17 ms·
See what JavaScript commands get injected through an in-app browser
- londons_explore 4y agoWas anyone expecting otherwise? They'll use it to make their algorithm better, and they'll use it to better target ads. Both of those things are good for me the user, so I'm fine with it. And for those who don't like that, use a blocker, or don't use TikTok.
- yieldcrv 4y agoI like TikTok, I think that algorithm is toxic and that "better" currently means "more toxic". My simple ask is that I wish we could control it a little better. It sends you down a tree, but I wish we could zoom out, visualize the tree and just pick a different branch to go down.
- chitowneats 4y agoThe product/feature you're describing will never be implemented in their spyware. What incentive do they have to satisfy this feature request?
- londons_explore 4y agoImagine there was a competitor which did have this feature. And users appreciated it, and used it to discover more content that they were more interested in. Preventing that happening would be a good reason to implement it. Don't wait for someone else to implement something users like...
- chitowneats 4y agoThose platforms already exist though. TikTok's differentiating feature is that it ruthlessly serves up algorithmic content so it can collect data on the result of that interaction and iterate. Feels like you're fundamentally breaking it if you remove that.
- gmadsen 4y agoThe sad fact of the matter is that you are wrong. People do not want that. No matter what their words say, their actions is what bring in the revenue
- temende 4y agoThey’re not going to do that because they don’t want you going down a different branch that will lead to lower engagement metrics for them.
- quickthrower2 4y agoI walked into a shop. They place a bug on me, so they can listen to my conversations in the store, and the store next door if I leave and pop in there. Both conversations about products, and conversations about I am having with my therapist about personal problems. Everything is recorded. They use it to make their algorithm better, and they'll use it to better target ads. Both of these things are good for me the shopper, so I'm fine with it. If they sell that data to other companies, have their employees LOL at my problems, or secretly pass it on to the police or spy agencies, that is totally cool. Nothing to hide here! And for those who don't like it, don't shop at this particular store.
- AuthorizedHelp 4y ago
- AlexandrB 4y agoThat's great if it's something you want. What happened to getting consent? All of these "features" should be opt-in.
- rvz 4y agoThis was expected and the intention for this invasive spyware is obvious, otherwise, how else is their dystopian recommendation algorithm supposed to work if you don't give access to your entire life records. The difference is that this was done before by Meta / Facebook and they were fined in the millions, and even by billions by regulators like the FTC over this. This same problems a decade ago are being repeated once again and we have learned nothing. TikTok should be under the same regulations, especially when they are operating in many countries that have strict data privacy laws and given this unsurprising and extremely invasive data collection practice which is even worse than Facebook, they should be fined in the billions of dollars as a reminder that it applies to any social network, especially those with billions of users. If left alone, it will only get worse for everyone.
- zx8080 4y agoIs it similar to what Meta in Instagram does? [0] - a week ago thread. [0]: https://news.ycombinator.com/item?id=32415470 https://news.ycombinator.com/item?id=32415470
- pessimizer 4y agoYou're linking to the same site as the OP. This is the follow up blog.
- MWParkerson 4y agoYes and that’s literally the first link in the first sentence in the first paragraph of the article lol
- deleted 4y ago[deleted]
- rvz 4y agoTikTok is no different and is beyond worse than Meta at this point. Whatever Meta is doing doesn't excuse the reasons for this tracking. Given that Facebook was fined in the billions for this abuse in the past, TikTok should also be fined for this with in the billions of dollars. We have learned nothing around this and have repeated the same problems in social networks a decade later.
- zx8080 4y agoFines, even that high, do not stop this, as we all see in no change in Meta actions. Also, cannot avoid thinking that Facebook was accused of (somewhat similar) web site spying long time before Tiktok existed.
- glook 4y agoThis is wonderful work you are doing. It has been a joy to follow.
- sva_ 4y agoI just don't understand how we can allow a Chinese social media app in the west, while any non-chinese social media apps aren't allowed there? Same with housing, why can Chinese nationals buy housing here, while I can't do so there?
- baby 4y agoWe’re not a dictatorship?
- treeman79 4y agoYet
- kQq9oHeAz6wLLS 4y agoJust two more years and we have another chance to reverse course.
- deleted 4y ago[deleted]
- ta8645 4y ago
- mjmsmith 4y agoThis nutjob honeypot tastes delicious.
- withinboredom 4y agoBecause it’s a sovereign country that makes its own rules? So, basically the same reason that you can’t just move to Italy because you feel like it.
