9 ms·
I'm disappointed that so many people think "hey they could just be doing this for innocuous reasons" instead of "oh maybe nobody should be doing this even if it
by patrickyeon 6y ago
I'm disappointed that so many people think "hey they could just be doing this for innocuous reasons" instead of "oh maybe nobody should be doing this even if it's the absolutely most straightforward way to do it."
Even if you're only looking for a shipping tracking number and then only so that you can provide useful auto-populate, will you lose out by only checking the clipboard when the user hits your text input field? Is it that much to ask that you find the least offensive way to serve your user?
On the other hand, what will you lose when the news gets out that you've created a keylogger? What about when someone else at your company pushes you to monitor for something else for strategic advantages? Or what about when another developer doesn't understand the implications and now your app is responsible for revealing passwords or other sensitive information? Are all of these worth saving one click?
- greggman3 6y agoThis is a OS bug not an app bug. You can't expect millions of app developers to get this right. An app should not be allowed to read the clipboard until a user chooses to "paste". That's on the OS for allowing this behavior. It's silly to think that making it possible to read the clipboard at any time that some how all millions of app developers will use it correctly even if they have no malicious intent.
- 013a 6y agoA high speed collision happens on a freeway, killing both drivers. This is a car manufacturer bug, not a human bug. You can't expect millions of drivers to get driving right. A car should not be allowed to drive fast. How about: stop apologizing for billion dollar corporations. Fault can be placed on both the OS and applications. I expect better, from everyone.
- greggman3 6y agoThe difference is one problem is trivially solvable. If an app isn't allowed to read the clipboard the problem is solved. Smart people choose solutions that actually solve the issue when those solutions exist rather than just making some guideline and praying people read it.
- jamaicahest 6y agoCompanies developing apps should be held accountable for their decisions, i.e. spying on the clipboard in this case. Don't excuse them with the reason "well it was easy to do, so it's ok" that's like saying "well my car was stolen, but it was easy to break the lock so it's ok"
- kkarakk 6y agoBy this logic, how do you trust Apple? they're a famously blackbox company with access to all your data. just because they say they're not data mining you, doesn't mean they are not. slippery slope arguments go all the way to the bottom
- IshKebab 6y agoAre you really suggesting that cars have never had bugs that cause crashes?
- AnonC 6y ago> An app should not be allowed to read the clipboard until a user chooses to "paste". Sounds good. There are clipboard apps on iOS that work with a share sheet and also get the clipboard content when launched. They could be modified to have the user actively paste in the app to store something if the app is launched in the foreground (just like crude apps on a desktop would).
- cbsmith 6y agoI'm not sure that looking at what a user is typing into the comment box for the application really qualifies as a significant privacy violation. That presumes a privacy model that isn't terribly intuitive or practical. Now, if they had evidence that the data from the keyboard was being sent up to a server, that'd be a different story.
- patrickyeon 6y agoIn this case we're talking about apps monitoring the copy buffer when they aren't foregrounded. Your example of monitoring a comment box isn't what we're discussing. In the copy buffer example, I think a privacy model of "an app in the background can't read what I'm copy-pasting in other apps" seems very reasonable and fits my idea of what a "standard user" would expect. Personally, I would prefer a world where nothing can pull from the copy buffer, it needs to be actively pushed by the user. It seems crazy to me that that isn't the case.
- bredren 6y agoI agree. I am very surprised Apple started with a notification. This absolutely should be permission based like location or anything else. There are zero cases where TikTok or facebook should need my clipboard. A notification that they’ve already done it is not enough. It should tell you every time even if you approved it. The only explanation I can come up with for why Apple isn’t making this opt in like location is it is so widespread it would break many apps. I just can’t understand how, or why they wouldn’t announce a transition-by date like with Sign in by Apple.
- bredren 6y agoI agree. I am very surprised Apple started with a notification. This absolutely should be permission based like location or anything else. There are zero cases where TikTok or facebook should need my clipboard. A notification that they’ve already done it is not enough. It should tell you every time even if you approved it. The only explanation I can come up with for why Apple isn’t making this opt in like location is it is so widespread it would break many apps. I just can’t understand how, or why they wouldn’t announce a transition-by date like with Sign in with Apple.
- untog 6y ago> Is it that much to ask that you find the least offensive way to serve your user? Up until now there’s been no way the user has been offended because they haven’t known it’s happening. So there’s no real incentive to do it when you focus on a text field vs anything else. And more broadly, there isn’t a downside if you use the API honestly: e.g. to check for a numeric code that matches whatever regex for one of your orders and otherwise disregard the data immediately. I’d bet a good number of users find it useful.
