Post ANVpkgBCOOERLDsGMi by lx@tooting.ch
(DIR) More posts by lx@tooting.ch
(DIR) Post #ANVpkgBCOOERLDsGMi by lx@tooting.ch
2022-09-11T06:27:34Z
0 likes, 0 repeats
RT @KrauseFX@twitter.com: "When opening a website from within the TikTok iOS app, they inject code that can observe every keyboard input (which may include credit card details, passwords or other sensitive information)TikTok also has code to observe all taps, like clicking on any buttons or links."https://twitter.com/KrauseFx/status/1560372509639311366
(DIR) Post #ANVpkgh6TlkiwAnk5w by strypey@mastodon.nzoss.nz
2022-09-13T05:56:43Z
0 likes, 0 repeats
@lxI thought Apple has removed the ability to do stuff like this in iThing apps?
(DIR) Post #ANVr4Xj1dRlYrljRB2 by lx@tooting.ch
2022-09-13T06:11:30Z
0 likes, 0 repeats
@strypey I don’t think that’s possible but they usually check every app when they approve it onto the store. I am sure TikTok found a way around their checks.Maybe CSP would help but that is another can of worms for website developers.