Live data from Hacker News

How Facebook tracks you on Android [video]

media.ccc.de

81–90 of 213 posts

Re: How Facebook tracks you on Android [video]

#81
I don't have a FB app on my phone, I have a FB account that has no posts. I look at it occasionally to track my "likes". Last week I was a conference in downtown Boston. I have no connection to the conference, I was there to meet my friend's daughter who lives oversees. While standing in line, people watching, I couldn't help but notice an extravagant fellow, I later discovered he was a an out of town PHD student there for the conference. Imagine my shock when my next web login to FB offered me this very man as a suggested friend!

Re: How Facebook tracks you on Android [video]

#82

I don't have a FB app on my phone, I have a FB account that has no posts. I look at it occasionally to track my "likes". Last week I was a conference in downtown Boston. I have no connection to the conference, I was there to meet my friend's daughter who lives oversees. While standing in line, people watching, I couldn't help but notice an extravagant fellow, I later discovered he was a an out of town PHD student the…

Is there a definitive answer on how these suggestions happen? (Other example: talk about X with someone; start seeing internet ads for X afterwards). Is it coincidence?

Re: How Facebook tracks you on Android [video]

#83

Earlier quoted context omitted.

>When the revenue stream of the creator of Android fundamentally depends on being able to tie devices to identity and behaviour, it's highly unlikely this is going to happen. Well put. I’ve tried to explain to people that I prefer Apple’s upfrontness that they are there to sell me a device and it’s software for money. Unlike Android systems where I feel the lead is intentionally buried by telling me how “free” the so…

iOS apps have similar issues, actually. On the Android side, you can at least use free and auditable apps from the F-Droid repository, and buy your device from an OEM vendor which will let you unlock it and install google-free LineageOS. (More speculatively, the community is now working on replacing AOSP altogether with the usual Linux desktop stack, via PostmarketOS. Not usable right now, but it's progressing rather…

> More speculatively, the community is now working on replacing AOSP altogether with the usual Linux desktop stack, via PostmarketOS

So you're telling me that 2019 is the year of the Linux desktop... on mobile?

Re: How Facebook tracks you on Android [video]

#84
post #24
post #15

Earlier quoted context omitted.

While you make good points about mobile apps, don't be too spoiled by the privacy offered by destop browsers. Because of their configuration and various APIs, they're almost as easy to fingerprint as mobile devices with advertising IDs. EFF has had a proof of concept online for quite a while https://panopticlick.eff.org/ And HN users are probably even more vulnerable since we will have customized our software making…

I know you're not disagreeing with me, but the issue you raise only distracts and lends ammo to the defenders of these prolific tracking mechanisms. It's the Nirvana fallacy. I'm sure there's a Google rep somewhere that will tell you that their "advertising ID" is better than the status quo on the web because the user can rotate it and, because it's reliable and easy for app devs to use, they are discouraged from bei…

Anybody suggesting technical solutions to this problem is completely misunderstanding the scale of it.

The only acceptable answer is a legal/regulatory solution.

Re: How Facebook tracks you on Android [video]

#85
post #73

Earlier quoted context omitted.

Which applications would that be? I’m sure there are applications that need unlimited access to your file system, read your text messages, and read your call logs. How has that worked out for the privacy and security of Android users?

For example any kind of Bluetooth companion app, including sensor readers, watch companion apps and pretty much anything there requires access to MAC to complete pairing. Any kind of mDNS and direct WiFi apps. Any kind of Wifi scanning and environment survey apps. Any kind of Wifi helper apps to setup other devices. Are you seriously claiming that our portable computers should lock us out from creating these kind of…

For example any kind of Bluetooth companion app, including sensor readers, watch companion apps and pretty much anything there requires access to MAC to complete pairing.

Your app on the phone wouldn’t need your Bluetooth ID (which is separate from the WiFi MAC ID). It would need the ID of the connecting device.

Any kind of mDNS and direct WiFi apps.

https://developer.apple.com/documentation/networkextension/n...

Are you seriously claiming that our portable computers should lock us out from creating these kind of new application experiences permanently and give ONLY Google and Apple the ability to create them? You want innovation in use of our portable computers to be permanently owned and controlled by Google and Apple exclusively?

We have an existence proof with both Android and Windows - and less so with Macs but only because they aren’t as large of a target - with what happens when apps are given unfettered access to the hardware and privacy related information even with user permissions. How often have we seen yet another privacy invasion from Facebook but only against Android users?

Re: How Facebook tracks you on Android [video]

#86

Earlier quoted context omitted.

Do you have a recommended setup to tackle fingerprinting? I'm using a VPN + ublock origin + https everywhere + temporary containers + don't track me google + chameleon + canvas blocker + custom user.js (that disables e.g. webgl). It's pretty good to address many tracking methods (e.g. cookies, IP) but fingerprinting is remarkably hard to prevent.

Disabling Javascript kills fingerprinting in the womb. Enable only for trusted sites as needed.

This 100%. It will also make your web experience a lot better because so much of the javascript out there just does things you don't want anyway, such as loading ads and displaying popups.

If you are a web developer or are familiar with web terminology like origins, domains, frames, XHR, etc on the web, and are willing to put in some time learning how to use it (15 mins for a seasoned web dev, maybe 30-60 mins otherwise) get uMatrix (https://github.com/gorhill/uMatrix). It will change your life! If not, use ScriptBlock on Chrome or NoScript on Firefox. Block all scripts (and if using uMatrix, cookies, XHR, and frames) by default and whitelist as you go for sites you trust (or want to use bad enough to potentially open yourself up for tracking).

Re: How Facebook tracks you on Android [video]

#87

I don't have a FB app on my phone, I have a FB account that has no posts. I look at it occasionally to track my "likes". Last week I was a conference in downtown Boston. I have no connection to the conference, I was there to meet my friend's daughter who lives oversees. While standing in line, people watching, I couldn't help but notice an extravagant fellow, I later discovered he was a an out of town PHD student the…

Is there a definitive answer on how these suggestions happen? (Other example: talk about X with someone; start seeing internet ads for X afterwards). Is it coincidence?

https://www.vox.com/the-goods/2018/12/28/18158968/facebook-m...

https://newsroom.fb.com/news/h/facebook-does-not-use-your-ph...

Re: How Facebook tracks you on Android [video]

#88

Earlier quoted context omitted.

Which applications would that be? I’m sure there are applications that need unlimited access to your file system, read your text messages, and read your call logs. How has that worked out for the privacy and security of Android users?

Much better than the privacy and security of iOS, which has had hundreds of millions of users infected with XCodeGhost. All while allowing much more useful applications to be built. The fact that the application must request permission to see that data gets those applications extra scrutiny from not only the user but the app store and third party security researchers as well.

And we have 30+ years of user behavior of computer users and almost 10 years of mobile user behavior with Android to know that most users aren’t going to give “extra scrutiny” to those applications and are just going to click “allow”.

And even if “security researchers” do find an issue with an Android app, how does that information get disseminated to users? Even if Google decides to close the hole, Android doesn’t exactly have a great track record of getting updates to users.

Re: How Facebook tracks you on Android [video]

#90

Earlier quoted context omitted.

If you watch the talk, that's not good enough. Any app you've installed that includes the FB SDK is leaking your data back to FB. And, according to the talk, that's a majority of popular apps.

F-Droid apps aren't going to include proprietary SDKs. Yet another reason to use F-Droid (on Android/AOSP).

The only real way to avoid stuff like this is to install something like little snitch for phones.
Post reply on HN