LinkedIn Says iOS Clipboard Snooping After Every Key Press is a Bug, Will Fix (zdnet.com) 38
A LinkedIn spokesperson told ZDNet this week that a bug in the company's iOS app was responsible for a seemingly privacy-intrusive behavior spotted by one of its users on Thursday. From a report: The issue was discovered using the new beta version of iOS 14. For iOS 14, set to be officially released in the fall, Apple has added a new privacy feature that shows a quick popup that lets users know when an app has read content from their clipboard. Using this new mechanism, users spotted last week how Chinese mobile app TikTok was reading content from their clipboard at regular short intervals. TikTok said the feature was part of a fraud detection mechanism and that the company never stole the clipboard content, but promised to remove the behavior anyway, to put users' minds at ease. This week, users continued experimenting with this new iOS 14 clipboard access detection system. Yesterday, a developer from the portfolio-building portal Urspace.io discovered a similar mechanism in the LinkedIn iOS app. In a video shared on Twitter, the Urspace developer showed how LinkedIn's app was reading the clipboard content after every user key press, even accessing the shared clipboard feature that allows iOS apps to read content from a user's macOS clipboard.
LinkedIn is one of the worst companies ever (Score:4, Informative)
Re: (Score:1)
Re: (Score:3, Informative)
Re: (Score:2)
Re: (Score:1)
"Linkedin helped me keep in touch with my ex-colleagues which was key to how I landed my last job"
It's called a rolodex, or as you people with your smartphones call it - a contacts list. Do you not know how to use one?
Re: LinkedIn is one of the worst companies ever (Score:1)
Re: (Score:1)
Remember that thing called television? A President of the United States once included in a televised speech the outcome of a baby's birth to comedianne Lucille Ball, whose marriage to Desi Arnez was being parodied in "I Love Lucy
Re: (Score:2)
Yes, I remember television. It was obsolete the instant on-demand was invented and that was long overdue.
Re: (Score:1)
Re: (Score:1)
Stealing what, exactly? I use LinkedIn for precisely two things:
* A place to put my resume online
* A contact list of colleagues I've worked with
The resume is public information. There's literally nothing to steal. Anyone is welcome to that information, as that's the point of a resume/CV. So there's no privacy issue here. The contact list is valuable to LinkedIn in aggregate, so they have an incentive to keep it private. I don't consider it all that confidential, but they're welcome to monetize that in
Re: (Score:2)
Re: (Score:2)
Assume all your datas are kept from companies. :(
"A bug", sure. (Score:5, Interesting)
You have to deliberately use the API to get the clipboard contents. The code to do so in the app shouldn't exist at all; someone must have put it there. How on earth do they expect anyone with even a little programming experience to believe that's "a bug"?
No, you got caught with your pants down just like other companies. Fix your shit and own up to it.
Re: (Score:2)
it's possible that they are using a third-party antifraud sdk and didn't think about disabling this feature. that would be a bug.
iOS business app development is mostly just gluing libraries together anyway. wouldn't be the first time something like this happened.
Re: (Score:2)
Re: (Score:2)
That seems likely.
When you include a library does it automatically get all of your app's permissions or do you have to explicitly delegate them?
Re: (Score:2)
For example, some input field is restricted to four characters, so I cannot paste more than four characters from the clipboard, so I check after each
Agreed (Score:2)
Agreed. I've been programming for longer than many Slashdot members have been alive, and I could see multiple routes to this bug.
I've also been actively studying, learning more, the entire time (currently via postgrad courses at Georgia Tech, among other things.)
Definitely possible for it to be a bug.
> You would do that whenever the app comes back to the foreground (because that means the user could have been in another app and copied something).
Well yeah that kinda does prove there is a
Again ? (Score:4, Informative)
I deleted the LinkedIn application when it happened, the web version is sufficient and less risky.
Never trust such a company.
Re: Again ? (Score:2)
I think that's a good idea in general. If a company has an app, but also has a perfectly serviceable mobile web site that does the same thing, avoid the app and just use the web site. I do this for a certain prescription discount company.
It's hard to believe (Score:5, Insightful)
Maybe you want to give companies that do this the benefit of the doubt. Maybe (and I speak without specific knowledge of developing iOS apps), some library they used had such a feature enabled by default (in which case shame on the library).
But, we see so much of this these days, I think a lot of folk's "benefit-of-the-doubt" bucket has been drained... and we assume the worst. Because Linkedin is one of those "information" companies, who's core business depends on how much info they have, and/or having more info than The Other Guy, it makes it all the harder to give them the benefit of the doubt.
Plus, of course, them calling it a bug. Suuuure. In my mind, a bug is something that crashes your program or gives a wrong answer to a calculation... not that does something (and does it correctly) that the program isn't supposed to do.
I won't be so naive as to say I don't know why every company these days seems to "telemeter" everything, even when they make a paid product. I just wish we hadn't ended up in a world where it was so prevalent.
Now, to go back to browsing the web on AmigaDOS...
Re: (Score:2, Funny)
Plus, of course, them calling it a bug. Suuuure. In my mind, a bug is something that crashes your program or gives a wrong answer to a calculation... not that does something (and does it correctly) that the program isn't supposed to do.
Well, your definition of "bug" is wrong. Something that shows an alert to a user without any need is a bug. Looking at the clipboard was no bug yesterday, but today it is.
Re: (Score:2)
Don't act so surprised. Everyone in the early 90s knew this was going to be the result of 'everything computers'. It's just that along the way, people have tried over and over to keep up with the mainstream mentality that, 'conspiracy theorists' are just annoying nerds that need tinfoil hats, trying to tell all of the 'sheeple' to wake up.' Remember all that BS? Yeah, it wasn't BS, and still isn't.
This will get worse and worse, and more and more things that, today, are seen as normal everyday life thing
Re: (Score:2)
Also, arguing, the way I am now, will land you in jail or worse.
Probably. Me too, but, at this rate, at least l'll be sharing a cell with actual humans instead of corporate soul suckers.
Re: (Score:2)
haha, we'll share a lot of comma-heavy conversations. ;) Looking forward to it.
Re: (Score:3)
Re: (Score:2)
Hand in cookie jar is a bug (Score:2)
Re: (Score:2)
If only I had mod points
oops it is a bug, sorry, will put another bug^H^H^H fix in to correct the problem
Seems this is happening a lot these days
Re: (Score:2)
Hand in cookie jar is a bug
Dick pick in the clipboard is a defense against the bug.
dumb as a fox (Score:3)
LinkedIn = Microsoft (Score:3, Informative)
Headline should have been, "Microsoft caught stealing clipboard contents".
There is no such thing as "LinkedIn" anymore. It is only a Microsoft brand and trademark now.
So I joined Linkiedin (Score:2)
just to add y business to it BUT wtf is it? It looks like a Google+ with spam promoting shit business and SEO spam posts.
TikTok Spying & LinkedIn Bug... Hypocrisy! (Score:2)
You know you're being manipulated when you only change the variable name in your code and you get a different outcome at runtime.
"Is a bug" (Score:2)
"LinkedIn Says iOS Clipboard Snooping After Every Key Press is a Bug"
Lol, right, a 'bug'. That's fucking adorable. "Whoops, clumsy ol' me!"
Comment removed (Score:3)
So, iOS v13 and earlier are OK? (Score:2)
And only v14 beta?