Privacy violation? After TikTok and 53 other apps were exposed, netizens revealed that LinkedIn frequently accessed the iOS clipboard. LinkedIn: It’s a bug
Author | Fu Jing
On June 23, 2020, Beijing time, Apple released the iOS 14.0 Developer Beta (developer test) version and iOS 14.0 Public Beta (public test) version at the WWDC 2020 Global Developers Conference.
iOS 14 has many features, one of which is a privacy protection feature-when a third-party application accesses the iPhone clipboard, the user will receive a reminder message.
However, when using the iOS 14 beta version, a LinkedIn user discovered a loophole and the user's privacy was suspected to have been violated.
1
Is LinkedIn violating user privacy?
On July 3, a user named “DonCubed” tweeted:
LinkedIn copies the contents of my clipboard every time I use the keyboard. When I use the iPad Pro, LinkedIn copies the contents of my MacBook Pro clipboard.
Under this tweet, "DonCubed" also attached a screen recording. It is not difficult to find that when the user enters text, a prompt with the content "LinkedIn pasted from another device" keeps appearing on the top of the screen.
Leifeng.com noted that a LinkedIn vice president, Erran Berger, responded:
After tracing the code path, we found that this situation is just a check of the equality between the clipboard content and the content currently typed in the text box. We do not store or transmit any clipboard content.
Recently, a LinkedIn spokesperson told foreign media ZDNet that the above situation discovered by users is a bug, and a fix for this bug is being developed and will be provided to users as soon as possible.
In this regard, Twitter user "DonCubed" gave a very simple and crude solution:
Switch to Android.
On the other hand, Weibo netizens were also shocked.
2
53 apps revealed
In fact, LinkedIn is not the only app that has encountered similar situations.
A week ago, a netizen named "Jeremy Burge" tweeted:
Every 1-3 times I type on the keyboard, TikTok will paste the contents of my clipboard.
The netizen also attached a screen recording, in which the iPhone kept reminding people.
Foreign media Naked Security reported that as early as March 2020, researchers Talal Haj Bakry and Tommy Mysk revealed that TikTok on Android and iOS can automatically read anything that users copy to the device clipboard, such as selfies, passwords, bank account information, and Bitcoin addresses. It is said that the data obtained will be used for advertising and tracking.
It is worth noting that this clipboard content copying mode is not only applicable to the local data of the device, but also to nearby devices (referring to two devices that share an Apple ID and are within 10 feet of each other).
As soon as the iOS 14 beta version and its privacy protection features were launched, many users discovered the clues. Therefore, TikTok responded:
This is because the function of combating spam and malicious swiping of comments accidentally triggered the system reminder. Some users will continue to swipe meaningless spam comments, and their main method is to click on the text box, copy, paste, and send. Therefore, TikTok launched the corresponding function, but this function does not access any content of the user's clipboard.
However, foreign media Naked Security released a complete list of 53 apps that have been found to have similar situations on June 30th local time (as shown below).
The list includes many apps that are familiar to us, such as the New York Times, CNBC, Reuters, The Economist, The Wall Street Journal, Weibo, etc.
So, since this situation has occurred on the iOS side, can we just switch to Android as netizens say?
Foreign media Naked Security also said that the situation on Android may be more serious - researcher Tommy Mysk said that considering that the Android API is much more relaxed, the situation on Android should be worse than that on iOS.
For example, before the release of Android 10, apps running in the background could also read the clipboard, while iOS apps could only do so when running in the foreground.
Source:
-
https://www.zdnet.com/article/linkedin-says-ios-clipboard-snooping-after-every-key-press-is-a-bug-will-fix/
-
https://nakedsecurity.sophos.com/2020/06/30/ios-14-flags-tiktok-53-other-apps-spying-on-iphone-clipboards/
Previous recommendations