9 ms·
How to prevent screenshots in a web browser
- EGreg 12y agoAnd oncw again if your user is a developer he'd or she'd be able to stitch it back together.
- scrollaway 12y agoThat was not the point of the article. In fact, had you read the article, you'd find that your point has been addressed three times over and that the author acknowledges it's all futile anyway.
- spaulo12 12y agoBut reading the article takes time! People need to comment quickly!
- mikeash 12y agoI don't think he quite does. His conclusion is basically that image protection isn't worth it, because more exposure is better. That's different from declaring it to be futile.
- EGreg 12y agoExactly. I read the article. At the end he declares it isn't worth it, which is a different sentiment altogether. He seems to believe that his last-minute addressing of the screenshot "attack" is adequate, even though earlier he was talking about an audience which is a developer themselves. For such an audience, his mitigation of the attack isn't really effective at all. That's what I was pointing out. He just forgot about the standard he set up in first part of his article when writing the update.
- NathanKP 12y agoThat demo messed with my eyes. Even though it is interlacing faster than the eye can see for some reason it still felt weird to look at it. Overall, not worth the trouble or the decline in user experience.
- mikeash 12y agoI'm pretty sure it's not interlacing faster than the eye can see, which is the whole problem. For this to work perfectly, your monitor refresh rate would need to be at least 2x higher than what your eyes can detect. And why would anyone build hardware with such a fast refresh rate? It's a cute idea, but in the end it ruins the image for normal uses just like the watermarks do.
- colanderman 12y agoWell, the website's down, so I can only speculate, but, how is the website to know the screen's refresh rate? If the site assumes, say, 60 Hz, but the rate is actually 72 Hz, you'll see an odd "fading" effect between the two interlace frames at a rate of 12 Hz, which is very noticeable. EDIT: Ah, I see he uses window.requestAnimationFrame [1] to sync with the frame rate, so this is not a problem. [1] https://developer.mozilla.org/en-US/docs/Web/API/window.requestAnimationFrame https://developer.mozilla.org/en-US/docs/Web/API/window.requ...
- mikeash 12y agoIt doesn't actually have to know. There's a JavaScript API called requestAnimationFrame which asks the browser to invoke a callback for the next display refresh. Invoke requestAnimationFrame again from that callback, and you'll get a steady stream of callbacks at the display refresh rate, or whatever the browser thinks it is. Here's the relevant code from the demo: var work = (function() { var toggle = false; return function tester() { frame1.style.opacity = toggle?.5:1; frame2.style.opacity = toggle?1:.5; toggle=!toggle; requestAnimationFrame(tester); }; })(); requestAnimationFrame(work);
- 12y ago
- GotAnyMegadeth 12y agoI could see it flickering and when I tried to print screen I got the image... Disclaimer: I only skimmed the artcle
- CanSpice 12y agoClearly the best way is to link to a popular site and have your webserver be overwhelmed by traffic. Can't serve images? Then users can't steal them!
- drz 12y agoTake a few screenshots, until you get one image with the odd lines, and one with the even lines, then stitch them back together in Photoshop. 2 minute job, tops.
- Aardwolf 12y ago2 minutes is quite a long time. Long enough to not bother unless you really want that particular image...
- programmer_dude 12y agoThis can be automated in javascript. There is no need for photoshop. I won't be surprised if someone comes up with a browser extension to neutralize it.
- drz 12y agoDepends on what your hourly rate is, and what they're charging for the image. For most people (especially the billions in the developing world) it's a good use of their time.
- spindritf 12y agoPreviously, https://news.ycombinator.com/item?id=8022315 https://news.ycombinator.com/item?id=8022315
- dyeje 12y agoYou could still subvert this by taking an actual picture of the screen with a camera I think.
- JetSpiegel 12y agoThe analog hole. If your eyes can see it, so does a camera.
- alexhawdon 12y agoYup. In audio copy protection this is referred to as the 'analogue hole' (http://en.wikipedia.org/wiki/Analog_hole http://en.wikipedia.org/wiki/Analog_hole), and there's pretty much nothing you can do about it.
- dsr_ 12y agoHow to drive away customers: prioritize your unproven loss of income over making an attractive product. Accuse all your users of copyright infringement.
- paulhauggis 12y agoI really dislike this attitude on HN. You can have great products that make no money because cracks get popular (I have done testing with my own software and know for sure this is the case) and get higher results than the original product listing on google, Adblock, and many other methods thought to be "rights". Even look at music piracy. Pirates did the big labels a favor: small, independent artists can't make a living anymore because everyone just expects it to now be free. They now are almost forced to go with a big label if they actually want to make any kind of living.
- colechristensen 12y agoRegardless of what you believe I am not going to patronize you if you treat me like a thief, likewise I'm going to fight tooth and nail to ensure that I am the one that controls the device I physically own, not a content business.
