Live data from Hacker News

iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

twitter.com

611–613 of 613 posts

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#611

Apps abusing clipboard can steal the passwords from the password managers when user copies it and associate with the user account via parallel construction. e.g. Time of stealing password from clipboard + time of my HN comment. I've been long weary of this, android 10 has made some changes like allowing only IME & in-focus apps to access the clipboard. Not a fool-proof way to prevent the issue. One more reason to des…

Apps can still read the clipboard at any time they want on Linux. A pure Linux OS is definitely better, but for other reasons.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#612

Earlier quoted context omitted.

I wonder if location prompts would be more effective if, instead of asking "Allow 'Example App' to access your location while you are using the app?", they explicitly state "'Example App' would like to know precisely where you are. Would you like to share your exact location?". I feel like those adjectives, "precisely" and "exact", would go a long way toward encouraging people to put more thought into the decision. S…

This is a neat idea. Also, many apps don't need your EXACT location, just something like a zip code for convenience. AFAIK there is no mechanism for an App to request permissions to get a "rough" idea of where you are as opposed to a precise location

The new iOS will have that feature though, IIRC.

Re: iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes

#613

Earlier quoted context omitted.

Yes and the app gets uninstalled and review bombed on google's play store. Seems like a successful democratic process to me.

>App steals data from millions >Gets catched years later and review bombed >Author walks away with pockets full and probably onto the next money-grabbing project Oh yes, classic "successful democratic process"

That's a bit of a stretch. On play store permission bombing is so prevalent and no one is installing any apps with less than 4 stars so I doubt the "malware" makes enough money to sustain this.
Post reply on HN