iOS14 reveals that TikTok may snoop clipboard contents every few keystrokes
twitter.com
twitter.com
I categorize this as another reason why "just trust us," just isn't acceptable enough when it comes to data privacy and ownership. Companies just cannot be trusted to treat their users' data with respect given the option of: profit or privacy.
(sourced from reddit: https://old.reddit.com/r/apple/comments/hejb9i/ios14_catches...)
Also, the closed-source OS means it's impossible to see what things are doing under the hood, or modify the behavior of the OS itself to be more privacy friendly.
For example, on Apple if you aren't happy with an app snooping on your IMU data, you're out of luck and can only just choose to not use the app. On Android (by modifying the OS) you can actually send back fake IMU data to make the app think it got the permissions it wanted but really didn't. Or you can let access to your photos, but only let it see a walled garden of a few select photos.
The answer is that if it's open then multiple people with differing interests, such as competitors, or even independent organisations such as non-profit auditors, can check the code.
I’m genuinely curious how you can imagine this is a realistic solution.
I'm not saying this is the most practical solution to this problem but at least it's a possibility.
Beyond that, have you considered the actual average user? You either never worked tech support or forgot. It’s bad out there, it’s like people are moving backwards with computer skills because of phones.
That's still a way better outcome than having a single uncountable company being able to do audits.
> Beyond that, have you considered the actual average user? You either never worked tech support or forgot. It’s bad out there, it’s like people are moving backwards with computer skills because of phones.
People are becoming worse with computer skills because manufacturers try very hard to remove owners from how their machine works, I'm not sure going further into this way will help. In a very locked down device like the iPhone, the phone owner can't even understand what it's doing even if they wanted to.
I think the point stands.
By defending user privacy, Apple is able to have a direct affect on the bottom line of its rival corporations.
All corporations behave according to incentives that will help they to progress further than their competitors. If they don't rival coporations will take the lead.
--
So following on from this. Is the crux of these arguments anti-capitalist?
No .. it's not anti-capitalism. It's realistic. Even more realistic if you believe in a capitalism system and want to compete.
I feel that capitalism works most successfully when it provides more people with a better quality of life.
Fundamentally, there are conceptual problems with a capitalist system .. factors that lead to scenarios that are likely to lead to the system operating sub-optimally.
An example of a problem; if a corporation is allowed to grow without limit, how can new companies realistically compete?
The remedy? I guess it's up for discussion. But I think regulation can prevent the worst form occurring, and many markets have measures in place to carry out this type of regulation.
--
Why am I saying this?
Because I feel that open-source is simply a remedy to a conceptual problem that exists within our capitalist economy. It is not antithetical to capitalism.
Namely, the question it serves to answer is; how do we balance the power provided by digital technologies with the incentive companies have to exploit these powers for commercial gain?
Open-source is a logical answer to this. You could argue, we don't have the tools available to highlight any injustices contained in a code-base. My answer would be .. that doesn't mean we conceptually couldn't or won't in the future.
Closed source is a conceptual dead end - and won't lead to a better future.
Eventually you have to trust someone. This added transparency from Apple is commendable. I support open source for publicly funded software, but if it's privately owned and funded, you can choose to buy and use it or not. Private companies are not under any moral obligation to open source their code or methods.
Some people are successful while open sourcing everything, and that is commendable too.
In theory it means something could maybe be safer, but it far from guarantees it.
I have debugged all sorts of issues with closed source applications using these tools.
Tools like strace can help you analyze a program's behavior from the outside, but you get limited insight into its internals (e.g., what algorithms is it using?).
Being open source does not automatically make software more secure. A successful compilation doesn't automatically make your code bug-free. Yet both are necessary to achieve the desired goal: security and correctness, respectively.
Or, do you trust that someone has looked at it? How much faith do you have in someone out there in the community?
My point isn't that open source isn't a good thing--my point is that it's not the silver bullet a lot of people blindly assume it to be. Hence the second line of my post:
> In theory it means something could maybe be safer, but it far from guarantees it.
The commented I replied to implied that one would walk through the entire stack, every line of code, to audit e.g. an app running on a phone. This is most certainly not what OP meant. Rather, on a whole OSS is mostly transparent, while proprietary software is not. There are of course bugs, but that's not the focus here with "safety".
What we care about is intention. Private companies's have a track record in implementing features that go directly against the benefit if their end-users, e.g. tracking or vendor-lock-in. These anti-features, like the one described in the article, are much harder to detect precisely because the software is proprietary.
If I'm not going to read the source code myself either way, why should I trust that random open source code-reader X who says "yup, didn't see any malicious code" vs a developer friend who works for apple and says "yup, no malicious code"?
Honestly, more often than not there's a lot of overlap between those people... And I'd bet that there's a ton of eyes I'd trust on iOS's source code given how many devs apple pays to work on it, while I think there's far fewer on most non-corporate open source projects.
A corporation like Apple (or TikTok) will sometimes decide to implement features that are antithetical to its users best interests, because there's a commercial imperative to do so.
If the code is closed-source, it's more difficult to assess whether this is the case.
Funny how you change your argument mid-paragraph. "It's okay! You have to trust somebody. Or maybe you don't. But anyway, it's a private company, so just don't buy it!"
Well the latter is not what GP was arguing in this thread is it? -.-
Perhaps, but Apple is the last company I would trust. They work in a culture of secrecy and engineer for obscurity rather than transparency, and that does not make them trustable at all.
> Private companies are not under any moral obligation to open source their code
But I will give far more trust to those who do so, or at least the privacy-critical parts. With Android I need to trust no-one; I can modify things on the OS level that do not necessarily execute apps in the way those apps expect to be executed, and that is the ultimate privacy guarantee.
I own the hardware, so how my hardware runs software should be my choice; the entire set of instructions and APIs for creating phone apps is merely a suggestion for how the OS should execute apps, and how a stock OS executes apps, but does not necessarily reflect how I choose to have my hardware execute them.
Features.
- The ability to run Android without Google. - The ability to change the location of your clock. - The ability to have some apps open with the status bar and navbar and some not. - The ability to change your WiFi network without opening settings (yes, I'm still upset they removed that. I use an Android 8 tablet daily, so I'm unlikely to forget). - Adding invisible left/right dpad buttons and a menu button in my navbar. - Change the number of quick settings. - Change the screen dpi (this is implemented these days, I think, but only with 3-5 settings available) - use adb without first plugging into a computer. Maybe I'm going somewhere and I'll need to restart my phone. - run Linux in a chroot (far better than proot) - install Fdroid privileged extension without losing access to security updates.
You can say full well that you don't care about these, you don't have to care. However, these are all things that you can't do without an alternative ROM (or without rooting, which loses access to updates).
It's a self-fulfilling prophecy. Don't bring it up next time. Reverse psychology (in an attempt to not get downvotes) doesn't work here, it just pisses people off (and is against the rules to complain about), so you WILL receive downvotes for mentioning it.
iOS 14 has this now.
And any access to sensitive data always prompts you. And if you deny the request it sends empty data back to the app. Exactly like what you describe.
My privacy shouldn't depend on Tim Cook's product management timeline.
Seems like a good thing, really.
Biggest advantage is that it's a pure Android with no bloatware from the manufacturer. Also you get a guarantee IIRC to have at least two versions upgrades for the phone (my Xiaomi came with Android 8, so 10 should be the last one), and most of all security updates.
All iOS is pure iOS. That’s the selling point for me, at least.
I don’t want iOS on my random experimental project laptop, for that I have Linux or windows, or vms. But, cellphones are not something I need to hack around on.
You can also choose to jailbreak an Apple device if you really want to be unpure, and luckily doing so won't prevent you from updating your phone in the future.
Different strokes for different folks. I like having the ability to sideload apps and flash a different OS to my phone
Also what bothers me about Android devices: I got a Galaxy S8 to do development for work, and not all manufacturers are created equal in updates of course; IIRC I waited almost a full year after the Google flagships to receive Android 9 — in fact I think I got Android 8 around the time Android 9 came out.
But imagine if Windows worked the way Android does. You buy a Dell Windows laptop and then you receive all your OS updates directly from Dell, they limit you to only 2 years of updates (if that), and put some bloated skin over the whole OS.
I don't know why Android users accept this.
$200 G7 got Android 10 about 3 weeks ago.
4 years is much better than current Android phones, though it's true it doesn't quite live up to the current Apple lineup where iOS 14 is going to support the 6S which will be 5 years old by the time it launches.