- meshko 12y agoLike it or not, you can't do it, so don't waste your time.
- stcredzero 12y agoTo be able to do this on browsers is foolish. Devices might be workable, though they would only be on the same level of deterrent as a cheap lock. A user could always take a photograph of the screen.
- kstrauser 12y agoThat attitude is realism. It's not unreasonable to take minor steps to make casual copying easier - the clear GIF overlay is a good example of that - but there ain't no such thing as perfect digital restrictions management. Anything beyond those minor steps becomes an inconvenient nuisance for your real customers and the risk/reward paying just isn't worth it. Imagine you have a stock photo website. Basically honest potential customers might try right-clicking a photo once to download it, and failing that will whip out their credit card. Basically dishonest non-potential customers aren't going to pay you and see your protections as something fun to be worked around. There just isn't a business case for heroic measures that can ultimately be trivially defeated.
- terminado 12y agohttp://www.patrick-wied.at/talks/image-protection/demos/cat.png http://www.patrick-wied.at/talks/image-protection/demos/cat....
- bsimpson 12y agoThat looks terrible in Chrome for Android.
- nbush 12y agoCool, I love counterintuitive (and even counterproductive) solutions just for their own sake. I tried to do a similar thing with text a while ago: http://nbush.github.io/headache/ http://nbush.github.io/headache/
- awhitty 12y agoThis is clever! I think it can be circumvented by removing all spans in a paragraph with more than 1 character.
- nbush 12y agoThanks! Yeah, there are many JS ways around this, but it would be more than enough to stop most people... including myself in most cases.
- fabrixxm 12y ago"Tired of people stealing your content? Looking to make copying HTML text a huge pain for your users? Sick and tired of useful, well-made Python scripts? Headache will make it so users cannot select, copy or paste html text without getting a bunch of garbage as well. Try copying this sentence. No, seriously, try it. Yeah that's right. Now try pasting it somewhere. Now the only way you can steal my sweet, sweet content is by writing it out letter by letter or writing your own noble script that filters out all the junk. Checkmate. You might say that this solution is unintuitive, massively inefficient and completely unnecessary. Well that's not the true Hacker Spirit now, is it? " ;)
- abbeyj 12y agoAs a challenge I wanted to see how hard it would be to circumvent this. Here's a bookmarklet: javascript:void(function(s,i){for(i=0;i<s.length;i++)if(window.getComputedStyle(s[i]).color=='transparent')s[i].style.display='none'}(document.getElementsByTagName('span'))) That should be one line with no spaces if gets line wrapped.
- nbush 12y agoNice work! Here's another solution posted in an earlier thread: javascript:d=document.createElement("div");d.innerHTML="<style>span:nth-child(odd) {display:none;}</style>";document.body.appendChild(d); I don't think there's any easy way for the obfuscation to stay ahead of JS reversal. Thanks for taking a look!
- shmerl 12y agoWhy would anyone want to do such stupid thing? It would prompt users to bypass it just because. And there are tons of ways to make a series of screenshots or even a video of the screen. Ksnapshot, imagemagick (import), ffmpeg, avconv etc. etc. > let’s assume things on the web should be protected… Let's assume DRM is a dumb and nasty idea which always leads to very crooked practices. Period. As if we don't have enough of this EME nonsense.
- stcredzero 12y agoThe evidence shows that DRM in the service of corporations and businesses tends to be nasty. But there are reasons to believe that DRM, if used to protect the data and privacy of individuals would be very valuable, with the caveat that it would have to be implemented in a trustworthy way. What if there was a way to provide access to your medical records to people who need them, only for as long as they need them? What if even the provider of the service couldn't easily circumvent this?
- shmerl 12y ago> But there are reasons to believe that DRM, if used to protect the data and privacy of individuals would be very valuable, with the caveat that it would have to be implemented in a trustworthy way. DRM can not be trustworthy by its mere definition (because trust is a mutual thing, and those who deploy DRM don't trust you - the user. So you have every reason not to trust them in return). And it never can be valuable since it's not only unethical and insulting towards users (since it uses presumption of guilt and police state ideas), but it's also completely ineffective and all it does is punishing paying customers, while the vast majority of actual pirates don't deal with it. DRM should just die out for good. > What if there was a way to provide access to your medical records to people who need them, only for as long as they need them? Authentication and information security has nothing to do with DRM, even though both can have features like encryption. Let's not mix unrelated subjects.
