SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    TikTok and 53 Other iOS Apps Still Snoop Your Sensitive Clipboard Data
Date    Sunday June 28 2020, @09:48PM
Author    martyb
Topic   
from the subverting-clippy dept.
https://soylentnews.org/article.pl?sid=20/06/28/159203

upstart writes in with an IRC submission:

Apple's iOS 14 beta added a feature that reveals each time an application copies text from the clipboard. A recent article in Ars Technica brought renewed focus to an issue we previously reported in February. This story includes a list of apps from the researcher's blog post.

TikTok and 53 other iOS apps still snoop your sensitive clipboard data:

In March, researchers uncovered a troubling privacy grab by more than four dozen iOS apps including TikTok, the Chinese-owned social media and video-sharing phenomenon that has taken the Internet by storm. Despite TikTok vowing to curb the practice, it continues to access some of Apple users' most sensitive data, which can include passwords, cryptocurrency wallet addresses, account-reset links, and personal messages. Another 53 apps identified in March haven't stopped either.

The privacy invasion is the result of the apps repeatedly reading any text that happens to reside in clipboards, which computers and other devices use to store data that has been cut or copied from things like password managers and email programs. With no clear reason for doing so, researchers Talal Haj Bakry and Tommy Mysk found, the apps deliberately called an iOS programming interface that retrieves text from users' clipboards.

[...] In many cases, the covert reading isn't limited to data stored on the local device. In the event the iPhone or iPad uses the same Apple ID as other Apple devices and are within roughly 10 feet of each other, all of them share a universal clipboard, meaning contents can be copied from the app of one device and pasted into an app running on a separate device.

That leaves open the possibility that an app on an iPhone will read sensitive data on the clipboards of other connected devices. This could include bitcoin addresses, passwords, or email messages that are temporarily stored on the clipboard of a nearby Mac or iPad. Despite running on a separate device, the iOS apps can easily read the sensitive data stored on the other machines.

[...] TikTok's continued snooping has gotten extra scrutiny for other reasons. When called out in March, the video-sharing provider told UK publication The Telegraph it would end the practice in the coming weeks. Mysk said that the app never stopped the monitoring. What's more, a Wednesday Twitter thread revealed that the clipboard reading occurred each time a user entered a punctuation mark or tapped the space bar while composing a comment. That means the clipboard reading can happen every second or so, a much more aggressive pace than documented in the March research, which found monitoring happened when the app was opened or reopened.

A tweet by Jeremy Burge gives an example of how this can be reproduced:

To reproduce:
1. Have something on your clipboard. Eg copy some text from Notes or a website
2. Open TikTok and start typing in any text field
3. You learn from iOS 14 beta each time an app "pastes" - but in this instance I didn't request it, and none of that text appears in UI

— Jeremy Burge (@jeremyburge) June 24, 2020

Here is the list of apps (emphasis retained from original) from a researcher's blog post:

List of Apps

This section summarizes the list of apps that snoop on the pasteboard every time the app is opened. The apps are listed alphabetically in the following format:

News

Games

Social Networking

Other

Note: the list is not meant to be exhaustive. The researchers surveyed a selection of popular apps. Given how many were found, it is likely there are many more.


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "previously reported" - https://soylentnews.org/article.pl?sid=20/02/27/0036244
  3. "blog post" - https://www.mysk.blog/2020/03/10/popular-iphone-and-ipad-apps-snooping-on-the-pasteboard/
  4. "TikTok and 53 other iOS apps still snoop your sensitive clipboard data" - https://arstechnica.com/gadgets/2020/06/tiktok-and-53-other-ios-apps-still-snoop-your-sensitive-clipboard-data/
  5. "researchers Talal Haj Bakry and Tommy Mysk found" - https://www.mysk.blog/2020/03/10/popular-iphone-and-ipad-apps-snooping-on-the-pasteboard/
  6. "universal clipboard" - https://support.apple.com/en-us/HT209460
  7. "end the practice in the coming weeks" - https://www.telegraph.co.uk/technology/2020/03/30/popular-apps-can-read-phones-clipboard-without-permission/
  8. "Wednesday Twitter thread" - https://twitter.com/jeremyburge/status/1276269507087138821
  9. "June 24, 2020" - https://twitter.com/jeremyburge/status/1275896964249530371?ref_src=twsrc%5Etfw
  10. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=41808

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, TikTok and 53 Other iOS Apps Still Snoop Your Sensitive Clipboard Data on 2024-04-25 21:13:14