken or allow it to be blocked.

They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.

The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.

Not a marketing logo.

reply
Neither of those use cases seem good or tasteful to me as a user, I don't think this concept of "secure (from the user) context" should exist, but maybe that's just me
reply
> This is the same technology that prevents you from accidentally screenshotting your password manager

I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.

reply
Can Snapchat no longer inform the other user when a screenshot was taken?
reply
can someone just take a picture of the phone with another phone, or use a screen recorder?
reply
Security is never absolute, it always "merely" raises barriers.
reply
lol. downvoting on this is quite dumb.

pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.

RIP rational.

reply
mmm on average we’ve probably considered the photograph of a screen, and we were focused on:

>To my knowledge, this is a misunderstanding.

re: an OS informing an app of a user action (but didn’t downvote ya)

reply
the other device then likely indexes it after a brief once-over by its own ai-enabled os. any crossover interactions, and it may as well be the same device. maybe some of you have not experimented enough with the theshold to have noticed yet.
reply
Able to elaborate for me?
reply
I think bsky's use of this malware feature is as benign as it's possible to get, but it's still a malware feature. As you point out, the real reason this exists is to enforce DRM and make your computer serve Netflix et al rather than the person who owns it.

> accidentally screenshotting your password manager;

I could not think of a more useless justification for installing malware into the OS. Okay, you've accidentally screenshotted your password manager. So what? Are you going to accidentally upload it to the internet too? I'd much rather live in a world where people who are that stupid face minor consequences for their actions than one in which all of our own computers are used against us.

reply
deleted
reply
As with most things, it would be ideal if we could have both good defaults to make things accessible and advanced user controls to allow users to retain control. That’s a rare mix these days.
reply
People like to say that. How many hundreds of additional options would a modern phone OS need to provide that though? How could applications possibly be tested? You could have a million installs and 300,000 of them could easily have fully unique combinations of options past what’s available today.

How could you ever provide support to a user? “First take 200 screenshots and send those to me…”

reply
> The app knowing I took a screenshot feels adjacent to me to a keylogger.

That is what this article is about and why you should read it before commenting. The whole point is that it doesn't need to know you're taking screenshots. That's why it's a clever trick.

reply
But for completeness, iOS apps can detect screenshots. That’s what allows them to show annoying popups with a share option when you take a screenshot.
reply
What? App-B on iOS knows when I'm taking a screenshot from App-Y? I don't have iOS to check but that seems crazy.
reply
No, I was talking about App Y knowing about a screenshot you take of App Y.

Isn’t that what everyone is talking about?

reply
Yes, that commenter is lost.
reply
I guess it would need permissions, but you can monitor the photo library with PHPhotoLibraryChangeObserver and check if a new item's subtype is photoScreenshot.

Otherwise userDidTakeScreenshotNotification only fires for your own app

reply
but you didn't read the part where the mechanism is explained? it doesn't do anything like capturing information. it just marks a button "sensitive" causing it to be hidden in a screenshot, thus revealing an icon that was put there underneath the button.
reply
Did you read the article? Bluesky doesn't know you're taking a screenshot, iOS just hides the follow button in the screenshot (consequently making the Bluesky logo visible).
reply
iOS does tell the app that a screenshot was taken though
reply
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".

Found in the HN commenting guidelines, linked at the bottom of most pages

reply
Noted, I'll keep that in mind when commenting in the future.
reply