You know how some popular apps don't let you out of the app when you click on a link, opening said link in their own little in-app browser instead?
As it turns out, this enables these apps to monitor what you do. And among the most popular apps that do this, TikTok appears to be the worst offender.
In a blog post Thursday, security researcher Felix Krause announced the launch of InAppBrowser, a tool that lists all the JavaScript commands executed by an iOS app as its in-app browser renders a webpage.
To show what the tool can do, Krause analyzed some popular iOS apps that have an in-app browser, and the results are disturbing. Krause's data shows that apps including TikTok, Instagram, Facebook Messenger, and Facebook, all modify webpages that are opened in the in-app browser. "This includes adding tracking code (like inputs, text selections, taps, etc.), injecting external JavaScript files, as well as creating new HTML elements," Krause says. They also fetch website metadata, though Krause says this is "harmless."
SEE ALSO: TikTok is a growing source of news among UK adultsWhen Krause dug a little deeper into what these apps' in-app browsers really do, he'd found that TikTok does some bad things, including monitoring all of users' keyboard inputs and taps. So, if you open a web page inside of TikTok's app, and enter your credit card details there, TikTok can access all of those details. TikTok is also the only app, out of all the apps Krause has looked into, that doesn't even offer an option to open the link in the device's default browser, forcing you to go through its own in-app browser.
UPDATE: Aug. 23, 2022, 9:59 a.m. EDT In a chat with Motherboard, Krause explained that his report "doesn’t say TikTok is actually recording and using this data." TikTok told the outlet that his findings are "incorrect and misleading.""We do not collect keystroke or text inputs through this code, which is solely used for debugging, troubleshooting, and performance monitoring,” a TikTok spokesperson said.
Check out Motherboard's article.
In a statement to Forbes, a TikTok spokesperson confirmed the practice, but says that "the Javascript code in question is used only for debugging, troubleshooting, and performance monitoring of that experience."
It's all needed to provide "an optimal user experience," she said.
Other apps Krause has looked at, like Instagram, also do some monitoring of their own, though none of them go as far as TikTok. And Snapchat and Robinhood are good examples, as they don't modify webpages or fetch their metadata of the sites you open in their in-app browsers.
Krause warns that apps actually have a way of hiding their JavaScript activity from his InAppBrowser tool, meaning they could be doing more monitoring behind the scenes. For now, the only way to make sure they can't do any monitoring is to open websites in the device's default browser — if the app even offers this option.
文章
1
浏览
68473
获赞
96
Here's a trick when you're stuck talking politics on Thanksgiving
Yep, folks, it's that time again. Off we go to home and hearth, suiting up for battle with Crazy FoxThere's a new Poco phone out, but it's kinda boring
When Xiaomi launched its Poco F1 (or Pocophone F1, depending on the market) phone in 2018, it made qAnnouncer sings 'Mr. Plow' song from 'The Simpsons' during Apple Cup blizzard
There's a Simpson's reference for any occasion.Friday night's annual Apple Cup was no exception. TheA cheerleader tried to trade pot brownies for homecoming queen votes
In an unprecedented and honestly impressive move, a cheerleader in Hartford, Michigan, last week attWhat If Microsoft Had Released an Officebook Instead of the Surface RT
Ever since release I've been following Microsoft's Surface tablets, and when I say following I meanThe hearing's over, but Twitter isn't buying Kavanaugh's argument
Brett Kavanaugh's seemingly tenuous relationship with the truth is still haunting those who watchedHow Britain's new child privacy protections will impact the internet
A massive crackdown on how tech and social media companies use children's data is underway in the UKA dog accidentally shot his owner with a gun
While driving to the New Mexico desert for a jackrabbit hunting trip with his trio of dogs, Tex HaroThe real winner at the AMAs was Lizzo's tiny purse
Famous performers from around the world gathered in Los Angeles on Sunday night for the 2019 AmericaApple rumored to release a stack of new gadgets in 2020. Here's what we know.
We know from multiple reports that Apple is planning to launch an affordable, 4.7-inch smartphone, lA dog accidentally shot his owner with a gun
While driving to the New Mexico desert for a jackrabbit hunting trip with his trio of dogs, Tex HaroSamsung's foldable Galaxy Z Flip could have a crease in its display
It turns out the most mocked feature of Samsung's Galaxy Fold could be making a comeback in the comp5 things I noticed during my 24 hours with the Apple Watch Series 6
Given my very brief time with the Apple Watch Series 6, I’m a little hesitant to fully deliverWatch Michelle Obama's eyebrows as she reveals that Melania Trump ignored her offer for advice
The complicated relationship between former First Lady Michelle Obama and current First Lady MelaniaUber launches new translation tool with more than 100 languages
It's great to get out of the country. But what happens when you get to Colombia or France or Belarus