Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

291–300 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#292

Earlier quoted context omitted.

Instagram and Facebook do the same thing.

not nearly to the same degree

Facebook knows your education, where you went, what class you were in, what friends you had at that point, how you look, how you looked 10 years ago, what family members you have, what relationships you have and had, where you work, what establishments you've recently visited, what articles you engaged with more than others on your feed. And a lot of it isn't even voluntary because other people can fill it in for you.

TikTok knows my age, my location and viewing habits, TikTok knows that I stared at clip x more than clip y. TikTok might have figured out my age, gender and my sexuality based on what I watch and can probably figure out more just from what I view but saying it's somehow more than Facebook is inane.

one is literally made to have as much information about you as possible, that's like the core concept of Facebook.

Re: See what JavaScript commands get injected through an in-app browser

#293

Earlier quoted context omitted.

If you sold a phone that sent call details back to the manufacturer you’d likely get locked up. Tik tok are not a party to these communications, and they’re not a carrier or service provider. What they’re doing is wire tapping.

TikTok is not a browser and has zero obligation to provide private communications. What you do inside TikTok's app is quite literally TikTok's business.

surely slurping up passwords at least seems ominous?

Re: See what JavaScript commands get injected through an in-app browser

#294
post #225

I always hate in app browsers and always reopen them in Safari, for UX reasons. Now I hate them even more, with even stronger reasons.

Unfortunately I think they’re very popular with unsophisticated users. I’ve heard stories about companies getting a ton of support emails because someone clicked on an article link shown in $someApp, the user was booted to Safari, and didn’t know how to get back to where they were before. I’ve heard of developers adding the in-app thing despite hating it personally just to reduce the support burden.

iOS makes this very easy where every app launching another provides a link in the top left. I find it hard to believe users of tiktok and snapchat with their weird hidden/discoverable functionality of swiping from different places would have issue with the button that says "But ok, let's say I am giving too much credit to people. Just put a setting in to use the default browser for those of us that want it?

Re: See what JavaScript commands get injected through an in-app browser

#295

They're going to heavily lockdown WKWebView after the Instagram and Tiktok revelations, probably in iOS16.1. They may even remove it entirely and force people to use SFSafariViewController (heavily locked down web browser, opaque to developers other than URL). Best of luck to anyone that was using javascript injection for legitimate purposes, others have ruined it for everyone by abusing user trust.

In an app I'm using postMessage and JS injection to communicate between our in-house HTML/CSS content (due to what we're building, we had and still have many legitimate reasons to code that way) to seamlessly integrate the native side and the dynamic HTML views.

Any change would be a huge nightmare for apps like ours, potentially impacting many other apps as well.

Re: See what JavaScript commands get injected through an in-app browser

#296

I hate that if I send Wordle or something cool to a friend that uses localStorage they lose their progress/settings once they leave the chat app. So frustrating to even explain to people that this thing they are scrolling isn't their own, Safari/Chrome!

It's just another piece in how Apple sabotaged the web.

Since "the web" has become about 7-10 walled gardens for 90% of the public, whether Apple "sabotages" "the web" in allowing these "garden" apps to use their own browsers is hardly any more broken than anything else.

Re: See what JavaScript commands get injected through an in-app browser

#297
post #259

Earlier quoted context omitted.

Yes, please give us more cookie consent banners!

See, you don't have to ask for consent if you don't want to do shady stuff. Websites don't have to have cookie banners if they don't want to track you across the web and apps don't have to have access web data prompt if they don't want access the browser data in the app. PS: very convincing GPT-3 bot comment, exactly what a redditor on autopilot would write(according to the profile, the OP is a bot).

A lot of people getting upset that you're highlighting that the account is a bot. Before anyone else tells mrktsn off, please read the user's profile.

https://news.ycombinator.com/user?id=Traubenfuchs

I also think that the bot did a good job here.

Re: See what JavaScript commands get injected through an in-app browser

#298
post #110

Earlier quoted context omitted.

> why can [XXX] nationals buy housing here, while I can't do so there? Simply because when XXX nationals come with all cash offers and willing to pay above market & waive all contingencies, sellers are willing to sell. It just so happens that certain nationals are more prone to having that sort of money than others.

No, it isn't about people being more prone to buy property in one place, rather than another. Let x be a any number in [0, infty) , I literally can not buy property in China for any x .

I think you missed my point.

The US is a capitalist society; if you have sufficient money US National or not, you have nearly carte blanche to do what you want.

Regardless of China et al laws for foreign home ownership, the US is very permissible simply because money.

Re: See what JavaScript commands get injected through an in-app browser

#299
post #252
post #118

Earlier quoted context omitted.

If I build an analytics company and build a product that my customers can use to "analyze" their users activity it'd almost be a total neglect on my end not to include common tracking mechanisms that are well documented like simple event hooks in js. I really don't get the rage against tiktok. What they do that is publicly known is not bad. Maybe there is something bad they're doing but these random HN top stories ar…

You're writing as if this is just analytics tracking a user's actions in their own UI. It's not! This is tracking actions users take, and data users enter, on 3rd-party websites . That is not "what happens in Tiktok's app," as you put it in your reply. It may be hosted "in" the app in a technical sense, but the typical user who is fullscreen viewing a totally different website may not feel like they are "in" the app…

And how do we know Instagram and yelp are not doing something similar? If you have in app browser you can track user activity much more invasively. That’s not an argument against tiktok, that’s an argument against in app browsers. If you’re so concerned with user privacy ask Apple to remove that functionality from all apps instead of slyfully picking and choosing the apps to attack.

Re: See what JavaScript commands get injected through an in-app browser

#300
post #259

Earlier quoted context omitted.

See, you don't have to ask for consent if you don't want to do shady stuff. Websites don't have to have cookie banners if they don't want to track you across the web and apps don't have to have access web data prompt if they don't want access the browser data in the app. PS: very convincing GPT-3 bot comment, exactly what a redditor on autopilot would write(according to the profile, the OP is a bot).

A lot of people getting upset that you're highlighting that the account is a bot. Before anyone else tells mrktsn off, please read the user's profile. https://news.ycombinator.com/user?id=Traubenfuchs I also think that the bot did a good job here.

Accusing authors of dissenting opinions of being bots is the definition of bad faith and fosters an unhealthy discussion culture.
Post reply on HN