• Snot Flickerman@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    209
    arrow-down
    6
    ·
    edit-2
    9 months ago

    TL;DR: ProtonMail might want to delete this before they get sued by Meta for defamation, because the original research does not say that about Meta, it says it about TikTok.

    I found the same sources, but if you’ll notice, the article that ProtonMail linked to actually isn’t about that. It’s about a different and new Facebook thing that has iffy privacy settings as well.

    It links to another Gizmodo article about it, buried deep in ONE paragraph.

    The problem? That article is about TikTok and the things detailed about the javascript injected that’s keylogging is all related to TikTok.

    When you click on a link in the Facebook or Instagram apps, the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing.

    This paragraph from the article links to this article in question:

    https://gizmodo.com/tiktok-keylogging-privacy-meta-1849433690

    This article references Meta a few times but is mostly about TikTok. Then THAT article links to the original blog post:

    https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser

    He has info on TikTok and Instagram, and while Instagram is injecting javascript into an internal browser instead of the default system browser, it is not noted as capturing text including passwords.

    Capturing text and passwords is only ascribed by the security research to TikTok and TikTok alone. Meta companies are using similar Js injection tactics, but they, according to the original research, do not include keylogging.

    • RaoulDook@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 months ago

      That lines up with everything I’ve read about TikTok being the worst of the spyware social media apps. Unfortunately most online discussion about that subject gets filled with “Whatabout America spying?” posts trying to normalize the acceptance of everybody doing it. The discussions should be about how TikTok is the worst AND Facebook is close on their tails for the race of spying. All of the spyware social media apps are a bad thing.