Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

321–330 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#321
post #310

Earlier quoted context omitted.

No my point is why single out tiktok when every other social app is doing the same exact thing for all we know in their in-app browsers. Just because the researcher in this particular article happened to go after tiktok?

Why not use an example if you know they are doing it, if you don’t have time to lookup what all the others are doing? Its a pretty weak defense that everyone else is doing the same wrong thing.

It's not a defense, I'm simply asking why is everyone pilling on tiktok over some javascript trickery just bc they're deemed an enemy of the state by our all mighty government?

Re: See what JavaScript commands get injected through an in-app browser

#322
post #115

TikTok should be banned. India has the right idea. We should align more with them. Banning it isn't for geopolitical reasons although I think those are valid given the CCP's publicly stated agenda (Global communist revolution essentially. Millions of lives sacrificed for Marx). It's just that one less mind hacking app for children is a good thing. What about FB, Insta who are just as bad etc? Simply doesn't matter. I…

Marx wouldn’t approve of some sort of great leap 2.0. CCP sucks, but since World Wars, have you seen the list of countries the US alone has invaded or led coups in? Add in the rest of the west.

It doesn’t matter much what some state’s publicly stated stuff is. There’s no reason to believe any country blindly. Their actions speak louder.

Re: See what JavaScript commands get injected through an in-app browser

#323

Earlier quoted context omitted.

How do you know that's the most common way? Because I doubt it is. People click links in chats and in their feeds way more than they click ads

That is completely wrong since most users cannot post a website link (hotlink if I need to spell that out...), let alone in a comment. The only way for a non-ad link to be opened from comments is to copy it and paste it in your native browser. Business accounts get a special link field that's part of their bio, so again, deeply embedded in TikTok... and those behave exactly like the ads do. TikTok has a permanent "Fl…

It's ironic how you were being condescending when you used the term hotlink ("if I need to spell it out...") and yet used the term incorrectly

Re: See what JavaScript commands get injected through an in-app browser

#324

They're going to heavily lockdown WKWebView after the Instagram and Tiktok revelations, probably in iOS16.1. They may even remove it entirely and force people to use SFSafariViewController (heavily locked down web browser, opaque to developers other than URL). Best of luck to anyone that was using javascript injection for legitimate purposes, others have ruined it for everyone by abusing user trust.

I highly doubt this will happen. There are a ton of apps that use things like Cordova or Capacitor (usually for cross-platform purposes). What I could see them doing is making apps declare URLs that they need access to. Basically, you get full functionality on declared URLs, but if you are just using WebView for a "generic" in-app browser you lose the ability to inspect random pages.

The mechanism you are describing is already implemented and advertised: https://webkit.org/blog/10882/app-bound-domains/

Apple „just“ need to enforce it.

Re: See what JavaScript commands get injected through an in-app browser

#325

Earlier quoted context omitted.

That is completely wrong since most users cannot post a website link (hotlink if I need to spell that out...), let alone in a comment. The only way for a non-ad link to be opened from comments is to copy it and paste it in your native browser. Business accounts get a special link field that's part of their bio, so again, deeply embedded in TikTok... and those behave exactly like the ads do. TikTok has a permanent "Fl…

It's ironic how you were being condescending when you used the term hotlink ("if I need to spell it out...") and yet used the term incorrectly

Ironic that you latch onto a completely inconsequential mistake to divert from the fact you had no idea what you were talking about.

Re: See what JavaScript commands get injected through an in-app browser

#326

Earlier quoted context omitted.

It's ironic how you were being condescending when you used the term hotlink ("if I need to spell it out...") and yet used the term incorrectly

Ironic that you latch onto a completely inconsequential mistake to divert from the fact you had no idea what you were talking about.

I just didn't feel like further arguing.

In that guy's other comment he was talking about Meta/Facebook too which is what I'm most familiar with and was primarily referring to about people clicking on links.

Even with TikTok I bet people click on profile links more than ads

Also that's not ironic, maybe you are thinking of another word

Re: See what JavaScript commands get injected through an in-app browser

#327
post #64
post #3

Is it similar to what Meta in Instagram does? [0] - a week ago thread. [0]: https://news.ycombinator.com/item?id=32415470

TikTok is no different and is beyond worse than Meta at this point. Whatever Meta is doing doesn't excuse the reasons for this tracking. Given that Facebook was fined in the billions for this abuse in the past, TikTok should also be fined for this with in the billions of dollars. We have learned nothing around this and have repeated the same problems in social networks a decade later.

Fines, even that high, do not stop this, as we all see in no change in Meta actions.

Also, cannot avoid thinking that Facebook was accused of (somewhat similar) web site spying long time before Tiktok existed.

Re: See what JavaScript commands get injected through an in-app browser

#328

Earlier quoted context omitted.

Ironic that you latch onto a completely inconsequential mistake to divert from the fact you had no idea what you were talking about.

I just didn't feel like further arguing. In that guy's other comment he was talking about Meta/Facebook too which is what I'm most familiar with and was primarily referring to about people clicking on links. Even with TikTok I bet people click on profile links more than ads Also that's not ironic, maybe you are thinking of another word

The entire thread from the parent is about TikTok.

And "you bet" wrong, since the profile links are only enabled for business accounts.

But you're right about one thing: it was not at all ironic you'd deflect. It's exactly what I'd expect after someone misses what a thread about and makes assumptions about a subject they don't know.

That was some people call sarcasm.

Re: See what JavaScript commands get injected through an in-app browser

#329

Earlier quoted context omitted.

I just didn't feel like further arguing. In that guy's other comment he was talking about Meta/Facebook too which is what I'm most familiar with and was primarily referring to about people clicking on links. Even with TikTok I bet people click on profile links more than ads Also that's not ironic, maybe you are thinking of another word

The entire thread from the parent is about TikTok. And "you bet" wrong, since the profile links are only enabled for business accounts. But you're right about one thing: it was not at all ironic you'd deflect. It's exactly what I'd expect after someone misses what a thread about and makes assumptions about a subject they don't know. That was some people call sarcasm .

I know they are only enabled for accounts that get some particular amount of views. But there are a lot of those accounts

You were the one who brought up Facebook first in your other comment...

Re: See what JavaScript commands get injected through an in-app browser

#330
post #299
post #252

Earlier quoted context omitted.

You're writing as if this is just analytics tracking a user's actions in their own UI. It's not! This is tracking actions users take, and data users enter, on 3rd-party websites . That is not "what happens in Tiktok's app," as you put it in your reply. It may be hosted "in" the app in a technical sense, but the typical user who is fullscreen viewing a totally different website may not feel like they are "in" the app…

And how do we know Instagram and yelp are not doing something similar? If you have in app browser you can track user activity much more invasively. That’s not an argument against tiktok, that’s an argument against in app browsers. If you’re so concerned with user privacy ask Apple to remove that functionality from all apps instead of slyfully picking and choosing the apps to attack.

Instagram does do the same thing afaik
Post reply on HN