Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apps abusing clipboard can steal the passwords from the password managers when user copies it and associate with the user account via parallel construction.

e.g. Time of stealing password from clipboard + time of my HN comment.

I've been long weary of this, android 10 has made some changes like allowing only IME & in-focus apps to access the clipboard. Not a fool-proof way to prevent the issue.

One more reason to destroy app duopoly, switch to pure Linux OS [1][2][3] and force app publishers to stick with web apps/PWA with more user control.

[1]https://store.pine64.org/product/pinephone-community-edition...

[2]https://postmarketos.org/blog/2020/06/15/pinephone-postmarke...

[3]https://puri.sm/products/librem-5/



Apps can still read the clipboard at any time they want on Linux. A pure Linux OS is definitely better, but for other reasons.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: