Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

71–80 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#71

So let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?

[deleted]

Re: See what JavaScript commands get injected through an in-app browser

#73
post #46
post #32

Earlier quoted context omitted.

We aren't talking about TikTok as an open source software repository. Their registered business, operations, leases/property purchases, payroll, advertising, data mining, international currency transfer and lots more are all not covered by the first amendment and can absolutely be regulated under a million clauses.

I'd be OK with all of that. Sanctions are a thing. Regulation of data storage is a thing. There's space for debate here. But none of that involves logic like "You can't distribute software in my country if you don't let me distribute software in yours", which was the first amendment violation you started with.

You are the only one who framed it in that way.

And the "software is free speech" argument itself doesn't apply when we are talking about something malicious that is installing keyloggers and transferring private data to overseas servers.

Re: See what JavaScript commands get injected through an in-app browser

#75
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Because of unfortunate politics - young people are thriving on TikTok so all discussions on limiting the platform under Trump were reasonably responded to with outcries about censorship. I think it's possible some change could happen under the current administration's watch (since it wouldn't be viewed as a free-speech crackdown) but there doesn't seem to be much interest now that it's just about security and not also about punishing your political opponents.

Re: See what JavaScript commands get injected through an in-app browser

#76

Earlier quoted context omitted.

Why is it unfair?

US companies like Meta, Google, are banned in China. Chinese companies are not banned in the US. US investors are barred from making controlling acquisitions of Chinese companies. Chinese investors are free to gain ownership in any US company they like. The rest of the world is generally playing on a level globalist playing field of free trade and open competition. The theory for decades has been that if the world tr…

> Chinese companies are not banned in the US

Huawei/China Telecom/etc. notwithstanding, though they are not exactly social media competitors vs. Google/Meta.

Re: See what JavaScript commands get injected through an in-app browser

#78
post #48

Earlier quoted context omitted.

> how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Because we are the West, and China is China. We have different laws and customs.

Why does that mean that a Chinese social media app can capture data unlawfully under GDPR, CCPA or or other regulations?

Exactly.

Given they are operating in countries like the EU, US, etc and they are doing the same privacy violations and actions like what Facebook did years ago but worse, and even after regulations such as GDPR, CCPA, etc and Facebook was fined in the billions by the FTC, TikTok should be no exception and must be fined in the billions for this invasive and repeated privacy violations.

Nothing has changed, even after the invasive tracking done by Facebook, and Instagram.

Re: See what JavaScript commands get injected through an in-app browser

#79
My question is just, “why do we let everyone ale do this? Why do we only react when it’s a Chinese company doing it?”

There is a call for comment by the fcc right now about how people feel about data collection and surveillance. Please go and send in a comment to regulate these behaviours

Re: See what JavaScript commands get injected through an in-app browser

#80
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Who cares? This is about privacy and security. Not a “why can’t we do it in your country back to you” argument
Post reply on HN