Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

381–390 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#381

Earlier quoted context omitted.

JavaScript can manipulate the contents of your clipboard without any interaction from the user. It's not just apps that can do this.

Manipulating the clipboard is not the problem, reading it is. AFAIK there is no way to read the clipboard from JavaScript without user interaction. If there is please post a repo. It used to be true but all that was fixed like 10 years ago.

Sadly, user interaction does not have to be something done by the user with intent. As another comment below mentions, the code to manipulate the clipboard can be hidden yet still kicked off by the user interacting normally with the website.

Don't know about a repo, but https://developer.mozilla.org/en-US/docs/Web/API/Clipboard_A...

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#382
post #325

Earlier quoted context omitted.

Of course, they inspect received/sent email for spam/antivirus purposes

It can also be used for safety/security — i.e. I believe GMail proxies remote images through their own servers.

Fastmail as well. It minimizes attack surface on a client. If you send an email to bob@fastmail.com, fastmail's IP is recorded as accessing the image, not Bob's home IP address.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#384

Earlier quoted context omitted.

At least in Android (not familiar with iOS) you can deny apps access to any and all permissions, the features just won't work. I.e. if you deny Snapchat access to the camera you can still browse the app, read messages etc - you just won't be able to take any photos.

That’s not my point: I’m arguing that apps like TikTok and Facebook are big enough that they could convince non-technical users (who are either ignorant-of, or just don’t care about, app permissions and privacy) to switch to an unofficial app-store where they could list their app without it being denied approval by Apple or Google for unreasonable app permission prompts. ...but the fact that unofficial app-stores for…

The scenario you're speaking of hasn't happened on Android.

As a famous example of a popular app that eventually caved into Google's demands is Fortnite [1] and children are tech savvy (or at least motivated) enough to install from outside the app store. If Fortnite couldn't do it, then no, it's not easy to imagine TikTok doing it, especially given TikTok's market share is made of mobile users mostly, so no PC, no PS 4, no Xbox.

There are indeed alternative app stores from Samsung, Amazon, maybe others, however Google's Play absolutely dominates the Android ecosystem.

I'm an iOS user myself, however this whole reasoning is bullshit. The only reason Apple keeps such a tight control is because they want to keep that 30% commission on all sales, which is highway robbery. And I also suspect them of wanting to have enough reason and leverage to get rid of any app that threatens their own products.

[1] https://techcrunch.com/2020/04/21/epic-games-launches-fortni...

---

Also the elephant in the room is the web.

I see grownups and children alike using the web successfully all the time. The web can be secure without a gatekeeper because browsers do a reasonable job at sandboxing. In fact it is the competitive nature of the market that makes it secure, consider that's how extensions and ad blockers happened (in the meantime I still don't have a browser on iOS capable of using uBlock Origin).

And yes the web has dark corners, yet we live with it just fine. Look, we're having this conversation on a web page that's not gated by Apple and we're still alive.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#385

Here's a test you should run. Create a bitly account if you don't have one and login and create a bitly link for anything, it doesn't matter what it is. Copy that bitly link to your clipboard and repeat what you're doing in that video. Monitor the bitly link for clicks. Better still do it on a website you control with a unique URL that won't get indexed by a search engine and monitor the web server log files for hits…

It's even easier than that, just use ngrok. I recorded a demo video of a web interface running locally via ngrok. Left the tunnel up while the video uploaded to YouTube so I could send it privately to a colleague and during processing I started to see requests on my tunnel. YT scraped the URL from the video and was requesting it one char at a time until the entire address was complete. IIRC this was almost two years…

That's wild! What do you mean they were requesting it one character at a time? The URL itself? If so,how do you know that? Do you also own urls in that "character space" leading up to your URL?

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#386
post #49

Earlier quoted context omitted.

And for macOS users, Touch ID takes this further without any devices, dongles or passwords, which 1Password, Dashlane, etc already supports.