Android puts much more emphasis on backwards compatibility, with Google moving more and more functionality into app libraries rather than system frameworks. Our app still supports Android 4.4 (released in 2014!).
iphoneOS 15 will be supported by iPhone 6S: this was released in 2015. If app supports iOS 12 (which most do, as it is only one version below the current iOS 13) it means they support iPhone 5S: which was released in 2013.
And Apple users are likely to update: 92% run the latest version, and 7% are on the iOS 12.
In the beginning, Android showed you what an app could before you installed it, and it was an all-or-nothing approach – if you didn't want the app to do those things, your only choice was to not install it.
In the beginning, iOS didn't have this, and instead it prompted you for permission the first time an app wanted permission to do something. Additionally, app review had rules that apps had to operate correctly if you refused permission and that apps couldn’t ask for permissions irrelevant to what you are doing. So you can install an app, then pick and choose what you grant permission for.
Later, Android added the prompts to work the same as iOS. iOS hasn't changed to include the Android approach.
So in the very very very beginning it was:
iOS: prompts for permissions, but almost nothing (including accessing user data) requires permissions anyway
Android: Granular permissions for everything, but only asked at install time.
Since then iOS has become "more Android-y" in adding increasingly more granular permissions, and Android has become "more iOS-y" in those permission grants being on-demand and time-gated.
This took a few years to improve, but even today, there are Android apps that will refuse to work if you don't grant some (unnecessary, in the view of the user) permission. That kind of behavior is very, very rare among iOS apps.
Remember the fun we had making fun of Apple Maps? Why in the world would Apple have dropped Google as the back end for their original Maps program, right? Well, it was because back in 2011 or so, Google refused to give Apple access to true turn-by-turn navigation features unless Apple gave them more access to user data. Rather than do that, Apple decided to go it themselves, even though that made the Maps product worse for years. This is consistent with Apple's behavior in other fields. (Hey, Siri!)
There are a lot of criticisms to be made of Apple, but "they're selling your data by proxy" just doesn't seem to be one of them.
[0]: https://dazeinfo.com/2018/10/01/apple-google-fee-iphone-sear...
Meanwhile if you use iCloud backups all your data is one subpoena away from law enforcement.
My point stands, apples revenue is not from privacy violating advertising and has no motivation for data collection beyond product improvement
Vizio isn't the only one but here's an example: https://www.tomsguide.com/amp/us/vizio-ftc-smart-tv-spying-p...
How-to disable additional snooping: https://www.consumerreports.org/privacy/how-to-turn-off-smar...
Mind you this goes above what most consumers would consider acceptable and can be blatantly sold to advertisers.
This is just what manufacturers have done but then there's just the attempts we know of by the CIA dump: https://news.ycombinator.com/item?id=20206536
It’s way too early for this to be a reasonable assumption. The fact that they made that comment implies they are aware how widespread the is.
Both systems have extreme downfalls with the strategy they have taken, Apple's walled garden, and Google's necessity to use tracking because they are an ad company and this is how they make money.
Overall, Apple's certainly the lesser of two evils, but I think I'll be considering a PinePhone next, once the software ecosystem has matured a bit. I'm going to start speaking with my wallet and not conceding to settling.
I had ESFileExplorer installed on a Nexus 7 tablet I barely used. One day I start it to find the charging has switched to “smart charging” where this software shows a banner ad on the home/charging screen. There is no end to the madness of what each app can do or even allowed to ask for.
I am not sure what happened in your case with ES or how that would be possible. It sounds like maybe the app just pushed you an advertisement as a notification. Notifications can be disabled on a per-app basis but I think it is pretty reasonable that they are enabled by default.
[1] https://www.androidpolice.com/2016/05/10/es-file-explorer-up...
[2] To those who might laugh at my paranoia about ES while I happily use Zoom, I teach classes and it is not an easy choice not to use Zoom.
They got worse, also with updates since they were acquired Lenovo. Last time that I surveyed the Android landscape (~2 years ago), Nokia was the place to go for a pristine Android experience with quick updates.
I haven't found a LineageOS device that will pass the SafetyNet checks yet, though.
Is LineageOS still signed with testing keys?
Btw, all these distributions (Lineage and Cynogenmod before that) don't benefit from automated updates. So that is another headache to remember to manually reflash/upgrade.
That varies by the ROM. Many do support automated OTA updates. (https://www.androidexplained.com/lineage-os-ota-update-locat...)
Though an extremely annoying side effect is that they are also handicapping one of the best android features: user scripting with tools like automagic4android [i] and tasker [ii]. To wit: https://www.reddit.com/r/tasker/comments/b1272l/android_q_ta...
[i] https://play.google.com/store/apps/details?id=ch.gridvision.... [ii] https://play.google.com/store/apps/details?id=net.dinglisch....
That seems like an obvious advantage to me.
In Apple the phone is the product.
I've probably had a smartphone as long as anyone. And I hope it's not just because some people work at Google. :)
In this instance, apps have been doing this for years. Apple knows this. It’s not entirely clear why they only decided to act on it now.
It seems like an intractable problem but I think we still have a few tricks up our sleeves. For one thing, we can look at what public companies report in their quarterly earnings and what major business decisions they make. For Apple, the vast majority of their revenue comes from hardware and services. A very, very tiny amount of their revenue comes from advertising.
Compare that with Google and Facebook. These companies make nearly all of their revenue from advertising. Why is this distinction important? Because advertising is all about data collection. Hardware sales? Much less so.
So when I need to figure out whether I should trust Apple vs trusting Google, I look at where their incentives are and how much they align with my own. Google's incentive is to collect as much of my data as possible and monetize it while keeping me engaged with search and YouTube. Apple's incentive, on the other hand, is to sell me new hardware and get me to subscribe to their services.
It seems pretty clear to me that Apple has far less incentive to snoop on my personal data and abuse my privacy than Google does, so I deem them more trustworthy. Is this a complete picture? Probably not. But I think it's still a valuable one.
Coming from GNU/Linux where most things are open and community maintained it’s definitely a step backwards.
Either iOS is secure or it's not. if it's secure there is no need for the walled garden. Let me run anything and trust its security.
If it's not secure then the walled garden is security theater because it's trivial for any app to hide its true intent.
This is flat out wrong. Security isn't binary.
How did you come to this statement? Because my initial reaction is not a flattering one for you, but hey, I’m learning too and I find this topic super interesting. Could you provide an example of a secure platform securing against threats in such an absolute way? Maybe QubesOS? I’d like to hear your reasoning a bit more.
Also, I want to touch on your statement of browsers not having walled gardens, and being secure in a general sense. Are you under the impression that modern browsers are equivalent to all other kinds of apps in regards to their threat profile? Also, are you aware that most modern browsers phone home URLs to check against a malicious site list? I look at this as “walled-garden lite”
Personally, I keep flip flopping between MacOS, Windows 10 with WSL2 + Fedora, and a 8GB RPI 4B, which for the last few days has been doing ok for a desktop.
My point? The security vs freedom debate is complicated, and for many, rages back and fourth even in the same person. There are very few absolutes in this world. Save your hills to die on for points you KNOW you’re right about, because in this, you’re waaaaaaay off base.
So let’s define our terms a little bit. What is our walled garden and what does it bring to the table in terms of security?
Off the top of my head I’m thinking we get more eyes during the review process, maybe some static/malware analysis, etc.. Another thing is the “soft controls”, not allowing certain classes of apps that Apple doesn’t feel “belong” in their garden. Well that’s a net security benefit too. Less apps, less possibility of exposure, more careful and selective choosing of apps allowed, you’re going to see less shady stuff and abuse.
Compare the two app stores, it’s not even close.
So the security benefits of a tight review/control process are pretty clear, and play out in the results of malware outbreaks between Google and Apples app stores.
The question of trading freedom for security is another topic, one that cuts deep into the fabric of western society. Too deep for this convo!
In the case of very popular, aggressively-marketed, apps like TikTok and Facebook’s: the lack of easy side-loading or alternative app-stores (with looser auditing) means they’re forced to comply with Apple’s regs against unnecessary permission prompts, and this means they simply can’t take advantage of users’ ignorance (or overriding desire to see the dancing bunnies) to get them to grant unnecessary permissions.
...but the fact that unofficial app-stores for unjailbroken iOS devices do not exist makes this impossible for now.
