How Bluesky draws its logo on screenshots
timmarinin.net542 points by gavide 13 hours ago
542 points by gavide 13 hours ago
If it's between this and a perpetual logo, I'll take this any day.
I actually really like this approach. The action button isn't relevant in this context, and it doesn't occlude the content.
There's certainly situations where you wouldn't want this (ie if you're developing the app and you want to redesign starting from a screenshot), but for the average user I think this isn't overly hostile. I understand that people are dogmatically opposed to intent being modified, but I think you need to balance nuance. I actually enjoy having an attributable source in shared elements, and I think this is a low-impact way of achieving that.
I actually hate that apps are allowed to blank out content on screenshots, and this can't be disabled. There are apps completely mis-using it, e.g. mobile payment apps which hardly show any sensitive data in most cases, but now I can't share e.g. infos on screen with someone else easily.
It's a classic case of someone discovering a feature and thinking "hell yeah, so much security" without understanding or caring about UX impications.
I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
> I've yet to see someone saying "oh, I'm so glad my screenshot was blacked-out because I didn't realize I was in a banking app". It feels patronizing.
Yes, this. Payment apps, government apps, IM communications.
The other day I almost rooted my phone in anger trying to get around this, before pausing and realizing that this would only cause even more problems with those apps, thanks to remote attestation "features".
My favorite recent case, I almost locked myself out of mobile government services when changing phones recently[0], and it would've made for a stellar bug report showing when "fail safe" design can easily become "fail deadly"[1], with UI view of access and invalidation history clearly showing the timeline of a problem... if only I could take a screenshot of it. But I can't, because "much sekhurity".
--
[0] - Well, it's not really that big of a deal. With government services, there's always a way back. Might involve walking to a local civil affairs office or, worst case, a police station or a notary, but there is a way back. Big cloud services, on the other hand...
[1] - Invalidating a certificate prior to issuing a new one sounds like a good security idea, but in the real world fails critically if the two operations aren't an atomic group. In my case, issuing a new certificate failed, and I ended up walking around for half a day with old one invalidated and not even knowing it.
On a similar note in terms of frustration, my bank ended up getting me to memorize my randomly-generated passwords twice because it blocked pasting. I guess it's to discourage writing them down in plaintext files, but I bet it just makes most people choose meaningful (and therefore weak and guessable) passwords.
Then they deserve you taking a photo with a second phone
Well, I did, after the fact, but it's only because I had a work phone on me (that doesn't yet actively block sharing to non-work devices).
I doubt most people have a second phone on hand, ready and able to capture actual screen shots when your phone is preventing screenhots.
> much sekhurity
This feeling usually hits me at airports, with my shoes off and water confiscated. The terrorists won.
We're heading for two devices, IMO. A useful one and one for communicating with bureaucracies.
Software that intentionally subverts the intent of the user is malware. We now live in a world where most financial institutions literally ship malware as their primary or only interference to access their systems.
I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.
People also take pictures of their government IDs (passports, drivers license, etc) and utility bills.
Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?
I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.
It’s my phone, I want to decide what I take photos and screenshots of.
> especially if the bank might be partially at fault if a scam happens
That's the crux.
Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).
Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.
This just reinforces the notion that apple is the one that actually owns the phone and they generously let you use it.
Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".
Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.
Hoping to not sound like a broken record, this is why having full ownership of your device and OS is important. My stock Pixel Android recently told me something along the line of "A security policy blocks screenshots for this app. Talk to your administrator if you want to change the policy". I looked in the mirror and my administrator said "time for a policy change, we're moving to GrapheneOS".
And just as important: Help your friends and family to move as well, so they can have ad blockers, NewPipe etc. We need a critical mass of users invested in their freedom, otherwise its going to be crushed by malicious/dumb security measures of their banking apps, corporate greed ("oh, a simple misunderstanding, when you clicked 'buy' you rented a limited license. Did you not read the ToS?") and police overreach. It's a perpetual battle.
“Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge. The right fix is selective redaction, not disabling screenshots everywhere.
> “Security” that makes ordinary sharing unusable is often just UX debt wearing a security badge.
Very true.
> The right fix is selective redaction, not disabling screenshots everywhere.
That's still a partial fix, though. It would address the problem of accidental screenshots in a better way, but the main point of contention is around intentional ones. Here, the problem is that the app vendor and the user have different notion of what is "sensitive".
I went to screenshot my upcoming Verizon Fios fiber install out of excitement and got an immediate warning dialog.
WARNING: You are in violation of the My Fios app end user licensing agreement that prohibits duplication of this screen. Please immediately delete this from your device.
... apparently buried in the app T&Cs is a "Distribution of the technician's picture or information is prohibited". Even if there's no tech assigned, the screen with the picture of the grey fake man with a fake hat apparently causes a big old warning if you screenshot it.
It is strange how this spawned a 100+ comments discussion on HN.
It's not about the logo. It's about abusing a platform feature that arguably shouldn't exist in the first place.
[flagged]
Consider the possibility that many HN users, who likely also constantly ask why mice are needed when vim/Emacs exist, are not the users who mostly use regular apps.
Uh, no? I highly doubt that a non-occluding watermark on screenshots is even in the top 100 gripes most people have with X. And I don't use either platform. If anything your argument is an accusation of bias without any discussion of merits.
Not sure why you think anyone is suggesting that non-occluding watermarks are a gripe people have with X.
GP is saying that BS gets a pass where X would not for a user hostile action.
From reading through a lot of comments on this thread, I'm honestly struggling to notice any super obvious pattern or bias other than the amount that people care about how screenshots work compared to the average person is a lot.
Yeah, the dead comment really cements the bias of hn despite what people claim.
I don’t use either platform, I have no interest in the debate. As an outsider looking in, the bias has been proven.
Not that it matters much, I am left-of-center generally speaking.
I don't think this says a whole lot about the direction of people's political views here as much as there being a general disdain for arbitrary claims of political bias that aren't based on any discernible evidence. I feel pretty confident that if I jumped into a random thread about some feature in the Brave browser and accused someone of defending it only because they agreed with Brendan Eich on Prop 8, I would get flagged too.
re: dead, I agree. I'm so tired of flags killing discussion. This site is highly regimented
What I want, as someone who vaguely leaned left and has gotten... less so, since certain revelations, are platforms that work. Where you can't just get booted off for things that are not-boot-off-worthy (sorry. wording sucks). In that view, Bluesky is something I'm interested in as a protocol. It should be something the Left and Right can both use, regardless of the people it tends to attract
From your profile:
> "You're posting too fast. Please slow down. Thanks." = censorship. Unaccountable [flag] = censorship.
> Mass un-elaborated on downvoting = censorship; needing 500 karma to downvote = censorship.
> Turn on showdead in your profile and see for yourself what people are "allowed" to comment vs what they're not. Userbase = mendacious pricks.
Apparently everything is censorship and everybody else is a prick. It's always someone else's fault. There's never responsibility taken for mean-spiritedness or rule violations.
Ever considered that if this is the hill you're dying on, your takes are just terrible and getting flagged is just this site's natural selection?
No, it's everyone else who is wrong? OK then.
I mean, the dead comment in this one is dead because of: "You're just defending Bluesky because you're on the same team politically" which is an unnecessarily unkind, snarky, uncurious way to communicate. That last paragraph was unnecessary but it tainted the entire post.
From the site rules:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly.
> Please don't fulminate. Please don't sneer, including at the rest of the community.
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
But, of course, it's everybody else's problem, never yours, never the owner of the dead comment.
