21 ms·
LinkedIn sued over allegation it secretly reads Apple users' clipboard content
- pwdisswordfish2 6y agoAwesome!
- ChrisMarshallNY 6y agoI’m wondering if a dependency common to these apps is the thing reading the clipboard.
- andy_ppp 6y agoPretty evil so my guess is the Facebook sdk...
- wakenmeng 6y agoWell, it's not rare. A lot of apps have sort of feature, search while inputing, to search before user completing spelling. And some apps go further to search and show what people copy from other place, because they thought user may want that. I think its original idea is to bring convienience to user, not to inspect privacy data. But this seems to end now.
- arpa 6y agoWell hello all the passwords that are safely copied from the password manager.
- dbt00 6y agoChecking the clipboard for relevant patterns and possibly enabling user actions is not the same thing as stealing your clipboard. Consider the Apollo reddit app: https://www.reddit.com/r/apple/comments/hejb9i/ios14_catches_apps_spying_on_your_clipboard/fvscjyz/ https://www.reddit.com/r/apple/comments/hejb9i/ios14_catches...
- asplake 6y agoThen these should be permissioned separately, the patterns perhaps available for inspection
- cassalian 6y agoPeople seem pretty upset about their clipboards, I wonder if apple/google will listen and make the reading of your clipboard something that you must get explicit user permission for (similar to your camera). IMO this is how almost every possibly permission should be and I think most users would agree with me that having 2 seconds of inconvenience when you first setup the app is worth the peace of mind gained.
- LoSboccacc 6y agoit should be split into "local clipboard" and "global clipboard" so that you still have copy paste within the program but paste outside the program require privilege there's plenty Android sketch/mind mapping apps for example that require access to storage, for saving and exchanging media, and the is doesn't allow for "allow access to some folder without giving them access to everything" and it's annoying most permissions actually should have that kind of don't allow global access without breaking the app functionality or even telling the app itself
- bluedino 6y agoBlackBerry Work (for iOS and Android) can work with solely the clipboard inside the app
- fencepost 6y agoThis. There are plenty of situations where I'd be happy with allowing an app to store its own internal data and maybe export local backups but I don't want to give permission to enumerate and read everything on the file system. Heck, I'm using Bouncer to remove permissions after I move away from apps. I fail to understand why more granular permissions haven't been a priority.
- smichel17 6y agoThere's no problem if I manually copy some text from a box in one app and paste it into another app, and I don't want a permission prompt for that. It's programmatic access that I care about (apps snooping clipboard content). Technically they could probably be implemented the same way and the "manual" action is actually just granting the programmatic permission to the keyboard app.
- filleduchaos 6y agoTo me the real problem is that so many people don't actually understand how clipboards work. If they did, they wouldn't have this (in my opinion) strange trust in their security in the first place. As a developer and as a user: don't put things in the general/system clipboard if they're truly sensitive/secret. Developers especially really should be promoting the use of named and/or private clipboards (and of the share sheet in Android and iOS).
- kalleboo 6y agoAnd drag and drop
- mileycyrusXOXO 6y agoHow am I supposed to use a password manager if I can't copy paste?
- filleduchaos 6y ago"How am I supposed to use a password manager if I can't put my plaintext password in a file that everyone can access?" Like I have already said, >> Developers especially really should be promoting the use of named and/or private clipboards (and of the share sheet in Android and iOS). And for the specific case of a password manager, iOS offers Password Autofill integrations. It's not the OS's fault if developers are too lazy to use the right tools for the right job.
- manquer 6y agoiOS does not offer auto fill for third party password managers and there is no unified service that Apple offers for web and desktop and works across OS and multiple browsers . So it is less to with developer laziness and more to do with lack of usability beyond iOS
- filleduchaos 6y ago> iOS does not offer auto fill for third party password managers Yes, it does - see the section very literally titled "Integrate a Password Management App with Password AutoFill" at https://developer.apple.com/documentation/security/password_autofill https://developer.apple.com/documentation/security/password_.... But again, many devs don't actually keep up with and/or look up the proper way to do things on the platform they're deploying on. > and there is no unified service that Apple offers for web and desktop and works across OS and multiple browsers Apple has a duty to its own software. Why exactly is the onus on Apple to offer a magical grand unified service instead of on third party software developers to actually take the time to study and use the appropriate tools on each platform they want to deploy on? If you want things to be secure you generally have to put in the work for it. 1Password spends resources building & maintaining browser extensions to integrate directly with input fields - why doesn't your password manager of choice offer similar? As a developer one could use named and/or private clipboards to actually have control over when and how the data their users clip is accessed - why not do that over complaining that a shared, global buffer that applications can access programmatically by design is, while convenient, also not exactly the most secure way to transmit sensitive data?
