Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

521–530 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#521

Earlier quoted context omitted.

That's wild! What do you mean they were requesting it one character at a time? The URL itself? If so,how do you know that? Do you also own urls in that "character space" leading up to your URL?

If the URL was https://myurl.com/some/thing/here I started seeing: https://myurl.com/s https://myurl.com/so https://myurl.com/som https://myurl.com/some etc. It took me a good 10 minutes to realize what was happening, especially since I was using a temp ngrok tunnel and no one should have had that URL.

Ahh gotcha. That's crazy.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#522

It seems like a ton of apps are abusing this feature: https://www.youtube.com/watch?v=pRSWdtoUAjo I categorize this as another reason why "just trust us," just isn't acceptable enough when it comes to data privacy and ownership. Companies just cannot be trusted to treat their users' data with respect given the option of: profit or privacy. (sourced from reddit: https://old.reddit.com/r/apple/comments/hejb9i/ios14_cat…

How, exactly, are they abusing it? Are you suggesting that they send the contents of the clipboard back to their servers? Do you have any proof that they are using the clipboard for nefarious purposes? It’s disappointing to see the lack of skepticism applied on a site like Hacker News.

I can guarantee you that there are tons of apps that send your clipboard verbatim to their analytics services, because some product manager "wants to see the data".

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#523

It seems like a ton of apps are abusing this feature: https://www.youtube.com/watch?v=pRSWdtoUAjo I categorize this as another reason why "just trust us," just isn't acceptable enough when it comes to data privacy and ownership. Companies just cannot be trusted to treat their users' data with respect given the option of: profit or privacy. (sourced from reddit: https://old.reddit.com/r/apple/comments/hejb9i/ios14_cat…

> It seems like a ton of apps are abusing this feature

Can they, if Background Refresh is off for the app? I allow it only for Apple apps.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#524
post #482

Earlier quoted context omitted.

In that Reddit thread the author of a Reddit app mentions that they look at the clipboard to see if you have a Reddit link, and offer to open that page in the app (as iOS offers no better way). On Twitter I saw a. Doing app mention they trigger the notification on every key press because they have custom ‘paste’ button that only shows when you have something copied.

For Apollo's use case there's a solution: iOS 14 adds a new API that lets you perform a pattern match against the contents of the clipboard. That way Apollo can attempt to match a Reddit link, and only actually read the clipboard if that match is successful.

Yeah the dev has commented on that. It sounds like they had a legit use case and will be using the new API.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#525
post #444

Earlier quoted context omitted.

Defense in depth right? First layer: iOS sandbox, second layer: App Store.

How about giving people a choice? If you like defense in depth: App Store. If you like freedom of choice: Open Market Store and side-loading.

This isn't a value judgement, but if enough users sideload or use the open market governments will probably have to step in to advocate permissions checking because Apple won't have the influence to regulate developer behavior on their platform(s).

You can sort of see this on other platforms - the Mac App Store has very few quality apps listed on the store and Apple is further moving towards locking down root permissions b/c users can download apps or install software from anywhere on the web. It's typical for users to install anti-malware software on new Android devices, etc.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#526

It seems like a ton of apps are abusing this feature: https://www.youtube.com/watch?v=pRSWdtoUAjo I categorize this as another reason why "just trust us," just isn't acceptable enough when it comes to data privacy and ownership. Companies just cannot be trusted to treat their users' data with respect given the option of: profit or privacy. (sourced from reddit: https://old.reddit.com/r/apple/comments/hejb9i/ios14_cat…

Why were this apps approved by the app store?

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#527
post #401

Earlier quoted context omitted.

Flatpak has done this better than iOS has. - Completely FOSS stack - Uses multiple repositories (no lock-in) - Everything is sandboxed with Bubblewrap - Fine-grained permission control that offers more than iOS: control whether apps can access the network, which directories an app can access, if it can print, and even whether or not it can access PulseAudio. - Cross-platform: runtimes are OCI container images and can…

Flatpak also clutters your hard disk with gigabytes of copied libraries and other data. I had to deinstall it to prevent a system crash, because my root partition went out of space rapidly - source of the problem: Two flatpak apps.

Isn't this the problem with iOS apps too? They can't share libs or .so between them, which is why each iOS app is colossal for no good reason, eg. Google Sheets 180MB alone, Google Docs also 180MB, YouTube 280MB..... insane sizes for these.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#528
post #388

Earlier quoted context omitted.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Looks like photos is addressed in iOS 14 https://appleinsider.com/articles/20/06/24/apple-fine-tunes-... Agree tighter control over contacts sharing would be nice but I don’t think it’s malicious on Apple’s part that this isn’t possible - they’ve quite clearly shown they are on the side of user privacy, but they do also tend to move at a fairly slow pace

That's a very good start. I hope the feedback during the beta causes those controls to evolve a little bit so that it's more straightforward to change which photos an app can access.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#529
post #388

Earlier quoted context omitted.

I am certainly happy about the steady pro-privacy process. I personally consider Apple full of shit until two features are released: 1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts. Sure, I could have a separate contacts app with "meta…

Looks like photos is addressed in iOS 14 https://appleinsider.com/articles/20/06/24/apple-fine-tunes-... Agree tighter control over contacts sharing would be nice but I don’t think it’s malicious on Apple’s part that this isn’t possible - they’ve quite clearly shown they are on the side of user privacy, but they do also tend to move at a fairly slow pace

This seems to increase the amount of work a user has to do in practice. I suspect most users will end up sharing the entire library. From the link above:

> There's also the entirely new option Select Photos..., which leads the user through to the Camera Roll to pick one or more images to share. It is specifically images that users can opt to share, rather than albums.

> Which then means there is an issue that the next time a user wants to post an image, they find their selection confined to solely the ones they specified before. To change that and allow all or just different images, the user has to go to Settings on their iPhone.

My wishlist for fixing photo privacy on iOS:

1) Applications don't need to ask for permission to write photos to iOS folders. These get written to a separate album ($appName or $appDeveloperName by default), e.g. if you save a photo from Twitter it gets saved to your Twitter folder.

2) Photos taken by the iPhone Camera (presumably your personal photos) get stored in a special 'Camera' folder. Apps can ask for read/write permissions specifically here. Eg a photo editing app like VSCO or Darkroom may only need read permissions to begin with, but if it also wants to in-place replace your photos with its edited photos, it'll need read+write permission as well.

3) What about apps that occasionally need access to photos (e.g. social media apps) but you don't want them to have access to everything? The solution is to implement a OS-level photo picker in iOS with a UI can't be over-ridden and which makes clear you're sharing your selected photos with $appName. And ensure apps which want access to photos have to make the user go through the OS-level photo picker.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#530

Earlier quoted context omitted.

Flatpak also clutters your hard disk with gigabytes of copied libraries and other data. I had to deinstall it to prevent a system crash, because my root partition went out of space rapidly - source of the problem: Two flatpak apps.

Isn't this the problem with iOS apps too? They can't share libs or .so between them, which is why each iOS app is colossal for no good reason, eg. Google Sheets 180MB alone, Google Docs also 180MB, YouTube 280MB..... insane sizes for these.

Similar in character, but it's probably a factor of 10 worse with Flatpak. With your examples on iOS, the bloat is stuff that's common to the google apps but not part of the platform. With flatpak, it includes stuff that is part of the platform but can't be relied on to be the right version.

It would be nice if Apple would let packages signed by the same key share versioned libraries between them, but I suspect relatively few developers would be able to take advantage of that. Maybe only google and microsoft, to a rough order of approximation.

Post reply on HN