- stcredzero 12y agotl;dr - Let's please think about the economics! Let's not just believe emotionally charged Internet aphorisms, but examine things thoughtfully. Authentication and information security has nothing to do with DRM, even though both can have features like encryption. Let's not mix unrelated subjects. What is the limiting of who can have my personal data and when, but Digital Rights Management, or DRM? One cannot stop at authentication, because to be complete, one has to prevent copying data. Without this, it becomes problematic to trace who has released information, and without some legal support, nothing at all is practical. DRM can not be trustworthy by its mere definition Sorry, but this is fluff. You could apply this "logic" to authentication as well. DRM has to involve some mutual trust and cooperation to the same extent that any protocol involves mutual trust and cooperation. The key is to realize that DRM as practiced by corporations is evil and unworkable because the economics were utterly unrealistic. Really, where DRM could help individuals would be the elimination of trivial deniability on the part of corporations. Right now, when your data privacy is breached, there is no cost to "break" anything and it's very hard to pin this on a particular corporation. Add a DRM mechanism, and then there is something tangible to apply protection laws to and a labor cost with definite intent to breach an individual's privacy. In aggregate, the cost and potential legal liability becomes too high to for virtually any corporation to contemplate. We would arrive at a situation where corporations could afford to violate the privacy of a few select individuals, but could no longer do so to the public wholesale. Ordinary citizens would enjoy a measure of protection, though rich individuals and corporations would not. Sounds pretty good to me. Underlying everything, I'm not so much advocating DRM, as I'm calling to question emotionally charged "magical thinking" combined with naive induction. Let's not just leave things at "DRM is bad" devoid of real examination of what's happening. EDIT: It also occurs to me that the historical factual differences between individuals and corporations should be used to modify the current formulation of "legal persons." "Legal Persons" should be considered as "persons" only in terms of a few specific factors, like the owning of property. The historical difference between actual and legal persons with regards to data privacy abuses would be an important corpus of information in support of this.
- stonogo 12y ago1. You can't. 2. Stop trying.
- philjackson 12y agoRead his "Was it all worth it?" section.
- kstrauser 12y agoTL;DR You can't, stop trying. It's not worth the effort, it's tilting at windmills, and it pisses your users off. Just stop.
- todd3834 12y agoI am glad that this guy tried. I found some of the techniques pretty clever and I enjoyed reading the article. I do not believe you can stop people from taking screenshots and stealing images but I never considered some of the techniques the author explained. He was much closer to solving this than I expected.
- shmerl 12y agoInstead of that, the author could just talk about why interlacing was used in video in the past. No need to bring any DRM context in the discussion. The tone of the article is what's offending, not the technical details.
- pa7 12y agoCould you please elaborate what's offending you? (author here) for me it was just a fun experiment I didn't intend to offend anyone
- shmerl 12y agoJust the notion that DRM is something that should be used in general. I find the concept of DRM to be insulting towards the users. Also this part: > seems like there is a problem — let’s solve it for fun and profit It's like saying: "Police state struggles with policing measures. Let's help it for fun and profit". I hope you get the idea why this can sound offending.
- todd3834 12y agoI don't see anything wrong with developing a better bike lock for fun and profit. Not to build a straw-man argument but isn't that the same line of thinking?
- wslh 12y agoThe answer is simple: you can't prevent (all) users from taking a screenshot in a web browser. The solution is trivial: launch a VM, make a screenshot, hook APIs such as DirectX, etc.
- cousin_it 12y agoSo here's a startup idea that can help with that. 1) Build a library for hiding encrypted information inside images. It should be hard to detect (indistinguishable from random) and robust (e.g. survive printing and scanning). 2) Build a web crawler, coupled with a key store. Crawl the internet for images that contain our encrypted info. 3) The copyright owners will be our paying clients. They will display images only to logged in users, use our service to embed the user information in the image, and deposit the encryption key with us. 4) Whenever the crawler finds a stolen image, we notify the copyright owners and send them the details of the user who leaked it. We don't notify the user, of course. Right?
- rasur 12y ago>for hiding encrypted information inside images. otherwise known as Steganography.
- aragot 12y agoI was under the assumption that image/theme services did that already, especially with website themes? That may be an idea for a copyright troll, btw. Disseminate not-for-commercial-use for free, then charge dozen of thousands of dollars when infringement is found.
- AlyssaRowan 12y agoI gather there was a distinct suggestion that at least one infamous copyright troll had done something like that because the only place their content had ever been found was on The Pirate Bay, uploaded by them, which they subsequently threatened users for downloading. (You can guess how well that turned out for them.)
- AlyssaRowan 12y agoIt seems to me that you've basically described Digimarc®'s business model.
- cousin_it 12y agoHah! Yes, you're right.
- skizm 12y agoI am having trouble with the last demo, I always get the full image when I print screen and then paste to paint. Anyone else?
- zobzu 12y agoIts kinda cool even thus of course id never want that on a website. That said, i took a screenshot on windows 8.1+Firefox and it worked just fine. I took a few more screenshots.... and they were all fine too...
