Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

121–130 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#121
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Because only US can buy cheap goods and services from the world with printed paper called dollars.

Re: See what JavaScript commands get injected through an in-app browser

#123
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

All of this. And, to be clear, much of that home purchasing is for investment purposes (vs simply Chinese nationals with residences here). And, don't forget farmland. Seems we'll look back on all of this at some point and decide maybe it wasn't the best idea.

> Seems we'll look back on all of this at some point and decide maybe it wasn't the best idea.

If that happens, I imagine our Congress will brew up some justification for seizing all that Chinese owned property.

Re: See what JavaScript commands get injected through an in-app browser

#124
post #97
post #59

Earlier quoted context omitted.

There is an interesting meta discussion here but the parent is over-simplifying things. > How we can allow a Chinese social media app in the west, while any non-Chinese social media apps aren't allowed there? Easy. The laws are different. "Non-Chinese social media app"s are not banned in China, just that if you run one it need to be licensed ( https://beian.miit.gov.cn/ ) first before you can start servicing. Licensi…

I appreciate your thoughtful response. I think that Chinese apps should at least be held to the same standards, as they are there, and I think it's reasonable to assume that they currently aren't. The thing is, and I don't believe this to be controversial, that China has built a digital database of all (or most) of its citizens based on the data they collected. Now the question is, do they stop there, or do they have…

> I think it's reasonable to assume that they currently aren't.

I don't see any reason they wouldn't be? If anything they probably face more scrutiny than US domestic companies exactly because they are foreign. The problem (at least in the US) is just that behavior like in this post should be illegal but it isn't (yet). They _feel_ ethically wrong but there's no punishment for doing it.

> (...) that China has built a digital database of all (or most) of its citizens based on the data they collected (...)

But so do companies like Google, or Meta, or Clearview etc... This is a real problem but Chinese companies are hardly alone here and they aren't even the first to start mass data collection. As for the domestic data collection and association, that's largely a domestic issue that their citizens need to figure out for themselves. For what it's worth, most countries do at least a little bit of domestic surveillance (as seen from the Snowden leaks), China just has a much more robust system with fewer safeguards.

> I think that we have to ask ourselves how that could threaten our democracy.

That is a good question and I think it should be asked of all tech companies.

Facebook had the whole election meddling thing which started the gears turning in legislative branches of how we might reign in companies as instruments that threaten democracy, and by now we all more or less assume countries like Russia and China will try to exert influence in other countries. However, getting the regulations right is hard even though it is also important. We'll need both experts in the technology (re: this whole thread about discreet behavior tracking that a layperson would never identify) and in the legal space to figure out how to protect individuals. This is not the cold war era. It should not be a battle of ideology. We should instead figure out how to protect people from institutions of power, be it hostile foreign powers, domestic tyranny, or just corporate greed.

Re: See what JavaScript commands get injected through an in-app browser

#125

Earlier quoted context omitted.

Stealing information without user permission is not free speech.

Tell that to Facebook and LinkedIn. I don't get the double standard. These practices should be illegal, full stop. Why is it ok for US companies to do the same kinds of things?

It is not a double standard. There are already legal and cultural limitations in the US that have much more respect for user consent, user privacy and intellectual property than in China.

Any US company caught putting arbitrary keyloggers in products can and should be condemned. Companies still track large amounts of data and pull shady antics, but the big difference is there is a means of holding US companies to account if they violate privacy standards, not least of which is through uncensored condemnation and legal action. That is not possible in China.

More stringent privacy norms and protections in the US would be welcomed. That doesn’t mean the status quo is comparable to China.

Re: See what JavaScript commands get injected through an in-app browser

#126
post #25
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

> reciprocity clauses are very common in areas like [...] Distributing software for you to run on your own hardware is speech, though, and it's protected by the first amendment. You can license the distribution of your own software if you want, but you can't tell me I can't give you software if you want it. Basically: how do you think this would work, in a way that wouldn't also make Linux or gcc or whatever availabl…

> Distributing software for you to run on your own hardware is speech, though, and it's protected by the first amendment.

This definitely needs a reference.

Re: See what JavaScript commands get injected through an in-app browser

#127
post #93

I can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this? Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content…

>> Does just not entering any keyboard input in the in app browser mitigate this? yes but i doubt the hundreds of millions of users, many of which are children, know this

To play devil's advocate... the most common way to end up in the in-app browser is to click an ad.

Non-technical people don't have a concept of "in app browser sandboxing". In their minds they clicked on an ad, they're still inside TikTok, TikTok's UI is showing, TikTok will show prompts based on the content shown... they probably assume TikTok has access to that page?

Honestly I'm more annoyed that Apple allows big apps to use the loophole that is the legacy webview than I am that TikTok uses that webview to do the exact single thing it's good for... having full control over the web content you're showing in app.

Re: See what JavaScript commands get injected through an in-app browser

#128
post #97
post #59

Earlier quoted context omitted.

There is an interesting meta discussion here but the parent is over-simplifying things. > How we can allow a Chinese social media app in the west, while any non-Chinese social media apps aren't allowed there? Easy. The laws are different. "Non-Chinese social media app"s are not banned in China, just that if you run one it need to be licensed ( https://beian.miit.gov.cn/ ) first before you can start servicing. Licensi…

I appreciate your thoughtful response. I think that Chinese apps should at least be held to the same standards, as they are there, and I think it's reasonable to assume that they currently aren't. The thing is, and I don't believe this to be controversial, that China has built a digital database of all (or most) of its citizens based on the data they collected. Now the question is, do they stop there, or do they have…

The US already has said files, no? That's what the Snowden whistleblowing was about.

Only data specifically about Americans(and Americans alone, contact with a foreigner is open to data collection) that hasn't traveled in and out of the country is protected from the spies, if the spies are to be trusted. They're already known to be lying to Congress, so chances are the American government has a file with all of your social media activity, except maybe your tic tock usage.

I see no reason to consider the Chinese apps special in this regard. American domestic apps have already shown themselves to be dangerous to american democracy, and the American government can do much worse things to Americans than the Chinese government can. The data collection itself is bad, but no government will cut off its own spies

Re: See what JavaScript commands get injected through an in-app browser

#129
post #110

Earlier quoted context omitted.

> why can [XXX] nationals buy housing here, while I can't do so there? Simply because when XXX nationals come with all cash offers and willing to pay above market & waive all contingencies, sellers are willing to sell. It just so happens that certain nationals are more prone to having that sort of money than others.

No, it isn't about people being more prone to buy property in one place, rather than another. Let x be a any number in [0, infty) , I literally can not buy property in China for any x .

> The answer is yes, foreigners are allowed to purchase property in China! The essential requirement is that you have studied or worked in China for at least one year on a residence permit. Foreigners are allowed to only own one residential property for dwelling purposes. You may not rent out the property or act as a landlord. Requirements and restrictions may differ in different provinces and cities. For example, Shanghai requires that non-Shanghai hukou families, including foreigners, have to provide proof of income tax or social insurance to the local government.

http://anychinavisa.com/news/can-foreigners-buy-a-house-in-c...

So to be more precise what you actually can't do is speculate in Chinese real estate.

Re: See what JavaScript commands get injected through an in-app browser

#130
post #48

Earlier quoted context omitted.

> how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Because we are the West, and China is China. We have different laws and customs.

Why does that mean that a Chinese social media app can capture data unlawfully under GDPR, CCPA or or other regulations?

You will find that HN is full of American business owners that are happy to unlawfully capture data protected by GDPR.
Post reply on HN