Redaction
9 min readCan blurred text be unblurred? When it can, and how to redact safely
Blur and pixelation only reduce information, and researchers and open-source tools have rebuilt text from both. What the evidence shows, the conditions recovery needs, why a live-page blur is a different thing again, and the redaction routine that leaves nothing behind.
Founder, Blurr.ing
The short version
Sometimes, yes. Published research has recovered text hidden under both pixelation and blur, and free tools such as Depix and Unredacter rebuild pixelated text when the font, size and block grid can be matched. Recovery is hard and far from guaranteed, but it is possible, so treat blur as a privacy screen, not a lock. For anything that would hurt if it were read (passwords, API keys, account numbers) cover it with a solid box, export a flat image, and if a secret already went out blurred, rotate it.
- A solid opaque box is the only common redaction that leaves nothing to recover.
- Pixelation keeps one average colour per block, and that average can be matched against candidate text.
- Recovery needs the font, size and alignment to be reproducible, so short strings in known UI fonts are most at risk.
- A blur on a live page hides pixels from a camera; the text is still in the page underneath.
- If a password or key was shared blurred, assume it can be read and rotate it.
On this page
Blur, pixelation and a black box are three different operations
They look alike at a glance, but blur, pixelation and a solid box do very different things to the pixels, and only one of them throws the information away.
- Blur replaces every pixel with a weighted average of its neighbours. The letters smear into each other, but the smear is a predictable function of the original shapes: dark strokes still make darker regions in roughly the right places.
- Pixelation (also called mosaicing) splits the area into blocks and fills each block with the average colour of the pixels it covered. Detail inside a block is gone, but every block still records how much ink was in it.
- A solid box paints over the area in one opaque colour. Every pixel under it becomes identical, so the image no longer holds anything about what was there except its size.
Blur and pixelation reduce information, and a box erases it. When the hidden text comes from a small, predictable set of possibilities, reduced information can be enough.
What the research and the public tools show
Recovering obscured text has been demonstrated in peer-reviewed research and in open-source tools anyone can download.
The 2016 UC San Diego study. Steven Hill, Zhimin Zhou, Lawrence Saul and Hovav Shacham used hidden Markov models, a well-established statistical technique, to recover both short and arbitrarily long redacted text. They tested across typefaces, font sizes, grid sizes, pixel offsets and noise levels, decoded real-world redacted examples, and concluded that mosaicing and blurring, despite their widespread use, are not viable approaches for text redaction.
Deep learning against obfuscation. The same year, Richard McPherson, Reza Shokri and Vitaly Shmatikov trained neural networks to recognize faces, objects and handwritten digits that had been pixelated, blurred the way YouTube blurs faces, or protected by the P3 image privacy system. The networks did not need to rebuild a clean image; they only needed to tell which candidate the obscured one was.
Depix. A proof of concept by the researcher who publishes as spipm recovers plaintext from pixelized screenshots. Its author wrote it after someone pixelated part of a password for a highly privileged account. It renders a reference sequence of characters in the same editor and font, pixelates that the same way, and matches blocks. Its limits are stated plainly: it works on images pixelated with a linear box filter, and the blocks have to be cut out exactly.
Unredacter. In February 2022 Dan Petro of Bishop Fox released a tool that guesses text character by character, pixelates each guess, and keeps the one whose blocks match. It solved a public pixelation challenge once he had matched the font, size and offset. His conclusion is blunt: when you need to redact text, use black bars covering the whole text, with no pixelation, no blurring and no swirling.
Faces are not exempt either. In 2007 German police reversed the digital swirl a suspect had used to disguise his face in photos, and Interpol published the restored pictures. A swirl is a reversible geometric distortion, which is a different weakness from blur, but it makes the same point: an effect that only rearranges or averages pixels can leave the original within reach.
When recovery is realistic, and when it is not
Most blurred screenshots will never be decoded, because recovery takes effort and favourable conditions. The research and tools above all lean on the same conditions.
- The font can be reproduced. Unredacter's own instructions call matching the font, weight and letter spacing the hardest and most important step. Screenshots of common interfaces, set in common system and code fonts, make that step easy.
- The character set is small. Digits, hex keys and short codes give an attacker far fewer candidates than free prose. A card number, a PIN or an API key is a better target than a paragraph.
- The text is short and on one line. A single field on a plain background is far easier than mixed text over a photo.
- The effect is mild relative to the text. Small blocks or a light blur over large type keep more of the shapes than heavy obscuring over small type.
- The image is clean. Lossless PNGs preserve the exact averages. Heavy JPEG compression, rescaling and noise all make matching harder, though the 2016 study tested noise and still succeeded.
The data people most often blur in screenshots, such as passwords, keys, account numbers, phone numbers and email addresses, is exactly the short, structured, interface-font text where recovery works best. A heavily blurred paragraph of meeting notes is a poor target. A lightly pixelated eight-digit code is a good one.