It’s very easy to imagine a TV ad or movie trailer ad for a TikTok or Facebook app with the cheerfully-voiced narrator saying “Just visit the TikTok Android App Store” or “Just open the Facebook iOS App Store” - then when the app is installed and first-opened the app would use a single “grant everything” permission prompt - or if the OS doesn’t allow that it could bombard the user with many prompts all-at-once and if the user denies any of them then a curtly-worded new messagebox would say “you must grant these permissions to use our app” otherwise the app quits. There’s not much Apple or Google could do to stop this that those app developers couldn’t work-around. Apple’s iOS App Store rejections for privacy reasons is a human solution to a non-technical problem, as it’s well-established that technical solutions to non-technical problems are ineffectual.
It can be argued this is possible on Android - which does allow for other app-stores - and I did wonder why this isn’t already happening with Android users - then I realised that probably most Android users have those horrible carrier and OEM locked-down devices that make it harder (if not impossible) to change system settings or add other app-stores.
They could, but they're absolutely not going to. Every barrier you put between and user and installing your app is a percentage of those installs that you're losing. Doubly so for "non technical" users, who can barely work the app store in the first place. No company of that size is going to lose that many downloads just to steal a few more downloads.
>then I realised that probably most Android users have those horrible carrier and OEM locked-down devices that make it harder (if not impossible) to change system settings or add other app-stores.
Stock android makes you jump through hoops to install third party apps, and for good reason. No, it's not because "OEM locked-down devices", the reason you don't see it on android is because it doesn't make business sense.
As a famous example of a popular app that eventually caved into Google's demands is Fortnite [1] and children are tech savvy (or at least motivated) enough to install from outside the app store. If Fortnite couldn't do it, then no, it's not easy to imagine TikTok doing it, especially given TikTok's market share is made of mobile users mostly, so no PC, no PS 4, no Xbox.
There are indeed alternative app stores from Samsung, Amazon, maybe others, however Google's Play absolutely dominates the Android ecosystem.
I'm an iOS user myself, however this whole reasoning is bullshit. The only reason Apple keeps such a tight control is because they want to keep that 30% commission on all sales, which is highway robbery. And I also suspect them of wanting to have enough reason and leverage to get rid of any app that threatens their own products.
[1] https://techcrunch.com/2020/04/21/epic-games-launches-fortni...
---
Also the elephant in the room is the web.
I see grownups and children alike using the web successfully all the time. The web can be secure without a gatekeeper because browsers do a reasonable job at sandboxing. In fact it is the competitive nature of the market that makes it secure, consider that's how extensions and ad blockers happened (in the meantime I still don't have a browser on iOS capable of using uBlock Origin).
And yes the web has dark corners, yet we live with it just fine. Look, we're having this conversation on a web page that's not gated by Apple and we're still alive.
I hear this line about their business model all the time, however it is bullshit. Given the opportunity all companies will take the money. And I fear that it is nothing more than a conspiracy theory, without much evidence, much like anti-vaxxing.
Google these days is a very big target. The EU would love to have reason to slap them with another fine, given all the legal tax evasion they've been doing. Yet they've always been transparent about what they collect and have always been responsible with user data (versus Facebook).
Don't get me wrong, I enjoy the privacy features of my iPhone, it always fared better than Android in that regard, but it has nothing to do with Apple's tight grip of its App Store.
And Google Play takes a 30% commission too ;-)
It's a large amount, even for Apple, but they would survive losing that. Besides that, they are even taunting Google by putting DuckDuckGo in their marketing copy:
https://www.apple.com/macos/big-sur-preview/
They also started a partnership with them in 2019:
https://www.cnet.com/news/apple-maps-gooses-duckduckgo-in-se...
I think they are slowly preparing to loosen that tie.
I hear this line about their business model all the time, however it is bullshit. Given the opportunity all companies will take the money.
I agree. Apple's incentives are just temporarily aligned with customer's privacy. Their margins on hardware, services, etc. are so large that they can afford to make privacy a differentiator. If they are not in that comfortable position anymore, they would monetize the vast user data trove.
But while this is the status quo, I am happy to use an iPhone for privacy.
Please, they are not going to leave $10 billion per year on the table.
In particular Tencent is notorious for not being the default app store on any phones, but somehow "mysteriously" if you follow links from WeChat or QQ or even certain websites, it will try to make your phone download the Tencent app store to install the app instead of just using your phone's default app store. Even your phone gives a warning not to do it, people still install it. And, sure enough, Tencent app store is now the biggest app store in China, with 25% of the market.
Tiktok is owned by Bytedance, which doesn't even have an app store in China, so i can't see them making a play.
Fortnite, on the other other hand, is owned by Epic who definitely used the popularity and income from Fortnite to leverage their way into the PC gaming marketplace, disrupting the major player (Valve). They might not have won this battle for the phone marketplace, but by the sounds of it they still haven't given up the war.
So, i do think it's fair for the grandparent poster to consider a future where users bypass whatever protections came from their phone manufacturer and end up shooting themselves in the foot. But i also think you're right that it doesn't matter. That's the "price of freedom".
We already see it a little bit now where some people choose Android over iOS (or vice versa) for ideological reasons. Loosening manufacturer restrictions even further seems reasonable to me. Some people would choose ultra-safety through open source, others would choose to use closed source from a company they consider trustworthy. Most would not care and just use whatever environment they are most familiar with, and install whatever plugins and cleaners they need to make them feel more secure. That's basically the PC market right now, and i think it's largely fine.
They'll simply annoy you to hell and not let you use the app until you've granted permanent location permissions.
Internet is a permission that is required if your app expects to go online. You cannot turn this permission off in the OS. If you modify Android to allow changing this permission (usually via Xposed) or rebuild the app to remove it from the manifest, many apps will actually crash when they try to go online; this is part of the reason why people use a firewall even on devices with Xposed installed. My vague understanding is that this is how Android works when an app tried to do something it can't--it closes the app. IIRC there is an Xposed module that filters by the URL, but I'm guessing it fakes the network response (more complex than simply disabling permission), and it doesn't work with ndk.
With Marshmallow, runtime permissions were introduced for a number of existing permissions, where it would prompt you the first time the app tried to access privileged data. If your app is older than Marshmallow (ie, written for lollipop or KitKat), disabling any of the enabled permissions is liable to crash the app as soon as it tries to use them.
For the full list of permissions on Android, see https://gist.github.com/Arinerron/1bcaadc7b1cbeae77de0263f4e... (there's a few links in the comments to Android source code; they cause my phone browser to crash, though)
Feel free to correct me if I'm wrong, or if this information is outdated; much of it was specific to Android 6 release.
I don't think Apple would allow that kind of permissions abuse, but apparently Google does.
Considering Citi’s corporate culture, I’d attribute this to incompetence rather than malice or a desire to spy on users.
I’ll bet they’re using a third-party anti-spyware library to examine the Android FS for keyloggers/etc to protect their users’ security. It’s well-intentioned, but still idiotic.
This is the same Citibank that’s been engaged in an idiotic arms-race with Google about blocking password-safes on their online banking login page for the past 5+ years - while also allowing me to do phone-banking without any real authentication - and STILL haven’t given me an EMV Chip+PIN credit-card, while the EMV Chip+Sign card I do have from them DOES have NFC without a purchase limit... anyone could steal my wallet and “tap” a couple grand off it. Arggghhhhhh.
The “banks who think they’re smarter about security than platform vendors” trope is getting real old.
https://www.reuters.com/article/us-citigroup-fine-idUSKBN1ET...
The $70m fine (a joke to a multi-billion-dollar company) is insignificant to the potential damages from a class-action lawsuit from a wide-ranging vulnerability in their online banking platform - hence their focus and over-engineering on their online banking security - while the risks from credit-card abuse and individual identity-theft are much more limited in scope - and are a known-quantity.
Even today, there are apps on Android that ask for needless permissions and refuse to continue unless the permissions or granted. That same app on iOS would provide more functionality (that's possible without having the permissions). There seems to be a very different mindset between Android developers compared to iOS developers.
Second, this effectiveness doesn’t require the walled garden and forcing apps to pay 30% of revenue to Apple.
It's working. But not because of Apple's Appstore policies.
If you like defense in depth: App Store.
If you like freedom of choice: Open Market Store and side-loading.
You can sort of see this on other platforms - the Mac App Store has very few quality apps listed on the store and Apple is further moving towards locking down root permissions b/c users can download apps or install software from anywhere on the web. It's typical for users to install anti-malware software on new Android devices, etc.
If the App Store remains the only method for installing apps, and Apple continues to reject apps that they simply don't like, then it's not a healthy platform for consumers in the end.
If you build it right, it is totally doable. Implement it like in Health so that the app just gets empty data and doesn’t really know if it has access or not.
