13 ms·
TikTok app to stop accessing user clipboards after being caught in the act
- jacknews 6y agobut what's next?
- nickthegreek 6y agoI'm happy that ios14 is adding more transparency on whats apps are accessing like this clipboard situation. I'd love to see more of these, like camera roll and mic access.
- RandallBrown 6y agoiOS 14 is adding an indicator for apps using the camera and microphone. You'll also be able to see apps that recently used them in the control center.
- natch 6y agoiOS 14 has a new workflow that lets the user give an app access to a photo or selected photos without the app getting access to any of their other photos. Big privacy improvement on that front at least. I don't know about mic access.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- grecy 6y agoI recently made the change in Firefox on macOS to stop websites from accessing the clipboard [1], and now pasting into Facebook is completely broken. I wonder if they've been checking out my clipboard contents. [1] https://www.ghacks.net/2014/01/08/block-websites-reading-modifying-clipboard-contents-firefox/ https://www.ghacks.net/2014/01/08/block-websites-reading-mod...
- gruez 6y ago>I recently made the change in Firefox on macOS to stop websites from accessing the clipboard I don't think you needed to do that. I searched around and wasn't able to find any proof of concept that was able to steal clipboard data from firefox. see: https://news.ycombinator.com/item?id=23635488 https://news.ycombinator.com/item?id=23635488
- annoyingnoob 6y agoToo little, too late. Already forced the family to uninstall it and its gone forever. Wish the kids could understand that its spyware with access to a lot of toxic social media.
- deleted 6y ago[deleted]
- Shank 6y ago> Already forced the family to uninstall it and its gone forever. Honestly you’d be better off educating them and telling them it’s a good idea than forcing them to jettison an app they probably love. Tons of apps do this (as discovered in iOS 14) and I highly suggest not doing a crusade against one when a lot more do it. See: https://youtu.be/pRSWdtoUAjo https://youtu.be/pRSWdtoUAjo
- annoyingnoob 6y agoFair enough, we don't have any of the known spyware - TikTok was the only one. I was already questioning the value of TikTok before it became well known that its spyware. I won't tell you about the week of crying because someone was calling my 8 year old a 'viscogirl' after seeing something on Tiktok about it. It really looks like toxic garbage to me.
- mikeyouse 6y agoIt's starting to fill up with Pizzagate "secret dungeon basement" conspiracy theories too.. probably better off without it.
- techntoke 6y agoDoesn't sound so far fetched when TikTok is allowed to violate COPPA and is a haven for child predators.
- saagarjha 6y agoYou sure it wasn't "VSCO girl"?
- Calvin02 6y agoThis is so ridiculous. Google Maps accesses the clipboard. Try it out: copy an address and open maps. So do Facebook and Instagram, I’m sure. The level of paranoia in the Valley is astounding.
- wycy 6y agoGoogle Maps has a clear use case for accessing the clipboard. If Tok Tok only accessed the clipboard on launch to check for a Tik Tok URL, that might be one thing, but there's no clear reason Tik Tok would need access to the clipboard literally every 3 keystrokes.
- ebg13 6y ago> Google Maps has a clear use case for accessing the clipboard. I don't think it does. Neither application should "access" the clipboard.
- bravoetch 6y agoI keep reading about naughty apps and wondering will the OS ever lock this stuff down.
- aetch 6y agoGoogle maps detects copied addresses and lets you route to them in one click.
- ebg13 6y ago> Google maps detects copied addresses and lets you route to them in one click. Routing to copied addresses is not a clear use case for letting something spy on everything the user copies, because we already have an invocation for handing clipboard contents to software exactly when the user desires it. It's called the "paste" command. At some point engineers need to stop doing things just because they can.
- justicezyx 6y ago
- jeffbee 6y agoThis is just an overblown yellow-peril panic, right? How does any app paste? By "accessing the user clipboards". How does the chrome omnibox do "text you copied"? By "accessing the user clipboards".
- geoah 6y agoYeah it seems like it. Chrome and a lot of other apps show an insane amount of these popups on IOS14 to either actually check your clipboard or just to toggle "paste" buttons.
- freeone3000 6y agoNormal apps wait until the user attempts to perform a paste action to access the clipboard, instead of accessing the clipboard every two seconds.
