Controlling a screenshot function to obfuscate sensitive information in a screenshot
In some implementations, a device may monitor a screenshot function of a user device. The device may receive, via an application, sensitive information associated with an operation of the application. The device may detect a screenshot instruction associated with the screenshot function capturing a screenshot of a graphical user interface of the application that is displaying the sensitive information. The device may control the screenshot function to suspend a capture of the screenshot of the graphical user interface. The device may identify a portion of the graphical user interface that includes the sensitive information. The device may mask portion of the graphical user interface to obfuscate the sensitive information. The device may enable the screenshot function to capture, according to the screenshot instruction, the screenshot with obfuscated sensitive information. The device may unmask the portion to enable the sensitive information to be displayed via the graphical user interface.
1 . A system for obfuscating sensitive information in a screenshot, the system comprising:
one or more memories; and
one or more processors, coupled to the one or more memories, configured to:
receive a screenshot instruction associated with capturing the screenshot, wherein the screenshot is of a display of a user device;
control, based on an authorization to control a screenshot function of the user device, the screenshot function to suspend a capture of the screenshot for a time period;
configure access to the screenshot function, wherein control of the screenshot function is enabled when a graphical user interface of an application of the user device is actively presented on the display of the user device, and is disabled when the graphical user interface is not actively presented on the display, wherein the application comprises an information management application;
mask, before an expiration of the time period, a portion of the graphical user interface of the user device that includes the sensitive information to form a masked portion that obfuscates the sensitive information on the graphical user interface;
verify, prior to enabling the screenshot function, that all fields designated as associated with sensitive information have been masked on the graphical user interface;
enable, after the masked portion is formed and after verification that all designated sensitive fields have been masked, the screenshot function to capture the screenshot; and
unmask, after the expiration of the time period, the masked portion to enable the sensitive information to be displayed via the portion of the graphical user interface.
2 . The system of claim 1 , wherein the portion of the graphical user interface that includes the sensitive information is identified based on being associated with a first field of the application that is designated as being configured to receive a type of sensitive information, and wherein the designated sensitive fields include the first field.
3 . The system of claim 2 , wherein the portion of the graphical user interface that includes the sensitive information is identified based on the first field being populated with content.
4 . The system of claim 1 , wherein the portion of the graphical user interface that includes the sensitive information is identified based on the portion of the graphical user interface being actively displayed on the display of the user device.
5 . The system of claim 1 , wherein the one or more processors are further configured to control a duration of the time period based on a length of time required to mask the portion of the graphical user interface.
6 . The system of claim 1 , wherein the one or more processors are further configured to control a duration of the time period based on at least one of:
a size of content, in the portion of the graphical user interface, that is representative of the sensitive information, or
a size of the portion.
7 . The system of claim 1 , wherein the one or more processors, to mask the portion of the graphical user interface, are configured to at least one of:
alter pixel values of the portion of the graphical user interface, or
overlay, on the display of the user device, a masking image over the portion of the graphical user interface.
8 . The system of claim 1 , wherein the one or more processors are further configured to:
perform an action associated with enabling the screenshot to be sent or stored, wherein the screenshot includes the masked portion of the graphical user interface or a non-masked portion of the graphical user interface that is not associated with the sensitive information.
9 . A method for obfuscating sensitive information, comprising:
receiving, by a device and via an application, sensitive information associated with an operation of the application;
detecting, by the device, a screenshot instruction associated with capturing a screenshot of a graphical user interface of the application that is displaying the sensitive information;
controlling a screenshot function to suspend a capture of the screenshot for a time period;
configuring, by the device, access to the screenshot function, wherein controlling the screenshot function is based at least in part on the graphical user interface being actively presented on a display of the device, wherein the application comprises an information management application;
identifying, by the device, a portion of the graphical user interface that includes the sensitive information;
masking, by the device and before an expiration of the time period, the portion of the graphical user interface to obfuscate the sensitive information;
verifying, by the device and prior to enabling the screenshot function, that all fields designated as associated with sensitive information have been masked on the graphical user interface;
enabling, after the portion of the graphical user interface is masked and after verifying that all designated sensitive fields have been masked, the screenshot function to capture the screenshot with obfuscated sensitive information; and
unmasking, after the expiration of the time period, the portion of the graphical user interface to enable the sensitive information to be displayed via the graphical user interface.
10 . The method of claim 9 , wherein the screenshot is monitored based on the application being configured to monitor the screenshot function, and wherein the screenshot function is controlled based on the application being configured to control the screenshot function to prevent screenshots from including content in at least one field of the designated sensitive fields, and
wherein verifying that all fields designated as associated with sensitive information have been masked comprises determining, by the device, that each designated field including the at least one field is visually obscured on the graphical user interface prior to enabling the screenshot function.
11 . The method of claim 9 , wherein the screenshot function is controlled by an operating system of a user device.
12 . The method of claim 9 , wherein masking the portion of the graphical user interface comprises:
removing, from a field of the graphical user interface that is within the portion of the graphical user interface, content that is representative of the sensitive information, or
altering a value of the content.
13 . The method of claim 9 , further comprising:
storing, in a data structure of a user device, the screenshot, wherein the screenshot includes the obfuscated sensitive information and a non-masked portion of the graphical user interface that is not associated with the sensitive information.
14 . The method of claim 9 , further comprising:
generating a report that indicates that the screenshot instruction was received when the sensitive information was displayed on the graphical user interface; and
providing, to a management device, the report and the screenshot.
15 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a user device, cause the user device to:
control, based at least in part on a screenshot instruction associated with capturing a screenshot of a display of the user device, a screenshot function of the user device to suspend a capture of the screenshot for a time period in accordance with an authorization to control the screenshot function;
configure access to the screenshot function, wherein control of the screenshot function is enabled when a graphical user interface of an application of the user device is actively presented on the display of the user device, and is disabled when the graphical user interface is not actively presented on the display, wherein the application comprises an information management application;
identify a portion of the graphical user interface of the user device that includes sensitive information;
mask, before an expiration of the time period, the portion of the graphical user interface to form a masked portion that obfuscates the sensitive information on the graphical user interface;
verify, prior to enabling the screenshot function, that all fields designated as associated with sensitive information have been masked on the graphical user interface;
enable, after the masked portion is formed and after verification that all designated sensitive fields have been masked, the screenshot function to capture the screenshot; and
unmask, after the expiration of the time period, the masked portion to enable the sensitive information to be displayed via the portion of the graphical user interface.
16 . The non-transitory computer-readable medium of claim 15 , wherein a duration of the time period is based at least in part on:
an amount of the sensitive information that is being presented on the graphical user interface, or
a set of characteristics of the display.
17 . The non-transitory computer-readable medium of claim 15 , wherein the screenshot function is controlled by an operating system of the user device.
18 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, to mask the portion of the graphical user interface, cause the user device to:
remove content that is representative of the sensitive information, or
alter a value of the content.
19 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions further cause the user device to:
store, in a data structure of the user device, the screenshot, wherein the screenshot includes the obfuscated sensitive information and a non-masked portion of the graphical user interface that is not associated with the sensitive information.
20 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions further cause the user device to:
generate a report that indicates that the screenshot instruction was received when the sensitive information was displayed on the graphical user interface.