Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

181–190 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#181
post #178

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

For what it's worth, Google doesn't allow you to log into your Google Account in a in-app browser for this exact reason... unless you enable some "Insecure App" settings in Google Admin settings.

I’ve always wondered how Google enforces this as a technical level. Wouldn’t it be easy to spin up an in-app browser that looks and feels just like a regular browser? How does one detect via JS (or other means) if it’s an in-app browser?

Re: See what JavaScript commands get injected through an in-app browser

#182
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

So, I see this bandied about a lot, but I don't see the big deal in being spied on by a government that has 0 say in my entire hemisphere? Like, I have much bigger concerns about spying done on behalf of the five eyes alliance than China (obviously this would be the opposite if I was living in China). What are they going to do with my silly viewing habits, sell my data to advertisers? Well, same deal with youtube, go…

All china has to do to have a serious negative impact on our society is give a slight boost to moronic, antisocial content (tide pod challenge or mass robbery anyone?), and a slight penalty to constructive, educational content. It would be basically impossible to detect this.

Remember that this is a country that regularly threatens a war that would likely involve the US.

Re: See what JavaScript commands get injected through an in-app browser

#183
post #21
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

Look, I'm no fan of the Chinese social construct, but in terms of investment and development in an area I've tried to work in for the past 20 years, namely high-tech renewable energy development, the USA has dropped the ball while China has run with it. The US response has been tariffs on Chinese monocrystalline silicon PV panels, in a rather pathetic attempt to prevent them from gaining market share, while promoting nonsense like CdTe panels and so on. GW Bush and Barak Obama blocked DOE money going to renewable R&D just like Reagan, Bush and Clinton did, because the USA is mostly a petro-state economy (just look at CVX and XOM profits recently FFS)..

So China ran away with renewable tech developement because greedy Wall Street executives didn't want competition to their lucrative fossil fuel investments. Fucking retards.

Re: See what JavaScript commands get injected through an in-app browser

#185
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Amusingly, TikTok isn't available in China - only DouYin, which is similar but separate. I'm not 100% sure on this at this point, but I think if Facebook/Google/etc were willing to do the same they would be allowed in China too, but as it stands they can't/won't comply with Chinese law (I may be mistaken on this, haven't read up on the topic in quite some time)

Yeah, and both TikTok and DouYin are owned by ByteDance. In fact didn't Google on occasion create a crippled/censored version of its search for some time in mainland China or Hong Kong or something?

Re: See what JavaScript commands get injected through an in-app browser

#186

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

[deleted]

Re: See what JavaScript commands get injected through an in-app browser

#187
post #73
post #46

Earlier quoted context omitted.

I'd be OK with all of that. Sanctions are a thing. Regulation of data storage is a thing. There's space for debate here. But none of that involves logic like "You can't distribute software in my country if you don't let me distribute software in yours", which was the first amendment violation you started with.

You are the only one who framed it in that way. And the "software is free speech" argument itself doesn't apply when we are talking about something malicious that is installing keyloggers and transferring private data to overseas servers.

I think it still applies even to "malware". It's just irrelevant. I don't understand GP's argument here either.

TikTok is not an American citizen. Nobody is preventing American citizens from printing the source code of TikTok on their tshirts so that people can compile it and use it. This is the only conceivable scenario where the 1st amendment would apply.

And even if that was happening, the US could rightfully ban use of Chinese owned servers in the US. Then we'd get what happens in China: a US-owned entity forms to run TikTok in the US. It is now subject to US rules and regulations etc.

Re: See what JavaScript commands get injected through an in-app browser

#188

Apple and Google have guidelines about what apps are/aren't allowed to if they want to be on their app store. "Protecting the user" is supposed to be one reasons they take a 30% cut of all in app purchases. Apple even uses this as an excuse to not allow side loading apps. How are they not blocking this?

[deleted]

Re: See what JavaScript commands get injected through an in-app browser

#189
post #186

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

[deleted]

[deleted]
Post reply on HN