upvote
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.

Yes, this. Payment apps, government apps, IM communications.

The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".

My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".

--

[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...

[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.

reply
On a similar note in terms of frustration, my bank ended up getting me to memorize my randomly-generated passwords twice because it blocked pasting. I guess it's to discourage writing them down in plaintext files, but I bet it just makes most people choose meaningful (and therefore weak and guessable) passwords.
reply
> much sekhurity

This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.

reply
Then they deserve you taking a photo with a second phone
reply
There might be a market for a USB-C camera to take phone screen photos to immediately upload back into the phone.
reply
Well, I did, after the fact, but it's only because I had a work phone on me (that doesn't yet actively block sharing to non-work devices).

I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.

reply
We're heading for two devices, IMO. A useful one and one for communicating with bureaucracies.
reply
And a third one for membership apps.
reply
Software that intentionally subverts the intent of the user is malware. We now live in a world where most financial institutions literally ship malware as their primary or only interference to access their systems.
reply
I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.
reply
People also take pictures of their government IDs (passports, drivers license, etc) and utility bills.

Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?

I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.

It’s my phone, I want to decide what I take photos and screenshots of.

reply
> especially if the bank might be partially at fault if a scam happens

That's the crux.

Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).

Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.

reply
Add a system setting to ON/OFF this feature. Add a recommendation to set this as ON in the "Security Checkup" section which all modern systems have as of lately, that pops-up a couple times a year for suggesting good defaults to the user.

Done.

reply
This just reinforces the notion that apple is the one that actually owns the phone and they generously let you use it.

Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".

reply
Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.
reply
"are you sure" checks work if you force deliberate effort on the part of the user.

Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.

reply
Well, it sounds like those people are just too stupid to own phones at all then.
reply
The number of times I've seen people blow though prompts which directly refer to the issue they are coming to me about... SMH
reply
People also get scammed using accessibility services, so some banks deliberately make their app inaccessible unless you're running a whitelisted screen reader. If you are running a non-whitelisted screen reader...
reply
The remote tech support scam using screen sharing apps like team viewer is unfortunately very common and is basically why this exists.

It's also patronizing to ask during setup or whatever if the user is dumb enough to get scammed like this, even though that is kinda the actual piece of information needed

reply
“Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge. The right fix is selective redaction, not disabling screenshots everywhere.
reply
> “Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge.

Very true.

> The right fix is selective redaction, not disabling screenshots everywhere.

That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".

reply
Hoping to not sound like a broken record, this is why having full ownership of your device and OS is important. My stock Pixel Android recently told me something along the line of "A security policy blocks screenshots for this app. Talk to your administrator if you want to change the policy". I looked in the mirror and my administrator said "time for a policy change, we're moving to GrapheneOS".

And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.

reply
I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog.

WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.

... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.

reply
[dead]
reply