If the app doesn’t function properly with an empty data set, reject such an app through App Store guidelines.
my Android phone warns me if an app is trying to use features that require permission while in background and asks me if I want to revoke the permissions, enable it only while the app is active or let it use it always.
pretty easy to use and anyone can guess that the bus or car sharing app doesn't need to use GPS all the time
When the controller is a "smart" app store, you know what they delete, but you don't know what they keep and why they do it.
they chose for you and never ask you if you're okay with it or not, so basically it's not your phone, it's their phone.
https://docs.microsoft.com/en-us/archive/blogs/larryosterman...
> I saw a post the other day (I'm not sure where, otherwise I'd cite it) that proclaimed that a properly designed system didn't need any anti-virus or anti-spyware software. Forgive me, but this comment is about as intellegent as "I can see a worldwide market for 10 computers" or "no properly written program should require more than 128K of RAM" or "no properly designed computer should require a fan". The reason for this is buried in the subject of this post, it's what I (and others) like to call the "dancing bunnies" problem.
> What's the dancing bunnies problem? It's a description of what happens when a user receives an email message that says "click here to see the dancing bunnies". The user wants to see the dancing bunnies, so they click there. It doesn't matter how much you try to disuade them, if they want to see the dancing bunnies, then by gum, they're going to see the dancing bunnies. It doesn't matter how many technical hurdles you put in their way, if they stop the user from seeing the dancing bunny, then they're going to go and see the dancing bunny.
> There are lots of techniques for mitigating the dancing bunny problem. There's strict privilege separation - users don't have access to any locations that can harm them. You can prevent users from downloading programs. You can make the user invoke magic commands to make code executable (chmod +e dancingbunnies). You can force the user to input a password when they want to access resources. You can block programs at the firewall. You can turn off scripting. You can do lots, and lots of things. However, at the end of the day, the user still wants to see the dancing bunny, and they'll do whatever's necessary to bypass your carefully constructed barriers in order to see the bunny
> We know that user's will do whatever's necessary. How do we know that? Well, because at least one virus (one of the Beagle derivatives) propogated via a password encrypted .zip file. In order to see the contents, the user had to open the zip file and type in the password that was contained in the email. Users were more than happy to do that, even after years of education, and dozens of technological hurdles. All because they wanted to see the dancing bunny. The reason for a platform needing anti-virus and anti-spyware software is that it forms a final line of defense against the dancing bunny problem - at their heart, anti-virus software is software that scans every executable before it's loaded and prevents it from running if it looks like it contain a virus. As long as the user can run code or scripts, then viruses will exist, and anti-virus software will need to exist to protect users from them.
—————
This was written 2005, before the iPhone and iPad. One could argue that the whole AppStore/Gatekeeper/Notarization system itself is a big giant patronizing Anti-malware-Software by Apple or focus on the last sentence, that on iOS the user can’t run non-sandboxed scripts and code.
But it is also the case were Apple again did “think different”.
> I saw a post the other day that proclaimed that a properly designed system didn't need any anti-virus or anti-spyware software. Forgive me, but this comment is about as intellegent as "I can see a worldwide market for 10 computers" or "no properly written program should require more than 128K of RAM" or "no properly designed computer should require a fan".
Ha!
- Completely FOSS stack
- Uses multiple repositories (no lock-in)
- Everything is sandboxed with Bubblewrap
- Fine-grained permission control that offers more than iOS: control whether apps can access the network, which directories an app can access, if it can print, and even whether or not it can access PulseAudio.
- Cross-platform: runtimes are OCI container images and can be targeted on any distro that supports Flatpak (which is almost all of them).
It's gained adoption from a number of recognizable FOSS and proprietary names: Zoom, Spotify, Steam, Firefox, VLC, Discord, Libreoffice, Skype, Inkscape, both Minecraft and Minetest, Microsoft Teams, Krita, IntelliJ IDEs (both Community and Professional), and Blender are available as Flatpaks through Flathub.
GNOME and KDE release almost all their apps as Flatpaks through the `gnome` and `kdeapps` Flatpak repos, and copy them over to Flathub when they're confident that Flatpak-ing didn't introduce any bugs.
It would be nice if Apple would let packages signed by the same key share versioned libraries between them, but I suspect relatively few developers would be able to take advantage of that. Maybe only google and microsoft, to a rough order of approximation.
Even Android is going into this direction, locking down APIs, access to Linux syscalls (not even considered part of NDK official APIs), background execution modes and file access.
"-This clock app needs to access your photos, contacts, all the hardware the phone has and all your cloud accounts -No -The app can not function without the required permissions."
>Gets catched years later and review bombed
>Author walks away with pockets full and probably onto the next money-grabbing project
Oh yes, classic "successful democratic process"
In Control Center it will also show you which App recently used those.
So that’s not more fine grained control, but it can help you understand when someone is abusing the permission.
I've asked in the twitter thread if early adopters of iOS 14 could also check if any apps access the microphone while in background (even though they shouldn't have to by use case).
I have the suspicion that some apps listen into conversations to apply speech recognition and NLP for targeted ads and maybe even more malicious practices - though I'm guessing networks close to FB for example would have been smart enough to have turned off those "features" for their apps by now but maybe not.
Still, it would be interesting: https://twitter.com/musha68k/status/1276112945496428544?s=21
I’m not saying it’s any better, or indeed worse, rather it’s an important distinction.
That being said, I of course know that the Chinese government didn’t force Apple to implement this privacy violating feature, and I know that the Chinese government didn’t force Apple to allow TikTok to abuse it. But many people see Apple as a privacy conscious company thanks to its marketing, and its good to remind people that for Apple, privacy is simply a marketing gimmick.
1. Contact sharing needs a complete overhaul. Some apps need to have access to my contacts. I get this. But they only need the name and the phone number. They don’t need addresses, birthdays and additional notes I put in m contacts.
Sure, I could have a separate contacts app with "meta data", but this would break the integration of Contacts in other Apple products.
2. Photos. It is either full access or no access. For example, I don’t trust WhatsApp. I share photos through WhatsApp by opening the Photos app, tap share, share via WhatsApp. This works okay.
But generally speaking: why can’t Contacts and Photos have the same sophisticated access control system like Health? Heck, make it optional for iPhone users, but at least offer it.
https://www.macrumors.com/2020/06/24/ios-14-users-give-apps-...
Maybe contacts too, but I haven’t read that anywhere.
Agree tighter control over contacts sharing would be nice but I don’t think it’s malicious on Apple’s part that this isn’t possible - they’ve quite clearly shown they are on the side of user privacy, but they do also tend to move at a fairly slow pace
I would have thought there was a big debate in Product Mgmt over this vs the more obvious allow an app access to a given album.
One presumes the sticking point came when someone took a photo out of an album. Does that mean they are explicitly removing access? I don't see it as a huge issue... maybe there is some kind of technical hurdle involved as well, otherwise the choice seems unusual
Also, I don't have to scroll through months of memes to get to that one good photo I took in July 2017... or was it August..... maybe it was 2016......... shit.
Sounds like only something people who aren’t stressed from their underpaid jobs can do? Most people are kept busy and don’t have time to fit into this dark (corporate app) pattern.
Plenty of people use photography as an escape from their work stress. I just don't understand what your point is.
Your post was in my eyes saying this issue was up to individual users to tackle. I disagree with that. I think it is instead the governments' role to regulate and reel in predatory and parasitic corporations.
[1] https://www.telegraph.co.uk/technology/2020/06/25/tiktok-sto...
She has albums for work stuff. She has albums for home decorating ideas. She has albums for the various screenshots she collects of things she wants to remember. She has albums for different places she's been.
I know that the people she's friends with use albums because I've heard it mentioned.
I think normal people use albums. Tech people don't. Which explains why a company like Apple, that tries hard to court normal people, not tech people, has them.
When it comes to security features, simple and obvious behaviour is good, pretty much always. The same is true of user interface design, and the lack of both documentation and natural discoverability on iOS has always been a pretty glaring weakness of the platform. Complexity creates edge cases, and edge cases create vulnerabilities, including due to misunderstandings and resulting human error.
Judging by the other replies to the parent comment, apparently I'm not alone here, so I'm guessing if Apple did any user research about this, that "big debate" probably lasted a few seconds...
> There's also the entirely new option Select Photos..., which leads the user through to the Camera Roll to pick one or more images to share. It is specifically images that users can opt to share, rather than albums.
> Which then means there is an issue that the next time a user wants to post an image, they find their selection confined to solely the ones they specified before. To change that and allow all or just different images, the user has to go to Settings on their iPhone.
