TikTok and Facebook Can Track Your Phone's Keyboard Entries
How on earth did I miss this??!!
Have you ever noticed that in some apps, when you click on a link, that link opens up in a browser? Well, often that browser is actually built into the app that you are using. It's not your default browser on your phone, it's the app's browser.
Well, it appears that TikTok has a built in browser and it is monitoring the keyboard entries of individuals who click links within the app. So, basically if you, or your child, is using TikTok and they click a link while in the app, that link will open up in the TikTok web browser and TikTok can then monitor your keyboard entries.
Check out this snippet from the Washington Examiner:
TikTok may be tracking the activity of users who leave its platform and go to third-party apps.
The video app allegedly tracks all keyboard inputs within TikTok's "in-app browser" through a piece of extra code that the app puts into third-party websites, according to research released by security analysts. These new details arrived a week after the analysts revealed that Facebook was tracking all activity occurring within its internal browser.
"[The TikTok app on Apple devices] subscribes to every keystroke (text inputs) happening on third party websites rendered inside the TikTok app," wrote researcher Felix Krause in a Thursday blog post. This means the app tracks every button push a user does while using the in-app browser, including passwords and credit card information.
TikTok confirmed that the software exists but said that the company was not actively using it. "Like other platforms, we use an in-app browser to provide an optimal user experience, but the Javascript code in question is used only for debugging, troubleshooting, and performance monitoring of that experience — like checking how quickly a page loads or whether it crashes," a spokesperson told Forbes.
Krause revealed last week that Meta injected code into websites viewed via an in-app browser installed within Facebook and Instagram. A Meta spokesperson told the Guardian that "we intentionally developed this code to honor people's [ask to track] choices on our platforms."
"For purchases made through the in-app browser, we seek user consent to save payment information for the purposes of autofill," said the company's spokesperson.
Other tech companies denounce this sort of "cross-host tracking." Apple has actively worked against this sort of tracking and incorporated an update in iOS 14.5 that required apps to get permission before tracking their data across apps operated by other companies. This sort of code is also being phased out by standard browsers such as Google Chrome and Mozilla Firefox. It's unclear when Meta or TikTok began injecting code into their in-app browsers.
Read the full article at the link below.
Promo Code “PARALLEL” = 1 Free Month Subscription
LINK:
https://www.washingtonexaminer.com/policy/technology/tiktok-monitors-keyboard-inputs-internal-browswer