You're not wrong and I do think that specific dead comment is dead for a reason. I just get a bit bristly when I do see legitimate comments buried under flags
PS - sorry. I love a great many things about HN. I'm glad the site does sometimes insist on decorum
This is phone OS developer's fault for even allowing it. When I take a screenshot, I expect to have an image of exactly whatever was displayed on the screen at the time. Its not a picture of your app, its a picture of my screen. Some banking apps used to (or still) prevent this and now some apps get a hook to insert their branding. My device serves some master other than myself.
This exists for a very good reason.
It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot. I think there are other places sensitive information won’t show.
Bluesky, and apparently others, are abusing the functionality for advertising purposes.
I think it’s a good thing it’s there. This functionality should be easy for apps.
I’d say this is one for app review or an App Store rule. But we all know those are a total joke.
I don't have an issue with BSky's use, but I regularly run into the functionality's abuse elsewhere, such as multiple of the biggest Thai banks' apps where every screen in the app entirely blocks screenshots (iOS). Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer? Blocked. Want to screenshot a promotion's terms for proof or a personal reminder? Blocked. It's even worse as multiple of the biggest brick-and-mortar Thai banks wholly dropped web access and are now smartphone-only. (Or more obscure, want to translate a single-language screen into another language? Blocked.) Etc.
>Doing a P2P money transfer and want to send a screenshot to the recipient for them to confirm their info before you hit submit on a non-reversible transfer?
Why not ask contact for data via text and just copy paste it with double check?
What if the app doesn't allow pasting? What if the communications app prevents copying?
For a short while, screenshots were a workaround for blocked copy-paste[0], as OCR (and, more recently, edge-deployed vision-enabled language models) would allow you to copy and paste any text from a screenshot. But guess what, now every other app is blocking screenshots!
--
[0] - Which is the default on mobile apps, and unfortunately desktop apps too. I hate webshit applications, but if they have one redeeming grace, it's that by default, all text can be selected and copied, and it takes nontrivial engineering effort to break that, so most webapp vendors don't bother.
1. On the pre-submit-button screen it shows the recipient's name to confirm, but as in the GP example, if the recipient's name is in a character set different than your own, it would be nice to be able to have someone who can confirm the recipient's name matches.
2. And even if you copy-paste the recipient's account number, that also relies on your counterparty not having mistyped their account number, so it would be nice for #1 to be possible to confirm the name.
I want to take a screen shot of the transaction I just did. Can't because some ahole decided for me that it's too sensitive information and blacks out the whole screen. this API is stupid without control in settings of the os
Yeah, I would rather see a warning in that case that the screenshot could contain sensitive information, with options to take a redacted screenshot or a normal one.
Yeah, I used to have this issue a lot. If I use my personal card for a business expense, I used to like to keep a screenshot of the transaction on the card as well as the invoice. As it's an app-only challenger bank, this is the only way short of exporting transactions as a PDF and that includes other transactions for the day. For a long time I used to use another phone to take a photo of my phone screen. Eventually, I just stopped bothering taking that photo because of the extra hassle, but it never stopped annoying me that I couldn't keep the records I wanted easily.
Lots of people here exposing their single sign on approve code because a scammer ask them to send them a screenshot.
I mean... "please read me the code you get via text" or "this really Bank of America, please type your OTP" seems to work well enough. We really don't need OS-level controls for stuff on the screen. People can just tell you what's on the screen.
So that means this change will result in a noticeable decline in such scams, right?
Right??
you don't have a share button tha generates a PDF and shares it with whomever?
Often, you don't, because the same developers of the bank app decided it's an unnecessary power user feature that doesn't fit in the MVP or something.
Or, even if they add it, there's no way to save the file, only to "share" it, which 99% of the times isn't what I want, and I'm frankly tired of routing through the mail app as a workaround. At this point, at least on Android side, there exist apps whose sole purpose is to be a share target and dump the information to file (and being apps on an app store, chances are top 10 are just thinly veiled malware).