It seems to me that Touch ID is slightly less secure, given that it stores your fingerprint on the device and you rely on the Apple module and crypto to be implemented securely. With a Yubikey, the only thing you have to do to stay secure is to not lose it or let others use it.

The attack surface is larger but it's still not an attack almost anyone needs to worry about - a 0 day on the T2 (which has never been publicly found/reported on) is something only worthy of nation state attacks on other nation states.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#387
post #366

Earlier quoted context omitted.

Fine-grained permissions aren’t useful if an application is going to request access to everything anyway - and non-technical or non-privacy-conscious users will click-through any and all permission prompts so [they can see the dancing bunnies]( https://blog.codinghorror.com/the-dancing-bunnies-problem/ ). In the case of very popular, aggressively-marketed, apps like TikTok and Facebook’s: the lack of easy side-loadin…

I don’t think this is the case. The way iOS tells users that an app is tracking location in the background has led to a large increase in users opting out in all the apps I’ve worked on. There are ways to be very effective at this as Apple has shown since that article was written over 15 years ago. Second, this effectiveness doesn’t require the walled garden and forcing apps to pay 30% of revenue to Apple.

Sounds like it’s working then? If an app asks me for location I personally go wtf no why do you need to know and most apps honestly don’t. I stick with apple for such a reason

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#388

It seems like a ton of apps are abusing this feature: https://www.youtube.com/watch?v=pRSWdtoUAjo I categorize this as another reason why "just trust us," just isn't acceptable enough when it comes to data privacy and ownership. Companies just cannot be trusted to treat their users' data with respect given the option of: profit or privacy. (sourced from reddit: https://old.reddit.com/r/apple/comments/hejb9i/ios14_cat…

People love to hate on Apple but the fact is, they continue to release features to better showcase or restrict developers that abuse your privacy. The "walled garden" also ensures they apply a ton of checks to apps to better restrict abuses. Sometimes it's overly sensitive and bad things happen, but in general it's awesome that over time it becomes harder and harder to get away with apps blatantly spying on you.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released:

1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts.

Sure, I could have a separate contacts app with "meta data", but this would break the integration of Contacts in other Apple products.

2. Photos. It is either full access or no access. For example, I don’t trust WhatsApp. I share photos through WhatsApp by opening the Photos app, tap share, share via WhatsApp. This works okay.

But generally speaking: why can’t Contacts and Photos have the same sophisticated access control system like Health? Heck, make it optional for iPhone users, but at least offer it.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#389

Earlier quoted context omitted.

Apples walled garden approach is not necessary for any of this though (nor does it even make it easier). You can introduce sandboxing, fine grained permissions etc without locking devs and consumers into a controlled app store - these are OS features, not app store features.

Fine-grained permissions aren’t useful if an application is going to request access to everything anyway - and non-technical or non-privacy-conscious users will click-through any and all permission prompts so [they can see the dancing bunnies]( https://blog.codinghorror.com/the-dancing-bunnies-problem/ ). In the case of very popular, aggressively-marketed, apps like TikTok and Facebook’s: the lack of easy side-loadin…

> Fine-grained permissions aren’t useful if an application is going to request access to everything anyway

If you build it right, it is totally doable. Implement it like in Health so that the app just gets empty data and doesn’t really know if it has access or not.

If the app doesn’t function properly with an empty data set, reject such an app through App Store guidelines.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#390

Earlier quoted context omitted.

It's even easier than that, just use ngrok. I recorded a demo video of a web interface running locally via ngrok. Left the tunnel up while the video uploaded to YouTube so I could send it privately to a colleague and during processing I started to see requests on my tunnel. YT scraped the URL from the video and was requesting it one char at a time until the entire address was complete. IIRC this was almost two years…

That's wild! What do you mean they were requesting it one character at a time? The URL itself? If so,how do you know that? Do you also own urls in that "character space" leading up to your URL?

My guess is that each frame of the video was OCR'd for text, so as the author typed a URL in one character at a time it was producing unique substrings on-screen and the youtube bot dutifully tried to fetch each of those unique substrings
Post reply on HN