- patrickyeon 6y ago"The OS snitching on us and then annoying the user" is an interesting definition of "offensive", but definitely not the one I meant. Let me put it another way: if you put the appropriate amount of effort into asking "what's the robust, minimally invasive, least-likely to be misinterpreted and/or abused, way for me to accomplish this?" you are likely to create a better product and less likely to have something like this pop up. So let's say you're making the tracking notifier, and you work for UPS. The regex is `1Z[0-9]{16}`. All good, you're being nice, someone opens your app and you already know what shipment they're interested in. Then a "growth hacker" joins your group and mentions that it'd be nice to know how many of your customers also use FedEx, so the regex is changed to also grab FedEx tracking numbers (`(1Z)?[0-9]{16}`, I think). And now someone gets the genius idea of checking up on package shipped by competitors and popping up a notification "tired of waiting on DHL? UPS delivers within 2 days 99.995% of the time" when they miss a delivery. Even though they never asked UPS abotu their DHL package. See how that progresses? See how it's offensive, even if you're not annoying your user more than you normally would with spammy push notifications, and even before your user suspects that you're spying like this? Do you see how this whole series of escalations aren't available, or at least not as easy, if you only check the copy buffer when it's likely a user is about to paste? Instead of "tweak what we already have" you have to "include a new snooping routine". If you're thinking "all is fair in love and war" here, and this seems like genius marketing: 1) this is your heads up that your morals are not in line with society's, and 2) do you think this will be a marketing win if the regex is loosened enough that you pop up a UPS notification about "package with tracking number (phone number someone just gave me)"? What about if my UPS account for work notifies me about some very private personal packages? Especially some shipped via OnTrak? Anyway, as I said in my first comment. I'm disappointed that people don't think they should try to worry about downsides and failure modes of their design and engineering work. Maybe it's a matter of norms and priorities being different in the consumer app/web world vs. many other domains.
- CGamesPlay 6y ago>will you lose out by only checking the clipboard when the user hits your text input field? Is it that much to ask that you find the least offensive way to serve your user? In your toy example of my app's main screen being a text box where the user can insert a tracking code, yes, I do lose by making the user wonder every time "you know I have a tracking code why are you making me type it in?" In a more realistic example of, say, Amazon, where the "track my previous order" button is not the main screen of the app, the convenience is further increased by doing the detection automatically. And what about non-text clipboard contents? Not every interface is a text-style document into which content can be embedded. Even "Copy URL" requires knowing that "share website" shared a URL and not a website. It doesn't make sense for images at all.
- manicdee 6y agoClearly there needs to be a way for the parcel tracking app to tell the OS, “I am looking for plain text strings that match this pattern.” Which iOS and macOS already have, they are called data detectors. When the message arrives notifying you of the tracking number, you can select “track this parcel” from the context menu. No need for an app to snoop on the clipboard.
- jurip 6y agoI know what data detectors are, but I most certainly don't get any such tracking option for any of my messages containing tracking codes. I still need to copy those codes into Parcel, and find the automatic pasteboard reading useful. And UIPasteboard doesn't offer such an API, AFAICT.
- patrickyeon 6y agoI'm not an iOS developer, but I think "Sharing and Actions" [0] is the right thing? In Android, 5 years or whatever ago it was by binding to an "Intent" IIRC. If I copy a link on Android, I can go to Chrome, click on the address bar, and it suggests "link you copied: $whatever". This is how this should work. If there's an image in my copy buffer, it doesn't need to do anything. I don't need Chrome monitoring my copy buffer when I'm doing other things in case I copy something that looks link-like. [0] https://developer.apple.com/design/human-interface-guidelines/ios/extensions/sharing-and-actions/ https://developer.apple.com/design/human-interface-guideline...
- GuB-42 6y agoWhy shouldn't apps use the API they are provided with? It wasn't offensive to the user before iOS changed the rules. It is just a technical detail behind a small feature. Every app can do bad things. For example, every app with a password field can use that data to crack your account on others services. You shouldn't reuse passwords but we all know that too few people follow that rule. If you installed an app from some company, it means that you trust it to some extent and with that in mind it is reasonable to think that the issue is innocious. If you think a company wants to steal your passwords, why did you install its app in the first place? Clipboard or not, it will find a way of doing bad things.
- statictype 6y agoWell, the problem is we don't know why they are using it. That almost makes the notifications useless. Apple puts app developers through an annoying review process. It seems like the least they could do is check with the developer on why they want that access and see if its legit or not.
- deleted 6y ago[deleted]
- ogre_codes 6y ago> Well, the problem is we don't know why they are using it. > > That almost makes the notifications useless. If your app is checking the clipboard or my location on a frequent basis, it's your job as the developer to communicate to me why you are doing this. If the notifications are frustrating, users will turn off the permissions or remove the application entirely. Crappy snooping applications are gone. Mission accomplished.
- frankchn 6y ago> If the notifications are frustrating, users will turn off the permissions or remove the application entirely. Crappy snooping applications are gone. Mission accomplished. Will they? That didn’t happen with the UAC dialogs in Windows.
- Kiro 6y agoYou ask all the questions from a company's perspective, presuming no users want this. As a user, I absolutely prefer the convenience.