LinkedIn is copying the contents of my clipboard on every keystroke(twitter.com)
twitter.com
LinkedIn is copying the contents of my clipboard on every keystroke
https://twitter.com/doncubed/status/1278757106468806656
360 comments
LinkedIn has a history of acting like a cretin: multiple data breaches, dark patterns where they don't fix their buggy mobile site and just put up a disclaimer "problems with the mobile site - download our app" (just so that they can harvest a wider range of data).
I managed many marketing campaigns on Linkedin over the years and spent thousands each month on the platform as a corporate user. If you think that paying for the service you'd be excluded from their shitty ads and get more granular opt-out features than under a free-subscription model - but nope.
they have literally done nothing to deserve any trust from their users. People still use it because they tell themselves "I might need it one day when I look for a job". That's also wrong - if you're doing it right you build good social connections in the real world because most (if not the only things) you get from LinkedIn is scams.
The only upside where I find LinkedIn useful is for OSINT purposes. It's very easy to find all types of people there and get a rough picture how companies are run (what their employees are working on and what security problems that might imply) and build what the recruiting industry calls talent-maps (competiter analysis) which can be useful in infosec for threat & counter-intel. But it has 0 value for any legitimate purposes (that they advertise the service for).
I managed many marketing campaigns on Linkedin over the years and spent thousands each month on the platform as a corporate user. If you think that paying for the service you'd be excluded from their shitty ads and get more granular opt-out features than under a free-subscription model - but nope.
they have literally done nothing to deserve any trust from their users. People still use it because they tell themselves "I might need it one day when I look for a job". That's also wrong - if you're doing it right you build good social connections in the real world because most (if not the only things) you get from LinkedIn is scams.
The only upside where I find LinkedIn useful is for OSINT purposes. It's very easy to find all types of people there and get a rough picture how companies are run (what their employees are working on and what security problems that might imply) and build what the recruiting industry calls talent-maps (competiter analysis) which can be useful in infosec for threat & counter-intel. But it has 0 value for any legitimate purposes (that they advertise the service for).
You have to imagine the Apple engineers who implemented this new clipboard notification knew this shitstorm was coming.
I've used plenty of software before that offers to do something based on clipboard contents, often when there isn't even anywhere to paste.
E.g. a phone dialer app that asks if you want to dial the number in the clipboard when you start it, an image editor that asks if I want to create a new image size the dimensions of the clipboard, a torrenting program that when I choose to import a torrent automatically grabs it from the clipboard before I even get the choice to pick another option (though I still can).
I would be very surprised if this wasn't originally part of something like that, and maybe the feature was removed but the detection function wasn't.
Because if we put down our pitchforks for a second, LinkedIn is owned by Microsoft, which also owns a major browser and the world's most popular operating system. Microsoft sure as hell doesn't need to sniff your clipboard in LinkedIn, if it wanted to do something for nefarious purposes.
Never attribute to malice that which is adequately explained by stupidity.
E.g. a phone dialer app that asks if you want to dial the number in the clipboard when you start it, an image editor that asks if I want to create a new image size the dimensions of the clipboard, a torrenting program that when I choose to import a torrent automatically grabs it from the clipboard before I even get the choice to pick another option (though I still can).
I would be very surprised if this wasn't originally part of something like that, and maybe the feature was removed but the detection function wasn't.
Because if we put down our pitchforks for a second, LinkedIn is owned by Microsoft, which also owns a major browser and the world's most popular operating system. Microsoft sure as hell doesn't need to sniff your clipboard in LinkedIn, if it wanted to do something for nefarious purposes.
Never attribute to malice that which is adequately explained by stupidity.
This is apparently coming from an open-sourced component called Hakawai.
Somebody had to scramble to remove the clipboard code ASAP: https://github.com/linkedin/Hakawai/commit/fa7e8497040f5c36e...
Edit: Don't do mobile, but seems like it was a hack to distinguish between text that was pasted and text added by autocorrect
Somebody had to scramble to remove the clipboard code ASAP: https://github.com/linkedin/Hakawai/commit/fa7e8497040f5c36e...
Edit: Don't do mobile, but seems like it was a hack to distinguish between text that was pasted and text added by autocorrect
Guess I'm never copying and pasting anything sensitive on my phone ever again. Still don't understand why clipboard-sniffing isn't behind a permissions flag.
LinkedIn has had so many privacy disasters over the years, and it's kinda crazy how we kinda tend to forget most of that eventually. I definitely wouldn't trust them with much of your data.
Very not cool. I am a medium LinkedIn user, but now it is going to be limited strictly to a PC browser, where I have some control. I just uninstalled it from my cell. I got caught in the siren song of convenience.
Now how many other apps do this.
Now how many other apps do this.
My hunch is these things are more boneheaded than nefarious. Probably looking for URLs to share or something silly like that and just implemented poorly. Obviously not good for the PR, but say sorry and fix the bug. Luckily this shouldn't happen much longer once iOS 14 is properly released.
One little weird trick I found is to use the browser for websites.
All the limitations I found on web pages that asks me to download the app are artificial. What is reddit doing that requires an app? What is facebook doing that requires an app? There is even less reasons now to use the YouTube app.
All the limitations I found on web pages that asks me to download the app are artificial. What is reddit doing that requires an app? What is facebook doing that requires an app? There is even less reasons now to use the YouTube app.
I thought I was safe if I blocked all of the permissions these apps "require" like Contacts on Android.
I'm uninstalling this app from my phone now. This isn't acceptable!
