Reddit and LinkedIn apps also caught copying and pasting clipboard contents
privateinternetaccess.com
privateinternetaccess.com
The incessant “install our app” messages on Reddit are a major turn off and one of the reasons I use Reddit so little. There’s no reason Reddit can’t work just fine in a browser. The only reason to encourage the app so much is if it benefits Reddit. At that point our relationship becomes adversarial and there’s no reason to continue.
Nothing here is surprising. The app was clearly user hostile and doing something nasty, now we just know what it was doing.
It's actually still so much better to pinch and zoom on the old site. The new one is super janky and totally broken on mobile. The app is just a pain to use anyway.
https://addons.mozilla.org/en-CA/firefox/addon/old-reddit-re...
https://chrome.google.com/webstore/detail/old-reddit-redirec...
This whole obsession with reducing information density and making more space for ads and huge 'cards' or pictures is pretty much a UX anti-pattern as far as I'm concerned. It's like how 'minimalism' is considered a rich-person's hobby because everything's spacious and clean, rather than small and cosy. Web minimalism takes up more space to do less, while tending to cost a lot more in terms of bandwidth used.
Plus when I share a link with friends/coworkers I know with old.reddit.com urls I'm not going to be sending them to the clunky new version, if they don't happen to be logged in or have the right settings. And I've been asked how they too can use old version multiple times already.
We all left Digg back in the day for Reddit for much the same reasons. And I'm usually a big proponent of modern JS frontends, assuming it's done carefully and performance-first. Reddit, like online newspapers, should be as simple as possible IMO. Like AMP minus Google.
Mobile friendly, with Firefox extensions to auto-redirect on Android
On Reddit, on my opinion it seems how bad the page looks on mobile is on purpose (Compared to, say, HN).
Besides that, I don't understand how clipboard access is not something the apps should ask permission for (And be able to work without it, obviously).
Finally, considering the obvious use the clipboard has, there should be some sort of "this time only" permission possible.
There is something wrong with sharing that information anywhere else - which should result in a permanent revocation of the dev cert for the organization that has produced it, as should any type of telemetry (spyware, as we called it in the old days).
That's why most of the modern web service must provide the brainless apps that is just a wrapper of the browser. Otherwise, people use whatever random garbage app they found at the app store that contains the service name and believe that is the web service you provide.
It is my opinion that smartphone makes people dumb. Or maybe it's reverse so the smartphone allow even the dumb people get access to the computer and the Internet.
Your post is interesting because I never thought about reddit's poor mobile user experience bouncing people, I think of it is as just one implementation of their API and the content is still fire
Is it some kind of wildcard cert that covers the entire internet? I'd have to research what it would break, and the security ramifications. Probably not worth it :(
Yeah, you'd set up a new CA.
> I'd have to research what it would break
Initially, anything using HPKP will break, and any apps doing cert pinning will break. It's probably not worth it.
1) A common UX pattern to detect relevant clipboard links in the app (e.g. open a reddit link automatically) -- many apps do this type of thing (e.g. Photoshop will use the dimensions of a clipboard image when creating a new image), but nobody's pointed out specific such functionality in LinkedIn (or reddit)
2) A third-party library (analytics, advertising) which does this automatically, which the app developers (LinkedIn, Reddit, etc.) weren't even aware of. If so, why though -- is there some particular analytics, tracking or fingerprinting reason? I'm having a hard time thinking of any particularly good one
3) Something else, like a common text editor library that checks the clipboard by default for some legitimate reason like preparing for formatting, images, etc., that is maybe just lazily coded (checking clipboard on every keystroke, rather than just a paste command)
I'm just curious if anyone has facts. Because there's a world of difference between good intent, questionable intent, bad intent, and lazy intent.
also looking at what they were trying to do in the first place -- check if contents was pasted... and whether the text would be autocorrected?! -- it all looks to me like apple has a bad, or not well understood, clipboard API.
apple needs to set guidelines around the clipboard API.
[1] https://github.com/firebase/firebase-ios-sdk/blob/c8625ec52e...
For example: "Did they honestly make this mistake or were they planning to use that innocuous framework call to implement clipboard-theft?" cannot be proven to be "honest" as a lack of evidence of dishonesty will be interpreted by doubters as "we haven't found the evidence of dishonesty yet". There are no facts that can usefully satisfy this question.
It would speak highly of LinkedIn, though, if they were to announce that they've also evaluated their Android app (where this warning is absent) and identified and removed code there as well. But that, itself, is no proof of either honest or dishonest intentions, any more than any other facts will be.
Seriously. Stop.
Apps allow far deeper and richer access to various data structures than what should be allowed; this has been proven time and again since mobile OS existed, I think both Apple and Google are to blame for ever allowing developers to freely access whatever they wanted, whenever they wanted, to upload it to any server, without any transparency or oversight (and that's a huge problem on Android, still).
If you can, use the browser (the new Firefox for Android is quite good), which at least limits your exposure to these third parties accessing information they should not.
old.reddit works okay in the browser, I am not so sure about LinkedIn as I don't use it. These days I just rely on using TOR for things like email, Protonmail has a .onion address which is a nice bonus.
I carry very few apps on my device, and I make an effort to exclusively use those found on f-droid, open source, not many permissions.
It's the biggest perk of Android; you can use any store you like, and most APKs install absolutely fine. Disable Play Services and various other tweaks and you're okay.
