Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

151–160 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#151
post #103

Why on earth is this even allowed in IOS in the first place ? Why do apps have the ability to control and change the browser? Instead of using the default one? Like android.

These same tools are what allow you to build and ship fully JS based apps on iOS instead of having to use Swift or Objective-C or anything like that. Arbitrary web views can be an entire app. Or they can reinvent the wheel and become in-app browsers. A lot of apps are fully or partially web based. Even Apple’s own apps use web views in crazy ways. For example, the entire Mac App Store used to be a web view. Parts of…

All of that is totally fine and not what people are upset about. If your entire app is just a web browser that renders your website, that should be fine too.

The problem is when they render external websites and unsuspecting users think they are using the phone's web browser. That is something Apple/Google can have rules about without banning/restricting web views.

Re: See what JavaScript commands get injected through an in-app browser

#152
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

I can’t understand how we allowed every industry to wholesale migrate to China and write off every manufacturing method and trade secret.

The answer both of our questions is of course money. Our version of capitalism is dominated by cult-like disciples of financial management principles.

If the US fucks with TikTok, well maybe they’ll mess with Office 365.

Re: See what JavaScript commands get injected through an in-app browser

#153
post #98

Earlier quoted context omitted.

Chinese companies are not categorically banned. Huawei had to do more than be Chinese.

I think you can still buy an iPhone in China, but the only Apple services that appear to be available are the App Store (some apps such as VPN apps and news apps are obviously unavailable) and Apple Music.

Usually services in China are run by a local partner.

Re: See what JavaScript commands get injected through an in-app browser

#154

Earlier quoted context omitted.

Eavesdropping on electronic conversations where both parties have a reasonable expectation of privacy is illegal in many jurisdictions already.

The thing is, in this situation you _don't_ have any resonable expectation of privacy, regardless of what the masses think is actually happening.

I’d genuinely like to see Tik Tok’s lawyers make that argument in court.

Re: See what JavaScript commands get injected through an in-app browser

#156
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Well, it's gonna cost me many downvotes, but this needs to be said. CCP has a tight grip on many US officials. The two publicly known cases are Pelosi's son and Biden's son, who are prominent investors, board members even, in chinese companies. That's public knowledge, but I bet it's the tip of the iceberg.

Re: See what JavaScript commands get injected through an in-app browser

#157

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

We'll find out soon enough, but no existing law covers it so clearly that it can be decided with certainty without a judge's imprint.

Re: See what JavaScript commands get injected through an in-app browser

#158

Earlier quoted context omitted.

The thing is, in this situation you _don't_ have any resonable expectation of privacy, regardless of what the masses think is actually happening.

I’d genuinely like to see Tik Tok’s lawyers make that argument in court.

I doubt that they'd have to. I'm sure their tos says "you absolutely have no expectation of privacy and you give us eternal rights to everything you do in this app in order to operate and improve this app" just like everyone else's does.
Post reply on HN