Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

401–410 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#401

Earlier quoted context omitted.

Apples walled garden approach is not necessary for any of this though (nor does it even make it easier). You can introduce sandboxing, fine grained permissions etc without locking devs and consumers into a controlled app store - these are OS features, not app store features.

And yet no one else has

Flatpak has done this better than iOS has.

- Completely FOSS stack

- Uses multiple repositories (no lock-in)

- Everything is sandboxed with Bubblewrap

- Fine-grained permission control that offers more than iOS: control whether apps can access the network, which directories an app can access, if it can print, and even whether or not it can access PulseAudio.

- Cross-platform: runtimes are OCI container images and can be targeted on any distro that supports Flatpak (which is almost all of them).

It's gained adoption from a number of recognizable FOSS and proprietary names: Zoom, Spotify, Steam, Firefox, VLC, Discord, Libreoffice, Skype, Inkscape, both Minecraft and Minetest, Microsoft Teams, Krita, IntelliJ IDEs (both Community and Professional), and Blender are available as Flatpaks through Flathub.

GNOME and KDE release almost all their apps as Flatpaks through the `gnome` and `kdeapps` Flatpak repos, and copy them over to Flathub when they're confident that Flatpak-ing didn't introduce any bugs.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#402
post #52

Earlier quoted context omitted.

I'm probably going to get downvoted to hell for saying this (again) but this still doesn't solve the problem of whether Apple themselves are abusing your privacy. Also, the closed-source OS means it's impossible to see what things are doing under the hood, or modify the behavior of the OS itself to be more privacy friendly. For example, on Apple if you aren't happy with an app snooping on your IMU data, you're out of…

> this still doesn't solve the problem of whether Apple themselves are abusing your privacy Eventually you have to trust someone. This added transparency from Apple is commendable. I support open source for publicly funded software, but if it's privately owned and funded, you can choose to buy and use it or not. Private companies are not under any moral obligation to open source their code or methods. Some people are…

> Eventually you have to trust someone.

Perhaps, but Apple is the last company I would trust. They work in a culture of secrecy and engineer for obscurity rather than transparency, and that does not make them trustable at all.

> Private companies are not under any moral obligation to open source their code

But I will give far more trust to those who do so, or at least the privacy-critical parts. With Android I need to trust no-one; I can modify things on the OS level that do not necessarily execute apps in the way those apps expect to be executed, and that is the ultimate privacy guarantee.

I own the hardware, so how my hardware runs software should be my choice; the entire set of instructions and APIs for creating phone apps is merely a suggestion for how the OS should execute apps, and how a stock OS executes apps, but does not necessarily reflect how I choose to have my hardware execute them.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#403

Earlier quoted context omitted.

not a single person, but the sum of all people looking at the different parts. that's how open source works.

I've said this before, but the dogmatic belief that open source automatically means something is safer just isn't true. In theory it means something could maybe be safer, but it far from guarantees it.

Being able to inspect the code is a necessary but insufficient measure for being secure. If you cannot inspect the source code, you are not fully aware of how the program works.

Tools like strace can help you analyze a program's behavior from the outside, but you get limited insight into its internals (e.g., what algorithms is it using?).

Being open source does not automatically make software more secure. A successful compilation doesn't automatically make your code bug-free. Yet both are necessary to achieve the desired goal: security and correctness, respectively.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#404
post #388

Earlier quoted context omitted.

People love to hate on Apple but the fact is, they continue to release features to better showcase or restrict developers that abuse your privacy. The "walled garden" also ensures they apply a ton of checks to apps to better restrict abuses. Sometimes it's overly sensitive and bad things happen, but in general it's awesome that over time it becomes harder and harder to get away with apps blatantly spying on you.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Both added in iOS 14.

I guess Apple's not "full of shit" anymore.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#405
post #392

Earlier quoted context omitted.

As extortionate as Apple’s fees are, I’m actually glad that they have a business model that isn’t dependent on invasion of privacy. Without them continually calling attention to it, Google would have little incentive to improve privacy.

Google payed Apple $12 billion in 2019 to remain the default search engine in Safari. I hear this line about their business model all the time, however it is bullshit. Given the opportunity all companies will take the money. And I fear that it is nothing more than a conspiracy theory, without much evidence, much like anti-vaxxing. Google these days is a very big target. The EU would love to have reason to slap them w…

Google payed Apple $12 billion in 2019 to remain the default search engine in Safari.

It's a large amount, even for Apple, but they would survive losing that. Besides that, they are even taunting Google by putting DuckDuckGo in their marketing copy:

https://www.apple.com/macos/big-sur-preview/

They also started a partnership with them in 2019:

https://www.cnet.com/news/apple-maps-gooses-duckduckgo-in-se...

I think they are slowly preparing to loosen that tie.

I hear this line about their business model all the time, however it is bullshit. Given the opportunity all companies will take the money.

I agree. Apple's incentives are just temporarily aligned with customer's privacy. Their margins on hardware, services, etc. are so large that they can afford to make privacy a differentiator. If they are not in that comfortable position anymore, they would monetize the vast user data trove.

But while this is the status quo, I am happy to use an iPhone for privacy.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#406
post #169
post #155

Earlier quoted context omitted.

