You have to imagine the Apple engineers who implemented this new clipboard notification knew this shitstorm was coming.
Of course, the responsible part of me knows that’s a bad idea. Sigh.
131–140 of 380 posts
You have to imagine the Apple engineers who implemented this new clipboard notification knew this shitstorm was coming.
Of course, the responsible part of me knows that’s a bad idea. Sigh.
LinkedIn is actually copying the clipboard while that user types in a different app. https://twitter.com/DonCubed/status/1278757201310388225
Looking forward to msft/linkedin employess minusing me into oblivion haha
You have to imagine the Apple engineers who implemented this new clipboard notification knew this shitstorm was coming.
I'm guessing that's part of the reason they didn't implement a clipboard permission. It would probably have broken a TON of stuff in weird ways. I expect to see an actual clipboard permission at some point.
When I want to login I have to paste my password, when I want to paste an email address into a Linkedin chat I need the clipboard.
So everyone would just grant that permission anyway as it makes a lot of apps useless without and they'd just continue their harvesting after that. It would be a very small percentage to selectively enable/disable the clipboard permissions for certain tasks.
LinkedIn has a history of acting like a cretin: multiple data breaches, dark patterns where they don't fix their buggy mobile site and just put up a disclaimer "problems with the mobile site - download our app" (just so that they can harvest a wider range of data). I managed many marketing campaigns on Linkedin over the years and spent thousands each month on the platform as a corporate user. If you think that paying…
I would agree with this one most of the time, but even their desktop web is horrible in Firefox. It wouldn't load the pages/header with buttons, wouldn't show new messages from time to time.
Earlier quoted context omitted.
I'm guessing that's part of the reason they didn't implement a clipboard permission. It would probably have broken a TON of stuff in weird ways. I expect to see an actual clipboard permission at some point.
Maybe I'm missing something but a clipboard permission seems to be pretty useless for most apps. When I want to login I have to paste my password, when I want to paste an email address into a Linkedin chat I need the clipboard. So everyone would just grant that permission anyway as it makes a lot of apps useless without and they'd just continue their harvesting after that. It would be a very small percentage to selec…
Does this recurring problem suggest a missing API?
Make clipboard behave like a channel[+], like GNOME native apps do, additionally require a standard paste command to paste, then this clipboard attack will be impossible to conduct. [+]:A sample pipe might be a good analogy for this behaviour. You cut or copy the input, send through the sample pipe, and the receiving end unpacks, receiving itself makes the sample disappear for further use. Multiple samples could be s…
You have to imagine the Apple engineers who implemented this new clipboard notification knew this shitstorm was coming.
Part of me wishes they dropped this feature in a random dot release, to give these developers a well deserved public flogging. Of course, the responsible part of me knows that’s a bad idea. Sigh.
LinkedIn is actually copying the clipboard while that user types in a different app. https://twitter.com/DonCubed/status/1278757201310388225
Earlier quoted context omitted.
Facebook (including Messenger) does it too. There might be a thin guise of "security" (i.e. email isn't a secure place to send your top-secret inbound message) but I'm inclined to suspect the main motivation is to drive people back to the platform and drive up their stickiness metrics. It's user-hostile.
It is not just Facebook and LinkedIn. I've seen this from random small sites. Some other silly shit that come to mind - having the unsubscribe link after half/full page of white space, once you click on unsubscribe "give us 24 to 48 hours to remove your email" etc. Really? they need 24 hours to delete (or change a flag) in the database?