Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

31–40 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#31
post #13

I feel like there is a litany of the internet: "that which can be collected will be." That's been true since the beginning. What continues to surprise me is that people think only "bad guys" do it. This is why we continue to lock down browsers and provide ever narrower permission classes.

That's because only "bad guys" do this. If a "good buy" does this, they automatically become a "bad guy".

I think I agree with you here. It's proof by definition.

Re: See what JavaScript commands get injected through an in-app browser

#32
post #25
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

> reciprocity clauses are very common in areas like [...] Distributing software for you to run on your own hardware is speech, though, and it's protected by the first amendment. You can license the distribution of your own software if you want, but you can't tell me I can't give you software if you want it. Basically: how do you think this would work, in a way that wouldn't also make Linux or gcc or whatever availabl…

We aren't talking about TikTok as an open source software repository. Their registered business, operations, leases/property purchases, payroll, advertising, data mining, international currency transfer and lots more are all not covered by the first amendment and can absolutely be regulated under a million clauses.

Re: See what JavaScript commands get injected through an in-app browser

#33
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Because the opposite would be considered racism and xenophobia.

Re: See what JavaScript commands get injected through an in-app browser

#34
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

What happened to free speech being the bastion of America and the only thing that can counter misinformation and propaganda?

Suddenly doesn't seem to work so well when a Chinese app is granted that privilege.

Re: See what JavaScript commands get injected through an in-app browser

#35
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

> how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there?

Because we are the West, and China is China. We have different laws and customs.

Re: See what JavaScript commands get injected through an in-app browser

#37

Can websites protect against this through the use of Content Security Policy (CSP) [0]? [0] https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP

It might make it much harder to inject stuff, but since the apps control all aspects of the embedded browser and CSPs are enforced by the browser, they could feasibly just disable CSP enforcement and have the embedded browser ignore the CSP.

Re: See what JavaScript commands get injected through an in-app browser

#38
post #34
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

What happened to free speech being the bastion of America and the only thing that can counter misinformation and propaganda? Suddenly doesn't seem to work so well when a Chinese app is granted that privilege.

Stealing information without user permission is not free speech.

Re: See what JavaScript commands get injected through an in-app browser

#39
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

Why is it unfair?

Taking a random stab: one argument could be that competition drives down profit margins. By reducing competition, China makes their tech artificially profitable locally, allowing them to compete in international markets on an uneven playing field.

Re: See what JavaScript commands get injected through an in-app browser

#40
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

Why is it unfair?

Because non-Chinese companies cannot compete in the Chinese market place without strict handicaps. Some cannot participate at all.

However the true question here is more likely to be "what does unfair mean".

Post reply on HN