- jeffbee 6y agoMalice or just stupidity? I can imagine a dozen different reasons a program might access the clipboard in a loop, all of which reduce to "we are bad programmers".
- thewindow 6y agoNot all of them reduce to bad programmers. It could be either of malice or stupidity. In this age when data is valuable, it is better to be safe and assume malice.
- hombre_fatal 6y agoTikTok reading it every couple seconds is definitely excessive. And frankly our tools fail us by not at least revealing that it's taking place -- new clipboard notification aside, as shown in TFA. How do I know how common vs weird this behavior actually is? I'd only refine your post to say that it's common for apps to read the clipboard without you pasting. Right click Chrome's omnibar and it will show "Paste and go to <clipboard contents>", my bittorrent client and RSS clients prepopulate the new torrent/feed form if I have a URL in my clipboard. Is the tiny convenience worth the ability to snoop? I don't think so. Or rather, I would like to decide that for myself.
- prodpo 6y agoTiktok has a lot of money. They can control speculator, then control America, then everyone.
- zkid18 6y agoGreat to see another layer of transparency in ios14. Bit I wonder why everyone talking about one specific app? I see a huge bias towards TikTok in headlines "iOS 14 caught TikTok and other apps spying on the clipboard" [0] "iOS 14 beta shows apps like TikTok still spy on your iPhone" [1] There a bunch of apps like VICE, Google News, WSJ that has been caught doing exactly the same. [2] I may find the explanation why TikTok did that. In China WeChat blocks direct links to their competitors. So apps like Taobao or Douyin have to find a workaround for deeplinks. When you want to share the video from Douyin with a friend in WeChat, Douyin generates the following message. 在东京刚毕业入职三个月的职场小白 搬家找房 坚持更新#日本vlog #东京 https://v.douyin.com/J8ceMYY/ https://v.douyin.com/J8ceMYY/ 复制此链接,打开【抖音短视频】,直接观看视频! In WeChat the link is not clickbale. To see the content user has to copy full text and go to the Douyin. The app will read the clipboard and perform the transition to the video. On the link below you can find the video - explanation [3] Probably they had re-use some code in TikTok. Definitely they need to be more accurate towards data safety but I don't think they really made a pipeline for spying using clipboard. There is a lot of buzz around TikTok these days, but I want to get an answer from other apps as well. [0] https://bgr.com/2020/06/26/ios-14-beta-privacy-features-tiktok-spying-clipboard-data/ https://bgr.com/2020/06/26/ios-14-beta-privacy-features-tikt... [1] https://mashable.com/article/iphone-ios-14-privacy-clipboard-apple-apps/ https://mashable.com/article/iphone-ios-14-privacy-clipboard... [2] https://www.youtube.com/watch?v=pRSWdtoUAjo https://www.youtube.com/watch?v=pRSWdtoUAjo [3] https://twitter.com/kidrulit/status/1277629462721384448 https://twitter.com/kidrulit/status/1277629462721384448
- xijinping250 6y agoWhile since you talk about bias, Why every app(facebook,twitter,youtube....) of US is banned by China? But China's company can earn money in America? Why US government allow this happen? They are huge threat to the safe of America!
- deleted 6y ago[deleted]
- thewindow 6y agoJust because other apps do that is no excuse for bad behaviour. Almost all apps get flack for bad behaviour. Tiktok is the newest popular thing on the block and it is expected to be widely covered. Honestly it is okay to discuss the bar behaviours of an app without blaming other apps.
- chvid 6y agoHotels.com and a host of others did the same thing, indicating that this is not particular nefarious. However we keep talking about TikTok. Why is that?
- joosters 6y agoWhy should that mean its not nefarious? Just because other apps are doing underhand privacy invasion doesn't make it any better - they are all scum! Everyone is talking about TikTok because the video that went viral showed TikTok.
- swalsh 6y agoBecause Tik Tok takes data collection to a whole new level. It uses this, and every other trick in the book. And that matters because it's not clear that this data will be constrained to the activities of sending me extremely targeted advertising. Now we can have a reasonable debate about that, but this has a new level of concern. As a Chinese app, how do I know the Chinese government will not use me as an unknowing participant in a future cyberwar? One thing Tik Tok does is collect a pretty exhaustive list apps installed on my phone. That could be used for identifying vulnerabilities they could potentially exploit.