Here's an open source solution on F-Droid, presumably malware-free:
https://f-droid.org/packages/com.mateusrodcosta.apps.share2s...
really? I'm not suprised by shitty developers developing shitty apps but i'm still baffled. Surely the bank would be getting tons of angry emails from customers if it happened in europe
Would they care?
They probably support proper export for business accounts. Business customers have leverage. Regular people? They're an annoying but necessary nuisance.
>This exists for a very good reason.
This exists for a very bad reason.
>It’s so if an app is showing a password or bank account number or other piece of sensitive information it doesn’t accidentally end up in a screenshot.
and also coincidentally if the app is showing something incorrect that you want to be able to verify and provide proof of now you can't.
>I think it’s a good thing it’s there. This functionality should be easy for apps.
I think it's a bad thing it's there. The functionality should be easy for me.
OTOH, I might very well want to take a screenshot of my own bank details, transactions, or other sensitive information. It's annoying that my information is being protected from myself.
You might have amazing operational security but lots of other people don't, and they make noise, which means governments write laws meaning that banks have to refund them for fraud.
So as much as a bank might agree with your stance on freedom of compute - they probably don't want to pay for it with actual money.
Banks have managed to externalize the costs of their own security onto people by inventing the concept of "identity theft", and pinning the blame for poor security practices on regular people.
They really shouldn't be allowed to double down on it.
And arguably, half of it isn't even really security, it's about keeping you in their app. Application interface is the ultimate sales platform, and banks are making extensive use of that fact.
Then it's a bad solution to a real problem. A better solution would be exposing a hook that apps can call when a screenshot is initiated that tells the OS to warn the user before saving the screenshot. This way the user is actually educated on the risk while still respecting their right to control the outcome.
The OS could draw an ugly censoring block over the sensitive information. That would protect the user's privacy when needed but also prevent apps mis-using the feature like this.
It could. But the root problem is, there is no such thing as unqualified "sensitive information". The information is sensitive to someone, for some reason. The problem with screenshots manifests when the app and the user disagrees about whether the information is sensitive and who has the right to control it.
The immediate technical problem is that OSes allow apps to declare what is "sensitive", and then follow those declarations unquestionably, preventing any preservation of that information.
The underlying social / political problem is that platform vendors allow app vendors to unilaterally declare what is and isn't sensitive, and proxy their opinion without question, and with no consideration for users and their context.
I don't think Apple cares about apps replacing the follow button with an icon. It's a weird use of the api, but it's not abusing the user or a security/privacy risk.
Yeah. I wonder if Apple does something to change this.
This is a failure of imagination for Apple, but it’s hard to blame them.
Who would think someone would put a button inside a “secure” text field and change the masked appearance to a logo?
If I was proposing this feature, I would never imagine someone would come up with something like that.
It's MY phone that I paid over $1000 for. Let me choose what is exposed and what is not.
This shows hardware won't be yours unless the software running on it is open source. Asking a company to modify its closed source software might work occasionally, but it's a band-aid and a never-ending battle.
> it doesn’t accidentally end up in a screenshot
Your banking app probably has an option to disable that because it's a legal requirement in so many places: People who can't see need to use assistive tools, and that includes screenshots and friends. If you are using a tiny/stupid bank in the US, file a ADA claim and get some money. In the EU check your Ombudsman.
No, it's so you can't screen-record Netflix. The bank doesn't care about that because it's not a liability issue to them, just fetishism; no way they pay Apple and Google for this capability.
Apple and Google should step in and allow users to remove these shenanigans with a little button on the screenshot preview screen, but resist this because of Netflix et al.
I don't think they're abusing functionality at all. I don't think screenshotting a skeet should, by default, leak the follow state of the user taking the screenshot, which is what would happen without the secure input swap
"Secure inputs" take many forms, and it doesn't feel like this is abuse in any meaningful way
One person's "sensitive input" is another's "key information".
Follow state is a useful bit of information. There's argument to be made for both hiding and preserving it.
