Comment by cwkoss

4 years ago

Don't all in-app browsers do this? I think I read that instagram does the same.

No not all of them do this. Yes, Instagram does, as per the chart in the article. The difference is Tiktok forces you to use their in app web view, and does not allow you to use your default browser, where they would not be able to inject their own JS code. Even worse, Tiktok monitors every single key stroke, a key logger in effect, where Instagram does not (according to the authors research).

If you open the article, it compares it to a few apps. TikTok blocks you from opening it in your default browser. The others don't

No, AFAIK not on android. As it uses the default browser, just in webview mode.

  • iOS and Android both have equivalent "bad" webviews that can be tampered with and "good" webviews that can't. Instagram on Android uses the "bad" one.