- joosters 12y agoIt broke my firefox :( First, a popup error message reporting: SyntaxHighlighter Can't find brush for :jscript and then the whole browser became unresponsive and needed to be restarted. On the plus side, you've helped Firefox development by discovering a new bug!
- Qantourisc 12y agoAlso this burns a lot of CPU cycles :(
- sidcool 12y agoIf someone gets really pissed off, they will just take a pic of their screen with an SLR and then photoshop it.
- justbaker 12y agoThe title is incredibly misleading..
- joeblau 12y agoYou're still sending the picture across the network to the screen in your most valiant attempt, but by using the inspector's resources, you can get a url link to the cat image[1]. Like you say at the end of the article, it's not really worth it. The site being slow is a better deterrent than anything written in the post. 9 Seconds to first byte[2]. [1] - http://www.patrick-wied.at/talks/image-protection/demos/cat.png http://www.patrick-wied.at/talks/image-protection/demos/cat.... [2] - http://www.webpagetest.org/result/140714_WZ_S9F/ http://www.webpagetest.org/result/140714_WZ_S9F/
- spiritplumber 12y agoIt took 20 years to get image interoperability down to "solved problem" status, so let's get start from scratch by coming up with something that you have no idea will work on cheap tablets, will eat up CPU on battery powered devices, and makes unwarranted assumptions about display technology! Yay!
- MrZongle2 12y agoAh, the newest form of "disabling right-click on a web page". Infuriating, bad design then. Still is.
- deleted 12y ago[deleted]
- fuzzywalrus 12y agoAnyone else try it? I was curious and tried his live demo URL. and I used OS X's built in screen capture while using Chrome. The screen capture worked, no special tricks needed. I didn't see any visual degradation between my screen shot and the original. The long and short of it is his DRM did not work.
- jamesgagan 12y agosame here cmd-shift-4 worked fine on both images.
- hobbes78 12y agoThat also happened to me. But then I realized I set the browser to display everything in 110% by default. If you go back to 100% indeed you can't do a proper screenshot...
- miketuritzin 12y agoThis article (which I enjoyed) reminded me of a paper [1] I co-authored a long time ago about protecting 3D content using a remote rendering system. The big advantage that we had over 2D content (images) is obviously that we never gave clients a full representation of the protected asset. [1] http://graphics.stanford.edu/papers/protected/protected.pdf http://graphics.stanford.edu/papers/protected/protected.pdf
- autokad 12y agointeresting article and method. when viewed from remote desktop, the image always appears interlaced. otherwise, on a regular screen its barely noticeable. at first glance it looks fine, but then i get the feeling something is off. if i blink or look away quickly, i can see some of the interlacing. but overall, interesting idea of treating the images more as movies rather than images
- ZoFreX 12y agoI think maybe you could do this. What about the new, controversial DRM extensions? They're for video, but you could just show a 1 frame video on loop as an image, right? If those support HDCP then it's encrypted all the way to the display, and it would be challenging to screenshot it. (Of course, you could take a photo of the screen, but that's a substantial degradation).
- drdaeman 12y agoIsn't HDCP broken?
- FedRegister 12y agoWhen will website authors learn that you control the content but the client, by virtue of owning their computer, controls the presentation. At best you can make suggestions. At worse you're at the total mercy of the user. If you want to give out indelible images then go back to print.
- qwerta 12y agoI got more solutions: 1) Ship your own lock-down hardware (tablet) to customers, so they can visit your website 2) Install booths around country which will show your website. No cameras or phones allowed inside!
- jastanton 12y agoI did something similar you can demo: http://jastanton.com/experiments/imagescrambler/ http://jastanton.com/experiments/imagescrambler/ Shuffle an image, re-assemble with a bunch of divs with background offset and just the right amount to bring the picture back. If you download the image you get a scrambled imaged. Doesn't protect against screenshot. Very fun :)
- russelluresti 12y agoSo, the demo obviously blinks (at least on my monitor), and the first time I took a screen shot, I got the whole image (though I only got half the second time). So, it doesn't actually work all that well. But cool write-up, I guess.
- snorkel 12y agoGood article explaining some clever techniques. I don't understand all of the whiners here who expected something perfect and foolproof.
- Scalar 12y agoI found this fairly clever but pretty impractical. If you put an image online you must assume that it is public domain. The only real way to prevent true theft is to offer a lower quality image but this defeats the purpose of putting your image online in the first place. Nonetheless there are pretty smart ways to monetize content like this and any professional source will pay to use it.
- meshko 12y agoThere is a silly Russian saying which school teachers usually use on that really smart asshole kid in the class -- "a fool got blessed by smart head". Somehow reading this made me think of that. Also think of the environment, how much power will you waste on this useless hack if it were to get wide adoption (not going to happen of course, but _if_)