My wishlist for fixing photo privacy on iOS:
1) Applications don't need to ask for permission to write photos to iOS folders. These get written to a separate album ($appName or $appDeveloperName by default), e.g. if you save a photo from Twitter it gets saved to your Twitter folder.
2) Photos taken by the iPhone Camera (presumably your personal photos) get stored in a special 'Camera' folder. Apps can ask for read/write permissions specifically here. Eg a photo editing app like VSCO or Darkroom may only need read permissions to begin with, but if it also wants to in-place replace your photos with its edited photos, it'll need read+write permission as well.
3) What about apps that occasionally need access to photos (e.g. social media apps) but you don't want them to have access to everything? The solution is to implement a OS-level photo picker in iOS with a UI can't be over-ridden and which makes clear you're sharing your selected photos with $appName. And ensure apps which want access to photos have to make the user go through the OS-level photo picker.
This has existed forever - in fact, for far longer than applications have had the option of requesting full access to your camera roll. Unfortunately most applications have decided they prefer to take over the experience, and provide absolutely no fallback option if you reject giving them access.
Apple really just needs to make it mandatory to present a UIImagePickerController instead of whatever "integrated experience" an app provides when permissions to the photo library are denied. That would have been a much saner solution than this abomination - I don't want Teams to have the ability to wander around my photo library just so I can share a quick snap of a whiteboard. But I don't get a choice, because denying permission just makes it throw an error message up saying it doesn't have access.
Initial launch - user chooses a few photos. User switches apps, and returns - the same photos are selected. User force quits app (or doesn't use app for a few days and it gets killed off) User opens app, and is then prompted whether they want to "Keep Current Selection" or "Select More Photos" the first time the app accesses the photo library in some way (I think this is based on when you do a photo permissions check, but not positive.)
#3 has existed since the iPhone added apps - UIImagePickerViewController - if you use it, you don't need photo permissions and you only get access to the photo the user selected. Most social media apps probably just skip using this because they want photos permission everywhere to do things like "post latest photo" or to show their own photo picker UI.
I guess Apple's not "full of shit" anymore.
Contacts: didn’t find a good source. This talks about "contacts autofill", not sure what that means exactly: https://www.apple.com/ios/ios-14-preview/features/
This is pretty clear to me, you type a name, it’s looked up in your contacts by the OS, data is retrieved if there is a match and placed in the form. This is not the same as sharing an individual contact and allowing the app to continue to read it later, but still gives you a means to give contact data to an app without giving it access to the entire list.
1) a way for apps to display a view that shows the contact name for a phone number, with specified styling / sizing / etc, but without being able to determine what that contact name is.
2) an App Store rule that forbids apps from requiring contact access unless they can't function without it. WhatsApp forces you to provide contact access, giving Facebook your place in the social graph even if you don't use Facebook, even though WhatsApp should be usable (using phone numbers) without it.
WhatsApp does work if you revoke Contacts permission after setting it up, but IIRC you can't onboard when you first install the app if you don't grant it. Forcing the granting of the permission should be against App Store rules.
I use WhatsApp after revoking its contacts permission and it's pretty much fine. As an aside, same with Signal, and I really don't understand why a supposedly privacy-focused app like Signal nags hard to get contacts permission when it works perfectly fine without; it even shows people's chosen nicknames next to their numbers.
In this world where we expect internet access, I'm beginning to think OSs need to manage certain types of data more proactively. I'm trying to wrap a general point around your concerns about contacts. Contacts seem one of the data types that need something approaching OS level tooling. For me, another is "tags". I want to use the same set of tags I apply to "files" to apply to "contacts" too.
I keep hoping someone will make a rival OS that tackles this head-on. Start at Haiku, sprinkle some of Apple's "the UI isn't a virtualised office any more" UI paradigm, model a small handful of human-centric data types (like places, people, maybe individual health, too) and the access and interaction rules that support them safely and really run with it.
They had a People hub that collated all your contacts and had reasonable sharing mechanisms for the data. HERE was essentially that places concept. I'm sure if Windows Phone had kept traction, it would be integrating your smart device health data into live tiles and a hub interface for all the metrics.
* let’s keep it time accurate :)
Nokia's maemo had this done with better execution. The SMS app had a plug-in for xmpp and I used it for Google talk. I think I used a third party one for Google voice. There was a Skype one that supported calling through the normal phone app but it didn't work very well. The clients were run on the phone and not in the cloud.
WP8 relaxed some of those restrictions but it wasn't enough to truly develop a IM client.
It's true that only Microsoft could create such integrations, but it was a business decision. On Windows Phone 7 era, regular developers couldn't deploy native code and you couldn't call native APIs directly from the managed .NET/Silverlight runtime. Native SDK wasn't available at all, but it was a regular Windows CE at its core.
Maemo's was way superior to Windows Phone. It's a shame that Microsoft trojan-horsed Nokia.
The feature should be a per-app opt-in instead of being enabled by default and buried in settings.
As I said, I'm glad they tackled the Photos problem. But of course, I could ask what took them YEARS to do so. They even have a private album in Photos but didn't think that some apps shouldn't get access to these pictures?
Which is exactly what most apps actually need.
WhatsApp has no good reason to look at any image you aren't explicitly choosing to share right now. The only user-facing WhatsApp feature that requires Photo library access is the scrolling list of recent photos on top of the in-app camera.
WhatsApp has a better case for asking to continually scan your contacts to show you people with accounts. But instead of just falling back to asking for a phone number when you don't give permission, it could show the contact picker, and check the accounts you pick.
Unfortunately, in both cases, WhatsApp takes the all-or-nothing approach - it asks for the blanket permission, and has no fall-back if it is denied.
If they don't use this control you can also inject whatever photos you want into most apps using the share sheet. It does mean you have to exit the app and go to photos, but as you point out, it's the app maker's fault for not supporting the extremely privacy friendly `UIImagePickerController`.
On Linux and BSD we've been having very good privacy features for years now.
Therefore I don't think that privacy is at the top of the list of Apple's motives.
The walled garden actually makes it harder to run software you and others can check to be sucure, instead you have to depend on some opaque QA somewhere in Apple to check that for you.
Not to mention you can't elect to use software that has features blocked by default for security reasons where you are sure it will not misuse them as you have audited the source (or even written it yourself!).
Hopefully, with reasonably open mobile hardware (PinePhone) other open mobile OS efforts will get more traction now, as the main obstacle of mobile OS development to this day has always been closed hardware & all the crapy proprietary software bundled with it.
All pretty silly all things considered but I can’t think of an easier way to do things.
Reading around it looks like there are better APIs for doing this, where you can ask iOS is the clipboard contains a string matching a pattern, which actually getting access to the content.
Okay, this could be simply a dynamic link library checking for a deep link in the clipboard.
Why do this? To preserve the state after install.
Firebase does it. When you click on a deep link but you don't have the app installed, the webpage would copy the url to clipboard and open the App Store, after you install the app and open it Firebase would check the clipboard and take you to the the correct screen.
The apps in the video don't need to be malicious, they simply could be checking if there's a deep link in the clipboard to restore user session.
Of course, with iOS 14 the best practice would be to do this only once after the install.
Yes? That's the definition of a deep link? The way you get notified is you open their app...
This is a special case when you don't already have the app installed, but being able to read the clipboard without warning is it's own thing, but this specific deep link use-case is extremely benign...
It’s disappointing to see the lack of skepticism applied on a site like Hacker News.
Chrome uses it so the URL appears when you select the address bar.
For example, a link saving app like Pocket might check if your clipboard currently contains a URL when you open it. That allows the app turn a slightly tedious operation (tap/hold input field to bring up context menu, tap paste, tap button to save) into a single tap ("save copied URL?").
Whether or not the convenience is worth it might be debatable, but I fail to see how one would call that nefarious.
It does appear that lots of apps don’t use these APIs, the developers probably never knew the existed till now, but there is a privacy preserving method of the building the functionality you talk of.
I don’t think that’s the case. You can check if there’s a URL in the clipboard but that’s a UTI thing.
Most of the URLs would likely be in the “strings” section of the clipboard.
I can totally expect others to detect copied URLs that may belong to the app's domain and then offer to direct you to that particular URL (for example, I think the SomethingAwful app on iOS does that - if it detects a forums.somethingawful address it'll offer to load that particular thread for you).
That said, I definitely want to see more visibility about when and why this is done. Apple are absolutely in the right to show me a popup whenever it happens, so apps are forced to be clear and transparent about it.
On Twitter I saw a. Doing app mention they trigger the notification on every key press because they have custom ‘paste’ button that only shows when you have something copied.