A blur on a live page is a different thing again
Everything above concerns images: a file that leaves your machine with obscured pixels in it. A blur applied to a live web page, which is what a browser extension like Blurr.ing does before you share your screen, works at a different layer, and it is worth being precise about what it does and does not protect.
On a screen share, a stream or a recording, viewers only ever receive pixels. If the page is blurred when those pixels are captured, the clear text never travels to them: the video carries the blurred version, and nothing in the stream contains the original.
What it does not do is remove the text from the page. The words are still there in the document, and the blur is drawn on top of them. Anyone sitting at your unlocked computer can turn the blur off or open the developer tools and read the page. So a page blur is a privacy screen for what the camera sees, not access control. Blurr.ing's Block clicks setting stops blurred content from being clicked, selected or copied during a demo, which helps against accidents, but it is still not a lock.
The pixel rules from earlier also apply to a blurred page that ends up in a recording or a screenshot: the frames contain a blur, and a blur of short, known-font text is the case research has attacked. For most of what you blur on a call (a customer list, an inbox, a dashboard) that is an acceptable risk. For a live secret, it is not.
How to redact so nothing can come back
The rule from every source in this article is the same: when the data must never be read, cover it completely. Here is the routine.
- Use a solid, opaque box. Black, white or any flat colour, at full opacity. Make it slightly larger than the text so no ascenders, descenders or partial letters peek out at the edges.
- Flatten the image. Export a plain PNG or JPEG. A layered file or a document where the box is a separate shape can still hold the original under the box, and a PDF can keep the text layer even when the page looks covered.
- Crop when you can. If the sensitive part is not needed for context, cut it out of the frame. A crop leaves nothing to analyse, not even the length of the hidden text.
- Keep length from leaking. A box exactly the width of a name hints at the name's length. For short identifiers, a box of a standard width gives less away.
- Rotate anything already exposed. If a password, token or key went out blurred or pixelated, assume it can be read. Changing it costs minutes; a leaked production key can cost far more.
| Method | Original kept in the image? | Use it for |
|---|---|---|
| Solid box, flattened | No | Passwords, keys, account and ID numbers |
| Crop | No | Anything not needed for context |
| Strong blur or large-block mosaic | Reduced, not removed | Faces in a crowd, background chatter, long text |
| Light blur or small-block pixelation | Reduced, often recoverable | Nothing sensitive |
| Box as a separate layer or shape | Yes, under the box | Never, until flattened |
Swipe sideways to see the whole table.
The full guide, including the layer and PDF traps, is in how to redact a screenshot.
Where Blurr.ing fits on that scale
Blurr.ing works before the pixels exist: you blur the page, then you share, stream or capture it. Three parts of it touch this question.
- Blurs on the page. Boxes you draw, elements you click and text you select are blurred in place, free and unlimited. As covered above, that protects what viewers see, and the text stays in the page underneath.
- Screenshots with the blurs baked in. The capture shortcut takes the shot with your page blurs already in the pixels, and the image is built in your browser, never uploaded. Free accounts get five captures; Premium removes the limit.
- Blur areas on the captured image. The capture card's own redaction is destructive by design: it reduces each area to one colour sample per cell before softening it, so the fine detail of the original is discarded rather than smeared. That is stronger than a plain blur, and it is still a mosaic underneath. For a live secret, use a solid box.
For that solid box, and for images you already have, the free redact image tool covers areas with an opaque box, a blur or a pixelation, right in your browser. Nothing is uploaded, so it works for the screenshots you would least want on someone else's server. Use blur where you want the shape of the content to read as content, and the box where the content must never be read at all.
Sources
Every product claim above was checked against the vendor's own documentation or the original research, not against other articles.
- On the (In)effectiveness of Mosaicing and Blurring as Tools for Document Redaction, Proceedings on Privacy Enhancing Technologies 2016: Hill, Zhou, Saul and Shacham (UC San Diego): hidden Markov models recover short and indefinitely long redacted text across typefaces, font sizes, grid sizes and noise, and the authors conclude that mosaicing and blurring are not viable for text redaction.
- Defeating Image Obfuscation with Deep Learning, arXiv 2016: McPherson, Shokri and Shmatikov: neural networks recognize faces, objects and handwritten digits that were pixelated, blurred as YouTube does, or protected by P3.
- Never Use Text Pixelation to Redact Sensitive Information, Bishop Fox: Dan Petro, February 2022: how Unredacter recovered a pixelated challenge image once the font and offsets were matched, and the recommendation to use black bars only.
- Unredacter, Bishop Fox on GitHub: The tool and its manual workflow: crop, set the block size, replicate the font in CSS, pick a character set.
- Depix, by spipm on Codeberg: Proof of concept that recovers plaintext from pixelized screenshots made with a linear box filter, using a reference image of characters rendered the same way.
- High-tech work led to alleged pedophile’s arrest, NBC News, October 2007: German police reversed the digital swirl that disguised a suspect’s face in photos, and Interpol published the restored images.