Traceable but not the kind of access an app has. Traceability can be spoofed not the data that app is reading from your device. No website is ever going to ask your contacts permission to proceed further while their are tonne of apps that won't let you use app if you reject that permission.
For example, GPay in India needs freaking location permission. God knows what it does with that data.
My point isn't that either apps or the Web are better. It's a more fundamental issue of software I use constantly talking to systems I don't control. It just so happens that the Web only exists if I accept that this will happen. Applications can exist even if I don't.
Sure, you still have to deal with tracking cookies and the like, but this a tiny amount of pain compared to what a full native app could do to you without your awareness. Wiping the slate with a web browser is a fairly trivial exercise too.
Progressive web applications are the best and brightest future we have. I can only hope that some sort of antitrust shake-up forces vendors like Apple to fully-embrace PWAs and other such alternatives. When looking at the technical specifications, there isn't a whole lot of good reasoning for requiring native apps outside of exclusivity and control over their ecosystem.
I never updated stock Droid OS on my 2017 phone. I disabled most google incl Google Play, Gmail, yet the system does not let me disable PLAY Services
How do you disable play services?
Plus then you wouldn't need to give apple 30% of your money, and spend hundreds or thousands of dollars on an Apple product, and pay for their dev kit.
"Win win win"
The web would have won were it not for Apple's insurmountable power.
We have to break Apple and Google up or force them to make a first-class application marketplace they don't control and don't tax.
Then again, take a look at your desktop/laptop OS, and by comparison mobile devices are almost fortress-like in their protections. We're still using security models based on the threats of several decades ago, with barely any attempt made by any of the major desktop OSes to develop a suitable defence to the biggest threats of 2020.
The real problem here, IMNSHO, is that most users don't take privacy and security seriously, which in turn is at least partly because most users lack even rudimentary understanding of what is happening and what could be done about it. Almost everyone suddenly has a life full of small, somewhat independent devices with significant computing power, sensors, and external connectivity. Even people who choose not to use such devices themselves will still find themselves affected by this technology because so many other people around them do use it, so unless you're willing to become some sort of modern-day hermit, you can't entirely escape the trap.
But until public awareness is increased, until these issues start becoming a matter of real competition and hitting inferior product developers in their quarterly results, until there is enough concern over the more serious abuses for politicians to learn about these issues properly themselves and legislate or regulate accordingly, trying to stay off as many radars as we can is sadly the only realistic strategy. You can avoid installing untrusted software on your computers and putting IoT devices in your home, and that's a significant improvement, but it's still far from ideal.
If you think in terms of who the paying customers were/are for desktop OSes (by-and-large, corporations and governments), the "threats of several decades ago" were—and continue to be—real threats to them (vis. industrial espionage/cyberwar); whereas the modern "threats" aren't things that threaten their interests at all, "only" things that affect the lives of individuals. A corporation won't lose money because a rival knows everything about its employees shopping habits.
Insofar as nobody's currently making money selling a desktop OS to consumers (Microsoft sells cloud with the OS as a loss-leader; Apple sells the hardware with the OS as a cost-center; and RedHat, Canonical, VMWare, etc. only make money from enterprise support) there's nobody incentivized to protect the wellbeing of individual customers on the desktop.
This looks like the root cause of the problem, except that in reality users are still paying for their OSes in many cases, it's just bundled in with the cost of the equipment and they don't see it as a separate line item.
However, given the huge barrier to entry for any new competitor, not only in building a better OS but also in developing the ecosystem around it, I am increasingly sceptical that this offers a realistic route out of the current hole we find ourselves in, at least not any time soon. That's why I favour better public education, and ultimately relying on competitive and/or statutory forces to push developers in a healthier (for customers/society) direction.
Not saying they should do that (probably should be a one-time "open link from clipboard" button instead).
Why? What is the reason for doing that check?
I've no idea if that is remotely valid as an excuse.
In 2020 it's still not a given that we should be allowed to review and read shit that's running on our machines, to at least check this kind of things. It's okay to be surrounded with black boxes everywhere that one cannot study if they wanted to.
It's still not considered as a disrespectful and weird practice to not provide the source code with software being distributed. And people are not told they should expect software to come with everything possible to inspect what it does, to the community or themself can review it.
If someone is not providing the source code because they fear that something bad will be discovered about it, or that the user will change something to better fit their needs, well something is wrong and is working against the user, especially if the software is gratis anyway. Providing source code could allow users to remove ads? Right, downloading, running and looking at ads is not something many users want to do, even if you consider that ads are legitimate.
Give me the code already or I won't run your software because I can trust you on doing the right things and on fully help me out, otherwise you would not have problem providing the code.
A case could be made for paid apps: obviously, making the code available could endanger the business model. But at the end of the day, the community and I cannot check that the app isn't doing anything shady if it is sold without its source code.
Would I mind if an open source app read my clipboard content? No, because I can check that it's doing something useful for me. These useful features are simply not available to proprietary software without the risk of feeling creepy.
Have you noticed how we are mistrustful against our everyday apps and relying operating system developers to cover our asses with complicated permission systems to compensate? This feel this is very wrong, doesn't it?
(permission systems would be also useful in a world where every think is open source, though, that would be a defense against attacks. But that would not be a defense against legitimate software!)
It still works.
To view 【US $21.83 40% Off | 10 Pcs KN95 Face Masks Dust Respirator KN95 Mouth Masks Adaptable Against Pollution Breathable Mask Filter (not for medical use)】 on AliExpress with code #_qsrSbGW#, copy the whole sentence and open the app.