Really nice app in general though.
iOS supports universal links, so a website and iOS application can indicate that when you open a link to the website but have the application installed, the application opens and takes you to the content. This is what TikTok can use to open links to TikTok in the application.
But this isn’t a general purpose website => app association. Only the website owner can allow an application to do this. You wouldn’t want, say, Google to set up their application to open DuckDuckGo URLs, for instance.
So when it comes to third-party Reddit clients, they can’t automatically open reddit.com URLs because they don’t own reddit.com. The clipboard trick is a workaround for that.
I think the conclusion is "Companies just cannot be trusted". At all. With anything.
We should assume guilty unless proven overthise for companies. They should go out of their way to show us their good will.
Honest question: Why do we need this feature?
As a user, I am happy to sacrafice whatever benefit it provides -- to end users -- to stop the abuse. Obviously the feature provides benefits to app developer personal data collectors.
OK by me to remove feature.
It's a pretty neat use of the feature, although I'd still gladly let go of it if it means that the other 20 apps I regularly use don't get to rummage through my clipboard for no good reason.
It's pretty handy since paste itself is a somewhat cumbersome shortcut on many keyboardless devices.
Can they, if Background Refresh is off for the app? I allow it only for Apple apps.
Obviously I might be wrong, but we live in times where many applications are reverse engineered and their traffic is MITM'ed all the time. I'm not sure if anyone’s sending those clipboard contents outside the device. That would be a problem.
Create a bitly account if you don't have one and login and create a bitly link for anything, it doesn't matter what it is.
Copy that bitly link to your clipboard and repeat what you're doing in that video.
Monitor the bitly link for clicks.
Better still do it on a website you control with a unique URL that won't get indexed by a search engine and monitor the web server log files for hits and keep a record of the IP addresses.
I wonder if Apple is playing 4D chess here though. As people learn about this, they will become outraged and care more about privacy. This in turn benefits Apple since that's their marketing stance.
I wish they just cut the bullshit and fixed these holes though, they've been around for years. It's really depressing to see Apple's fantastic security work in other parts of the stack be completely and utterly compromised by OS design decisions like this.
Accessibility apps likely have a lot of examples like this too
It does require a user initiated event to work, but then you can access the user's clipboard with:
`await navigator.clipboard.read();`
There are some additional restrictions though (you can read them in the first link) which it might make sense for iOS as a whole to adopt.
It used to be true but all that was fixed like 10 years ago.
It's somewhat similar to how Firefox has disallowed auto-playing videos except on user permission or a user-triggered event.
Which has been mostly worked around by the bad actors, who use things like mouse-over or scroll to trigger the event.
“Click Reject All Cookies to exercise your GDPR rights!”
Somehow I didn't even realize that's how they were getting around it! I just thought, "Dang, I thought I turned that crap off." Good callout.
Don't know about a repo, but https://developer.mozilla.org/en-US/docs/Web/API/Clipboard_A...
I wouldn't expect that most people would double-check to make sure a series of gibberish characters matches what they expect, especially if they don't have any reason to suspect that paste wouldn't output exactly what they copied a moment ago.
Why 4D? Isn't chess just a 2D game with wormholes?
Ockham's razor says that they just don't care enough about this.
Or Googlebot?
etc.
It took me a good 10 minutes to realize what was happening, especially since I was using a temp ngrok tunnel and no one should have had that URL.
Dunno is the ‘feature’ is still there, it was over five years ago.
Of course it doesn't work when Signal fetches it before him to make a preview!
Had to set it to exactly 2 views and then he could view the password.
And iirc the Signal-desktop release for Linux I was using could not disable previews of links. And even if it could, his end might have previewed it.
Put a button “click her to see password, you got one chance” to trigger the POST.
Edit: However, tiktok is one of the chattiest apps I've looked at. They have a huge number of tracking/logging/collection endpoints constantly slurping data in the background. See my hosts list which aims to block this:
https://github.com/llacb47/mischosts/blob/master/tiktok-host...
That way it wouldn't be possible for users to block individual hosts to prevent tracking. I guess it's not worth the effort though because laypeople won't care either way?
This. I remember at my last company, we ended up with 8 or 9 different analytics tools all getting different data and showing one or two "cool views" the PM had put together.
It's such a big problem that solutions like segment.io exist to broker your events to N different downstream solutions.
Truly, this is the darkest timeline.
Some content providers don't allow you to view content if you block the advertising hosts.
Then it becomes a matter how you want to deal with failure, do you want the site to break if your ads don't load?
Maybe you just didn't copy anything TikTok was interested in keeping track of. I can think of a lot of really obnoxious things you can do with clipboard data, everything from scanning the contents to collect interests, scanning for URLs, collecting information about what applications are installed. A lot of this could be analyzed on device and it would only update infrequently.
Odds are, like almost every other application it cares about website URLs to deep-link. Pretty much every reddit client does that for instance.
Not sure if TikTok does something similar, but there are certainly innocent reasons for checking the clipboard.
Edit: fair responses, all. You've convinced me.
A few months ago I would have said the same thing as you, but then I experienced some applications which looked at what I had copied and automatically did all the hard work. It's a pleasant surprise to see it happen, and having experienced it, I am happy that the applications have this functionality.
Of course if you're living in a world where all the code on your device is considered hostile, then you may not want this. But I use almost only free software and there you can generally start with a presumption of goodwill instead of starting with a feeling of distrust, like with TikTok.
FWIW, the one I use only checks once — upon startup. It's sometimes annoying that I have to kick it out and re-launch if I've copied a tracking URL from e-mail after the delivery tracking app is already open, but now that I know that's the price of privacy, I'm perfectly OK with it.
I believe Slack was one of these. I thought it was useful at the time.
Even if you're only looking for a shipping tracking number and then only so that you can provide useful auto-populate, will you lose out by only checking the clipboard when the user hits your text input field? Is it that much to ask that you find the least offensive way to serve your user?
On the other hand, what will you lose when the news gets out that you've created a keylogger? What about when someone else at your company pushes you to monitor for something else for strategic advantages? Or what about when another developer doesn't understand the implications and now your app is responsible for revealing passwords or other sensitive information? Are all of these worth saving one click?
Now, if they had evidence that the data from the keyboard was being sent up to a server, that'd be a different story.
Personally, I would prefer a world where nothing can pull from the copy buffer, it needs to be actively pushed by the user. It seems crazy to me that that isn't the case.
A notification that they’ve already done it is not enough. It should tell you every time even if you approved it.
The only explanation I can come up with for why Apple isn’t making this opt in like location is it is so widespread it would break many apps. I just can’t understand how, or why they wouldn’t announce a transition-by date like with Sign in by Apple.
A notification that they’ve already done it is not enough. It should tell you every time even if you approved it.
The only explanation I can come up with for why Apple isn’t making this opt in like location is it is so widespread it would break many apps. I just can’t understand how, or why they wouldn’t announce a transition-by date like with Sign in with Apple.
Up until now there’s been no way the user has been offended because they haven’t known it’s happening. So there’s no real incentive to do it when you focus on a text field vs anything else.
And more broadly, there isn’t a downside if you use the API honestly: e.g. to check for a numeric code that matches whatever regex for one of your orders and otherwise disregard the data immediately. I’d bet a good number of users find it useful.
So let's say you're making the tracking notifier, and you work for UPS. The regex is `1Z[0-9]{16}`. All good, you're being nice, someone opens your app and you already know what shipment they're interested in. Then a "growth hacker" joins your group and mentions that it'd be nice to know how many of your customers also use FedEx, so the regex is changed to also grab FedEx tracking numbers (`(1Z)?[0-9]{16}`, I think). And now someone gets the genius idea of checking up on package shipped by competitors and popping up a notification "tired of waiting on DHL? UPS delivers within 2 days 99.995% of the time" when they miss a delivery. Even though they never asked UPS abotu their DHL package.
See how that progresses? See how it's offensive, even if you're not annoying your user more than you normally would with spammy push notifications, and even before your user suspects that you're spying like this? Do you see how this whole series of escalations aren't available, or at least not as easy, if you only check the copy buffer when it's likely a user is about to paste? Instead of "tweak what we already have" you have to "include a new snooping routine".
If you're thinking "all is fair in love and war" here, and this seems like genius marketing: 1) this is your heads up that your morals are not in line with society's, and 2) do you think this will be a marketing win if the regex is loosened enough that you pop up a UPS notification about "package with tracking number (phone number someone just gave me)"? What about if my UPS account for work notifies me about some very private personal packages? Especially some shipped via OnTrak?
