It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.
This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.
I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.
Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?
I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.
It’s my phone, I want to decide what I take photos and screenshots of.
That's the crux.
Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).
Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.
Done.
Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".
Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.
It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed
Very true.
> The right fix is selective redaction, not disabling screenshots everywhere.
That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
GP is saying that BS gets a pass where X would not for a user hostile action.
I don’t use either platform, I have no interest in the debate. As an outsider looking in, the bias has been proven.
Not that it matters much, I am left-of-center generally speaking.
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
> "You're posting too fast. Please slow down. Thanks." = censorship. Unaccountable [flag] = censorship.
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.