If you’re using a password-manager (like we’re supposed to!) and use it to copy passwords (say, your Amazon employee internal credentials...) while you have TikTok open, the TikTok app would see it and could upload it somewhere.
...and we only know about this issue now because iOS 14 adds clipboard snooping notifications - and that was only a month ago! Think about the stuff that the app could be doing that we don’t yet know about.
There’s too many bloody-obvious security vulnerabilities that are decades old but don’t get fixed until they either become a meme (like SQL Injection) or the platform vendor does something about it (iOS 14 clipboard notifications) - and don’t forget that the SIGINT community is sitting on millions of dollars worth of zero-days that they won’t disclose to vendors unless they feel like it - so I fully expect there to be more surprises in TikTok - and other apps - in the years to come - probably indefinitely.
Not trying to derail this via whataboutism, I just feel like the core HN ethos is lost when we mindlessly repeat the obvious geopolitically-driven narrative here without any critical thinking.
What I definitely do understand is Amazon's concerns with just the base level of data collection that's seemingly the norm in our industry. Which prompts the quesiton, why are we comfortable as a society with this sort of collection, by anyone?
[1] https://www.businessinsider.com/apple-ios-14-catches-reddit-...
Here's a rundown of just general apps that would be on everyone's home screens doing the same thing.
Really Apple should take a stand and give all of them 30 days to fix their apps or get banned.
But TikTok annoyed me in particular for a long time. Nothing to do with geopolitics, I already hated it before I knew it was owned by China and everyone started banning it.
It was just that for the past months every time someone forwarded me a stupid video I was supposed to like, it had a TikTok logo on it. So in my view this became the source of "stupid videos people bother me with". Not exactly a charming quality.
Especially with the lockdown it became extra annoying, every day I got multiple stupid lockdown videos and the ones with people doing stupid stuff and then the coffin dancers thing.
So that's my personal reason for hating on TikTok. The privacy revelations just sealed the deal. Not saying it's a valid reason for everybody but it's my reason :P
This quote comes to mind:
> I used to be with ‘it’, but then they changed what ‘it’ was. Now what I’m with isn’t ‘it’ anymore and what’s ‘it’ seems weird and scary. It’ll happen to you!
But TikTok associates itself by putting their logo on the videos which is something I haven't seen before.
Woooooooorrrrld staaaaaaaar
Also if you ever see a 7 second vertical video, sleep well knowing you just watched a Vine (not really a logo, but association all the same)
It's just content watermarking.
Watermarking is essential to preserve your brand online. I assume you remember eBaumsWorld - and how they put their watermark and footer on all image-content that they rehosted: because those images would appear verbatim in FW:FW:FW... chain emails and shared over AIM,YIM,MSN,IRC, etc.
Back in the day, eBaumsWorld and others were criticized for putting their watermark on content that they rehosted, especially when they didn't own, produce, or commission that content. At least the vast majority of the content on TikTok was directly uploaded to it, and TikTok's watermark includes the username of the relevant account.
Their animated logo is obnoxious and distracting - but when I compare it to the DOGs on American TV news channels it isn't so bad, it's actually unobtrusive in comparison.
Thirty days later the show of brinkmanship ends up with a bunch of iPhone users unhappy that half of their favorite apps work.
This wouldn't be as big an issue if the PRC was a NATO ally, or least had a reputation for government transparency and accountability - and wasn't asserting ridiculous territorial claims - and didn't have an egregious human-rights record - and wasn't actively suppressing freedom-of-expression - and so on. Take away a couple of these issues and TikTok's suspicious business conduct over the past few years would be about the same level as scummy American Freemium game makers. I stress that (and despite appearances) I'm trying not to make a Sinophobic argument.
At the same time, I recognize that companies in China need to integrate themselves with the CCP/PLA/etc in order to succeed in that market.
What are other companies? Those that doesn't pose a threat? like those ones only produce cheap toys and clothes?. I think as long as Chinese government remain as independent and "different", anything comes out of there that really challenges current status quo would receive similar criticism like yours, regardless what or how those company behaves. Curious how do you recognize those companies "need to integrate themselves with the CCP/PLA/etc"?
Your password should never be in your clipboard at least with iOS. If you’re using either the native password manager or a third party password manager, the password manager is directly integrated with the keyboard and would auto fill into your app.
https://techcrunch.com/2018/06/05/password-autofill-in-ios-1...
The ones that particularly annoy me are the ones that haven't updated to the new Android biometric API versus just supporting the old fingerprint API. I'm looking at you Chase mobile app.
The other is the way they hide what they're doing so elaborately.
I wouldn't call it a national security concern, no. Someone who works with critical or military infrastructure should have a locked-down phone anyway for work stuff.
But really I wonder how this kind of stuff is OK in the eyes of Apple with their self-proclaimed privacy focus. I'm pretty sure if I were to submit an app that does all this, it'll be rejected right away. Popularity seems to overrule that.
I suspect you’re right and would be very interested in the results of this experiment if you (or anyone else) happen to undertake it.
We found out other apps too (like LinkedIn) constantly check the clipboard, and one HN commenter here said it was due to a text editing library, nothing intentional.
Literally the only fact is that it's a Chinese company.
And it's not like there's even much it seems like they could do, with how sandboxed phone apps are. I'm not saying iOS or Android are perfectly secure, but it't totally different from installing something on your desktop with root permissions.
Either it's just generic hate for China that's bizarrely gone viral, or else it's a story intentionally being pushed by the US government for god-only-knows what political reason, like leverage in trade negotiations or something.
But it's completely weird, and nobody should be taking it at face value.
https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
https://penetrum.com/tiktok/tiktok_15.2.3_static_analysis.pd...
Things they found - Excessive data collection - Privacy policies that allow distribution of said data - Execution of OS commands - Insecure cryptography usage - Potential SQL injection code from user defined variables - Storing of API tokens - Webview enabled by default along with insecure webview enabled
Other social networking and entertainment apps are crammed full of tracking code, analytics, advertising networks, that all collect excessive user data, don't put it in their privacy policies, etc. And similarly, we hear about bad use of cryptography and SQL all the time.
Apps can be pretty bad in general with these things.
Now obviously, apps and code in general should be improved.
But the question here is, is TikTok really that much worse? That it's such a worse threat than others, that it needs to be banned? Because that's what I still don't see evidence of.
The issue for me is where the data is going and who has control of it. A quote from the article about TikTok trending today (https://news.ycombinator.com/item?id=23832183)
All Chinese Internet companies are compelled by the country’s National Intelligence Law to turn over any and all data that the government demands, and that power is not limited by China’s borders. Moreover, this requisition of data is not subject to warrants or courts, as is the case with U.S. government requests for data from Facebook or any other entity;
https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
https://penetrum.com/tiktok/tiktok_15.2.3_static_analysis.pd...
Things they found - Excessive data collection - Privacy policies that allow distribution of said data - Execution of OS commands - Insecure cryptography usage - Potential SQL injection code from user defined variables - Storing of API tokens - Webview enabled by default along with insecure webview enabled - App copies data to clipboard. Sensitive data should not be copied to clipboard as other applications can access it. - Files may contain hardcoded informations like usernames, passwords, keys etc.