Anyway, as I said in my first comment. I'm disappointed that people don't think they should try to worry about downsides and failure modes of their design and engineering work. Maybe it's a matter of norms and priorities being different in the consumer app/web world vs. many other domains.
"Is it that much to ask that you find the least offensive way to serve your user?"
So, suppose UPS is not doing anything that you've just described. Say they are regexing for UPS numbers only. How would that be considered offensive?
Suppose you want to offer this capability but only check the copy buffer when the user has signalled an intent to provide you with input. How is that not the least galling design decision? I'm having trouble figuring out how to express that it also serves as a personal (and team-internal) signal that "we are here to serve the user, and not to take advantage of them, even if that's inconvenient for us". Maybe that doesn't matter, or maybe lacking that is what leads to things like the Uber "Ride of Glory" blog post and worse?
Something I meant to imply in my first comment, but not the reply to you, is that furthermore limiting your exposure to user data limits the likelihood that a series of bugs puts it into your logs and then leaked out to the world. No, it's not done on purpose, but no amount of good intentions fixes it. Defaulting to being less invasive also reduces your likely level of impact.
In your toy example of my app's main screen being a text box where the user can insert a tracking code, yes, I do lose by making the user wonder every time "you know I have a tracking code why are you making me type it in?" In a more realistic example of, say, Amazon, where the "track my previous order" button is not the main screen of the app, the convenience is further increased by doing the detection automatically.
And what about non-text clipboard contents? Not every interface is a text-style document into which content can be embedded. Even "Copy URL" requires knowing that "share website" shared a URL and not a website. It doesn't make sense for images at all.
Which iOS and macOS already have, they are called data detectors. When the message arrives notifying you of the tracking number, you can select “track this parcel” from the context menu. No need for an app to snoop on the clipboard.
If I copy a link on Android, I can go to Chrome, click on the address bar, and it suggests "link you copied: $whatever". This is how this should work. If there's an image in my copy buffer, it doesn't need to do anything. I don't need Chrome monitoring my copy buffer when I'm doing other things in case I copy something that looks link-like.
[0] https://developer.apple.com/design/human-interface-guideline...
How about: stop apologizing for billion dollar corporations. Fault can be placed on both the OS and applications. I expect better, from everyone.
slippery slope arguments go all the way to the bottom
Sounds good. There are clipboard apps on iOS that work with a share sheet and also get the clipboard content when launched. They could be modified to have the user actively paste in the app to store something if the app is launched in the foreground (just like crude apps on a desktop would).
It wasn't offensive to the user before iOS changed the rules. It is just a technical detail behind a small feature.
Every app can do bad things. For example, every app with a password field can use that data to crack your account on others services. You shouldn't reuse passwords but we all know that too few people follow that rule.
If you installed an app from some company, it means that you trust it to some extent and with that in mind it is reasonable to think that the issue is innocious. If you think a company wants to steal your passwords, why did you install its app in the first place? Clipboard or not, it will find a way of doing bad things.
That almost makes the notifications useless.
Apple puts app developers through an annoying review process. It seems like the least they could do is check with the developer on why they want that access and see if its legit or not.
If your app is checking the clipboard or my location on a frequent basis, it's your job as the developer to communicate to me why you are doing this.
If the notifications are frustrating, users will turn off the permissions or remove the application entirely. Crappy snooping applications are gone. Mission accomplished.
Will they? That didn’t happen with the UAC dialogs in Windows.
If I find someone digging through my mailbox, I don't start rationalizing their reasons for it - I ask them to explain themselves, and that explanation had better fucking be a good one.
I copy passwords from a password vault. I don’t want your app knowing that I just opened Hacker News five seconds ago and have this password-looking text in the clipboard.
And just about every PM or founder I've ever worked with seems to think like this - when given the choice between the straightforward, obvious way to do something, and some crazy, brittle, privacy-abusing hack that might improve conversion by 5%, they'll choose the latter every time. This is a perfect example of this kind of thing, "let's just check the contents of the clipboard every 2 seconds in case the user doesn't know how to paste." It might have even been born out of real complaints from a fraction of users who really can't figure out how to paste. And somewhat depressingly, in the defense of PMs it does actually seem to work sometimes and improve conversions. And all your competitors are probably doing it already anyway. So the only way to stop this crap is for the platform itself to step in.
Another example that's also fixed in iOS 14 - Apple already provides a perfectly usable share sheet for choosing a photo, where I can look through my whole phone and pick just a single photo to give to the app. But for some crazy reason, seemingly every app wants to recreate this themselves. So they require you to give them access to your entire photo album so that they can display it back to you with a marginally different design and a different color background than the default page. Now in iOS 14, Apple is giving the user an option to just pick individual photos to share anyway, and then presumably make it appear to the app that those are all the photos you have on your phone.
Two very welcome improvements IMO.
I cannot think of a single good use case of a background app reading the clipboard like TikTok is doing in this link.
Now I am gleeful about this because it's win-win for me as a consumer and software engineer. Better privacy and use of my data as a consumer. More $$ work as an engineer when all those analytic pipelines need to be re-architected and rebuilt.
The way I see it, it's not a problem it's a responsibility. The problem was the lack of responsibility in the first place.
If TikTok is actually constantly loading the clipboard, that's obviously terrible. I'd bet this behavior is gone by the next release, and that shows how useful this new notification is.
Same issue with notes from that app's developer saying what's going on and how they will fix it: https://twitter.com/ecormany/status/1275903947899797505
People keep saying this but I've never seen one of these app-specific paste widgets. And even if I did, I wouldn't miss it in the slightest for the sake of not allowing every app to be reading my clipboard at all times.
It's inexcusable to me that there isn't a permissions prompt for this. Two of my most common types copy-pasted strings are URLs and passwords.
IIRC having an address (or address-looking string) in your clipboard will cause it to show up as the first result on the search screen in Google Maps.
As well as the “Address you copied” iOS Google Maps search field feature?
However, it seems like there should still be a way to provide nearly as much convenience to users while still protecting their privacy.
Here’s one:
The Google Translate app does.
Both pocket and instapaper will prompt if open with a link in your clipboard.
Several reddit clients as well, I’ve seen in on narwhal and the Apollo dev explicitly noted they do that in the corresponding Reddit thread.
I am a web developer, but I wasn't actually able to find information about whether this is a real risk or not last year when I began doing it. Can anybody clarify?
The workaround (for legitimate apps) is to simply always keep that "Paste" option enabled--even if the clipboard is empty. That way you won't freak out your users and only suffer the most minor of usability consequences.
Having said that I don't think TikTok has any relevant functionality such as enabling a "Paste" option so... Most likely nefarious!
https://developer.apple.com/documentation/uikit/uipasteboard...
Also iOS 14 has new clipboard related APIs to further check the content without actually accessing it.
The purpose of hasStrings was performance not indicating intent, so that wouldn't be surprising
Does pasting text into a video as an annotation require “Paste” to be enabled in this way?
Edit: This seems to be the app TikTok, not a website.
about:config -> dom.event.clipboardevents.enabled=false
https://bitwarden.com/help/article/setup-two-step-login-yubi...
With a Yubikey, the only thing you have to do to stay secure is to not lose it or let others use it.
It's easily testable, though, that a webpage that isn't focused (because an extension's pane is open) doesn't receive input events. Likewise, Chrome [1] and Firefox [2] extensions themselves cannot bind to relevant keys for example. All in all I would say that going through an empty tab is unnecessary - even though I got into the habit of doing it as well - and even if this wasn't true 2FA should be enough to thwart most malicious actors.
[1]: https://developer.chrome.com/extensions/commands [2]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
So if you care enough it's best to mitigate that risk by using the standalone application for your password manager, or better yet use a completely separate device like your phone!
If you really want to be safe, you should use the standalone desktop apps and skip the browser extension altogether. Doing that empty tab thing probably doesn't protect you from anything.
Chrome implements a "clipboard-read" permission that can be requested by calling navigator.clipboard.read(). When a page calls that it will display a permission request dialog (like those asking for permission to show notifications on seemingly every single news web page). A little clipboard icon will also appear in the nav bar showing the status of the permission (visible after a read attempt is made during that visit)
Firefox is apparently on track as well, although for now the clipboard.read function is not implemented for pages and can only be called by extensions. I'm not sure what the permission dialog for extensions is like.
https://developer.mozilla.org/en-US/docs/Web/API/Clipboard_A...
So... it may be safe. But it is a work in progress and each browser is different. I've only checked the most well-documented method for reading the clipboard... maybe there is some other half-implemented feature or event listener that happens to leak some clipboard data...
