Live data from Hacker News

See what JavaScript commands get injected through an in-app browser

krausefx.com

91–100 of 330 posts

Re: See what JavaScript commands get injected through an in-app browser

#91
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

The wisdom of reciprocity also is older than all governments today. See Golden rule and Silver rule.

There were governments when those rules were formulated. Unless you mean, "Older than all governments in existence today," which might be true.

Re: See what JavaScript commands get injected through an in-app browser

#92
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

> why can [XXX] nationals buy housing here, while I can't do so there?

Simply because when XXX nationals come with all cash offers and willing to pay above market & waive all contingencies, sellers are willing to sell.

It just so happens that certain nationals are more prone to having that sort of money than others.

Re: See what JavaScript commands get injected through an in-app browser

#93

I can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this? Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content…

>> Does just not entering any keyboard input in the in app browser mitigate this?

yes but i doubt the hundreds of millions of users, many of which are children, know this

Re: See what JavaScript commands get injected through an in-app browser

#94

I can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this? Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content…

They do a lot more than that.

> TikTok iOS subscribes to every tap on any button, link, image or other component on websites rendered inside the TikTok app.

> TikTok iOS uses a JavaScript function to get details about the element the user clicked on, like an image (document.elementFromPoint)

And that's just a sample of the calls the author was able to find.

Re: See what JavaScript commands get injected through an in-app browser

#95
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

I would zoom out a bit.

For example, when the media in The West "front pages" the smog in Beijing keep in mind The West owns a good part of that. It's not like what's manufactured in China stays in China. I would presume their water ways are nasty as well.

Just one example mind you. The point is, there are other imbalances. That's not to say TikTok should get a free pass, only that it's complicated than an app for app comparison.

Re: See what JavaScript commands get injected through an in-app browser

#96
"TikTok subscribes to all keyboard inputs (including passwords, credit card information, etc.) and every tap on the screen, like which buttons and links you click."

How does Apple even remotely allow this?

They ban apps for the most arbitrary of reasons, I know small devs that get bumped for tiny things.

This is beyond ridiculous.

A company that has ~100M american users, and CCP on the board with a CEO/Board completely and publicly compliant with the 'wishes of the CCP' including reporting any and all sorts of things, is literally able to collect any data including passwords.

WTF.

How is this not a giant story?

How does the US Government not issue an immediate statement/warning to the general public and talk to Apple/Google about this issue?

My gosh.

Re: See what JavaScript commands get injected through an in-app browser

#97
post #59
post #9

I just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?

There is an interesting meta discussion here but the parent is over-simplifying things. > How we can allow a Chinese social media app in the west, while any non-Chinese social media apps aren't allowed there? Easy. The laws are different. "Non-Chinese social media app"s are not banned in China, just that if you run one it need to be licensed ( https://beian.miit.gov.cn/ ) first before you can start servicing. Licensi…

I appreciate your thoughtful response. I think that Chinese apps should at least be held to the same standards, as they are there, and I think it's reasonable to assume that they currently aren't.

The thing is, and I don't believe this to be controversial, that China has built a digital database of all (or most) of its citizens based on the data they collected. Now the question is, do they stop there, or do they have a file on all of us? The technology is cheap, and I think based on video data etc that they collect through apps like this, they might well build a social graph of the rest of the world (i.e. who does exist, what are their interests/beliefs/political affiliations, and what are the relations between those entities.)

The repercussions of using such apps might be, that they have info on citizens in the rest of the world, which might allow them to nudge people into giving into their political goals (this has already been happening after people posted stuff critical of China on sites like Twitter) - and I think that we have to ask ourselves how that could threaten our democracy.

Re: See what JavaScript commands get injected through an in-app browser

#98

Earlier quoted context omitted.

US companies like Meta, Google, are banned in China. Chinese companies are not banned in the US. US investors are barred from making controlling acquisitions of Chinese companies. Chinese investors are free to gain ownership in any US company they like. The rest of the world is generally playing on a level globalist playing field of free trade and open competition. The theory for decades has been that if the world tr…

> Chinese companies are not banned in the US Huawei/China Telecom/etc. notwithstanding, though they are not exactly social media competitors vs. Google/Meta.

Chinese companies are not categorically banned. Huawei had to do more than be Chinese.

Re: See what JavaScript commands get injected through an in-app browser

#99
post #21

Earlier quoted context omitted.

People are going to reply to you with the usual "we are better than them", "we are a democracy" etc., but reciprocity clauses are very common in areas like international trade, travel, disarmament treaties, emissions control and lots more. In fact China would never have been allowed into the WTO (which happened in 2001) had they not made sweeping changes to their economy and assured the world that they would compete…

The wisdom of reciprocity also is older than all governments today. See Golden rule and Silver rule.

[deleted]

Re: See what JavaScript commands get injected through an in-app browser

#100

Was anyone expecting otherwise? They'll use it to make their algorithm better, and they'll use it to better target ads. Both of those things are good for me the user, so I'm fine with it. And for those who don't like that, use a blocker, or don't use TikTok.

This was expected and the intention for this invasive spyware is obvious, otherwise, how else is their dystopian recommendation algorithm supposed to work if you don't give access to your entire life records.

The difference is that this was done before by Meta / Facebook and they were fined in the millions, and even by billions by regulators like the FTC over this. This same problems a decade ago are being repeated once again and we have learned nothing.

TikTok should be under the same regulations, especially when they are operating in many countries that have strict data privacy laws and given this unsurprising and extremely invasive data collection practice which is even worse than Facebook, they should be fined in the billions of dollars as a reminder that it applies to any social network, especially those with billions of users.

If left alone, it will only get worse for everyone.

Post reply on HN