Researchers who flagged TikTok and 55 other iOS apps for clipboard snooping in March say the majority of apps they identified still continue the practice
despite it being inconspicuous to the naked eye—can be regularly accessed by apps that in many cases aren't even installed locally on the device.” https://arstechnica.com/... Steven Bellovin / @stevebellovin : The list of apps that do this, including @NPR, @nytimes, @wsj, @foxnews, and more, is appalling. https://twitter.com/...
Context & Ripple Effects
In March, researchers flagged TikTok and 55 other iOS apps for reading users' clipboards without obvious cause; three months on, they report the majority never stopped. What changed in between was visibility: the iOS 14 beta now tells users when an app touches the clipboard, which is how the practice became front-page news rather than a researcher's spreadsheet.
That exposure forced admissions fast — TikTok pledged on June 26 to stop clipboard reading, blaming anti-spam checks — but this follow-up shows voluntary promises lagging behind the flag list, with Steven Bellovin calling the implicated apps' roster, including NPR, the New York Times, the Wall Street Journal, and Fox News, appalling.
First-order effects
- The named publishers — NPR, NYT, WSJ, Fox News among them — are now publicly tied to a covert data-collection practice their own reporting often covers critically, creating immediate reputational pressure to explain or remove the behavior.
- TikTok's June 26 pledge to stop clipboard reading is directly undercut by the finding that most flagged apps persist, shifting scrutiny from 'does this happen?' to 'who actually fixed it?'
Second-order effects
- Apple's iOS 14 clipboard notifications turn every remaining offender's next read into a user-visible event, so developers who ignored the March research face forced patches and app-store embarrassment once the OS ships.
- The pattern echoes 2015, when Apple moved to ban 256 apps over a rogue ad SDK (researchers found 256 iOS apps abusing a third-party SDK); platform-level enforcement, not press coverage, has historically been what ends these practices at scale.
Third-order effects
- If covert collection keeps surviving disclosure cycles, enforcement migrates from app-makers' promises to OS-level telemetry — the same mechanism later surfaced by Mysk's finding that major iPhone apps skirt privacy rules via push notifications (apps skirting Apple's rules through push notifications) — making operating-system vendors the de facto privacy regulators.
- Recurring SDK- and API-driven collection incidents point toward durable governance pressure on third-party code inside popular apps, where a single embedded component exposes dozens of brands at once.
The trend: Mobile platforms are replacing voluntary developer disclosure with user-visible privacy signals — clipboard alerts today, push-notification tracing later — forcing data-collection practices into the open whether or not the flagged apps fix themselves.