- thewindow 6y agoTim tok has no business snooping into by clipboard. It is bad behaviour irrespective of if it was nefarious or not. No need to justify this by bringing up behaviour of apps.
- toohotatopic 6y agoWhy do phones need the clipboard at all? There is a 'share with' infrastructure. Why not explicitly send copied data to the desired app directly instead of storing it in a central place?
- seanalexander 6y agoCopy and paste.
- catalogia 6y agoI used to see lots of people question the merits of copy/paste when iOS didn't have it, because iOS didn't have it. When iOS finally got it, I thought the matter settled. The people who previously dismissed the feature now considered it the best Apple innovation since sliced bread (or perhaps the multi-buttoned computer mouse.) Do you never copy/paste text within the same document? How do you rearrange sentences, paragraphs, etc? Highlight-and-drag is cumbersome in long documents and is really an implementation of cut/paste, not copy/paste.
- gruez 6y agoThat works for sharing an article or a post, but how do you quote a portion of a post?
- parliament32 6y agoOn Android, you can happily select some text then hit Share (same menu as Copy and Cut).
- gruez 6y agoThat pattern is mainly used to open an app to a specific activity. eg. opening google search to a particular search phrase, or opening the dialer to a particular phone number. I can't see it working for when you're writing a email, and want to include a link/quote/image.
- 6y ago
- chrisshroba 6y agoAn interesting reddit comment by someone who uncovered many more shady data collection practices by Tik Tok: https://www.reddit.com/r/videos/comments/fxgi06/not_new_news_but_tbh_if_you_have_tiktiok_just_get/fmuko1m/ https://www.reddit.com/r/videos/comments/fxgi06/not_new_news...
- numair 6y agoMost of the anti-TikTok comments that have emerged recently are beyond hysterical. We are arguing about China using this app as a primary nexus of intelligence gathering, in a world where they already have the US government’s entire OPM database?[1] A lot of apps are doing the stupid clipboard detection thing. As others have commented, there’s reasons for this that range from spam detection to link shortening. It’s lousy, I agree, but this has been a very common thing in a pre-iOS 14 world. 1: https://en.m.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach https://en.m.wikipedia.org/wiki/Office_of_Personnel_Manageme...
- abledon 6y agowhats an OPM database? this?? https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3245162/ https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3245162/
- numair 6y agoThought the OPM hack was common knowledge, guess not. I added a link!
- gruez 6y ago>In June 2015, the United States Office of Personnel Management (OPM) announced that it had been the target of a data breach targeting the records of as many as four million people I'm pretty sure that tiktok has more than 4M users. I guess you can argue that OPM has more % of "high value" users compared to tiktok, but it's also 5 years out of date and contains different sets of data entirely. OPM data doesn't have your minute-by-minute location history and clipboard history, for instance.
- apta 6y agoThey'll use whatever data they can get their hands on.
- manquer 6y agoIntelligence gathering with OPM kind of leaks is passive activity, which can potentially be used for leverage. Platforms like TikTok are active propaganda tools already, and can be used to shape discourse in democracies. It is a major concern whether such tools are owned by foreign governments (tikTok) or private companies who do not need to comply with any regulations(Facebook twitter) etc.
- dagav 6y agoWhen I installed TikTok, my phone's battery life shortened by 2-3x. That's suspicious enough for me to stay far away from it
- rdlecler1 6y agoThe security implications of allowing communications on a platform that is subject to the absolute control of a foreign government, seems like a very very bad idea. That can be a lesson learned the easy way or the hard way.
- systemvoltage 6y agoI honestly think we give Chinese apps too much equal footing. In about 5-8 years, when China has insane surveillance network around the world (they already have), this comment is going to sound the most sensible thing to do - blanket ban any application developed and served by the CCP or similar government. People teeter-totter about righteousness and freedom of choice, but IMO we need to stop feeding the CCP with more power/$$$/influence ... NOW ... Freedom of choice is great when there is fairness and democratic values built in, when the government isn't on some Han-supremacy drug and expansionist motives. Someone will inevitably respond with whataboutism and smear American companies into the mix as if they're expressing their understanding of hypocracy and one-sidedness. It is supposed to be one-sided. The west offered two-way street which China declined to walk on. So, now all bets are off. Equivalency with the western apps/services/goods is no longer a valid counter argument. On fair, just, and rational grounds - I am a progressive. In unfair, unjust and irrational waters - I am a conservative.