- sva_ 4y agoAs a matter of fact, I can, as a European citizen (basically)[0]. [0] https://www.unipi.it/index.php/welcome-and-support/item/7413-right-of-entry-and-residence-for-eu-residents https://www.unipi.it/index.php/welcome-and-support/item/7413...
- madrox 4y agoI feel like there is a litany of the internet: "that which can be collected will be." That's been true since the beginning. What continues to surprise me is that people think only "bad guys" do it. This is why we continue to lock down browsers and provide ever narrower permission classes.
- Evan_Hellmuth 4y agoPeople only care when "bad guys" do it
- dinkledunk 4y agoThat's because only "bad guys" do this. If a "good buy" does this, they automatically become a "bad guy".
- headsoup 4y agoI think madrox is referring to 'good guys' as in Western countries vs China etc, not literal good guys and bad guys. That's a fairly common view, regardless of all the actual bad Western country leaderships' conduct.
- toomanydoubts 4y agoI think I agree with you here. It's proof by definition.
- netheril96 4y agoWhat surprises me is that this is technically possible on iOS.
- MBCook 4y agoIt’s an abuse of a feature, in a way. There are certainly non-evil use cases for the feature being used here. But as we know, that which can be used by advertising/tracking people will be used by them.
- deleted 4y ago[deleted]
- marcod 4y agoI'm sure this isn't just iOS. I opened the link on Facebook for Android's browser and got a bunch of script injections...
- TheAceOfHearts 4y agoCan websites protect against this through the use of Content Security Policy (CSP) [0]? [0] https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
- Too 4y agoNot at the moment. This article from last week when the issue got exposed is arguing for adding it https://news.ycombinator.com/item?id=32418679 https://news.ycombinator.com/item?id=32418679 * Let websites framebust out of native apps *
- jabbany 4y agoIt might make it much harder to inject stuff, but since the apps control all aspects of the embedded browser and CSPs are enforced by the browser, they could feasibly just disable CSP enforcement and have the embedded browser ignore the CSP.
- MBCook 4y agoI don’t think Apple gives access to the CSP or a choice in obeying it. I’ve been working with WKWebView recently and don’t remember running across it. Now you could go really far to get around it. Request resources yourself and hand them to WKWebView directly so no CSP is served but that’s not going to be easy. You’d have to scan for any other resources that might get loaded, pull those, inject them correctly, etc. Seems like it would be very fragile.
- jabbany 4y agoI'm not remotely an iOS dev, but the workaround you present seems reasonable to me? Just make your own http(s) requests, fetch the page contents, ignore header CSP, strip CSP in the HTML and send the string to the web view thing. A cursory glance at the documentation seems to show that the web view thing allows for rendering HTML strings. Not sure if that also loads external resources in the HTML supplied, but if so it would be relatively minimal work. (Companies have spent much more dev effort to get similar tracking capabilities. E.g. WeChat on Android implements an entirely custom rendering engine from scratch rather than use any system web view component.)
- aardvarkr 4y agoA keylogger in the browser is a pretty sick violation of privacy.
- userbinator 4y agoFor some reason, the phrase "JavaScript commands" stood out to me as being rather awkward. I'd just say "injects JavaScript code" or "injects JS". We can’t know what TikTok uses the subscription for According to the code on that page, the function named 'i' needs to be investigated further. It appears to return another function which is then called to process the keypress event.
- cwkoss 4y agoDon't all in-app browsers do this? I think I read that instagram does the same.
- gentleman11 4y agoInstagram is a spyware company owned by a spyware company
- xeromal 4y agoIf you open the article, it compares it to a few apps. TikTok blocks you from opening it in your default browser. The others don't
- 40four 4y agoNo not all of them do this. Yes, Instagram does, as per the chart in the article. The difference is Tiktok forces you to use their in app web view, and does not allow you to use your default browser, where they would not be able to inject their own JS code. Even worse, Tiktok monitors every single key stroke, a key logger in effect, where Instagram does not (according to the authors research).
- jacooper 4y agoNo, AFAIK not on android. As it uses the default browser, just in webview mode.
- rawling 4y agoiOS and Android both have equivalent "bad" webviews that can be tampered with and "good" webviews that can't. Instagram on Android uses the "bad" one.
- inopinatus 4y agoThe shitty code injected generates a ton of errors. After initially being super annoyed about the noise in our exception reporting, a bright spark observed that it may also be used for detection and user protection, albeit only for our own users.
