LinkedIn's iOS app has taken the ongoing issue of snooping at users' clipboards to whole,Seung Ha (승하) Archives new level. The company has already said it's a mistake that will be fixed.
The issue of iOS apps monitoring copy-paste data has been a subject of concern since March, when a pair of software developers published their research. Tommy Mysk and Talal Haj Bakry discovered that a large number of existing apps (at the time) checked out users' clipboard data every time those apps were opened.
This is alarming when you really sit down and think back on all the times you've copy-pasted sensitive data, such as a sign-in credentials from your password locker or a credit card number that you don't feel like typing in again. If you haven't done that, great. But plenty of people have. And you probably don't want strangers peeping at your clipboard data regardless.
The snooping issue reared up again in recent weeks with the beta release of iOS 14. Apple's next major operating system update for iPhone includes a new feature that lets people look at how their data is being accessed, something that's been described as the privacy equivalent of "nutrition labels."
As people started playing with the beta, some discovered that a number of major apps, like TikTok, are still doing some form of clipboard snooping. On Thursday, one Twitter user, Don Morton, demonstrated how LinkedIn's snooping is among the most invasive examples, with the app copying what's in the clipboard with every keystroke.
This Tweet is currently unavailable. It might be loading or has been removed.
Morton also discovered that Reddit's app is doing the same thing. (A fix is in the making for that as well.)
This Tweet is currently unavailable. It might be loading or has been removed.
Morton went and wrote at greater length about the real issue with this snooping in a Substack post. While these companies ought to fix their apps, he wrote, the bigger issue is that such data is accessible to developers in the first place.
"I could easily see 'phishing apps' starting to pop up (if they are not already) with the sole intention to scrape as much clipboard data as possible. To me, this is just as bad or even more worrying than the companies that have already been called out for it. For the most part, the companies that have been getting called out have motive to be 'good'. I’m just starting to think about companies or apps that have no intention of being good," Morton wrote.
The Substack post also includes a list of major apps that are still doing the snooping (and any company response, when there is one). He also recommends checking to see if your password manager has a feature that wipes clipboard data after a short amount of time.
LinkedIn exec Erran Berger responded to Morton's tweet with a technical explanation of what's happening here, adding that "we don't store or transmit the clipboard contents." A company spokesperson later confirmed to ZDNet that the issue is a bug, and work is already underway on a fix.
UPDATE: July 4, 2020, 4:04 p.m. EDT Added a note about Reddit confirming a fix is coming.
Topics Cybersecurity iOS LinkedIn Privacy
Ford cars add Android Auto and Apple CarPlay in first OTA updateTry not to obsess over this monkey named 'Uncle Fat'Inside the haunting, tooThe conspiracy theory behind Gisele Bündchen's troubling Tom Brady revelationYouTube expands mobile livestreaming capabilities to more usersThis is what happens when you let kids choose their baseball team name'Luke Cage' Season 2 aims for 'bulletproof dopeness,' says showrunnerJeff Sessions trolled with KKK costume projected on a building in D.C.There is a protective bubble around Earth and we put it thereCheck out this exclusive art for the new SpiderJustin Timberlake finally replies to that Seth Rogen tweetBeauty bloggers are trying to make pomFacebook's new notifications bundle Instagram and Messenger together'DuckTales' reboot taps LinTake a sneak peek at four new 'Overwatch' skins coming next weekPrepare your sweet tooth: A Nutella café is coming to the U.S.How 'Unbreakable Kimmy Schmidt' pulled off a flawless 'Lemonade' tributeBeauty bloggers are trying to make pomThe future of retail is permanent popOh my god, please shut up about The Skimm Secret Service shelled out $7,500 on golf carts this Thanksgiving 6 helpful Google Calendar tips and tricks Randi Zuckerberg tweets about sexual harassment on Alaska Air flight HBO Max launches annual subscriptions and tiers Watch Matt Lauer's interview with Bill O'Reilly over sexual harassment Kahlil Greene uncovers the whitewashed origins of TikTok trends Xiaomi shows off phone that can charge to 100% in 8 minutes Thousands of Tesla cars recalled for loose brake bolt British Parliament is actually calling on Trump to delete his Twitter account Twitter revives the Trump/Obama crowd size debate after tree lighting ceremony NASA Mars rover sends back photos of shimmering, otherworldly clouds Australia wants to throw Prince Harry his bachelor party 'Gravity Falls' is the perfect show for the start of summer Hilarious Amazon fail is too good to even get mad about Twitch warns creators about a wave of DMCA takedown requests I, not Ryan, started the fire in 'The Office'. The cloud made me do it. Mashable wants your post 5 things you didn't know you could do with a Roku NBC employees reveal chilling details of Matt Lauer's alleged sexual harassment FDA clears heart monitoring AliveCor Kardia Band for the Apple Watch
1.611s , 10136.2578125 kb
Copyright © 2025 Powered by 【Seung Ha (승하) Archives】,Pursuit Information Network