Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

461–470 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#461

Here's a test you should run. Create a bitly account if you don't have one and login and create a bitly link for anything, it doesn't matter what it is. Copy that bitly link to your clipboard and repeat what you're doing in that video. Monitor the bitly link for clicks. Better still do it on a website you control with a unique URL that won't get indexed by a search engine and monitor the web server log files for hits…

It is honestly still kind of crazy that Apple still hasn't fixed this gaping hole in their security model, along with others. A notification is not solving the problem. I wonder if Apple is playing 4D chess here though. As people learn about this, they will become outraged and care more about privacy. This in turn benefits Apple since that's their marketing stance. I wish they just cut the bullshit and fixed these ho…

wonder if Apple is playing 4D chess here though

Why 4D? Isn't chess just a 2D game with wormholes?

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#462

Earlier quoted context omitted.

Looks like photos is addressed in iOS 14 https://appleinsider.com/articles/20/06/24/apple-fine-tunes-... Agree tighter control over contacts sharing would be nice but I don’t think it’s malicious on Apple’s part that this isn’t possible - they’ve quite clearly shown they are on the side of user privacy, but they do also tend to move at a fairly slow pace

The choice of only allowing access to specific actual photos seems an unusual one. I would have thought there was a big debate in Product Mgmt over this vs the more obvious allow an app access to a given album. One presumes the sticking point came when someone took a photo out of an album. Does that mean they are explicitly removing access? I don't see it as a huge issue... maybe there is some kind of technical hurdl…

I, like probably a lot of iOS users, don't have any albums. I just have the Camera Roll, which contains several years of my life history.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#464

Earlier quoted context omitted.

Android has supported piecemeal permissions for ages (only let app X access this one photo, or this one contact), which Apple seems to be starting to copy in iOS 14 (though, as usual, seemingly without a single thought to the long-term UX).

Not sure about this. I can give an app permissions to contacts, not a specific contact. Unless they changed this in Android 11?

You can send an Intent to request that the user pick a contact, without having the contacts permission. The app gets a copy of the contact that the user picked.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#465

Earlier quoted context omitted.

Apples walled garden approach is not necessary for any of this though (nor does it even make it easier). You can introduce sandboxing, fine grained permissions etc without locking devs and consumers into a controlled app store - these are OS features, not app store features.

Fine-grained permissions aren’t useful if an application is going to request access to everything anyway - and non-technical or non-privacy-conscious users will click-through any and all permission prompts so [they can see the dancing bunnies]( https://blog.codinghorror.com/the-dancing-bunnies-problem/ ). In the case of very popular, aggressively-marketed, apps like TikTok and Facebook’s: the lack of easy side-loadin…

If one clicks through, the original Microsoft blog post by Larry Ostermanns is even more intriguing:

https://docs.microsoft.com/en-us/archive/blogs/larryosterman...

> I saw a post the other day (I'm not sure where, otherwise I'd cite it) that proclaimed that a properly designed system didn't need any anti-virus or anti-spyware software. Forgive me, but this comment is about as intellegent as "I can see a worldwide market for 10 computers" or "no properly written program should require more than 128K of RAM" or "no properly designed computer should require a fan". The reason for this is buried in the subject of this post, it's what I (and others) like to call the "dancing bunnies" problem.

> What's the dancing bunnies problem? It's a description of what happens when a user receives an email message that says "click here to see the dancing bunnies". The user wants to see the dancing bunnies, so they click there. It doesn't matter how much you try to disuade them, if they want to see the dancing bunnies, then by gum, they're going to see the dancing bunnies. It doesn't matter how many technical hurdles you put in their way, if they stop the user from seeing the dancing bunny, then they're going to go and see the dancing bunny.

> There are lots of techniques for mitigating the dancing bunny problem. There's strict privilege separation - users don't have access to any locations that can harm them. You can prevent users from downloading programs. You can make the user invoke magic commands to make code executable (chmod +e dancingbunnies). You can force the user to input a password when they want to access resources. You can block programs at the firewall. You can turn off scripting. You can do lots, and lots of things. However, at the end of the day, the user still wants to see the dancing bunny, and they'll do whatever's necessary to bypass your carefully constructed barriers in order to see the bunny

> We know that user's will do whatever's necessary. How do we know that? Well, because at least one virus (one of the Beagle derivatives) propogated via a password encrypted .zip file. In order to see the contents, the user had to open the zip file and type in the password that was contained in the email. Users were more than happy to do that, even after years of education, and dozens of technological hurdles. All because they wanted to see the dancing bunny. The reason for a platform needing anti-virus and anti-spyware software is that it forms a final line of defense against the dancing bunny problem - at their heart, anti-virus software is software that scans every executable before it's loaded and prevents it from running if it looks like it contain a virus. As long as the user can run code or scripts, then viruses will exist, and anti-virus software will need to exist to protect users from them.