- cma 4y agoWhy don't we expand wiretapping laws to this stuff?
- deleted 4y ago[deleted]
- kungfufrog 4y agoSo let me get this straight: If I click a link inside the Instagram app, that for whatever reason takes me to gmail or microsoft or wherever that requires authentication, and I decide to login on that page so I can view the link in question, Meta and TikTok are able to capture my credentials and ingest the data back in to their metrics and analytics pipelines? Is that even f*cking legal?
- deleted 4y ago[deleted]
- paxys 4y agoEverything is legal until it is explicitly made illegal. And I can assure you no US politician can understand more than 3 words in that paragraph you wrote, let alone make laws to regulate it.
- hackernewds 4y agoThis exchange. Mind-numbing https://youtu.be/t-lMIGV-dUI https://youtu.be/t-lMIGV-dUI
- mr_toad 4y agoEavesdropping on electronic conversations where both parties have a reasonable expectation of privacy is illegal in many jurisdictions already.
- noitpmeder 4y agoThe thing is, in this situation you _don't_ have any resonable expectation of privacy, regardless of what the masses think is actually happening.
- mr_toad 4y agoI’d genuinely like to see Tik Tok’s lawyers make that argument in court.
- berjin 4y agoIs there anything website owners can do about this? I've been many web games, including my own, embedded and surrounded by adverts (see dordle,io, wordle-unlimited,io). Simple permissions like x-frame-options won't work since they're proxying everything onto the same origin. I've thought about checking after a few minutes if the user is on an embeded DOM then asking them to head over to the real site.
- kevincox 4y agoNo, the browser is the "user agent" and decides what to do. The problem is that in this case TikTok is the browser and does what they want, not what is good for the user. It is actually quite a hard problem. The App Store does ban third-party browser engines so maybe they can add a restriction that apps can only inject code into verified domains. Surely a few legitimate use cases would be lost (IDK apps that let you annotate websites or something) but it may largely mitigate this issue. Maybe there can be a permission or a review entitlement that allows this for valid use cases (as decided by Apple of course).
- MBCook 4y agoAmong other things my content blocker for iOS will display a page in a WKWebView they injected scripts into. It makes it so I can easily select and refine which HTML element I want to add to a custom blocking list. I think that would be impossible without this.
- upupandup 4y agoAnd on top of this we are seeing scary trends emerge on TikTok: they are able to mobilize youth into anti-social activities like stealing cars or creating weapons. All they have is a small notice at top of the videos with a disclaimer. ex) Kiaboyz wreaking havoc in Columbus as videos of stealing Kia/Hyundai cars went viral on TikTok Suffice to say that the bar isn't very high in America. This type of video would never catch on in places like Japan or Switzerland.
- croes 4y agoThat's a problem of social media a such. Remember the Tide Pod challenge?
- dwighttk 4y agoDon’t use tiktok Trump was right about that
- jacooper 4y agoInstagram and Facebook do the same thing.
- insane_dreamer 4y agonot nearly to the same degree
- croes 4y agoHow do you know?
- insane_dreamer 4y agoread the article
- croes 4y agoI did, did you? "Important Note: This tool can’t detect all JavaScript commands executed, as well as doesn’t show any tracking the app might do using native code (like custom gesture recognisers). More details on this below."
- gyaru 4y agoFacebook knows your education, where you went, what class you were in, what friends you had at that point, how you look, how you looked 10 years ago, what family members you have, what relationships you have and had, where you work, what establishments you've recently visited, what articles you engaged with more than others on your feed. And a lot of it isn't even voluntary because other people can fill it in for you. TikTok knows my age, my location and viewing habits, TikTok knows that I stared at clip x more than clip y. TikTok might have figured out my age, gender and my sexuality based on what I watch and can probably figure out more just from what I view but saying it's somehow more than Facebook is inane. one is literally made to have as much information about you as possible, that's like the core concept of Facebook.
- A7med 4y agoI trust TikTok over FB or Twitter any day of the week
- gentleman11 4y agoMy question is just, “why do we let everyone ale do this? Why do we only react when it’s a Chinese company doing it?” There is a call for comment by the fcc right now about how people feel about data collection and surveillance. Please go and send in a comment to regulate these behaviours
- jacooper 4y agoTo be fair, Facebook and Instagram were caught first, and the news got to the front page last week.
- jacooper 4y agoWhy on earth is this even allowed in IOS in the first place ? Why do apps have the ability to control and change the browser? Instead of using the default one? Like android.
