Researchers unblurred mosaiced text in 2016. Your OTP is not special.
A PETS paper showed blur and mosaic on text can be recovered. Short numbers are the easy case.

The paper is from 2016. The title is dry: mosaicing and blurring as document redaction. The result is not: those filters often leave enough structure that text comes back.
You do not need to implement their method. You need to stop treating a light mosaic over a six-digit SMS as equivalent to deletion.
Hill, Saorma, and Saul published “On the (In)effectiveness of Mosaicing and Blurring as Tools for Document Redaction” at PETS. The PDF is public from UCSD. This post is a reader’s note for people who redact screenshots, not a restatement of their algorithms.
What did PETS 2016 actually study?
Document redaction habits: mosaic (pixelation) and blur over printed characters. The question was whether those tools, as people use them, remove enough information. The answer, often, was no. Recovery is not a consumer “enhance” button. It is leftover structure plus a small alphabet plus time. Cite the paper if you argue with a teammate who thinks a polite smear is a standard. Do not cite it as proof that every photo on the internet can be inverted.
Screenshots of UI type are not the same corpus as scanned print. They rhyme. Monospace OTPs, account numbers, and recovery codes are short and high-contrast. That is the dangerous shape.
Why do short secrets lose?
Languages have redundancy. Digit codes have almost none, but the character set is tiny. Guessing 000000–999999 with visual hints is a different sport than recovering a paragraph. A stem that still looks like a 1 or a 7 cuts the search. Mosaic cells that still follow an 8 are a hint. A long sentence under a heavy fill is a different problem — and a solid bar makes it a non-problem.
Practical version: if you would rotate the string after a leak, do not use the filter the paper found wanting. Use a fill. Can you unblur?
Does this mean all blur is useless?
No. A crowd face where the requirement is “not identifiable at a glance” is not a six-digit code. The paper is about treating mosaic and blur as document redaction. Screenshot policy can still use blur for glance-level identity and bars for rotatable secrets. Mixing those standards is the mistake. Blur vs bar.
A highlighter tint on iPhone is not even the paper’s blur. It is worse: leftover contrast you can stretch with Photos sliders, as 9to5Mac showed in 2018. Do not cite PETS for that demo. Cite 9to5Mac. Do not cite 9to5Mac for mosaicing mathematics. Cite PETS.
Should you upload a screenshot to “test” the paper?
No. You would be handing the secret to a third party to satisfy curiosity. If you need a check, zoom locally, invert, raise brightness. If glyphs return, paint a bar. Export a new PNG. Keep the original off the ticket.
Academic recovery methods are not a product you owe your bug report. Deletion of samples is. A black rectangle in a raster file is inspectable without a lab.
What should teams tell people instead of “just blur it”?
Solid fill. New file. Inspect at zoom. Rotate if it was ever on a file that left the building. PNG first so you are not inventing JPEG ghosts around a smear. Crop chrome that you do not need. The paper is a reason to retire mosaic-as-policy for account numbers, not a reason to write a novel in the style guide.
Put the rule in the bug template: secrets get a bar, faces may get blur, highlighter is not a bar. Link the PETS PDF for the person who wants a citation. Do not ask reporters to reproduce recovery. Ask them to zoom the export until they cannot name a glyph. The paper’s title already says ineffectiveness. Believe the title for OTPs and account numbers.
Replace the samples in the browser and download the PNG. Zoom until no digit has a stem: paint a fill in BlurThis.
