Article count:16428 Read by:87919360

Hottest Technical Articles
Exclusive: A senior executive of NetEase Games was taken away for investigation due to corruption
OPPO is going global, and moving forward
It is reported that Xiaohongshu is testing to directly direct traffic to personal WeChat; Luckin Coffee is reported to enter the US and hit Starbucks with $2, but the official declined to comment; It is reported that JD Pay will be connected to Taobao and Tmall丨E-commerce Morning News
Yu Kai of Horizon Robotics stands at the historical crossroads of China's intelligent driving
Lei Jun: Don't be superstitious about BBA, domestic brands are rising in an all-round way; Big V angrily criticized Porsche 4S store recall "sexy operation": brainless and illegal; Renault returns to China and is building a research and development team
A single sentence from an overseas blogger caused an overseas product to become scrapped instantly. This is a painful lesson. Amazon, Walmart, etc. began to implement a no-return and refund policy. A "civil war" broke out between Temu's semi-hosted and fully-hosted services.
Tmall 3C home appliances double 11 explosion: brands and platforms rush to
Shareholders reveal the inside story of Huayun Data fraud: thousands of official seals were forged, and more than 3 billion yuan was defrauded; Musk was exposed to want 14 mothers and children to live in a secret family estate; Yang Yuanqing said that Lenovo had difficulty recruiting employees when it went overseas in the early days
The app is coming! Robin Li will give a keynote speech on November 12, and the poster reveals a huge amount of information
It is said that Zhong Shanshan asked the packaged water department to sign a "military order" and the entire department would be dismissed if the performance did not meet the standard; Ren Zhengfei said that it is still impossible to say that Huawei has survived; Bilibili reported that employees manipulated the lottery丨Leifeng Morning News
Account Entry

Privacy violation? After TikTok and 53 other apps were exposed, netizens revealed that LinkedIn frequently accessed the iOS clipboard. LinkedIn: It’s a bug

Latest update time:2020-07-04
    Reads:


Android is probably in a worse situation than iOS

Author | Fu Jing

On June 23, 2020, Beijing time, Apple released the iOS 14.0 Developer Beta (developer test) version and iOS 14.0 Public Beta (public test) version at the WWDC 2020 Global Developers Conference.

iOS 14 has many features, one of which is a privacy protection feature-when a third-party application accesses the iPhone clipboard, the user will receive a reminder message.

However, when using the iOS 14 beta version, a LinkedIn user discovered a loophole and the user's privacy was suspected to have been violated.

1


Is LinkedIn violating user privacy?

On July 3, a user named “DonCubed” tweeted:

LinkedIn copies the contents of my clipboard every time I use the keyboard. When I use the iPad Pro, LinkedIn copies the contents of my MacBook Pro clipboard.

Under this tweet, "DonCubed" also attached a screen recording. It is not difficult to find that when the user enters text, a prompt with the content "LinkedIn pasted from another device" keeps appearing on the top of the screen.

Leifeng.com noted that a LinkedIn vice president, Erran Berger, responded:

After tracing the code path, we found that this situation is just a check of the equality between the clipboard content and the content currently typed in the text box. We do not store or transmit any clipboard content.

Recently, a LinkedIn spokesperson told foreign media ZDNet that the above situation discovered by users is a bug, and a fix for this bug is being developed and will be provided to users as soon as possible.

In this regard, Twitter user "DonCubed" gave a very simple and crude solution:

Switch to Android.

On the other hand, Weibo netizens were also shocked.

2


53 apps revealed

In fact, LinkedIn is not the only app that has encountered similar situations.

A week ago, a netizen named "Jeremy Burge" tweeted:

Every 1-3 times I type on the keyboard, TikTok will paste the contents of my clipboard.

The netizen also attached a screen recording, in which the iPhone kept reminding people.

Foreign media Naked Security reported that as early as March 2020, researchers Talal Haj Bakry and Tommy Mysk revealed that TikTok on Android and iOS can automatically read anything that users copy to the device clipboard, such as selfies, passwords, bank account information, and Bitcoin addresses. It is said that the data obtained will be used for advertising and tracking.

It is worth noting that this clipboard content copying mode is not only applicable to the local data of the device, but also to nearby devices (referring to two devices that share an Apple ID and are within 10 feet of each other).

As soon as the iOS 14 beta version and its privacy protection features were launched, many users discovered the clues. Therefore, TikTok responded:

This is because the function of combating spam and malicious swiping of comments accidentally triggered the system reminder. Some users will continue to swipe meaningless spam comments, and their main method is to click on the text box, copy, paste, and send. Therefore, TikTok launched the corresponding function, but this function does not access any content of the user's clipboard.

However, foreign media Naked Security released a complete list of 53 apps that have been found to have similar situations on June 30th local time (as shown below).

The list includes many apps that are familiar to us, such as the New York Times, CNBC, Reuters, The Economist, The Wall Street Journal, Weibo, etc.

So, since this situation has occurred on the iOS side, can we just switch to Android as netizens say?

Foreign media Naked Security also said that the situation on Android may be more serious - researcher Tommy Mysk said that considering that the Android API is much more relaxed, the situation on Android should be worse than that on iOS.

For example, before the release of Android 10, apps running in the background could also read the clipboard, while iOS apps could only do so when running in the foreground.

Source:

  • https://www.zdnet.com/article/linkedin-says-ios-clipboard-snooping-after-every-key-press-is-a-bug-will-fix/

  • https://nakedsecurity.sophos.com/2020/06/30/ios-14-flags-tiktok-53-other-apps-spying-on-iphone-clipboards/


Previous recommendations




Latest articles about

Database "Suicide Squad" 
Exclusive: Yin Shiming takes over as President of Google Cloud China 
After more than 150 days in space, the US astronaut has become thin and has a cone-shaped face. NASA insists that she is safe and healthy; it is reported that the general manager of marketing of NetEase Games has resigned but has not lost contact; Yuanhang Automobile has reduced salaries and laid off employees, and delayed salary payments 
Exclusive: Google Cloud China's top executive Li Kongyuan may leave, former Microsoft executive Shen Bin is expected to take over 
Tiktok's daily transaction volume is growing very slowly, far behind Temu; Amazon employees exposed that they work overtime without compensation; Trump's tariff proposal may cause a surge in the prices of imported goods in the United States 
OpenAI's 7-year security veteran and Chinese executive officially announced his resignation and may return to China; Yan Shuicheng resigned as the president of Kunlun Wanwei Research Institute; ByteDance's self-developed video generation model is open for use丨AI Intelligence Bureau 
Seven Swordsmen 
A 39-year-old man died suddenly while working after working 41 hours of overtime in 8 days. The company involved: It is a labor dispatch company; NetEase Games executives were taken away for investigation due to corruption; ByteDance does not encourage employees to call each other "brother" or "sister" 
The competition pressure on Douyin products is getting bigger and bigger, and the original hot-selling routines are no longer effective; scalpers are frantically making money across borders, and Pop Mart has become the code for wealth; Chinese has become the highest-paid foreign language in Mexico丨Overseas Morning News 
ByteDance has launched internal testing of Doubao, officially entering the field of AI video generation; Trump's return may be beneficial to the development of AI; Taobao upgrades its AI product "Business Manager" to help Double Eleven丨AI Intelligence Bureau 

 
EEWorld WeChat Subscription

 
EEWorld WeChat Service Number

 
AutoDevelopers

About Us Customer Service Contact Information Datasheet Sitemap LatestNews

Room 1530, Zhongguancun MOOC Times Building,Block B, 18 Zhongguancun Street, Haidian District,Beijing, China Tel:(010)82350740 Postcode:100190

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号