@cR0w @Salty @GossiTheDog @xanathar
I'm not even sure that's the conflation. It seems that we're not accounting for frequency and impact; two extremely significant metrics in risk assessment.
The frequency of a user photographing a screen is likely small. Compared to automatically screenshoting a screen every 20 seconds.
The impact of a user photographing a screen is likely high, but not compared to automatically screenshoting EVERY app, performing OCR on the text, saving it to a DB, et al
@cR0w @Salty @GossiTheDog @xanathar
Or, to put it more bluntly, it's intellectually dishonest to pretend like a user is going to take 1400 photos during an 8 hour work day, OCR them, catalogue them, and potentially lose them to hackers.
And worse than dishonest, it's immoral to shirk our responsibility as infosec practitioners and equate the two risks.
(8hrs * 60m * 60s)/20sec = 1440 photos in a 8hr shift.