LinkedIn sued over allegation it secretly reads Apple users' clipboard content
reuters.com
reuters.com
there's plenty Android sketch/mind mapping apps for example that require access to storage, for saving and exchanging media, and the is doesn't allow for "allow access to some folder without giving them access to everything" and it's annoying
most permissions actually should have that kind of don't allow global access without breaking the app functionality or even telling the app itself
Technically they could probably be implemented the same way and the "manual" action is actually just granting the programmatic permission to the keyboard app.
It could work if windows had a copy paste api with levels of access and trusted the apps to honor the access level. Then the browser could tell windows if a user clicked paste or if a website did.
At jobs I've literally copy PHI all over the place for data processing.
Copy and paste is vital and often top secret.
Technically, any application (at least any application that lives in the system tray) can take screenshots of the whole screen as often as it likes. You can probably imagine it doesn't even need to store it on disk. It could just do some quick computation and send it to whoever.
1. I care a lot: I want to be asked every single time whether I approve of my clipboard getting read.
2. I care a moderate amount: ask me the first time an app tries it, then stop asking me for a while.
3. I don't care: let apps do whatever they want. I'll let other people worry about my security.
(albeit phrased more diplomatically, of course)
This will be news to pretty much every clipboard implementation that exists, considering that they all rely on programmatic access.
Copying and pasting aren't magic opaque syscalls, they're things that programs implement (or rely on a common library to implement).
Perhaps this could be the default way of interacting with the clipboard, and then apps that want to be able to read it a different way (e.g. Google Chrome wanting to be able to offer you a "Go To Link You Copied" button) could request an additional permission.
[1]: https://cdn4syt-solveyourtech.netdna-ssl.com/wp-content/uplo...
Putting apps copying clipboard up in your face is one such solution and it seems to be highlighting the abusers, no?
Even if an app has a genuine need to copy clipboard, having it in front of user every time will be useful.
Paste and go isn’t a feature worth sacrificing the privacy of your clipboard contents
Terminal emulators, not sure to be honest. Why not stick to traditional cut and paste shortcuts?
Photo editors: nobody said you need a text box to paste to. Set your UI element as “pasteable” or whatever’s needed and let the app handle whatever clipboard contents comes it’s way. If it’s not supported it gets ignored.
So there's no difference between an app directly retrieving data from the pasteboard and you hitting the paste button. The message about the app retrieving from the pasteboard still appears if you hit the paste button.
It would likely need to be moved out to an IPC call to make this possible.
Imagine if you were writing an email to a close friend, about looking for a new job because you think your boss is incompetent. You copy and paste it for some reason (reformatting, whatever).
You do not want that to be seen by a job network site that has you connected to your boss.
Facebook’s SDK’s which are embedded in more than 30-40% of all Android apps also scan the users internal network and also uses Bluetooth looking for devices nearby.
I was shocked to discover that more than half of the third party apps I had installed had Facebook’s software embedded in them.
So far I've found: Spotify Tinder Yelp Duolingo
Explanation from LinkedIn and the actual (open-sourced) code in question linked in the top comment: https://news.ycombinator.com/item?id=23719995
That explanation seems plausible to me, and would imply that there is no spying going on there.
That's the last paragraph, which probably should have been stated sooner. The timeout issue could be a mistake, but if not it seems to support the spying theory.
I can't think of any laws that would ban applications from accessing information as provided by the operating system.
Can’t think of anything else
1) I go to a site and it auto fills the login. Not sure when clipboard needs to be involved there. Shouldn’t that just be the application taking data from its database, recognizing the associated form, and filling it?
2) I search for a login manually and copy to clipboard. In that case I’d only ever want it to paste when I issue a paste command manually
- read clipboard
- write password into clipboard
- restore clipboard after X seconds
For example, if the implemented functionality is attempting to make a "temporarily store password in clipboard" feature and implementing it by "reading from clipboard/writing to clipboard/restore clipboard contents after N seconds", there should instead be an atomic "store data in clipboard temporarily" feature.
"The user initiates a paste command manually" is a requirement that may be trivial for a human to express but near impossible for software to implement.
What? No.
Sure, there would be changes required, but both Android and iOS could support this pretty easily IMO.
"There would be changes required" is a very euphemistic way to phrase what would basically be banning all apps that don't use the high-level views in the OS SDK from having clipboard functionality. Funnily enough, if Apple were to come out tomorrow and say "we're removing the ability to cut, copy and paste from any and all apps that don't use UIKit" this website would have a field day tearing them to shreds and smugly posting about "walled gardens".
Convenience, freedom, security. Pick two.
https://www.reddit.com/r/apple/comments/hejb9i/ios14_catches...
As a developer and as a user: don't put things in the general/system clipboard if they're truly sensitive/secret. Developers especially really should be promoting the use of named and/or private clipboards (and of the share sheet in Android and iOS).
Like I have already said,
>> Developers especially really should be promoting the use of named and/or private clipboards (and of the share sheet in Android and iOS).
And for the specific case of a password manager, iOS offers Password Autofill integrations. It's not the OS's fault if developers are too lazy to use the right tools for the right job.
Yes, it does - see the section very literally titled "Integrate a Password Management App with Password AutoFill" at https://developer.apple.com/documentation/security/password_....
But again, many devs don't actually keep up with and/or look up the proper way to do things on the platform they're deploying on.
> and there is no unified service that Apple offers for web and desktop and works across OS and multiple browsers
Apple has a duty to its own software. Why exactly is the onus on Apple to offer a magical grand unified service instead of on third party software developers to actually take the time to study and use the appropriate tools on each platform they want to deploy on?
If you want things to be secure you generally have to put in the work for it. 1Password spends resources building & maintaining browser extensions to integrate directly with input fields - why doesn't your password manager of choice offer similar? As a developer one could use named and/or private clipboards to actually have control over when and how the data their users clip is accessed - why not do that over complaining that a shared, global buffer that applications can access programmatically by design is, while convenient, also not exactly the most secure way to transmit sensitive data?
Even Firefox Focus, considered to be a "privacy-focused" browser, has this notification pop up every time you add a character to their address/search bar.
This isn't about privacy. It's a money grab by lawyers.