"accidentally end up in a screenshot" --- how often do you even take a screenshot on a phone, much less accidentally?
Almost daily on my iPhone.
The side button (https://support.apple.com/en-gb/guide/iphone/iph7d116e557/io...) is on the exact opposite of the volume up button. Pressing the side button to shut down and lock the screen is something I do a lot. Press button (2) with the thumb and you will see that it is very natural to have your index or middle finger resting where the volume buttons are.
And occasionally I press hard enough with my thumb that the finger on the perpendicular side of the phone presses the volume up button and whoops I have taken a screen shot instead.
That said. I do consider this "feature" an abuse of privacy API:s, and I also often get annoyed that I cannot take screen shots of my bank app to for example send account information, or confirm a transaction, or report a graphical bug to the developers at the bank.
Consider that people use their phones differently than you. I take screenshots on a daily basis, accidental ones at least once a week. Usually it's just the lock screen though.
I take them constantly. Not even sure how. I think it means I am “of a certain age” these days.
Now get off my lawn.
i take many screenshots, but about half of them are accidental (somehow it recognizes the "tap three times" gesture whenever it feels about it)
Account numbers appear on checks. They are not exactly secret, and if I want to take a screenshot of one, I should be able to.
But how can I take a screenshot that intentionally shows the password or whatever?
Use a device with an operating system that doesn't think it knows better than you what you want.
You're not that unlikely to leave that feature in place if you have such an operating system. What you really want is two controls: one for "safe screenshot", and another for "raw screenshot".
If it's to prevent accidents, it should just prompt user to confirm saving the screenshot with sensitive information.
As it is, it is just an annoyance that requires you to do stupid workarounds like taking a photo of your screen.
Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
Funny enough, that's what the big passkey folks want: https://github.com/keepassxreboot/keepassxc/issues/10407
Really glad open-source password managers are resisting the bullying and not implementing DRM.
For now: https://github.com/keepassxreboot/keepassxc/issues/10406
Or not: https://github.com/Kunzisoft/KeePassDX/issues/2321
They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.
> Imagine if a password manager didn't allow you to copy the password since you might accidentally paste it somewhere incorrect.
... have you heard of passkeys?
Yes, it's as stupid as it sounds. And works about as well.
If a dev forgot to obfuscate the password and rendered it as plain text on the screen, then what are the chances they remember to program the blur into this screenshot api hook. Or why not add an alert, “what me to blur sensitive info? Yes/No”
Unfortunately there's platform-level features for marking surfaces as sensitive/secure. So your dev would typically just mark the whole app as such, and be proud of their proactive problem solving.
Which is why everyone should root the their phone to turn this kind of shit off.
1000%. Apps should not even be able to know that I've taken a screenshot - let alone change the contents of it.
The app doesn't know. It just produces a widget tree, and the OS-provided renderer renders it this way or that way. In particular, it chooses not to render controls marked as "security-sensitive" when the rendering is intended for a screenshot; it could instead put empty boxes in their place, etc. The app has no idea and no control, AFAIK.
Even having never developed on iOS before, I was able to find this in the first google search result for "ios api to detect screenshot": https://developer.apple.com/documentation/uikit/uiapplicatio...
Open the amazon app. Take a screenshot. See a toast message informing you that the amazon app has detected you've taken a screenshot. Fucking used for fucking profiling.
Don't apps like Snapchat notify the other person if you take a screenshot of your messages?
Yes, iOS has userDidTakeScreenshotNotification for that.
https://developer.apple.com/documentation/uikit/uiapplicatio...
Yes, Snapchat does this. Apps absolutely have the ability to know when a screenshot is taken.
Snapchat advertises that they detect screenshots. They try. But they're well aware that they can't actually know.
For example, their bug bounty program policy helpfully informs you that "screenshot detection avoidance" is not considered a vulnerability: https://hackerone.com/snapchat . That's because it's always possible.