"TikTok wants to see what you've copied into your clipboard: Never, Once, Always, Uninstall that spyware".
Then I could make informed decisions, like sure, my package tracker can see if there's a FedEx URL in my clipboard. I'm OK with that. There's literally no reason why I'd ever want Instagram to check my clipboard, though. May you do, and you could give it permission.
A 10 square mile box.
I think this is due to the flame war or rating system of HN, where active discussions are relegated to oblivion. Instead of trusting biased and funded media - we here need to introspect, without us being silenced.
May be we are mostly left so we don't have a much stronger opinion unless its right - is that the case?. Just curious - why the slack?.
e.g. Time of stealing password from clipboard + time of my HN comment.
I've been long weary of this, android 10 has made some changes like allowing only IME & in-focus apps to access the clipboard. Not a fool-proof way to prevent the issue.
One more reason to destroy app duopoly, switch to pure Linux OS [1][2][3] and force app publishers to stick with web apps/PWA with more user control.
[1]https://store.pine64.org/product/pinephone-community-edition...
[2]https://postmarketos.org/blog/2020/06/15/pinephone-postmarke...
What is the use case for “read whatever was copied from anywhere for any reason at any time”? If there is one (e.g. full-fledged word processor maybe), that should still be a separate entitlement and require a higher bar, e.g. extensive app review.
Seems that iOS14 offers a specific new API to check if there's something on the clipboard without actually seeing it which is what all these apps are trying to do.
> Starting in iOS 10, the UIPasteboard class provides properties for directly checking whether specific data types are present on a pasteboard, described in Checking for Data Types on a Pasteboard. Use these properties, rather than attempting to read pasteboard data, to avoid causing the system to needlessly attempt to fetch data before it is needed or when the data might not be present.
https://developer.apple.com/documentation/uikit/uipasteboard
I suppose that the current scheme is that apps are monitoring paste events, and when it happens have a look at the clipboard for copied data.
Perhaps the clipboard shouldn't be visible at all, and only when the user decides to paste content should the targeted app receive a "paste" message with the copied data (or perhaps some more complicated selection mechanism with a list of recent copies à la emacs). This would essentially merge the 2 steps process outlined above into a single operation.
It's probably more complicated than that though.
We have developed a free Windows app and will release it soon.
This can be disabled by setting a preference: https://www.ghacks.net/2014/01/08/block-websites-reading-mod...
But I'm not sure if that's always been the case.
This is the beta process working exactly as it should.
You could also look at it as _what they had offered apps unlimited access to in the previous 13 OS versions_.
But at the same I can't help but be bitter. The smartphone scene is very active ever since, I don't know, 2011? All the companies and shady information dealers have gathered mountains of private information.
Is this not too little, too late? This would have been welcome at the iPhone 5 release. Nowadays I wonder what difference would these measures even make.
Those features would have been welcome a few years ago, that's for sure, but let's not blame them now that they do what's right.
What's out there is already out there, you're right, but we can hope that those shady information dealers will have much more trouble in the future.
I have the same impression. Which is saddening because I thought of going back part-time to Android and experiment with homelab builds and p2p architecture with a few spare Android devices. But I am not comfortable with how much and lower-level Google and the phone's vendor have and I am sure that no matter how I secure an app with access to photos/contacts/etc. then the kernel could likely still extract the info it needs... Don't know, but I am quite paranoid about smartphones lately.
> let's not blame them now that they do what's right.
Agreed. Better late than never. I simply feel that marketing trumps privacy concerns here. Apple wants to have what to brag about every year so features that should come once every 2-3 months are coming annually instead.
I'm not sure how the Google Maps app can do this without snooping at my clipboard.
Of course it's still possible to check the clipboard when the app receives focus, just like on iOS.
https://www.military.com/daily-news/2019/12/30/army-follows-...
"Why was TikTok banned?"
"Because the violated the basic capitalistic principal of existing not to make money but to amass a Nazi-like ledger/database of every person in the world on behalf of a nation state."
That new technical solution in the beta certainly comes handy, but legislation is better.
I'd be in favor of banning application-initiated access entirely. I realize this would interfere with 1PW and similar. That was always a hack, and the fact that so many apps snoop on the clipboard is a great reason for it to stop! Sensitive dataflows for things like passwords need far better protection.
There is a part of me that is little sad Apple did not just wait to add this feature until iOS 14 released or one of the last GM's.
If only because it would be a huge wakeup call for users about what their apps are doing and possibly collecting, instead of it all being patched out now. Instead we are seeing basically no traction on this outside of tech circles.
https://news.ycombinator.com/item?id=21383241
Happy to see it's going mainstream. I'm hopeful that iOS 14 will provide a way to limit this behavior on a per-app basis.
https://community.signalusers.org/t/ios-14-catches-apps-spyi...
https://www.forbes.com/sites/zakdoffman/2020/03/12/simple-ap...
Or some other evil purposes.
People need to learn to stop trusting these apps.
They could even collude behind the scenes, once they’ve communicated over the clipboard as a channel to establish a link, to replace the original data in the clipboEOF[CITIZEN:8EF7720=FLAGGED]
Is it all done locally?
It can be an elegant design choice, but also a design choice that appears to be or is an abuse of privacy.
https://developer.apple.com/documentation/uikit/uipasteboard...
For decades, all programs running on your computer had access to the clipboard. A primary intended purpose of the clipboard is precisely to share information between different programs. Maybe it is in fact a security issue that should be rethought, but calling it an abuse of privacy seems extreme.
Absolutely not, this was a terrible decision to begin with. Users copy sensitive things to the clipboard all the time.
I use a password manager on my iPhone and I am copying and pasting my passwords all the time. If some random app is scraping my clipboard silently and sending the data to a third party, that means my passwords are compromised. I am very much NOT OK WITH THIS.
Keep in mind, this permission should be fundamentally different than the permissions for just manually copying and pasting. I don't want to have to deal with permissions to "allow clipboard use" that I have to approve every time I want to paste something. That would be obnoxious. I am only worried about restricting permissions for invisible passive snooping.
It sounds like this feature is working as intended - closing was was a silent security risk.
tl;dr: Since Apple doesn't give a way to open URLs in 3rd party apps, he inspects the paste buffer for reddit URLs, but he aptly points out that he could read anything in the paste buffer if he wanted to:
"Hey! I make Apollo for Reddit and a few people asked me about this and if Apollo does anything with the clipboard so I wanted to answer.
Since iOS doesn't have a mechanism to open URLs in a specific third party app Apollo has a feature where if you open the app with a Reddit URL on your clipboard it'll offer to open that URL in Apollo, I think I copied this from Instapaper awhile ago. This does cause a potentially creepy looking notification with Apollo sometimes, but just wanted to explain why/what it's doing. It's literally just like "Hey iOS, is there a URL on the clipboard? Oh there is, is it a Reddit one? Okay cool let me ask them if they want to open it." Obviously at no point does anything else happen like it leaving the device or anything. It'll show this banner even if there's not a Reddit URL because it needs to check the URL to see if it's a Reddit URL in the first place. Schrodinger's Reddit URL.
But the clipboard API (prior to iOS 14) was very open, as someone else said, what if medical records were on your clipboard as text? Well in Apollo's case, that doesn't qualify it as a URL, so it wouldn't even "look". (And even for URLs, it doesn't store a list of them even on the device, it just opens it if you ask to, and then saves the most recent URL so it won't keep repeatedly prompting you if you say no.)
But that doesn't mean other apps couldn't be! They could be doing some Creepy Shit™ so I think this API change is good. It means I'll have to be more clear with Apollo doing this, and I've already had a few Apple engineers reach out with ways, but I think it's a very good change for user security."
From: https://old.reddit.com/r/apple/comments/hejb9i/ios14_catches...
It's possible that TikTok isn't doing anything and this is a bug, but it's more likely they're using the clipboard in a way they shouldn't.
How are we supposed to know if the app's continuous request for clipboard access is ok or not?
I feel like that was literally the only value-add in the App Store review process and the fact that its a feature in iOS seems to indicate that Apple is throwing in the towel here and saying "we don't know if this is a privacy issue or not so we will just notify you about it".
Why do members of our own society not know the negative effects of using this technology?
WE as society cannot allow this impunity that is occurring by a very well powerful corporation, a nation-state sponsored Corporation, no less. Where does it end? Why do we allow this to occur? Why do members of our own society not know the perils of using this technology?
No, not because we're communists. Rather, this is an existential issue for HN: if we want to have a forum for curious conversation, we have to limit the amount of damage people can inflict on it in this way.
Please don't create accounts to break HN's guidelines with.