Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

111–120 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#111
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Honestly, this type of discussion is seriously irritating, because it implies that TikTok is doing something unique that other apps aren't doing. Just as the article demonstrates, many western countries do the exact same thing that TikTok does, except TikTok seemingly takes it one step further (probably because of shoddy programming). Applying geographic-based arguments to technology is just a bandaid. The problem needs to be solved in all situations, not just in situations where people aren't politically happy.

Any company injecting keyloggers or monitoring systems into web content should be subject to the same equally damning judgement. Just because it's China doesn't make keylogging bad. Keylogging is bad because keylogging is bad. Companies like Fullstory [0] and Hotjar [1] are used all over the western internet and effectively act as full session recorders. Sure, used well they can be used for analytics, but you could just as easily inject Fullstory or Hotjar into an in-app browser and suddenly record all data a user does. Should this be possible? No. Does it help to just ban China? I mean sure, but why should you be okay with a western company doing it?

TikTok is a short video app used mostly by younger generations. It produces highly accurate recommendations for videos to watch. We're not talking about something like a banking app, a healthcare app, or even a messaging app. It's a video-based social network. There are bigger fish to fry than TikTok in almost every single possible category of app. Yet, TikTok is always brought up because it's from China.

[0]: https://www.fullstory.com/

[1]: https://www.hotjar.com/

Re: See what JavaScript commands get injected through an in-app browser

#112

Was anyone expecting otherwise? They'll use it to make their algorithm better, and they'll use it to better target ads. Both of those things are good for me the user, so I'm fine with it. And for those who don't like that, use a blocker, or don't use TikTok.

I walked into a shop. They place a bug on me, so they can listen to my conversations in the store, and the store next door if I leave and pop in there. Both conversations about products, and conversations about I am having with my therapist about personal problems. Everything is recorded. They use it to make their algorithm better, and they'll use it to better target ads. Both of these things are good for me the shop…

No post body was provided.

Re: See what JavaScript commands get injected through an in-app browser

#113

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

Everything is legal until it is explicitly made illegal. And I can assure you no US politician can understand more than 3 words in that paragraph you wrote, let alone make laws to regulate it.

Re: See what JavaScript commands get injected through an in-app browser

#114

Why on earth is this even allowed in IOS in the first place ? Why do apps have the ability to control and change the browser? Instead of using the default one? Like android.

It's the in-app browser. The one that opens within the app, so that people don't need to switch to another app, and usually used for short-lived sessions. It doesn't modify or spy on the actual separate browser (Safari etc), just on whatever happens inside the app (as you would expect, app knows what's going on within itself), and it just so happens that sometimes in the app there is a browser page being displayed, which then goes to reason can also be spied on.

Android has these in-app browsers too, they may or may not be subject to this.

Re: See what JavaScript commands get injected through an in-app browser

#115
TikTok should be banned. India has the right idea. We should align more with them.

Banning it isn't for geopolitical reasons although I think those are valid given the CCP's publicly stated agenda (Global communist revolution essentially. Millions of lives sacrificed for Marx). It's just that one less mind hacking app for children is a good thing. What about FB, Insta who are just as bad etc? Simply doesn't matter. If people left FB for TikTok, and TikTok disappears, some significant % won't come back and that's a win.

Re: See what JavaScript commands get injected through an in-app browser

#116
post #52
post #34

Earlier quoted context omitted.

What happened to free speech being the bastion of America and the only thing that can counter misinformation and propaganda? Suddenly doesn't seem to work so well when a Chinese app is granted that privilege.

How is stealing users credit card information and all keystrokes free speech again ?

Reading is tough, but the parent comment is about allowing TikTok to exist in the west.

Also, as mentioned in the first sentence of the article, this is exactly what Meta does in the Facebook and Instagram apps.

Re: See what JavaScript commands get injected through an in-app browser

#117

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

Hey don't even worry about it, just look at this hilarious picture of a kitten instead

Re: See what JavaScript commands get injected through an in-app browser

#118
post #94

I can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this? Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content…

They do a lot more than that. > TikTok iOS subscribes to every tap on any button, link, image or other component on websites rendered inside the TikTok app. > TikTok iOS uses a JavaScript function to get details about the element the user clicked on, like an image (document.elementFromPoint) And that's just a sample of the calls the author was able to find.

If I build an analytics company and build a product that my customers can use to "analyze" their users activity it'd almost be a total neglect on my end not to include common tracking mechanisms that are well documented like simple event hooks in js. I really don't get the rage against tiktok.

What they do that is publicly known is not bad. Maybe there is something bad they're doing but these random HN top stories are not it. If NSA/US govt really wants us to avoid tiktok it needs better convincing than "omg they're stealing the x,y of your finger when you tap on an image."

Re: See what JavaScript commands get injected through an in-app browser

#119
post #114

Why on earth is this even allowed in IOS in the first place ? Why do apps have the ability to control and change the browser? Instead of using the default one? Like android.

It's the in-app browser. The one that opens within the app, so that people don't need to switch to another app, and usually used for short-lived sessions. It doesn't modify or spy on the actual separate browser (Safari etc), just on whatever happens inside the app (as you would expect, app knows what's going on within itself), and it just so happens that sometimes in the app there is a browser page being displayed, w…

AFAIK Android in app browsers are just a different look for the default browser, I think its called WebView.

Re: See what JavaScript commands get injected through an in-app browser

#120
post #97
post #59

Earlier quoted context omitted.

There is an interesting meta discussion here but the parent is over-simplifying things. > How we can allow a Chinese social media app in the west, while any non-Chinese social media apps aren't allowed there? Easy. The laws are different. "Non-Chinese social media app"s are not banned in China, just that if you run one it need to be licensed ( https://beian.miit.gov.cn/ ) first before you can start servicing. Licensi…

I appreciate your thoughtful response. I think that Chinese apps should at least be held to the same standards, as they are there, and I think it's reasonable to assume that they currently aren't. The thing is, and I don't believe this to be controversial, that China has built a digital database of all (or most) of its citizens based on the data they collected. Now the question is, do they stop there, or do they have…

> do they have a file on all of us

I would be astonished if they did not. The data is freely available and inexpensive, I imagine they are hoovering it all up constantly.

Post reply on HN