The apps definitely know. Horsemen example: If you screenshot on Amazon (and Business version) iOS apps, it “helpfully” pops its own share sheet.
I wonder if this is the expectation of the majority or just the expectation of us tech people.
Because I assume most people want to take a screenshot because they want to capture something they are seeing in the app, most people probably are even annoyed to have the system indicators visible there.
Bank apps black out the whole screen when I take a screenshot and it’s super annoying. As a user, I should be able to take a screenshot of my screen. I can use a camera or another phone to do it anyway.
iOS allows something similar. twitter (X) will also add a logo. I believe reddit did the same but i stopped using their app a while ago.
Reddit has a toggle in its settings to disable it. X, too, I think.
Personally, I wish iOS didn't even facilitate this.
edit: to be clear, I don't think iOS should notify the app at all. The app could register areas as "invisible to screenshots" perhaps - I'm torn on that functionality.
That's what bluesky is doing in this case. It is showing the button on an area that is "invisible to screenshots", and the butterfly is behind it, so it shows through when a screenshot is taken
iOS allows something similar because this is iOS. iOS allows something exactly the same because this article is about iOS.
The thing that really irritates me about the banking apps blocking screenshots is that it's pretty clear to me it's not about protecting customers but denying customers the ability to document something related to their account.
No, it's about saving the bank money - and what costs them a lot of money is the average person being fooled into sending people their account information easily.
So...
> and now some apps get a hook to insert their branding.
No, apps can already insert their branding anywhere they want. They're writing the app. If they want their logo to be visible in screenshots, they have infinite ways to do that.
This particular way seems basically prosocial. It's much more useful to me as a consumer of the screenshot to see that it came from Bluesky than to see that there was a "Follow" button. It's not what the feature they're using was intended for, but I can't call it an abuse of the feature. What they're actually doing is good.
The fact that you're getting unexpected behavior isn't good. Sometimes you want to create a picture of sensitive information. You should be able to override the app developer's security settings.
if only there was some kind of app review process... but Apple doesn't care.
I guess the Bluesky bros got inspired by Threads, again.
> I expect to have an image of exactly whatever was displayed on the screen at the time
Do you/should you (we) really expect that though? I regularly use color filters on my apple devices— grayscale to avoid distractions during the day and red tint at night. More recently I’ve been using the motion dots. I don’t know that I can say with confidence that I never want any of those “personal-perceptional-modifiers” to appear in a screenshot, but for most folks, I would guess it’s approximately never.
I want those things included, at least by default. A screenshot normally captures the user’s screen size, brightness, zoom level, font choices, etc.
It is often important to people that the screenshot is an accurate record of what was on the screen.
The effects of cramming 2 separate workflows and 5 features into one thing called "screenshot" because anything else would end up with something too complicated for users to understand the interaction (sarcasm that figuring out what the behavior is locked to in these scenarios is just as confusing).
While we're at it, this "share" containing the copy/paste flow is the exact same kind of thing. And screw whatever logic decides to copy the URL of an image instead of the actual image sometimes from Safari when I select to copy it!
And whatever’s worse than screw for copying presumable pngs as .webp or whatever that format is
Actually, I’m a little worried by what this post demonstrates but not the logo or the use of the api.
I’m worried that switching apps and screenshots _doesn’t_ put the logo in. If the point of the switch is privacy, isn’t that a bug? Shouldn’t it apply the privacy screen during any screenshot? What if there was sensitive information on there when you were switching and taking the screenshot?
Can they do something similar so that caps include the full date/time? I hate when caps are perpetually “1 hour ago”.
This is in fact a watermark to promote the application, which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app. I didn't know that Sam literally named the file GrowthHack.tsx, which is pretty funny.
> which otherwise wouldn't be recognizable since Bluesky looks like every other microblogging app.
The text at the top of the screenshot is
> Eric Roston
> @eroston.bsky.social
So it's pretty easy to tell IMHO.
what happens when it’s a custom handle like @example.com?
