Really cool concept. While it wouldn't phase someone actively trying to retrieve the source image (i.e., I'm sure someone could write a screenshotting service for Android) that could get around this pretty readily, I'm sure that this would phase all the basic screenshotting functionality on mobile (and otherwise) currently.
I wonder if there's a way to obscure the source image even more though; while the details aren't clear the the source positive and negative frames, it's still pretty clear that it's an image of a face. Perhaps the addition of some sort of noise that could be cancelled out would work.
It would also be interesting to see this applied to video streams in addition to just static images.
EDIT: A very simple workaround that would be easy for the general public is to just take a picture of the screen with another device. Example: http://i.imgur.com/ZLdpp.jpg
I was about to mention rapid screenshoting as an exploit, but you took care of that. However, couldn't a rapid screenshoting application end up replacing the default screenshot function if this technique became commonplace? As the bar for using the vulnerability gets lower, the technique grows more and more useless. Maybe this can be modified to eliminate the exploit somehow (my thoughts go towards adding more randomness in some way or another)?
Even if it were to become a commonplace way to time-protect images, I can't really see Apple making their screenshotting functionality actually deal with it - they'd be doing it just to circumvent this simple security system, it wouldn't have any other benefits. On Android, though (and jailbroken iOS), I can definitely see people writing mods to break this right away.
I don't think that this technique (even in a more complicated form) could ever be exploit-proof. Even with more randomness or noise, a computer can ultimately compute the same averaging that our eyes are doing, and could always get the source image back.
There's an even easier exploit too: just record the screen with another device.
Comments
Really cool concept. While it wouldn't phase someone actively trying to retrieve the source image (i.e., I'm sure someone could write a screenshotting service for Android) that could get around this pretty readily, I'm sure that this would phase all the basic screenshotting functionality on mobile (and otherwise) currently.
I wonder if there's a way to obscure the source image even more though; while the details aren't clear the the source positive and negative frames, it's still pretty clear that it's an image of a face. Perhaps the addition of some sort of noise that could be cancelled out would work.
It would also be interesting to see this applied to video streams in addition to just static images.
EDIT: A very simple workaround that would be easy for the general public is to just take a picture of the screen with another device. Example: http://i.imgur.com/ZLdpp.jpg
Your very simple workaround is also mentioned by the author as 'the analog hole' if I presume correctly.
I was about to mention rapid screenshoting as an exploit, but you took care of that. However, couldn't a rapid screenshoting application end up replacing the default screenshot function if this technique became commonplace? As the bar for using the vulnerability gets lower, the technique grows more and more useless. Maybe this can be modified to eliminate the exploit somehow (my thoughts go towards adding more randomness in some way or another)?
Even if it were to become a commonplace way to time-protect images, I can't really see Apple making their screenshotting functionality actually deal with it - they'd be doing it just to circumvent this simple security system, it wouldn't have any other benefits. On Android, though (and jailbroken iOS), I can definitely see people writing mods to break this right away.
I don't think that this technique (even in a more complicated form) could ever be exploit-proof. Even with more randomness or noise, a computer can ultimately compute the same averaging that our eyes are doing, and could always get the source image back.
There's an even easier exploit too: just record the screen with another device.