I'm working on a project that aims to give a lot of freedom for user-generated content, and I've been wondering for a while how to protect from the picture-in-picture attacks.
One way is to ban an entire color region around a particular color you choose for fields requesting passwords or doing other sensitive data. The problem with it is of course that it's too big of a limitation.
But how about a pattern like yellow/black checkerboard or stripes? This would require the parent to be able to analyze the child's look, and whenever the security pattern would be detected, it would display some kind of a warning about the content being similar to a secured input without actually being the secured input...