I often offer "suggestion" on peoples faces. Some are not too happy about it.
But seriously, I think this isn't as much a problem if the user is made aware of the fact, which I would dispute being the case.
Clipboards might contain sensitive info, so that would disqualify any of those apps and consequently the phone in a corporate context and in a context of, frankly speaking, saner people.
Should work like all other privacy settings. The first time the app tries to access the clipboard, the OS should prompt “Reddit is trying to access the clipboard [Allow / Deny]”. Then the preference is set and can be changed in settings.
They have this for certain things. MyFitnessPal asks me incessantly to have access to my "step" permission. I vehemently agree we should have more access to fine-grain permissions. Although apps should be punished for nagging me to change my settings every time I open the app.
This kind of thing is why I insist on using Reddit via mobile Web instead of their app, no matter how much they nag me to switch. Native apps allow lots of invasions of privacy like this. Web apps inherently don't, and they can still do everything that I'd want for sites like Reddit.
+1. RedReader[1] is just awesome. In fact it's one of the few UIs I've used that I felt completely at home with from the first time I used it. It's filled to the brim with tools and options but I always find what I'm looking for.
In that case, I'd still have to either audit the app's code or trust the author. With mobile Web, I know it won't spy on me like that because the browser won't let it.
The problem is that you cannot lock down the browser either.
You can deny some sorts of things, but -- and this is all apple -- you do not have permission to install really useful extensions that put control in your hands.
Examples available on macos (so far) that are different:
* firefox + umatrix which give fine control of what is permitted/not at the browser level
* little snitch which can give fine-grained control of what network access applications can have (and the browser can be further restricted)
(I think little snitch might have a hole where dns lookups might still go through, unverified)
I've removed them. Is there any justification why these apps shouldn't simply be listed with a spyware warning? I've tried to see the "innocent misunderstanding" angle but I just can't.
Linkedin. Not sure why it needed to snoop the clipboard. Anyone care to explain why it needed that access?
I can't see any reason why Reddit needed it either. Reddit broke their web experience as well.
Can't these apps rely on paste? Or it is a tooling/sdk issue?
I also found the app I use to top up phone credit was demanding camera access on android. Removed that as well. Spyware.
If this is spyware and the actual contents are being sent somewhere, you’ll hear about it.
This seems pretty overblown. Here is a simple explanation: the apps exhibit different behavior when a relevant URL is on the clipboard. Reddit does this.
That being said, I’m glad apple is giving the clipboard some privacy attention. Tons of people send their passwords thru the clipboard.
Snooping the clipboard is usually either spyware activity or utility behavior. Its not as if its a password manager expiring a copied password. Its not even something grabbing text from the clipboard because I've set it up to do so in some text processing utility.
Linkedin doesn't need this kind of functionality. They simply got caught.
Plenty of other shenanigans going on. This is likely just one of many.
Genuine Question: Can/Does apple allow some apps to not show this warning. I don't have an iphone but if safari has a feature like Chrome to show the copied url then this should pop up every time I open safari. Which is not good for apple and is a good enough feature I guess.
20 comments
[ 4.5 ms ] story [ 926 ms ] threadBut seriously, I think this isn't as much a problem if the user is made aware of the fact, which I would dispute being the case.
Clipboards might contain sensitive info, so that would disqualify any of those apps and consequently the phone in a corporate context and in a context of, frankly speaking, saner people.
The clipboard is one of those things where this behavior is unwanted. It's one of those where it is important to be asked every time.
Do we know of apps that send the clipboard to a remote server?
[1] https://f-droid.org/app/org.quantumbadger.redreader
You can deny some sorts of things, but -- and this is all apple -- you do not have permission to install really useful extensions that put control in your hands.
Examples available on macos (so far) that are different:
* firefox + umatrix which give fine control of what is permitted/not at the browser level
* little snitch which can give fine-grained control of what network access applications can have (and the browser can be further restricted)
(I think little snitch might have a hole where dns lookups might still go through, unverified)
Linkedin. Not sure why it needed to snoop the clipboard. Anyone care to explain why it needed that access?
I can't see any reason why Reddit needed it either. Reddit broke their web experience as well.
Can't these apps rely on paste? Or it is a tooling/sdk issue?
I also found the app I use to top up phone credit was demanding camera access on android. Removed that as well. Spyware.
This seems pretty overblown. Here is a simple explanation: the apps exhibit different behavior when a relevant URL is on the clipboard. Reddit does this.
That being said, I’m glad apple is giving the clipboard some privacy attention. Tons of people send their passwords thru the clipboard.
Snooping the clipboard is usually either spyware activity or utility behavior. Its not as if its a password manager expiring a copied password. Its not even something grabbing text from the clipboard because I've set it up to do so in some text processing utility.
Linkedin doesn't need this kind of functionality. They simply got caught.
Plenty of other shenanigans going on. This is likely just one of many.
https://news.ycombinator.com/item?id=23716451
https://news.ycombinator.com/item?id=23634138
https://news.ycombinator.com/item?id=23691190