- jquery 6y agoThe CCP has already shown they’re willing to abuse TikTok to stir unrest in the USA, you aren’t even making a theoretical argument. I’m a lot more worried about China than Russia, when it comes to bad behavior by state actors.
- justicezyx 6y agoWhat?! I dont have any memory of "CCP abuses TikTok to stir unrest in USA" being reported. Is there really such evidence? If there is evidence, then please just ban the goddamn app out of any mobile smart phone platforms. It's too dangerous to open the lid of such mass bring-washing machine. Even in the Arab-spring, it was just passively allowing the information to propagate organically. No one with sane judgement should allow these apps being used as manipulation tools by any minority group...
- gcbw3 6y agomaybe i do not know how clipboard works, but the message "<active app> pasted from <inactive app>" is the worst possible label. Also funny how every app shows it. Guess IOS14 will be known by non technical users as "the cookie-law iphone version" and everything will continue as usual.
- jp42 6y agoJust wanted to inform audience here that TikTok is blocked in China. [1] [1] https://en.wikipedia.org/wiki/List_of_websites_blocked_in_mainland_China https://en.wikipedia.org/wiki/List_of_websites_blocked_in_ma...
- brightball 6y agoStuff like this is why I prefer a reactive web interface over a mobile app. It seems like unless you need direct access to the camera or it’s a game a web version should be fine.
- wildchild 6y agoI don't think all these whores were concerned about it.
- xchip 6y agoIt looks like apps can spy as much as they want and that it has little implications for the perpetrators... "ooops sorry! now let's carry on"
- jb775 6y agoApple manually reviews the code of every app update. Why aren't they blocking this functionality from getting released in the first place? I feel like every time I submit an app update I get questioned about why my app needs access to $xyz feature.
- deleted 6y ago[deleted]
- ebg13 6y ago> manually Do you really think so?
- racl101 6y agoGood on Apple. This and backwards compatibility, make a compelling case for iOS.
- knodi 6y agoYa, little fucking late to back track that now.
- feross 6y agoDuplicate of: https://news.ycombinator.com/item?id=23653562 https://news.ycombinator.com/item?id=23653562
- techntoke 6y agoTikTok also is violating COPPA. Any underage child that signs up with a Google Account, you can clearly see from the Google account settings that they are collecting email addresses and other personal information. I believe Google and other app store providers should just remove them.
- bradley195 6y agoIs it possible for apps to read photos (not just metadata)?
- wuunderbar 6y agoCan someone answer why iOS even allows the ability to read the clipboard buffer in the first place? Just seems like poor privacy and security design.
- MuffinFlavored 6y agoso that if you switch from app A to app B, it can check your clipboard buffer for if you have a URL pasted into it and load that URL in the context of the app example: if you copied twitter://foo/tweet/bar or https://twitter.com/foo/tweet/bar https://twitter.com/foo/tweet/bar, it checks your clipboard and loads that tweet instantly at least that's what i read over on reddit about this on r/apple
- ebg13 6y agoExcept that letting apps randomly pull from the clipboard, where you might have copied passwords, bank account numbers, or any other sensitive information, is such an obviously unsafe idea that the person who suggested it should have been immediately sent to special privacy consciousness training. For what? To save one "send to app" or "paste"? At least reserve that functionality exclusively for the operating system on the grounds of "TRUST YOU? HAHAHAHAHA".
- beervirus 6y agoA super minor convenience feature, and enabling it allows apps to just read from my clipboard at will? The juice ain't worth the squeeze.
- ebg13 6y agoI know, right? It's not super hard to imagine a parallel universe where any software can copy to the clipboard but only the OS, upon user request, can paste back out of it. And yet here we are wallowing in filth. Why, because people have never heard of a callback before? Let the application include a "paste" handler function, and then all clipboard exfiltration must be initiated by the user at the OS UI layer. Simple. Safe.
- perfectstorm 6y ago
- hnick 6y agoI'm starting to think these devices need to provide examples when throwing up the permissions prompt. Worst case examples of what this permission can enable so that app developers might at least try to limit their requests.
- qserasera 6y agoToo little too late. They should be barred from US markets however there may be worse actors out there that borderline criminals could call ‘industry standard’.
- MarioKartBowser 6y agoHi, sure, let the PLA brainwash your child.