—————

This was written 2005, before the iPhone and iPad. One could argue that the whole AppStore/Gatekeeper/Notarization system itself is a big giant patronizing Anti-malware-Software by Apple or focus on the last sentence, that on iOS the user can’t run non-sandboxed scripts and code.

But it is also the case were Apple again did “think different”.

> I saw a post the other day that proclaimed that a properly designed system didn't need any anti-virus or anti-spyware software. Forgive me, but this comment is about as intellegent as "I can see a worldwide market for 10 computers" or "no properly written program should require more than 128K of RAM" or "no properly designed computer should require a fan".

Ha!

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#466
post #388

Earlier quoted context omitted.

People love to hate on Apple but the fact is, they continue to release features to better showcase or restrict developers that abuse your privacy. The "walled garden" also ensures they apply a ton of checks to apps to better restrict abuses. Sometimes it's overly sensitive and bad things happen, but in general it's awesome that over time it becomes harder and harder to get away with apps blatantly spying on you.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Roughly speaking, current OSs "stop" at tools for interacting with data, and the hardware behind it.

In this world where we expect internet access, I'm beginning to think OSs need to manage certain types of data more proactively. I'm trying to wrap a general point around your concerns about contacts. Contacts seem one of the data types that need something approaching OS level tooling. For me, another is "tags". I want to use the same set of tags I apply to "files" to apply to "contacts" too.

I keep hoping someone will make a rival OS that tackles this head-on. Start at Haiku, sprinkle some of Apple's "the UI isn't a virtualised office any more" UI paradigm, model a small handful of human-centric data types (like places, people, maybe individual health, too) and the access and interaction rules that support them safely and really run with it.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#467
post #459

Earlier quoted context omitted.

Do normal people really use albums? Other than the autogenerated ones I have a single one, from 2013.

Yes they do. People who value the curation of their photos will take the time to do it. I create an album for any event etc. which I expect I'll want to photograph. It's easier to share and re-share the same set of photos, and it acts like a log of cool stuff. Also, I don't have to scroll through months of memes to get to that one good photo I took in July 2017... or was it August..... maybe it was 2016......... shit…

> People who value the curation of their photos will take the time to do it.

Sounds like only something people who aren’t stressed from their underpaid jobs can do? Most people are kept busy and don’t have time to fit into this dark (corporate app) pattern.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#468
post #401

Earlier quoted context omitted.

And yet no one else has

Flatpak has done this better than iOS has. - Completely FOSS stack - Uses multiple repositories (no lock-in) - Everything is sandboxed with Bubblewrap - Fine-grained permission control that offers more than iOS: control whether apps can access the network, which directories an app can access, if it can print, and even whether or not it can access PulseAudio. - Cross-platform: runtimes are OCI container images and can…

Flatpak also clutters your hard disk with gigabytes of copied libraries and other data. I had to deinstall it to prevent a system crash, because my root partition went out of space rapidly - source of the problem: Two flatpak apps.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#469
post #388

Earlier quoted context omitted.

People love to hate on Apple but the fact is, they continue to release features to better showcase or restrict developers that abuse your privacy. The "walled garden" also ensures they apply a ton of checks to apps to better restrict abuses. Sometimes it's overly sensitive and bad things happen, but in general it's awesome that over time it becomes harder and harder to get away with apps blatantly spying on you.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Add Background App Refresh to this please - considering that apps exfiltrate 4G/WiFi connectivity info (helpful to triangulate your current location) regularly to tracker/analytics scum APIs with this feature - it should be exposed as a Privacy setting, not buried in Settings. I don’t understand what’s hard about this for Apple to be eerily silent on this.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#470
I applaud Apple for the continued privacy efforts, including finer-grained Photos access (linked by another poster in this thread: https://appleinsider.com/articles/20/06/24/apple-fine-tunes-...).

But at the same I can't help but be bitter. The smartphone scene is very active ever since, I don't know, 2011? All the companies and shady information dealers have gathered mountains of private information.

Is this not too little, too late? This would have been welcome at the iPhone 5 release. Nowadays I wonder what difference would these measures even make.

Post reply on HN