- jmiserez 6y agoPrevious discussion of the issue: https://news.ycombinator.com/item?id=23716451 https://news.ycombinator.com/item?id=23716451 Explanation from LinkedIn and the actual (open-sourced) code in question linked in the top comment: https://news.ycombinator.com/item?id=23719995 https://news.ycombinator.com/item?id=23719995 That explanation seems plausible to me, and would imply that there is no spying going on there.
- chiefalchemist 6y ago> "According to the complaint, LinkedIn has not only been spying on its users, it has been spying on their nearby computers and other devices, and it has been circumventing Apple’s Universal Clipboard timeout." That's the last paragraph, which probably should have been stated sooner. The timeout issue could be a mistake, but if not it seems to support the spying theory.
- kanox 6y agoDoes the lawsuit have any merit? I can't think of any laws that would ban applications from accessing information as provided by the operating system.
- andersco 6y agoMy hope is that stories like this help to educate non technical users about what a clipboard is and does. That in turn might result in improved clipboard privacy.
- electro_blah 6y agoshitty company that uses dark patterns[0] [0]https://twitter.com/darkpatterns https://twitter.com/darkpatterns
- sloshnmosh 6y ago“ According to the complaint, LinkedIn has not only been spying on its users, it has been spying on their nearby computers and other devices” Facebook’s SDK’s which are embedded in more than 30-40% of all Android apps also scan the users internal network and also uses Bluetooth looking for devices nearby. I was shocked to discover that more than half of the third party apps I had installed had Facebook’s software embedded in them.
- kraemahz 6y agoIs there a list of these somewhere? What are the steps needed to verify for myself? Exfiltration of data from my phone is theft; I prefer not to be stolen from. So far I've found: Spotify Tinder Yelp Duolingo
- throwclassy491 6y agoI am a noob, so please correct if wrong. I think you can use the fdroid app 'ClassyShark3xodus' to scan apps installed and apks on your phone for trackers etc. https://f-droid.org/en/packages/com.oF2pks.classyshark3xodus/ https://f-droid.org/en/packages/com.oF2pks.classyshark3xodus...
- kraemahz 6y agoThat got me far enough to get started, thanks!
- eyeball 6y agoWhat functionality would be broken if clipboards were changed to be completely unreadable other than when the user initiates a “paste” command manually?
- Denvercoder9 6y agoChrome on Android shows any URL on the clipboard as a suggestion when focusing the address bar. It's a marginal but quite noticably improvement in user experience.
- TehCorwiz 6y agoPassword managers. Auto fill forms. Can’t think of anything else
- riffraff 6y agowhy do password managers need to _read_ the clipboard? It seems they would only need to _write_ to it.
- eyeball 6y agoI see two behaviors in 1Password 1) I go to a site and it auto fills the login. Not sure when clipboard needs to be involved there. Shouldn’t that just be the application taking data from its database, recognizing the associated form, and filling it? 2) I search for a login manually and copy to clipboard. In that case I’d only ever want it to paste when I issue a paste command manually
- thewisenerd 6y agoin my experience, to "restore" clipboard contents after a certain period of time; - read clipboard - write password into clipboard - restore clipboard after X seconds
- jen20 6y agoThere’s no reason this couldn’t be a platform-provided function though - a clipboard “stack” would be rather useful anyway.
- IceWreck 6y agoYeah, please just use mobile websites instead of apps whereever possible.
- justapassenger 6y agoWhile LinkedIn is sketchy, this is a modern iteration of ambulance chasing lawsuits.
- manquer 6y agoIf it improves privacy by making the cost of acquiring a user’s information higher then that’s a very good thing .
- justapassenger 6y agoYou can also say that ambulance chasers improve public safety by making errors more costly. This isn't about privacy. It's a money grab by lawyers.
- DavideNL 6y ago...just imagine how many passwords must have leaked like this. Or is there some kind of 'limitation' when accessing clipboard data copied from password managers?
- jannes 6y agoSome password managers have a feature to automatically clear the clipboard contents 30 seconds after copying a password. But I have only seen this on Android, Windows and macOS. Not on any iOS apps, likely due to tougher restrictions on executing in the background.
- DavideNL 6y agoYea, 1Password on iOS also clears the clipboard after 90 seconds.
- olcor 6y agoThis is very weird, I notice a lot of apps are doing this. Even Firefox Focus, considered to be a "privacy-focused" browser, has this notification pop up every time you add a character to their address/search bar.
- mtbnut 6y agoSo, do we need to redefine the term “sandbox” as it relates to secure software? Obvi, it doesn’t do what we’ve been told it was supposed to do. Apple uses the term about 600 times per keynote, but we now know it’s been lip service. They either lied or just did a shitty job securing iOS. However, “sandbox” doesn’t necessarily imply secure; that would be a “secure sandbox,” in which case we were all naive, heard “sandbox,” and assumed it was secure, which by default and definition, it isn’t.