4 ms·
What I find odd: - why was iOS allowing it in the first place? - why does an app have access to the clipboard unless copy/paste is deliberately invoked from w
by reactspa 6y ago
What I find odd:
- why was iOS allowing it in the first place?
- why does an app have access to the clipboard unless copy/paste is deliberately invoked from within the app by the user? (my clipboard often contains highly sensitive info)
- pat2man 6y agoProbably for performance reasons. If I copy an image I want it to paste immediately.
- statictype 6y agoThere are good reasons for enabling an api for copying to the clipboard. A password manager should be able to copy passwords to the clipboard without the user having to select the plain text password in a text field. Not sure about pasting.
- TheSpiceIsLife 6y ago> A password manager Should have a dedicated API to transmit passwords to password fields. Or, more broadly, if I had half a brain I’d get in to digital security research, so much low hanging fruit!
- novok 6y agoThere is a dedicated password api system, but sometimes, you just run into apps or websites that don't integrated with that API well.
- kstrauser 6y agoThere are legitimate user-centric reasons for doing this: - I have an app, Parcel, that upon launch sees if I have something resembling a tracking number in my clipboard. If I do, it asks if I want to track that package. - A popular Reddit client, Apollo, looks for Reddit URLs in the clipboard. If it finds one, it asks if you want to open that conversation in the app. Sure, both of those apps work fine without that feature. Those are definitely nice conveniences, though, and they’re designed to make my life as the user just a little easier. So, there are genuinely useful reasons for an app to do this. There’s zero legit reason for TikTok to check every 30 seconds that don’t involve spyware. I want a dialog box: “Allow this app to access your clipboard?”, just like you get for access to location services, photos, the camera and mic, etc. Then I can let well-behaved apps do that for my benefit, and can tell creeper apps like TikTok to mind their own damn business.
- inetknght 6y ago> There are legitimate user-centric reasons for doing this This trope is dragged out often. The answer is no. No, these are not legitimate use cases. Just like Cambridge Analytica wasn't a legitimate use case, neither is polling a clipboard for changes. An application should be told of changes. If there were a permission dialog to allow the user to opt-in the application to being told instead of requiring the user to explicitly paste, then maybe. Only maybe. But allowing any (third party) application to see the communication between two (first party) applications is completely unacceptable.
- scubbo 6y agoCan you elaborate on why not? More specifically, what is illegitimate about those use cases? Do you deny that users would want these features? I will readily concede that the infrastructure and tools that enable those use-cases also potentially enable exploits - but what is that you know about users that I don't which leads you to believe that these use-cases are not legitimate?
- kstrauser 6y agoYou’re speaking for yourself. For me, those are legitimate use cases and I like it when apps use that functionality appropriately. The key is that I want to decide if and when I allow an app to do it. In the case of Parcel, 99% of the time I open the app (as opposed to looking at its widget), it’s to add a new package to track. If I didn’t have something in my clipboard that I wasn’t about to add to it, I probably wouldn’t have opened the app in the first place.