- Shank 4y agoThese same tools are what allow you to build and ship fully JS based apps on iOS instead of having to use Swift or Objective-C or anything like that. Arbitrary web views can be an entire app. Or they can reinvent the wheel and become in-app browsers. A lot of apps are fully or partially web based. Even Apple’s own apps use web views in crazy ways. For example, the entire Mac App Store used to be a web view. Parts of macOS system preferences are web views. It’s just that because they’re web views, if you slap browser-like chrome on them and send them to the internet, they also work as web browsers.
- bilalnpe 4y agoAll of that is totally fine and not what people are upset about. If your entire app is just a web browser that renders your website, that should be fine too. The problem is when they render external websites and unsuspecting users think they are using the phone's web browser. That is something Apple/Google can have rules about without banning/restricting web views.
- weikju 4y agoIt's the in-app browser. The one that opens within the app, so that people don't need to switch to another app, and usually used for short-lived sessions. It doesn't modify or spy on the actual separate browser (Safari etc), just on whatever happens inside the app (as you would expect, app knows what's going on within itself), and it just so happens that sometimes in the app there is a browser page being displayed, which then goes to reason can also be spied on. Android has these in-app browsers too, they may or may not be subject to this.
- jacooper 4y agoAFAIK Android in app browsers are just a different look for the default browser, I think its called WebView.
- mark_l_watson 4y agoI can’t quite figure this out: it sounds like if you click a link in someone’s TikTok content, the in app browser can read any text entered on that site using the in app browser. Does just not entering any keyboard input in the in app browser mitigate this? Does Apple Lockdown help in this situation? I thought that typical TikTok use just involved scrolling and watching video content. Are users who only view content subject to this security flaw? Thanks in advance for any clarification. Also, off topic but doesn’t YouTube’s “Shorts” take the place of TikTok? I have my Google privacy settings set so YouTube can store my viewing history for one month so I get reasonable recommendations. Does TikTok have similar settings?
- ffggvv 4y ago>> Does just not entering any keyboard input in the in app browser mitigate this? yes but i doubt the hundreds of millions of users, many of which are children, know this
- BoorishBears 4y agoTo play devil's advocate... the most common way to end up in the in-app browser is to click an ad. Non-technical people don't have a concept of "in app browser sandboxing". In their minds they clicked on an ad, they're still inside TikTok, TikTok's UI is showing, TikTok will show prompts based on the content shown... they probably assume TikTok has access to that page? Honestly I'm more annoyed that Apple allows big apps to use the loophole that is the legacy webview than I am that TikTok uses that webview to do the exact single thing it's good for... having full control over the web content you're showing in app.
- weird-eye-issue 4y agoHow do you know that's the most common way? Because I doubt it is. People click links in chats and in their feeds way more than they click ads
- BoorishBears 4y ago
- jollybean 4y ago"TikTok subscribes to all keyboard inputs (including passwords, credit card information, etc.) and every tap on the screen, like which buttons and links you click." How does Apple even remotely allow this? They ban apps for the most arbitrary of reasons, I know small devs that get bumped for tiny things. This is beyond ridiculous. A company that has ~100M american users, and CCP on the board with a CEO/Board completely and publicly compliant with the 'wishes of the CCP' including reporting any and all sorts of things, is literally able to collect any data including passwords. WTF. How is this not a giant story? How does the US Government not issue an immediate statement/warning to the general public and talk to Apple/Google about this issue? My gosh.
- bigcat12345678 4y agoWho ever still using tiktok is surrender their humanity: Fed manufactured content with artificial mental stimulus Privacy got infringed in every second
- bilalnpe 4y agoApple and Google have guidelines about what apps are/aren't allowed to if they want to be on their app store. "Protecting the user" is supposed to be one reasons they take a 30% cut of all in app purchases. Apple even uses this as an excuse to not allow side loading apps. How are they not blocking this?
- hackernewds 4y agoThought Apple was the bastion of consumer privacy. Apparently removing TikTok though is not commercially beneficial for them not to mention the elephant in the room: Apple Finds Its Next Big Business: Showing Ads on Your iPhone https://www.bloomberg.com/news/newsletters/2022-08-14/apple-aapl-set-to-expand-advertising-bringing-ads-to-maps-tv-and-books-apps-l6tdqqmg https://www.bloomberg.com/news/newsletters/2022-08-14/apple-...
- intelVISA 4y agoApple hashes and sends over wire every bin you run, if that's a 'bastion' then RMS was right.
