Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

81–90 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#81
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

It's amazing. Tiktok has been HN's darling for the longest.

We must be on different HNs because every time I see Tiktok brought up a bunch of people complain about privacy and the culture on the platform.

Re: See what JavaScript commands get injected through an in-app browser

#82
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

All of this. And, to be clear, much of that home purchasing is for investment purposes (vs simply Chinese nationals with residences here).

And, don't forget farmland.

Seems we'll look back on all of this at some point and decide maybe it wasn't the best idea.

Re: See what JavaScript commands get injected through an in-app browser

#83
post #21
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

"had they not made sweeping changes to their economy and assured the world that they would compete on a fair playing field, rules that they still (mostly) have to follow today. "

This is really quite false.

Rules are broken all the time, they are difficult to arbitrate, and often they are not.

The CCP requires foreign entities to surrender critical IP, then hand it off to a state-backed competitors, they don't allow full ownership of local companies, there's direct political interference including the requirement for all companies to directly hire CCP members as oversight, and if it's important enough, to have the CCP right on the board.

All of this in addition to the death by a thousand cuts the system can make for foreign competitors via local bureaucratic requirements at every level.

This applies not only to commerce but critical institutions such as WHO which are directly compromised by China (i.e. not allowing any material investigation into 'lab leak origins' etc. etc..)

The OP presented the situation very clearly: there is no way in any scenario that China would allow an American company to have a TikTok like app used by large swaths of the Chinese population, controlled by the US.

Neither would Russia.

On some level, that kind of thing is a bit understandable, I don't quite mind if China would not allow 'Facebook' to be the #1 communications tool in China, that said, it should be reciprocal.

And for other things, like high-speed rail etc. China has been grabbing IP using leverage that never should have been allowed.

Re: See what JavaScript commands get injected through an in-app browser

#84
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

Because it’s a sovereign country that makes its own rules? So, basically the same reason that you can’t just move to Italy because you feel like it.

So uh - how is that Great Firewall thing in China legal then?

Trade limitations have always and will always exist. Heck there are hundreds of limitations in trade between the US and Canada - including the complete illegality of Kinder Eggs in the US, which I still find hilarious.

Re: See what JavaScript commands get injected through an in-app browser

#85
post #81

Earlier quoted context omitted.

It's amazing. Tiktok has been HN's darling for the longest.

We must be on different HNs because every time I see Tiktok brought up a bunch of people complain about privacy and the culture on the platform.

No way, it used to be almost universally praised here 2-3 years ago. Not so much recently: https://news.ycombinator.com/item?id=28133017

Re: See what JavaScript commands get injected through an in-app browser

#86
post #21
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

The wisdom of reciprocity also is older than all governments today.

See Golden rule and Silver rule.

Re: See what JavaScript commands get injected through an in-app browser

#88
I can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this?

Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content subject to this security flaw?

Thanks in advance for any clarification.

Also, off topic but doesn’t YouTube’s “Shorts” take the place of TikTok? I have my Google privacy settings set so YouTube can store my viewing history for one month so I get reasonable recommendations. Does TikTok have similar settings?

Re: See what JavaScript commands get injected through an in-app browser

#89

My question is just, “why do we let everyone ale do this? Why do we only react when it’s a Chinese company doing it?” There is a call for comment by the fcc right now about how people feel about data collection and surveillance. Please go and send in a comment to regulate these behaviours

To be fair, Facebook and Instagram were caught first, and the news got to the front page last week.

Re: See what JavaScript commands get injected through an in-app browser

#90
post #45

Don't all in-app browsers do this? I think I read that instagram does the same.

No not all of them do this. Yes, Instagram does, as per the chart in the article. The difference is Tiktok forces you to use their in app web view, and does not allow you to use your default browser, where they would not be able to inject their own JS code. Even worse, Tiktok monitors every single key stroke, a key logger in effect, where Instagram does not (according to the authors research).
Post reply on HN