Skip to main content


Warning: There’s an app for blurring out sensitive information in images called Obfuscate being featured on #GNOME Software right now.

Please be careful.

The default blur setting can easily be reversed.

The default should be to replace the areas with a solid colour or a pattern not derived from the underlying information.

This really should not be a featured app in its current state.

#security #linux #apps #obfuscate

in reply to Aral Balkan

😬 This really should be common knowledge, I've seen lots of people make the same mistake.

Having this misfeature in a "featured app" is absolutely dangerous.

in reply to Aral Balkan

For a visual example of how trivial it is to reverse such techniques, see hackaday.com/2022/02/23/pixela…
in reply to Aral Balkan

Contents of blur

extension

this.addEventListenerFile(filePath)

in reply to jan ale

Contents of blur
Yep. (And yes, that’s an autocomplete corruption – the screenshot was from a bug report I filed for Helix Editor) :)
in reply to Aral Balkan

Contents of blur
And, of course, thank you for the case in point :)
in reply to Aral Balkan

Right, the app’s developer has agreed to change the default tool to pure colour replacement (which is secure).

While he wants to keep the blur tool also (for non-sensitive stuff/aesthetic uses), I hope that he’ll be adding a warning to it when it is first used that alerts people not to use it for sensitive information and/or that the app description reflects that.

All in all, a positive development.

And now I can go back to coding…

in reply to Aral Balkan

it seems like this could be achieved more safely with a combined effect like pixelate first and then blur
in reply to Aral Balkan

Right on with you for pointing out a thing and the developer working on it "toot" de suite!
Unknown parent

mastodon - Link to source
Aral Balkan
Well at least he came around eventually – that’s more than you can say for some folks :) It’s also understandable that folks become defensive sometimes when you criticise their baby. That said, all I really care about is that no one is hurt by revealing sensitive information about themselves. Fingers crossed this will be a quick update.
in reply to Aral Balkan

I really don't understand why the dev got so defensive at the point of denial, just say "I'll check this" even without planning to do anything would still have been a better first response.