[Cryptography] iOS apps peeking at contents of clipboard

Jerry Leichter leichter at lrw.com
Thu Jul 9 09:04:39 EDT 2020


Perhaps off-topic - no direct cryptographic content other than perhaps a warning not to cut and paste your credential - but as has been widely reported, quite a number of iOS apps have been found to be grabbing the contents of the clipboard for no clear reason.

What I found interesting - and here it does overlap with the kinds of excuses we often see from all kinds of vendors - is the explanation from (I think LinkedIn, perhaps others) that they looked at the clipboard "only to see if it matched what the user was typing."  That's about as much of an explanation as looking at the clipboard "because we're running on a ARM processor."

Has anyone come across an explanation of why a app might want to check - at each character entered, mind you - whether what was being typed matched the contents of the clipboard?  The only case I can come up with is trying to prevent a user from cutting and pasting a password (or sometimes an email address) into both the primary and "confirmation" fields.  I could imagine some bizarre security rule forbidding that - just as some web pages, to this day, try to prohibit pasting into password fields.  But I've yet to see any webpage or app actually allow it and then complain....
                                                        -- Jerry



More information about the cryptography mailing list