You know how some popular apps don't let you out of the app when you click on a link, opening said link in their own little in-app browser instead?
As it turns out, this enables these apps to monitor what you do. And among the most popular apps that do this, TikTok appears to be the worst offender.
In a blog post Thursday, security researcher Felix Krause announced the launch of InAppBrowser, a tool that lists all the JavaScript commands executed by an iOS app as its in-app browser renders a webpage.
To show what the tool can do, Krause analyzed some popular iOS apps that have an in-app browser, and the results are disturbing. Krause's data shows that apps including TikTok, Instagram, Facebook Messenger, and Facebook, all modify webpages that are opened in the in-app browser. "This includes adding tracking code (like inputs, text selections, taps, etc.), injecting external JavaScript files, as well as creating new HTML elements," Krause says. They also fetch website metadata, though Krause says this is "harmless."
SEE ALSO: TikTok is a growing source of news among UK adultsWhen Krause dug a little deeper into what these apps' in-app browsers really do, he'd found that TikTok does some bad things, including monitoring all of users' keyboard inputs and taps. So, if you open a web page inside of TikTok's app, and enter your credit card details there, TikTok can access all of those details. TikTok is also the only app, out of all the apps Krause has looked into, that doesn't even offer an option to open the link in the device's default browser, forcing you to go through its own in-app browser.
UPDATE: Aug. 23, 2022, 9:59 a.m. EDT In a chat with Motherboard, Krause explained that his report "doesn’t say TikTok is actually recording and using this data." TikTok told the outlet that his findings are "incorrect and misleading.""We do not collect keystroke or text inputs through this code, which is solely used for debugging, troubleshooting, and performance monitoring,” a TikTok spokesperson said.
Check out Motherboard's article.
In a statement to Forbes, a TikTok spokesperson confirmed the practice, but says that "the Javascript code in question is used only for debugging, troubleshooting, and performance monitoring of that experience."
It's all needed to provide "an optimal user experience," she said.
Other apps Krause has looked at, like Instagram, also do some monitoring of their own, though none of them go as far as TikTok. And Snapchat and Robinhood are good examples, as they don't modify webpages or fetch their metadata of the sites you open in their in-app browsers.
Krause warns that apps actually have a way of hiding their JavaScript activity from his InAppBrowser tool, meaning they could be doing more monitoring behind the scenes. For now, the only way to make sure they can't do any monitoring is to open websites in the device's default browser — if the app even offers this option.
文章
79
浏览
629
获赞
567
Samsung, stop trying to make the Galaxy Buds Live happen
Samsung has basically confirmed its new earbuds will be called the Galaxy Buds Live — not, sadElon Musk's X is now banned in Brazil
Brazil just gave Elon Musk's X the boot.On Friday, Brazil's top court orderedthat Musk's social mediShop Echo devices at their lowest prices at Best Buy
SAVE UP TO $25:The Amazon Echo Dot and Pop are down to some of their lowest prices ever at Best Buy.Best Amazon deals of the day: Apple iPad mini 6, Sonos Beam Gen 2, Amazon 2
Check out the best Amazon deals of the day as of Aug. 29: OUR TOP PICKApple Store is down, you know what that means
Apple Store is down ahead of Apple's event, meaning you'll soon have new ways to part with your hardAI uses too much energy. Big tech won't say how much.
Imagine you're buying a new laptop. You come across a model that can do some pretty nifty stuff, butBest AirTag deals ahead of October Prime Day
Best AirTags deals ahead of Prime Big Deal Day Best overall AirTags dealElon Musk's X fined over $400,000 for refusing to address child abuse concerns
X, formerly Twitter, owes the Australian government some money.Bloomberg reported on Thursday that EHilarious new Tyra Banks meme reveals we're all scared, too
Have you ever had that moment when you're terrified but afraid to express it in front of a group ofYouTube to add tools to detect AI
YouTube is building tools to detect AI-generated likenesses of artists like actors and musicians, thPrime Day 2024 printer deals: Save on HP, Canon
UPDATE: Jul. 10, 2024, 4:05 p.m. EDT This article has been updated to include the latest printer andPrime Day 2024 printer deals: Save on HP, Canon
UPDATE: Jul. 10, 2024, 4:05 p.m. EDT This article has been updated to include the latest printer and26 Years of The Elder Scrolls
It's been nearly a decade and two console generations since Skyrim came out in 2011. Since then, BetBest speaker deal: The Google Nest Audio is just $49.99
SAVE $50:The Google Nest Audio Smart Speaker is on sale for $49.99 at Best Buy, marked down from theBest early Prime Day Apple Watch deals: Series 10, 9, SE, and more
UPDATE: Oct. 7, 2024, 1:15 p.m. EDT This post has been updated with the latest pricing and availabil