Honestly I didn't know that was a possibility. In that case yes, it's probably harder in when that's in play.
Well, I have not once found a single case where an app reacting to screenshots and controlling the process in any way was anything to me but hostile and annoying. This one does not help.
It somehow is perfect example of how modern software engineering feels to go astray for me. A feature in my device working completely in benefit of the one providing said software. I wish, and wish only I can, that this trend goes away at some point.
It is actually astonishing to me that this is not something which can be turned off at the OS level, or as a permission setting in the app permissions.
The app knowing I took a screenshot feels adjacent to me to a keylogger. Imagine how many apps are capturing that information silently. To my mind, a screenshot is something that is happening outside of the app context, the app knowing about it is a security flaw imo.
> The app knowing I took a screenshot feels adjacent to me to a keylogger.
To my knowledge, this is a misunderstanding. The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager; the developer has simply performed a nifty trick to display a small icon behind where the “follow” button would otherwise be displayed.
There are plenty of instances where this sort of thing can be annoying, such as when you try to screenshot a streaming service app and DRM enforcement leaves you with a blank screenshot, but IMO this particular instance is actually very tasteful; seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
The app actually is notified after the screenshot is taken: https://developer.apple.com/documentation/uikit/uiapplicatio...
Android does it too: https://developer.android.com/about/versions/14/features/scr...
This prevents us from taking scrolling screenshots (a native feature in many smartphones today that is often useful when there is more than one screen of content).
I dislike this hijacking for that reason and wish there was a way to turn it off.
Spotify uses this and it annoys me all the time.
If you screenshot what you are listening to, after the screenshot is taken spotify will open a full-screen popup to "share" the song you are listening to. This is quite dumb, especially since if you wanted to share a song via the screenshot, you can do so in the OS-level screenshot UI, and then you would close it and see Spotify's own similar version of the same UI. Spotify just really wants you to use their own share button so that they can track you.
I’ve seen another app do that but for a different reason. It’s for security cameras and they use it to show a “hey idiot just press the save a picture button, don’t take screenshots” popup, which is also hostile.
I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
> I’m not sure why the app needs to be notified. There must be some use but I can’t think of it off the top of my head.
My pet theory: it's because Snapchat got big early, platforms added the feature to facilitate Snapchat's business model, and then banks started abusing it, and it stuck around "because sekhurity".
Yeah it’s Snapchat. If you take a screenshot of a (potentially extremely private, intended to be ephemeral) image, it notifies the person who sent it.
Anyone can take a "snap" of the phone screen with another phone's camera so this is a losing battle anyway.
It amuses me that browsers in incognito mode refuse to allow screenshots on mobile. But same browser running incognito on a desktop can be merrily screenshotted. What is the difference they are trying to enforce based purely on device form factor/OS.
Yes, it is very annoying. But I think they are already tracking you.
They want use to use the share button so your recipient is more likely to open Spotify (or whatever app) themselves.
Very interesting! Parent poster is correct, that notification does feel akin to a key logger… although I’m not sure that it applies to this bluesky feature.
So in this instance, am I right in understanding that iOS posts a notification after the user has completed a screenshot, which would make it impossible for the developer to use this notification to trigger anything that would modify that screenshot? Hence the developer’s work around?
> This is the same technology that prevents you from accidentally screenshotting your password manager
Yes, and I would say it's a bad thing that the OS tries to prevent this.
> seeing “follow” on every screenshotted post is just useless noise, but a small unobtrusive platform icon is a useful reminder that the post came from Bluesky and not another very visually similar service like X(cancel) or Mastodon.
I would say it's a bad thing that Bluesky makes the screenshot look different from what was on screen for the user. If I cared about excluding the "useless noise" from a faithful depiction of the pixels on my screen, I could address that myself.
Why is this feature bad?
