🔥 New Post: Announcing InAppBrowser - see what JavaScript commands get injected through an in-app browser
👀 TikTok, when opening any website in their app, injects tracking code that can monitor all keystrokes, including passwords, and all taps.
krausefx.com/blog/announcin…
Felix Krause
28.2K posts
- 📝 One of these is Apple asking you for your password and the other one is a phishing popup that steals your password krausefx.com/blog/ios-priva…
- Imagine reviewing the designs for this screen, considering that the user has to understand it *while* they’re on a call, and thinking: yep, ship it
- Apple is so far removed from all this, I'm curios how they plan on making up for it.AI innovation right now
- 💥 New Post: Instagram & Facebook tracks everything you do on any website in their in-app browser krausefx.com/blog/ios-priva…
- Replying to @KrauseFxWhen opening a website from within the TikTok iOS app, they inject code that can observe every keyboard input (which may include credit card details, passwords or other sensitive information) TikTok also has code to observe all taps, like clicking on any buttons or links.
- Replying to @KrauseFxWow, what an honour to have my work featured on @Forbes Including statements by TikTok confirming the code I found exists and does what I expected. forbes.com/sites/richardn… via @richardjnieva
- Replying to @KrauseFxInAppBrowser.com - a new tool I used to investigate the in-app browsers of apps (that use them) to look for any external JavaScript code being injected.
- "Should I implement a custom share-sheet for my iOS app?" - a handy chart, please use it
- 📍 Any app gets complete access to where you've been the last years within a second, when you grant access to photos github.com/KrauseFx/detec…
- Converting HEIC files to JPGs is actually built into Finder now, no need to manually use ‘Preview’ or similar.


















