Show HN: Secure sensitive info while recording videos live or screen sharing
blurweb.app
blurweb.app
Overall OBS can just create a generally better presentation, and make you look competent, in addition to helping with this specific issue. And of course it is free.
1. Do whatever you can to minimize sensitive info exposure before you even start streaming or recording. For example I created a shell script which backs up and clears my shell history and does other things[0]. Make a note to use a browser where your history is cleared too.
2. Sometimes it's easier to say screw it and show the sensitive information with full intent that you're going to change your API keys, password or whatever sensitive data is shown. This ends up being much better because now you don't need to worry about blurring anything because you know you'll re-roll your keys. This is really good for pre-recorded videos vs live streams.
3. If you need to hide secrets, put all secrets into an .env file and have a .env.example file handy to show how to set them up without showing your real secrets. This is another way to eliminate ever having to blur anything and have a 0% chance of ever exposing a secret.
4. If you need to hide something, put a solid color over it instead of blurring it so it can't be reversed.
5. One of the pain points with hiding something in a video is the sensitive info might be on a page where you're scrolling up and down on the page which means you need to move your solid color rectangle or expand it based on which frame is showing. But overall this isn't too bad with most video editors since you can click and drag a rectangle onto a specific point in your timeline. If you adhere to the first 3 steps, you'll often only need minor hiding in all of your streams and videos.
6. Often times you're hiding unexpected things, like maybe you're logged into GitHub to make a video about an open source project but you view your GitHub feed which shows a list of private organizations you do freelance work for. This is the type of stuff to watch out for, which IMO also makes certain editor plugins that try to hide secrets not that useful since you can hide them in other ways, and it sets you up with a false sense of security because there's many other sensitive things outside of your editor to think about.
I'm not trying to deter you from building your tool, but I suppose I'm having trouble seeing how I would use it in practice. I'd be curious to hear how other folks handle this.
[0]: https://nickjanetakis.com/blog/bash-aliases-to-prepare-recor...
https://gitlab.com/stavros/itsalive
It's a Live is a piece of software that lets you prerecord all your commands (by typing them all up in a simple text file) and then replays them when you press keys on the keyboard.
If you run through a rehearsal once or twice, there's no risk of exposing anything (since it'll always replay the presentation the same way), and it has some niceties like showing you the previous/current/next commands, allows you to take over control and resume easily, etc. I quite like it.
You start up something by typing into the start menu, but between pressing the first and second letters for some frames unintended documents could flash up.
You need to try typing the alphabet one by one into these fields to see whether anything sensitive comes up.
Edit: nice recommendations on your part!
If you use a VM or burner device the chance of such happening is negligible. You can also use a second account which has less rights than your main account. A feature which Google's Android conveniently has (guest mode).
As others have mentioned, I'd like more secure ways to blur the area, e.g., completely blanking it out, or filling with random text and then blurring.
Edit: Would also be useful to replace the text instead of blurring, that way viewers could see realistic information without revealing real keys, etc.
Edit: Please allow the plus (+) symbol for emails.
can you explain Please allow the plus (+) symbol for emails? please
The text example in the article that GP linked[1] looks pretty reversible to me indeed. Not sure it needs a neural network, or at least it could be enhanced a lot with character frequency checking or matching words against a dictionary, but I haven't ever seen text unblurred where I didn't expect it might be possible.
Personally I don't find blurring to be less annoying than a reasonable color. Pitch black stands out a lot, but something close to the background color (but clearly distinct) is unobtrusive while also being clear that something was censored and not just a broken image.
[1] https://hsto.org/storage2/eff/36d/77a/eff36d77a583b46e461c12...
You have some typos on your page, I found two within the first ten seconds of [skim-]reading. Find them and fix them! :)