I'm uninstalling this app from my phone now. This isn't acceptable!
Ever copy and paste sensitive data on your laptop? Clear that clipboard before using your iPhone.
Apple's Universal Clipboard may share your clipboard across devices.
Apple's Universal Clipboard may share your clipboard across devices.
One of my hobbies is looking at url strings with GET key/value pairs. Programmers must forget that they're visible to users. LinkedIn has a search workflow that shows "origin=TYPEAHEAD_ESCAPE_HATCH" which I've always found humorous.
Discord throws the warning every time you tap on the text box. https://www.reddit.com/r/discordapp/comments/hfcvbu/is_disco... fixed with a single line change. They were trying to determine if the paste button should show up or not.
I am curious what LinkedIn is actually doing with the data. Is it being exfilled somehow? Or is it just doing something in a really dumb way? I don't trust them at all to not be taking the data, but what purpose does it have?
I am curious what LinkedIn is actually doing with the data. Is it being exfilled somehow? Or is it just doing something in a really dumb way? I don't trust them at all to not be taking the data, but what purpose does it have?
This is precisely how Chinese authorities track down activists using apps without Location data, it was disclosured few weeks ago.
They patiently read user's clipboard data and wait for a picture taken and copied to clipboard, then extract its EXIF geoloc tags and send the coordinates to the police.
They patiently read user's clipboard data and wait for a picture taken and copied to clipboard, then extract its EXIF geoloc tags and send the coordinates to the police.
hypothesis: "technology" is largely data collection platforms with thin veneers on top (social networking, dating, food delivery, etc)
if you agree with that premise, then it's no surprise that every possible source of data that can be collected upon, will be collected upon.
if you agree with that premise, then it's no surprise that every possible source of data that can be collected upon, will be collected upon.
Has anyone replicated the issue described by the Twitter user? It's probably important to verify these kinds of claims before they get upvoted. This looks and feels like disinformation.
LinkedIn is actually copying the clipboard while that user types in a different app.
https://twitter.com/DonCubed/status/1278757201310388225
https://twitter.com/DonCubed/status/1278757201310388225
Microsoft Teams does this in the chat box for every keystroke. It says "Pasting from device" on each press. I filed a RADAR with Apple before the TikTok report but now I feel stupid.
Apple is doing the right thing. These other companies appear to have the issue.
Apple is doing the right thing. These other companies appear to have the issue.
Does this recurring problem suggest a missing API?
Illegal and immoral. How can anyone trust these people with personal data and access to your devices?
We have allowed empires to be built on scummy business practices that are fundamentally user hostile. We are under no obligation to maintain them.
We have allowed empires to be built on scummy business practices that are fundamentally user hostile. We are under no obligation to maintain them.
The potential of this sort of malicious behaviour always makes me nervous when I have to copy a password from password managers (generally I'll rely on Autofill, but when Autofill fails I have to copy my 128+ character passwords).
Glad Apple added this feature, it seems to work well as it exposes these issues.
He's typing IN the LinkedIn app though, right? Can apps read the clipboard when running in the background too?
He's typing IN the LinkedIn app though, right? Can apps read the clipboard when running in the background too?
When you install software from JetBrains and have the registration key on your clipboard it will autofill it into the key input field.
There are so many programs using this that it all boils down to trust.
Personally I don't trust LinkedIn so I keep away from them. But in this case they still might have a valid reason for this.
The fix: be more transparent about why the app is doing it. And the browser/OS could show a popup every time an app reads the clipboard to make the user aware of this.
There are so many programs using this that it all boils down to trust.
Personally I don't trust LinkedIn so I keep away from them. But in this case they still might have a valid reason for this.
The fix: be more transparent about why the app is doing it. And the browser/OS could show a popup every time an app reads the clipboard to make the user aware of this.
Apple has it's 'rigorous' app approval process, why is this not found in there? I've gotten rejected for all kinds of stuff. But I guess they are not doing any quality checks on the apps during this approval process?
Here I've justified the $100 yearly developer fees in that they have this rigorous checks, but apparently they're not really checking the apps?
This is apple failing us, nothing else.
Here I've justified the $100 yearly developer fees in that they have this rigorous checks, but apparently they're not really checking the apps?
This is apple failing us, nothing else.
After LinkedIn took the contents of my Contacts and uploaded it. I swore I would never install it to another mobile device again.
I’m going to stop referring to these apps as copying the clipboard, and use the proper and accurate terminology: ‘keylogger’
I'm glad iOS14 is showing this but IMO it's the wrong solution. I know this is easier said than done but basically the OS should make it impossible for an app to read the clipboard unless the user chooses "PASTE". I have no idea how that would work on iOS. It can work pretty well in the browser. I'm not saying the browser is doing this well, but it is possible for the browser to be made so only a browser level paste gives the current page/iframe the contents of the clipboard so you know the user specifically wanted whatever is in the clipboard passed to that page/app.
Why does a website or app even need access to the clipboard? I would maybe naively think that the OS could send the characters on the clipboard as if they were typed quickly, end of story.
https://twitter.com/eberger45/status/1278843576638570496
------ Hi @DonCubed . Appreciate you raising this. We've traced this to a code path that only does an equality check between the clipboard contents and the currently typed content in a text box. We don't store or transmit the clipboard contents.
----------
An example of this is in a library we have open sourced, and you can find the fix here [https://github.com/linkedin/Hakawai/ (https://github.com/linkedin/Hakawai/pull/161/files/3881de368...). We will follow up once the fix is live in our app.
-----------