4 ms·
Pixelation is one of these hilarious instances of where a needlessly complicated approach is used to do something that can be done much quicker, easier, and, as
by usrbinbash 5y ago
Pixelation is one of these hilarious instances of where a needlessly complicated approach is used to do something that can be done much quicker, easier, and, as it turns out, way more secure.
Wanna redact text?
Put a solid bar over it. There, done. No takesies-backsies from that one.
- kawsper 5y ago> Put a solid bar over it. There, done. No tacksies-backsies from that one. And this is not so good advice if you're using software that supports layers and your solid bar is in another layer than what you're trying to hide. Wanna redact text? Delete it.
- usrbinbash 5y ago> Delete it. Redaction and Deletion are not equivalent. There are many instances where a visible redaction is required rather than a deletion.
- zauguin 5y agoSure, but you should still delete it. You can always add a bar at the old position afterwards. Then it's still a visible redaction, but you don't end up having a hidden copy of the unredacted text.
- signal11 5y ago> if you're using software that supports layers ...then really you should know how to flatten? Not understanding the tools you use for sensitive tasks like hiding/redacting data is a recipe for disaster.
- jrm4 5y agoSeems like "flatten" ought to be a trivially easy mechanism to implement in software somewhere, and maybe even as a standalone application for the less familiar. Basically just a nicely trimmed screenshot, no?
- lnenad 5y agoLol, that's really a stretch/nitpick, like saying: > Delete it. And this is not so good advice if you're using software that supports history and your deletion action is in another action that you can simply revert.
- deleted 5y ago[deleted]
- tomp 5y agoAlso make sure that you print the document with solid bar over confidential text, and then scan it. Replicating this process digitally is quite hard. Most pdf editors will put a square over the text, so that the original can be easily recovered.
- core-utility 5y agoWould "print to PDF" be a good enough scenario for most people putting a square over the text? I admittedly haven't looked hard enough into it but theoretically it should be flattening it.
- tomp 5y agoNo, because “Print to PDF” preserves text (i.e. text is selectable in the resulting .pdf document), so it’s gonna be selectable behind a black square as well. Although I just checked, MacOS Preview has a feature “redact” that (is supposed to) actually redact text. Well done!
- core-utility 5y agoOn MacOS 10.15 Preview, I drew an "annotated" black box over a paragraph that was recognized as text. I exported it in two ways, 1) "Export as PDF" and 2) Print -> Save as PDF. Both results did not include the underlying text under the box. That's not to say it's definitely not there, but it's at least something.
- usrbinbash 5y ago1. Delete the text 2. Set Background Text Color to black 3. Put spaces in place of redacted text 4. Save
- enriquto 5y agoFor further security, put a random number of spaces (or just one) so that the length of the secret is not leaked.
- deleted 5y ago[deleted]
- e12e 5y ago> Put a solid bar over it. There, done. No takesies-backsies from that one. Well, mostly. But say you know the name that's redacted belongs to a small group (eg: US president since 1970 to today) - you could probably rule out (and mabye rule-in, determine) the redacted name, based on font-size, kerning etc in the document. I wonder how fare a machine learning model could go, for longer reports - say 1000 pages with ~100 pages redacted - and the style of writing could be approximately inferred from the visible content - how many sentences/paragraphs could the AI fill in with some probability?
- usrbinbash 5y ago> But say you know the name that's redacted belongs to a small group True, but sometimes there is no way around this, because redacting part of the text visually, so that it is clear where and how much was redacted, may be a requirement. If there is no such requirement, one can always just replace the part of text like so: This is the original text that I am going to redact now. This is [REDACTED] now.
- nickjj 5y ago> you could probably rule out (and mabye rule-in, determine) the redacted name, based on font-size, kerning etc in the document. Depending on what you're redacting you can eliminate this variable. For example when I want to redact a piece of sensitive text in a video often times I'll make the solid black bar longer than the text being hidden. This way you can't infer the length of it based on the length of the bar. Of course this only works when you can extend the bar in such a way where it won't hide non-sensitive info that's important to see. In practice it works well, for example for redacting browser history just make the bar the entire width of the browser URL bar and for API keys or secrets often times the key exists as an env variable on its own line so extending the black bar is no problem.
- deleted 5y ago[deleted]
- core-utility 5y agoI always get a little paranoid with a solid bar even. For example, if I'm trying to block my SSN on a PDF out, I don't trust that the block won't stay a mutable block when saving it. I tend to "print" a new PDF in hopes that it flattens the document.
- MaxBarraclough 5y ago> I tend to "print" a new PDF in hopes that it flattens the document. I wouldn't count on that. A well-implemented print-to-PDF feature will try to avoid rasterising whenever possible. If you want to turn your document (whether in PDF format or something else) into a raster image, there are proper tools for that.