The paper is from 2016. The title is dry: mosaicing and blurring as document redaction. The result is not: those filters often leave enough structure that text comes back. You do not need to implement their method. You need to stop treating a light mosaic over a six-digit SMS as equivalent to deletion.
Hill, Saorma, and Saul published “On the (In)effectiveness of Mosaicing and Blurring as Tools for Document Redaction” at PETS. The PDF is public from UCSD. This post is a reader’s note for people who redact screenshots, not a restatement of their algorithms, and not a how-to for recovering anyone else’s secrets.
What did PETS 2016 actually study?
Document redaction habits: mosaic (pixelation) and blur over printed characters. The question was whether those tools, as people use them, remove enough information. The answer, often, was no. Recovery is not a consumer “enhance” button. It is leftover structure plus a small alphabet plus time.
Cite the paper if you argue with a teammate who thinks a polite smear is a standard. Do not cite it as proof that every photo on the internet can be inverted. The authors measured a redaction habit that looks finished on a scan or a PDF and is not. They were not writing a crime guide, and this page is not either.
Screenshots of UI type are not the same corpus as scanned print. They rhyme. Monospace OTPs, account numbers, and recovery codes are short and high-contrast. That is the dangerous shape. A long paragraph under a heavy fill is a different problem, and a solid bar makes it a non-problem.
Why short secrets lose under mosaic and blur
Languages have redundancy. Digit codes have almost none, but the character set is tiny. Guessing 000000 through 999999 with visual hints is a different sport than recovering a paragraph. A stem that still looks like a 1 or a 7 cuts the search. Mosaic cells that still follow an 8 are a hint.
Practical version: if you would rotate the string after a leak, do not use the filter the paper found wanting. Use a fill. The comparison of smear versus deletion lives in blur vs bar. The consumer “unblur this photo” crowd is a separate mess, covered in can you unblur?
Open larger image in a new tabDoes this mean all blur is useless?
No. A crowd face where the requirement is “not identifiable at a glance” is not a six-digit code. The paper is about treating mosaic and blur as document redaction. Screenshot policy can still use blur for glance-level identity and bars for rotatable secrets. Mixing those standards is the mistake.
A highlighter tint on iPhone is not even the paper’s blur. It is worse: leftover contrast you can stretch with Photos sliders, as 9to5Mac showed in 2018. Do not cite PETS for that demo. Cite 9to5Mac. Do not cite 9to5Mac for mosaicing mathematics. Cite PETS. The Markup trap has its own page: iOS highlighter reveal.
How to check a mosaic before you call it redaction
Uploading a screenshot to a “test the paper” site would hand the secret to a third party to satisfy curiosity. Zoom locally instead.
- Open the export, not the layered editor file. Zoom until one character fills the screen.
- Look at cell edges. If you can still name a 1, 4, or 7 from the stem, the mosaic is a hint, not a deletion.
- Invert the image or raise brightness in any photo app. What you should see is a uniform slab, not a ghost of a glyph.
- If anything returns, paint an opaque fill over the whole run, including padding past descenders, then export a new PNG.
Academic recovery methods are not a product you owe your bug report. Deletion of samples is. A black rectangle in a raster file is inspectable without a lab.
Open larger image in a new tabShould you upload a screenshot to “test” the paper?
No. If you need a check, zoom locally, invert, raise brightness. If glyphs return, paint a bar. Export a new PNG. Keep the original off the ticket. Free unblur pages may keep or process uploads in ways you cannot see. Read the service’s retention and privacy policy before you send a sensitive file. An OTP plus the chat header around it is a complete gift.
The paper does not ask you to paste a WhatsApp code into a “research demo.” The paper asks you to stop calling mosaic a redaction standard. Believe the title for OTPs and account numbers, then rotate anything that was ever on a file that left the building.
What should teams tell people instead of “just blur it”?
Solid fill. New file. Inspect at zoom. Rotate if it was ever on a file that left the building. PNG first so you are not inventing JPEG ghosts around a smear. Crop chrome that you do not need. The paper is a reason to retire mosaic-as-policy for account numbers, not a reason to write a novel in the style guide.
Put the rule in the bug template: secrets get a bar, faces may get blur, highlighter is not a bar. Link the PETS PDF for the person who wants a citation. Do not ask reporters to reproduce recovery. Ask them to zoom the export until they cannot name a glyph.
Hub walkthrough for the actual paint: how to blur. If the string is still on screen when you capture, do not screenshot the OTP in the first place.
If you still see a stem
The box is too small, too transparent, or still a mosaic. Enlarge it. Switch to a fill. Download again. Do not send the first export “plus we will mention it in the caption.” Captions get stripped. Pixels do not.
JPEG recompress in a chat bubble can outline a light smear. Start from PNG so you are not stacking your own lossy pass on the leftover structure the paper already warned about. Format notes: PNG vs JPEG.
What to tell coworkers
PETS 2016 is a measurement of mosaic and blur as document redaction. Short, high-contrast strings are the easy case. An OTP, a card PAN, a recovery code: fill, new PNG, zoom until no stem. Faces in a standup photo can still take a heavy blur if policy is glance-level. Do not mix those bars. Do not upload the sample to prove the paper. Replace the samples in the browser and download the PNG. Zoom until no digit has a stem: paint a fill in BlurThis.





