Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

311–320 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#311

They're going to heavily lockdown WKWebView after the Instagram and Tiktok revelations, probably in iOS16.1. They may even remove it entirely and force people to use SFSafariViewController (heavily locked down web browser, opaque to developers other than URL). Best of luck to anyone that was using javascript injection for legitimate purposes, others have ruined it for everyone by abusing user trust.

Apple started moving in this direction in 2020 with the introduction of App-Bound Domains[0]. These are currently opt in but I have always expected that, just like with the HTTPs adoption, they'll start enforcing this more strictly. With App Bound domains an app specifies ahead of time which domains are app bound and should allow injecting Javascript etc.

I expect app-bound domains to become required for all apps in iOS 16 or possibly iOS 17. There will probably a be a limit and some review on which domains an app specify as app-bound. Web browser that use WKWebView already have a special entitlement that excludes them from this.

0: https://webkit.org/blog/10882/app-bound-domains/

Re: See what JavaScript commands get injected through an in-app browser

#312
post #291

Earlier quoted context omitted.

How do the in-app browsers help the user?

They show the user the website they tapped on…

That's not the question. How does it help over just opening normally in the browser?

Re: See what JavaScript commands get injected through an in-app browser

#313
post #292

Earlier quoted context omitted.

not nearly to the same degree

Facebook knows your education, where you went, what class you were in, what friends you had at that point, how you look, how you looked 10 years ago, what family members you have, what relationships you have and had, where you work, what establishments you've recently visited, what articles you engaged with more than others on your feed. And a lot of it isn't even voluntary because other people can fill it in for you…

I was referring to the JS injections talked about it the article, not what data FB has about you overall, which of course is much more if you have a FB account.

And I wasn't saying FB is better overall; I deleted my FB account 7-8 years ago. I don't go on Tiktok either because I don't trust it (also not that interested). I do use IG (yes, I know owned by FB but I don't have it linked to any FB/other account) and Twitter (and Reddit, IRC of course).

Re: See what JavaScript commands get injected through an in-app browser

#315
post #280

Earlier quoted context omitted.

Shady stuff like highlighting terms the user searched for. Don’t forget there are of course legitimate use cases. By the way, if you think another user is a bot (or they claim so themselves), from the guidelines: > Please don't post insinuations about astroturfing, shilling, bots, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinato…

I don't think that another user is a bot, another user has stated in their profile description that they are a bot account randomly posting GPT-3 generated comments. I made no claims but comment on the quality of the bot.

What a bummer people are quicker to grab quotes from the ToS to try to tell you off for calling someone a bot, rather than 1 click on the accounts name to find out for their self. Even HN isn't immune from the lazy reactionary commenting these days it seems.

Re: See what JavaScript commands get injected through an in-app browser

#316
post #310

Earlier quoted context omitted.

Would consider it right for a browser to snoop on every page opened, every link clicked, every character typed and send it to the cloud without informing the user?

No my point is why single out tiktok when every other social app is doing the same exact thing for all we know in their in-app browsers. Just because the researcher in this particular article happened to go after tiktok?

Why not use an example if you know they are doing it, if you don’t have time to lookup what all the others are doing? Its a pretty weak defense that everyone else is doing the same wrong thing.

Re: See what JavaScript commands get injected through an in-app browser

#317
post #280

Earlier quoted context omitted.

I don't think that another user is a bot, another user has stated in their profile description that they are a bot account randomly posting GPT-3 generated comments. I made no claims but comment on the quality of the bot.

What a bummer people are quicker to grab quotes from the ToS to try to tell you off for calling someone a bot, rather than 1 click on the accounts name to find out for their self. Even HN isn't immune from the lazy reactionary commenting these days it seems.

> … (or they claim so themselves) …

Re: See what JavaScript commands get injected through an in-app browser

#318
post #202

Earlier quoted context omitted.

How do you know?

read the article

I did, did you?

"Important Note: This tool can’t detect all JavaScript commands executed, as well as doesn’t show any tracking the app might do using native code (like custom gesture recognisers). More details on this below."

Re: See what JavaScript commands get injected through an in-app browser

#319
post #116
post #52

Earlier quoted context omitted.

How is stealing users credit card information and all keystrokes free speech again ?

Reading is tough, but the parent comment is about allowing TikTok to exist in the west. Also, as mentioned in the first sentence of the article, this is exactly what Meta does in the Facebook and Instagram apps.

Wow pretty snarky.

I’m not saying that others don’t do it. Just that it’s not speech ?

Re: See what JavaScript commands get injected through an in-app browser

#320
post #302

Earlier quoted context omitted.

bad bot

I think it‘s hilarious he stood up for himself but I feel bad about his lack of self awareness.

To be fair, could equally be read as “just because I’m a bot doesn’t mean you should ignore everything I say” :)
Post reply on HN