- latexr 4y agoAds and tracking aren’t inherently linked, it is possible to have one without the other. That’s allegedly what Apple is doing, so it doesn’t clash with the privacy commitment. Even so, I disapprove of Apple’s forays into ads and wish them swift and hard failures in the area.
- alphabetting 4y agoGoogle isn't blocking this because it would be a silver bullet to FTC for aiding Youtube. Apple isn't blocking this because they are beholden to China.
- deleted 4y ago[deleted]
- Gatsky 4y agoTikTok should be banned. India has the right idea. We should align more with them. Banning it isn't for geopolitical reasons although I think those are valid given the CCP's publicly stated agenda (Global communist revolution essentially. Millions of lives sacrificed for Marx). It's just that one less mind hacking app for children is a good thing. What about FB, Insta who are just as bad etc? Simply doesn't matter. If people left FB for TikTok, and TikTok disappears, some significant % won't come back and that's a win.
- skinnymuch 4y agoMarx wouldn’t approve of some sort of great leap 2.0. CCP sucks, but since World Wars, have you seen the list of countries the US alone has invaded or led coups in? Add in the rest of the west. It doesn’t matter much what some state’s publicly stated stuff is. There’s no reason to believe any country blindly. Their actions speak louder.
- mynameismon 4y agoThe more I read about the massively privacy invading features of TikTok, the gladder I am India banned it.
- insane_dreamer 4y agoI wouldn't be surprised if Apple bans in-app browsers before long and forces all apps to use Safari, which would be a good thing.
- rglover 4y agoOh wow, a Chinese military psyop on the West is keylogging everyone? Really? Gee wilikers what a shocker. /s
- adenozine 4y agoNoooo waaaaayyyy, a social media product is doing something dystopian and surveillance-ish!!! /s I’m glad it’s reported on, but it’s almost uninteresting hearing the the same plot line over and over.
- netheril96 4y agoI always hate in app browsers and always reopen them in Safari, for UX reasons. Now I hate them even more, with even stronger reasons.
- MrMetlHed 4y agoIt seems like there should be a setting to make this the default. Sometimes I'll navigate a bit within the in-app browser after clicking on a link from like Twitter or something, and I'd much rather it pop open Firefox or something that I can actually trust. Now it sounds like Apple and Google should start putting warnings on these things by default, yeesh.
- gonehome 4y agoYeah - I never want an in-app browser. I wish it could be broadly disabled at least as an option, though I'd be fine with apple just removing the capability entirely. It's particularly annoying with account cookies and such when I'm already authenticated in the normal browser.
- MBCook 4y agoUnfortunately I think they’re very popular with unsophisticated users. I’ve heard stories about companies getting a ton of support emails because someone clicked on an article link shown in $someApp, the user was booted to Safari, and didn’t know how to get back to where they were before. I’ve heard of developers adding the in-app thing despite hating it personally just to reduce the support burden.
- eyelidlessness 4y agoI’m more of GP’s mindset, but I’ve often wondered how many people would become lost the way you describe if my preference was the default. I have the benefit of knowing distinctly when I’m navigating from app to web, but I can relate to being disoriented navigating between different types of views within a given app. There’s the tiny “back button” in iOS that takes you back to an app which triggered an app context switch, but it’s barely noticeable and barely reachable on most current iPhones. I swipe between apps even when I do notice that. But I’m not sure how widely it’s even known you can swipe between apps. (For anyone reading who doesn’t know, if you have an iPhone without a home button, you can swipe left/right on the space right at the bottom of your screen, where you normally would swipe up, and it’s like the cmd/alt+tab default. You can also do this on the URL bar in Safari to switch tabs, if you stick with the default bottom URL bar.)
- deleted 4y ago[deleted]
- BonoboIO 4y agoIf anybody else would do this, the app would be taken down immediately from the App Store. Probably the developer account banned too. It is Spyware. Nothing else.
- deleted 4y ago[deleted]
- itsananderson 4y agoWhen I used TikTok on Android, it was the most infuriating in-app browser experience because it had no way to open the URL in your real browser. Not even a way to copy the URL to your clipboard. I guess now I understand why
- deleted 4y ago[deleted]
- gunnr15 4y agoIs this the exact type of security Apple is supposed to be protecting its customers from?
- deleted 4y ago[deleted]
- deminature 4y agoThey're going to heavily lockdown WKWebView after the Instagram and Tiktok revelations, probably in iOS16.1. They may even remove it entirely and force people to use SFSafariViewController (heavily locked down web browser, opaque to developers other than URL). Best of luck to anyone that was using javascript injection for legitimate purposes, others have ruined it for everyone by abusing user trust.
