Live data from Hacker News

LinkedIn is copying the contents of my clipboard on every keystroke

twitter.com

361–370 of 380 posts

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#361

Earlier quoted context omitted.

You seem pretty moved by this discussion. What is your use case that is broken by protecting the clipboard and filesystem? using the components in the UIKit and AppKit SDKs Yes, if you want to provide a native feel, with native features like clipboards, and native accessibility features, use the native widgets. They usually tend to be stylable any way you want (my UI experience is with HTML, Qt, Swing, Win32, Winform…

> You seem pretty moved by this discussion. What is your use case that is broken by protecting the clipboard and filesystem? Yes, I am pretty moved, because this is ostensibly a technical audience and the level of sheer "I don't know how my operating system works" I'm seeing here is quite alarming indeed. I don't have to have a particular use case to point out that "applications should not be able to access the files…

I think you're being a bit pessimistic about OS developers' abilities. Also I think you are reading more into what people are saying than they are actually saying with respect to permissions vs "programmatic access", and "applications" vs any code whatsoever.

Just to clarify my perspective on the situation: I have developed a significant amount of software for DOS, Win9x, WinXP and later, cross-platform JVM (UI and server-side), Linux (CLI, framebuffer, X11, Gtk, Qt, OpenGL, kernel modules, backend servers), HTML5+JS, embedded devices in ASM, Oracle/MySQL/Postgres/MSSQL DBs with stored procedures, probably other things I've forgotten, and a tiny bit of mobile native. I have worked with a few sandboxing/containerization systems like Docker, simple chroot, etc. Cloud hosting, AWS, OpenStack, bare metal, local systems. I have seen viruses, worms, hacks, spyware, malware, etc. affect anything with a network connection or a floppy disk drive.

I know what I am saying is possible when I say that arbitrary code should not have arbitrary access to the system-wide clipboard or filesystem until the user grants it, and that the usecases that require such broad grants are extremely uncommon.

Android provides Intents instead of FS access, but app devs all have to have their "custom experiences" that just conveniently give them significant fingerprinting, snooping, and tracking abilities.

Some Linux GUIs will already use the Gtk file picker in GNOME, and the Qt file picker in KDE.

X11 though I love it (I am working on an Xlib project right now in fact) is already a security nightmare, never mind that even highlighting text without choosing "copy" puts it into one of the system clipboards, or at least used to do so.

Even Signal now wants to force everyone to add a (likely easily brute forced by unsavory intruders) PIN so they can upload your contacts to their servers.

So yes, all the evidence points to a safer system for filesystems and clipboards and contacts and whatever else is possible, and all the evidence in threats points to it being necessary.

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#362
post #355

Earlier quoted context omitted.

I'm a professional earning 1.5-2.5 the average national salary. I'm moving abroad to a new city and ready to pay 20-30% of my net salary on rent. I'm paying the rent and media regularly on time and the deposit on move in. I demand apartment in the price range 5-15 EUR/m^2 per month, in comfortable standard, and the full deposit back on move out. What invalidates me as a good tenant? Then given my requirements above,…

> What invalidates me as a good tenant? Nothing, I believe you are a good tenant. But this competitive market with limited resources has "perfect is the enemy of good" situation. Landlords can choose and they want perfect.

> But this competitive market with limited resources has "perfect is the enemy of good" situation. Landlords can choose and they want perfect.

The same applies to (online) dating and recruitment. The life fundaments of a perfectly average individual - housing, life partner, and employment are becoming out of reach for most. We've got a deadlock situation over here.

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#363

Earlier quoted context omitted.

This should be higher, above all of the mobs teething for vengeance. It’s an innocuous comparison of text input to the pasteboard to prevent unwanted autocorrect insertions.[0] Probably the same code used by TikTok too. the code and and comments are here: [0] https://github.com/linkedin/Hakawai/pull/162/commits/c3f8958...

Just, no. There is NO possible excuse for accessing my private clipboard buffer without my involvement - as a result of a direct action I have overtly initiated.

If there is no legitimate reason for it to happen, should this be prevented at the OS level?

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#364
post #247

Earlier quoted context omitted.

> what, exactly, constitutes "direct user request" that both... > 1) does not break common programming techniques (e.g. an application rolling its own GUI, or implementing its own modes/keybindings) A callback method that you can define to do anything you want in your program when the OS hands you the result of a user initiated paste operation because your program had focus. If you want custom keybindings to initiate…

> A callback method that you can define to do anything you want in your program when the OS hands you the result of a user initiated paste operation because your program had focus. If you want custom keybindings to initiate the paste operation, you can register that desire with the OS. Wonderful! Now how does this brilliant little solution account for applications that don't centre their operations on the keyboard? H…

> How does this work for clicking on a UI element to paste?

The same way as designating keybindings. Registration with the OS. I don't care if you have to do it by defining hotspot outlines for bespoke-from-raw-pixels interface elements.

> How does this work for using non-tactile forms of input - say, a voice command?

Voice interface is mediated by the OS. Register your desired custom paste command.

> the very real and undebatable need to allow programs to simulate keyboard events?

False. I'm happy to debate it. But before we do, I have to ask you to try to not be stuck in the "how things are done now" mindset.

> What happens to operating systems that have the implementation of a system clipboard as out of scope"

Then they have decided to punt on user safety. Be angry at them and demand better. Also, you're derailing.