Even if one were to ignore Google’s data collection, any non-vanilla android installation would have been butchered by the vendor (Samsung, Motorola, etc) to the point any expectation of security (and in turn privacy) is lost to the least secure app pre-installed. I had ESFileExplorer installed on a Nexus 7 tablet I barely used. One day I start it to find the charging has switched to “smart charging” where this softw…

I often use Motorola devices as I find they are one of the OEMs which applies the fewest customizations to the OS. However Samsung is definitely a problem when it comes to that. I am not sure what happened in your case with ES or how that would be possible. It sounds like maybe the app just pushed you an advertisement as a notification. Notifications can be disabled on a per-app basis but I think it is pretty reasona…

I often use Motorola devices as I find they are one of the OEMs which applies the fewest customizations to the OS.

They got worse, also with updates since they were acquired Lenovo. Last time that I surveyed the Android landscape (~2 years ago), Nokia was the place to go for a pristine Android experience with quick updates.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#407
post #366

Earlier quoted context omitted.

I don’t think this is the case. The way iOS tells users that an app is tracking location in the background has led to a large increase in users opting out in all the apps I’ve worked on. There are ways to be very effective at this as Apple has shown since that article was written over 15 years ago. Second, this effectiveness doesn’t require the walled garden and forcing apps to pay 30% of revenue to Apple.

Sounds like it’s working then? If an app asks me for location I personally go wtf no why do you need to know and most apps honestly don’t. I stick with apple for such a reason

The point was "it's an OS feature, not an Appstore feature, so Apple's Walled Garden approach has nothing to do with that feature, Apple's OS has".

It's working. But not because of Apple's Appstore policies.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#408

Earlier quoted context omitted.

Google payed Apple $12 billion in 2019 to remain the default search engine in Safari. I hear this line about their business model all the time, however it is bullshit. Given the opportunity all companies will take the money. And I fear that it is nothing more than a conspiracy theory, without much evidence, much like anti-vaxxing. Google these days is a very big target. The EU would love to have reason to slap them w…

Google payed Apple $12 billion in 2019 to remain the default search engine in Safari. It's a large amount, even for Apple, but they would survive losing that. Besides that, they are even taunting Google by putting DuckDuckGo in their marketing copy: https://www.apple.com/macos/big-sur-preview/ They also started a partnership with them in 2019: https://www.cnet.com/news/apple-maps-gooses-duckduckgo-in-se... I think th…

I really think Apple will buy DuckDuckGo at some point. The question is, to what extent will Apple make DuckDuckGo (or whatever they'll rename it to) available for non-Apple platforms?

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#409

Earlier quoted context omitted.

That’s not my point: I’m arguing that apps like TikTok and Facebook are big enough that they could convince non-technical users (who are either ignorant-of, or just don’t care about, app permissions and privacy) to switch to an unofficial app-store where they could list their app without it being denied approval by Apple or Google for unreasonable app permission prompts. ...but the fact that unofficial app-stores for…

The scenario you're speaking of hasn't happened on Android. As a famous example of a popular app that eventually caved into Google's demands is Fortnite [1] and children are tech savvy (or at least motivated) enough to install from outside the app store. If Fortnite couldn't do it, then no, it's not easy to imagine TikTok doing it, especially given TikTok's market share is made of mobile users mostly, so no PC, no PS…

This is true in most parts of the world, but in China where almost all phones are Android and Google apps are not preinstalled on any of them, the alternative app store hijacking definitely happens.

In particular Tencent is notorious for not being the default app store on any phones, but somehow "mysteriously" if you follow links from WeChat or QQ or even certain websites, it will try to make your phone download the Tencent app store to install the app instead of just using your phone's default app store. Even your phone gives a warning not to do it, people still install it. And, sure enough, Tencent app store is now the biggest app store in China, with 25% of the market.

Tiktok is owned by Bytedance, which doesn't even have an app store in China, so i can't see them making a play.

Fortnite, on the other other hand, is owned by Epic who definitely used the popularity and income from Fortnite to leverage their way into the PC gaming marketplace, disrupting the major player (Valve). They might not have won this battle for the phone marketplace, but by the sounds of it they still haven't given up the war.

So, i do think it's fair for the grandparent poster to consider a future where users bypass whatever protections came from their phone manufacturer and end up shooting themselves in the foot. But i also think you're right that it doesn't matter. That's the "price of freedom".

We already see it a little bit now where some people choose Android over iOS (or vice versa) for ideological reasons. Loosening manufacturer restrictions even further seems reasonable to me. Some people would choose ultra-safety through open source, others would choose to use closed source from a company they consider trustworthy. Most would not care and just use whatever environment they are most familiar with, and install whatever plugins and cleaners they need to make them feel more secure. That's basically the PC market right now, and i think it's largely fine.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#410
post #388

Earlier quoted context omitted.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Looks like photos is addressed in iOS 14 https://appleinsider.com/articles/20/06/24/apple-fine-tunes-... Agree tighter control over contacts sharing would be nice but I don’t think it’s malicious on Apple’s part that this isn’t possible - they’ve quite clearly shown they are on the side of user privacy, but they do also tend to move at a fairly slow pace

That is incredibly good news, thanks for the link.
Post reply on HN