As someone who develops apps for confidential conversations, making it harder for people to screenshot the confidential stuff is a feature the sending party wants, that is why they send in your app as opposed to others. It doesn’t make things impossible, just hard enough that 95% of people won’t bother to take a copy.
Same for example with disappearing audio messages on whatsapp
What I don’t like is the app being informed that I took a screenshot. The OS can hide things in screenshots without this.
One user wants it not to be shared, but the other user might have various reasons to want to take that screenshot - maybe it's evidence of something they need to share urgently with others, whatever. It's definitely hostile to that other user. I get why you'd set it up that way, but it's a tension that really goes against the "full control of your own device" ideal a lot of people have.
Don't send me anything you don't want screenshotted. Easy-peasy. I'll accept an opt-out of whatever protections are in place for the general user, but I don't accept that those protections should remain in place for all users. It's hostile.
Honestly, even schoolkids know to have another phone/camera(usually a friends) take a picture of their phone screen.
In a world where people have multiple old phones lying around it isn't that hard to come up with this workaround.
If you send it, it is no longer yours to control.
If it is my phone, it should be mine to control. Too often it really isn't my phone...
It's mostly dumb because of obvious analog loop holes. I at minimum carry 4 devices with cameras, often as many as 12. If I want to capture the disappearing message... I will do it; making it annoying just makes me pissed at the developer + the is.
> Yes, and I would say it's a bad thing that the OS tries to prevent this.
Another way to look at it is the OS makes certain guarantees to the developer around security. Giving control of this to the user would erode that guarantee from the OS to the developer. The result of that is that some developers would simply never display some information (e.g. due to their own contracts or reasonable concerns about fraud/abuse/etc.).
Very similar to the video pipelines in modern devices. Prior to video pipelines which the OS could attest could not be hijacked by the user, many content providers simply would not allow e.g. Netflix to release their content on certain platforms. That the OS does provide such an attestation option for developers allows uses that otherwise would not exist.
"The app does not know that you are taking a screenshot, rather iOS knows you are taking a screenshot (as it must) and is excluding an element on display that has been designated by the developer as sensitive information. This is the same technology that prevents you from accidentally screenshotting your password manager"
And that is reasonable, but it is also a surface where an app touches the OS, which should be a permission boundary that I can control. Allowing the option to opt-out of screenshot blocking with a proper double-confirm warning and biometric auth is also reasonable.
The OS notifies the app after the screenshot is taken. The app doesn’t get to do anything in response to it being taken or allow it to be blocked.
They’re abusing an iOS text rendering control function handled by the OS. Before the screenshot is taken iOS swapped out the rendered text for “sensitive” fields and images that.
The replacement is supposed to be something like a masked account number, password asterisks, or just general blur.
Not a marketing logo.
It's wrong. iOS sends an event on screenshot.
https://developer.apple.com/documentation/uikit/uiapplicatio...
> This is the same technology that prevents you from accidentally screenshotting your password manager
I should be able to screenshot anything I want, including my password manager. I should be able to opt-out at the OS level, or any other level that enforces it. That's why it's definitely a user hostile feature.
Neither of those use cases seem good or tasteful to me as a user, I don't think this concept of "secure (from the user) context" should exist, but maybe that's just me
Can Snapchat no longer inform the other user when a screenshot was taken?
can someone just take a picture of the phone with another phone, or use a screen recorder?
Security is never absolute, it always "merely" raises barriers.
lol. downvoting on this is quite dumb.
pretty sure i was pointing out it is best not to think you are safe sending a message without considering the fact that people do these things.
RIP rational.
mmm on average we’ve probably considered the photograph of a screen, and we were focused on:
>To my knowledge, this is a misunderstanding.
re: an OS informing an app of a user action (but didn’t downvote ya)
the other device then likely indexes it after a brief once-over by its own ai-enabled os. any crossover interactions, and it may as well be the same device. maybe some of you have not experimented enough with the theshold to have noticed yet.