Warning: There’s an app for blurring out sensitive information in images called Obfuscate being featured on #GNOME Software right now.
Please be careful.
The default blur setting can easily be reversed.
The default should be to replace the areas with a solid colour or a pattern not derived from the underlying information.
This really should not be a featured app in its current state.
For a visual example of how trivial it is to reverse such techniques, see https://hackaday.com/2022/02/23/pixelating-text-not-a-good-idea/
Right, the app’s developer has agreed to change the default tool to pure colour replacement (which is secure).
While he wants to keep the blur tool also (for non-sensitive stuff/aesthetic uses), I hope that he’ll be adding a warning to it when it is first used that alerts people not to use it for sensitive information and/or that the app description reflects that.
All in all, a positive development.
And now I can go back to coding…
@paul Yeah. Just opened an issue and wrote a warning in GNOME Software in the reviews also.
@paul I mean the icon for the app is a credit card with the number obfuscated (ironically, the technique in the icon _is_ secure, unlike the default behaviour of the tool itself). I’m worried this will lead people to do exactly what is shown using it.
@aral 😬 This really should be common knowledge, I've seen lots of people make the same mistake.
Having this misfeature in a "featured app" is absolutely dangerous.
Good info. And I agree, always black out text with a solid color.
PS. that comment section is a shitshow.
Contents of blur
@janale Yep. (And yes, that’s an autocomplete corruption – the screenshot was from a bug report I filed for Helix Editor) :)
@aral @nanda It seems that some progress has been made, if they put the black bars as default and issue a warning when the blur is selected is good news, but the arrogance of the dev will make steer away from this app. Constructive criticism, like in this case, should always be welcomed. Really don't get it
@astrisk @nanda Well at least he came around eventually – that’s more than you can say for some folks :) It’s also understandable that folks become defensive sometimes when you criticise their baby. That said, all I really care about is that no one is hurt by revealing sensitive information about themselves. Fingers crossed this will be a quick update.
@aral i found using a rectangle the matches the color of the underlying text somewhat (instead of pure black) can be an aesthetic solution while still being reasonable secure, especially for text with a dark theme (where a black rectangle would just completely disappear)
i wonder how hard would it be to automate that – perhaps quantizing the color to a small palette, to avoid disclosing information through quirks in the color auto-detection algorithm
Went to flathub and saw Obfuscate in the recent updated apps, took a look and the dev already applied the corrections, great news
@aral it seems like this could be achieved more safely with a combined effect like pixelate first and then blur
@aral Blurring or pixelating are terrible options to hide the stuff. iirc, coloring over the image with an 100% opaque brush is better.
@aral True folks should be very carefull
This is my personal Mastodon.