> what, exactly, do you think happens when (for example) a C program calls `getchar()`?

What do YOU think happens? You think that your program talks directly to your keyboard buttons? And why do you think that this question is relevant?

> If you consider something a secret, then may I suggest that you don't (both as a user and as a developer) put it in the general shared buffer for applications?

Frankly, I think this is a bullshit user-hostile copout. Treating the clipboard as "general shared buffer between applications" is exactly what caused this madness. The clipboard is an extension of the user, like writing something down on paper so they can then reading it back later, and should be treated as such with sanctity.

Try approaching from the perspective that all of your "what if"s have a safe non-almost-100%-of-the-time-user-hostile solution. Because the freewheeling "steal my secrets" API is almost 100% of the time extremely user hostile and computers are meant for people to use.

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#365
post #289

Earlier quoted context omitted.

We were trying to recruit via LinkedIn for our startup but soon realized what a shitty business model LinkedIn has. We had to pay around ~5,00EUR for each and every click on "Apply" to our job posting, which doesn't mean they even filled out the form. And now, where LinkedIn is full of Indian scammers (not meant in a racist way, but it is definitely perceived that way) we had costs for a "Local Area" limited job post…

> full of Indian scammers (not meant in a racist way, but it is definitely perceived that way) (I'm not Indian but) the non-racist way to say that is 'full of scammers', since the scammers' nationality has nothing to do with your distaste for their behaviour.

'Indian' in this case is the geography, not the demographic. They explained that, albeit with a lot of words. 'Scammers from India' would've taken care of the whole thing. Or if they wanted to gird their loins / show their work a bit more, maybe something like 'scammers with Indian IP addresses.'

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#366
post #318

Earlier quoted context omitted.

LinkedIn (Microsoft) is a company that previously used man-in-the-middle techniques to move people's private emails to its servers.[1] People no longer give them the benefit of that doubt because of the reputational damage these previous violations have caused. They should stop making "innocent" mistakes with other people's privacy and deal with this more professionally at the highest levels. If they don't people wil…

Sure, I get it. LinkedIn's email plugin thing was a security nightmare. But in this case, the code is right there! Take a step back and look at the entire forest: The outrage is over an app accessing data specifically designed to be shared across applications. That's what Copy fundamentally means- make this thing globally available to all my programs. You can poll pbpaste/xsel in your terminal and generate a log of t…

> That's what Copy fundamentally means- make this thing globally available to all my programs

Wouldn't that be:

Copy means- "make this thing go into MY clipboard".

Paste means- "make my clipboard available to THIS application".

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#367
post #363

Earlier quoted context omitted.

Just, no. There is NO possible excuse for accessing my private clipboard buffer without my involvement - as a result of a direct action I have overtly initiated.

If there is no legitimate reason for it to happen, should this be prevented at the OS level?

Yes. People copy passwords, SSNs, crypto wallet secrets, and more in a clipboard that pretty much any app or website or system service can see without permission. I'm surprised we haven't seen more attacks on it, honestly.

I have long wanted to build a secure multi-clipboard, one where you can copy with Ctrl+shift+1, ctrl+shift+2 etc and paste with Ctrl+1 and Ctrl+2

It would keep those hidden from any app until explicitly pasted. I was thinking you could co-opt the system keyboard to get the same functionality, but it clears the system clipboard instantly after any copy/paste.

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#368
post #187

Earlier quoted context omitted.

I actually really like how Apple implemented this though. If apps aren't doing something very clearly nefarious, it's not annoying at all.

It's not necessarily nefarious though. https://twitter.com/twolivesleft/status/1275776460918157315

Maybe apple should implement some more APIs around clipboard metadata, they could allow queries on content type and length or something without that notification. Or even check the hash of clipboard contents. Anything to protect privacy but still allow useful features.

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#369
post #216

Earlier quoted context omitted.

There are so-so approximations of it, like the guardian vpn/firewall: https://guardianapp.com/

Unfortunately the approximations are not that great, requiring you to route all your network traffic through an unknown company.

I'm sure there are open-source versions you can self-host

Re: LinkedIn is copying the contents of my clipboard on every keystroke

#370
post #187

Earlier quoted context omitted.

It's not necessarily nefarious though. https://twitter.com/twolivesleft/status/1275776460918157315

Maybe apple should implement some more APIs around clipboard metadata, they could allow queries on content type and length or something without that notification. Or even check the hash of clipboard contents. Anything to protect privacy but still allow useful features.

In fact, they did.

For querying content type, there are pre-existing APIs (e.g. `hasStrings` [1]), which AFAIK don't trigger the banner. In fact, the documentation already recommended using those methods over querying the actual clipboard contents, for performance reasons. But they're relatively new compared to the rest of the UIPasteboard API, having been added in iOS 10.

For going beyond content type, there are new APIs in iOS 14 that let you check if the clipboard contents are a "ProbableWebSearch" or "ProbableWebURL" without triggering the banner. [2] Doesn't seem like there's more flexibility beyond those two options, although I found a thread [3] suggesting that more might be added in the future. I wonder what ProbableWebSearch does.

[1] https://developer.apple.com/documentation/uikit/uipasteboard

[2] https://developer.apple.com/documentation/uikit/uipasteboard...

[3] https://developer.apple.com/forums/thread/649996

Post reply on HN