Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

131–140 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#131

Apple and Google have guidelines about what apps are/aren't allowed to if they want to be on their app store. "Protecting the user" is supposed to be one reasons they take a 30% cut of all in app purchases. Apple even uses this as an excuse to not allow side loading apps. How are they not blocking this?

Thought Apple was the bastion of consumer privacy. Apparently removing TikTok though is not commercially beneficial for them

not to mention the elephant in the room: Apple Finds Its Next Big Business: Showing Ads on Your iPhone https://www.bloomberg.com/news/newsletters/2022-08-14/apple-...

Re: See what JavaScript commands get injected through an in-app browser

#132
post #113

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

Everything is legal until it is explicitly made illegal. And I can assure you no US politician can understand more than 3 words in that paragraph you wrote, let alone make laws to regulate it.

This exchange. Mind-numbing

https://youtu.be/t-lMIGV-dUI

Re: See what JavaScript commands get injected through an in-app browser

#133
post #113

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

Everything is legal until it is explicitly made illegal. And I can assure you no US politician can understand more than 3 words in that paragraph you wrote, let alone make laws to regulate it.

Eavesdropping on electronic conversations where both parties have a reasonable expectation of privacy is illegal in many jurisdictions already.

Re: See what JavaScript commands get injected through an in-app browser

#135
post #25

Earlier quoted context omitted.

> reciprocity clauses are very common in areas like [...] Distributing software for you to run on your own hardware is speech, though, and it's protected by the first amendment. You can license the distribution of your own software if you want, but you can't tell me I can't give you software if you want it. Basically: how do you think this would work, in a way that wouldn't also make Linux or gcc or whatever availabl…

> Distributing software for you to run on your own hardware is speech, though, and it's protected by the first amendment. This definitely needs a reference.

[deleted]

Re: See what JavaScript commands get injected through an in-app browser

#136
post #66

Is there anything website owners can do about this? I've been many web games, including my own, embedded and surrounded by adverts (see dordle,io, wordle-unlimited,io). Simple permissions like x-frame-options won't work since they're proxying everything onto the same origin. I've thought about checking after a few minutes if the user is on an embeded DOM then asking them to head over to the real site.

No, the browser is the "user agent" and decides what to do. The problem is that in this case TikTok is the browser and does what they want, not what is good for the user.

It is actually quite a hard problem. The App Store does ban third-party browser engines so maybe they can add a restriction that apps can only inject code into verified domains. Surely a few legitimate use cases would be lost (IDK apps that let you annotate websites or something) but it may largely mitigate this issue. Maybe there can be a permission or a review entitlement that allows this for valid use cases (as decided by Apple of course).

Re: See what JavaScript commands get injected through an in-app browser

#137
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

What I don't understand is why Google has let YouTube become one big advertisement for TikTok. Every video I watch on YouTube is preceded by a TikTok ad.

Re: See what JavaScript commands get injected through an in-app browser

#138
post #48

Earlier quoted context omitted.

> how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Because we are the West, and China is China. We have different laws and customs.

Why does that mean that a Chinese social media app can capture data unlawfully under GDPR, CCPA or or other regulations?

Any app built and run by any country can capture data unlawfully. The keyword is unlawfully.

Re: See what JavaScript commands get injected through an in-app browser

#139

Earlier quoted context omitted.

The wisdom of reciprocity also is older than all governments today. See Golden rule and Silver rule.

There were governments when those rules were formulated. Unless you mean, "Older than all governments in existence today," which might be true.

Of course there was reciprocity between people prior to the first government. It almost certainly wasn't called the golden or silver rule, but of course it existed.

Re: See what JavaScript commands get injected through an in-app browser

#140
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

If non-Chinese companies are willing to abide by Chinese laws (including those about censorship, etc.), they'll be able to operate in China. Chinese social media apps abide by US regulations around social media and private surveillance, which are almost nonexistent, so they can operate in the US.

The only way to prevent this is to create laws specifically targeting the Chinese for being Chinese, because 1) the chance for domestic regulation on social media and surveillance is very low, and 2) any regulation we're likely to pass would be about "spreading misinformation" and "foreign interference," so would probably end up closely resembling Chinese regulations.

Post reply on HN