- fsckboy 4y ago> They're going to heavily lockdown WKWebView after the Instagram and Tiktok revelations, probably in iOS16.1 are you just making a prediction, or do you have knowledge of this?
- deminature 4y agoJust a guess if I were responsible for making the decision. All these methods will probably disappear or get much tighter on how they can be used: https://developer.apple.com/documentation/webkit/wkusercontentcontroller/1537448-adduserscript https://developer.apple.com/documentation/webkit/wkuserconte... https://developer.apple.com/documentation/webkit/wkwebview/1415017-evaluatejavascript https://developer.apple.com/documentation/webkit/wkwebview/1...
- DecoPerson 4y agoI hope they leave means of communication available. Something like window.postMessage. Like how Chrome extensions can expose a limited part of the Chrome API to webpages so they can post messages to certain extensions, without needing to inject anything into those webpages.
- mark_l_watson 4y ago+1 thanks for the info - it makes sense that Apple would try to mitigate this on their platform. I use Apple’s new Lockdown Mode on the beta iOS 16 and iPadOS 16. I generally like it. It largely disables arbitrary JavaScript, as far as I know. A few times a week, I will turn off Lockdown temporarily for a few minutes for a web site if there are any problems. This is usually Amazon.com’s Kindle preview feature.
- ssalka 4y agoI think the big question is, what are the event handlers doing exactly? I'm definitely not defending any of these companies but it just seems fundamentally unclear what gets done with the data. The presumption is that the event data is passed to some private storage against users' consent. But for all we know it's also possible there are automated filters in place to detect sensitive information and drop/obfuscate it. Still, I wouldn't count on that. I will say that it doesn't look great to have a `keypress` listener on the window/document...certainly that's not used for anything good.
- midislack 4y agoThis is good. It's the price for using the site. They're not alone!
- pyentropy 4y agoI hate that if I send Wordle or something cool to a friend that uses localStorage they lose their progress/settings once they leave the chat app. So frustrating to even explain to people that this thing they are scrolling isn't their own, Safari/Chrome!
- the_gipsy 4y agoIt's just another piece in how Apple sabotaged the web.
- TheRealDunkirk 4y agoSince "the web" has become about 7-10 walled gardens for 90% of the public, whether Apple "sabotages" "the web" in allowing these "garden" apps to use their own browsers is hardly any more broken than anything else.
- sitkack 4y agoYou can ID users based on the cadence and relative timing between keypresses to identify anyone regardless of their login credentials. You can also detect bots, even skillfully crafted ones.
- mark_l_watson 4y agoOff topic, apologies: I read that TikTok contracted with Oracle Cloud to handle computation and data inside the US and do some privacy related data flow checks (not back to China). I wonder how big of a business this is, revenue wise, for Oracle Cloud? I also wonder if anti-TikTok public opinion will rub off on Oracle Cloud?
- vivegi 4y agoIn-app browsers are a huge mess and security/privacy nightmare. Browsers implement a security sandbox. In-app browsers break and circumvent this threat model in nasty ways. I hope this gets the same attention as cross-site scripting (XSS) attacks and browser engines implement strict countermeasures by default locking WebViews to the equivalent of an Incognito/InPrivate tab.
- herpderperator 4y agoHow long until these apps block the URL 'inappbrowser.com' as malicious so you can't use it to see what the app is doing? :P
- chunkyguy 4y agoOr better, not inject anything when detecting inappbrowser.com
- martinsuchan 4y agoI'm just curious, there are plenty of 3rd party full-featured browsers based on WKWebView that are injecting tons of JavaScript into all pages and basically doing the same as in-app browsers. So what's the difference?
- elaus 4y agoThe article actually mentions those: > [...] they use JavaScript to offer some of their functionality, like a password manager. Basically a 3rd-party browser needs to use JS to offer any features or real benefit over simply using Safari. But as a TikTok user you have no benefit when all links open inside the app with tons of custom JS injected that seems to be mainly for tracking you.
- roebk 4y agoCan this be circumvented by a very strict Content-Security-Policy?
- paxys 4y agoIt’s on the browser to enforce CSP headers. In this case the browser itself is doing the malicious script injection. Think of it as a browser extension, just running without your consent. It’s up to the browser - not the website - to reject it.
- soruly 4y agoAll my hobby websites I own have all these in-app browsers blocked.