Live data from Hacker News

How Facebook tracks you on Android [video]

media.ccc.de

101–110 of 213 posts

Re: How Facebook tracks you on Android [video]

#101

I seriously loathe the people hating on the web. On the web one can preview, debug, and block stuff at each application and network layer. Use Lynx, disable JS, install ad and tracking blockers, edit hosts file - you are the king. Want to see the true evil? Native Android and iOS applications, there doesn’t exist an alternative platform anymore. You think that app is free? Not even web-style in-app advertisements giv…

Anyone else feeling like there is a resurgence in web?

Apps were the hot thing for a while, but now that major players have an app, they have figured out it matters little.

I dont do my shopping on the Target App. I'm sure they are getting economic indicators that web on mobile is just as effective.

Re: How Facebook tracks you on Android [video]

#102

Earlier quoted context omitted.

What is your motivation posting this? Because it sounds like a great example of "whataboutism". Just because an evil is done a lot, and in different contexts doesn't make it not evil.

Every other comment here boils down to "get an iPhone". If the claim that this is also happening on iOS is true then it's highly relevant to the discussion.

Apple users have the need to defend Apple at every turn.

Android users enjoy bashing Google at every turn.

Just like I bash M$ despite loving windows 10 and Excel... (actually I've gotten better about this)

Re: How Facebook tracks you on Android [video]

#103
post #99

Earlier quoted context omitted.

> Thr fact that Apple which could do this without significant adverse monetary impact but has chosen not to They restrict access to most of the things listed above, giving randomised fakes where necessary. The advertising ID they do let apps access is unique to a publisher so they can't be tied together with behaviour from apps by other publishers, and it's trivially disabled/resettable by the end user (Settings > Pr…

Where do you get that IDFA is unique to the publisher?

Apologies, I'm conflating two slightly different things there.

There's the identifierForVendor [0] which is unique to the publisher. This is pretty safe to use however you see fit (within reason).

Then there's the advertisingIdentifier [1], which is not unique, but can easily be permanently zeroed out by the user. Apple also have some fairly stringent rules about how it can be used [2], not to mention further rules about not identifying people surreptitiously [3]:

> 5.1.2 Data Use and Sharing

> (iii) Apps should not attempt to surreptitiously build a user profile based on collected data and may not attempt, facilitate, or encourage others to identify anonymous users or reconstruct user profiles based on data collected from Apple-provided APIs or any data that you say has been collected in an “anonymized,” “aggregated,” or otherwise non-identifiable way.

They ask you to explicitly confirm that you're following the advertising identifier rules in particular every single time you submit to the App Store.

[0] https://developer.apple.com/documentation/uikit/uidevice/162...

[1] https://developer.apple.com/documentation/adsupport/asidenti...

[2] https://support.appsflyer.com/hc/en-us/articles/207032086-Ap...

[3] https://developer.apple.com/app-store/review/guidelines/#dat...

Re: How Facebook tracks you on Android [video]

#104

Earlier quoted context omitted.

Disabling Javascript kills fingerprinting in the womb. Enable only for trusted sites as needed.

This 100%. It will also make your web experience a lot better because so much of the javascript out there just does things you don't want anyway, such as loading ads and displaying popups. If you are a web developer or are familiar with web terminology like origins, domains, frames, XHR, etc on the web, and are willing to put in some time learning how to use it (15 mins for a seasoned web dev, maybe 30-60 mins otherw…

Thanks. Care to share a uMatrix setup that reports a non-unique fingerprint on https://panopticlick.eff.org ?

Re: How Facebook tracks you on Android [video]

#105
Wrangling 3rd party application access to platform providers' suite (ios, android, browser extensions).

Cookies seem to be the majority of the aggregate identity/behavior data, which you can use various rules in the protocol to limit tracking to some extent.

I've found that opting out on a regular basis of the large adverts for a little extra peace of mind.

uBlock/uMatrix Origin, ghostery, duck.com, dns encryption, vpn, ip6.

removing old wireless access points from history/cache and disabling nfc, blutooth advertisement.

removing duplicate/shared passwords from your various authentication providers and using keypass or a secure password scheme that is easy to remember.

Log out manually of various applications such as facebook, google, microsoft, etc.

Contacts list. Clean em' up.

Keep your phone and hands sanitary at all times :)

Re: How Facebook tracks you on Android [video]

#106
post #80

Earlier quoted context omitted.

Being on official f-droid categorically means no proprietary sdks. The app could still make calls to random servers, but that would be in the open since the app needs to be open source.

Is that true? F-Droid usually lists apps that I "won't like" because they include non-free software.

F-droid doesn't have non-free software. F-droid flags some apps with anti-features for various reasons like non-free network services (https://f-droid.org/wiki/page/Category:Apps_with_NonFreeNet_...), which is quite useless honestly since it makes no difference even if a remote service is free since you don't control that end. Perhaps historically f-droid allowed non-free dependencies (https://f-droid.org/wiki/page/AntiFeatures), but I don't think that's a thing any more. I don't see any major apps in that category.

Re: How Facebook tracks you on Android [video]

#107

Earlier quoted context omitted.

Every other comment here boils down to "get an iPhone". If the claim that this is also happening on iOS is true then it's highly relevant to the discussion.

Apple users have the need to defend Apple at every turn. Android users enjoy bashing Google at every turn. Just like I bash M$ despite loving windows 10 and Excel... (actually I've gotten better about this)

Don't worry, I bash Windows 10 and Office too (yes, including Excel), and I'm someone who actively dislikes them. OTOH, the best thing I could say about Apple these days is that iOS is genuinely better built than it's obvious alternatives (Android and ChromeOS) and that they do a tolerable job of supporting their mobile hardware, but that's kinda damning with faint praise.

Re: How Facebook tracks you on Android [video]

#108

Earlier quoted context omitted.

> Thr fact that Apple which could do this without significant adverse monetary impact but has chosen not to They restrict access to most of the things listed above, giving randomised fakes where necessary. The advertising ID they do let apps access is unique to a publisher so they can't be tied together with behaviour from apps by other publishers, and it's trivially disabled/resettable by the end user (Settings > Pr…

>I'm not really sure how you can arrive at the conclusion that Apple are holding back; they seem clearly committed to improving privacy as demonstrated by their continuous work in the area. Given the Apple phone was successfully hacked in the FBI case, I'm not sure why HN seems to think they are the bastion of privacy. Given the other anti-consumer and anti-developer practices at Apple, I wouldn't trust them to prote…

I was responding to somebody who is under the impression that Apple are purposefully choosing not to protect user privacy. The most powerful government in the world hacking an Apple product in their possession without Apple's consent isn't relevant to that. If anything, the fact that Apple went to court to avoid being compelled to aid them in the endeavour supports what I am saying.

I'm not saying that Apple products are 100% impenetrable against nation states; I'm pointing out that Apple are clearly putting serious effort into protecting user privacy.

I'm not sure why this is such a foreign concept to so many people. This is something Apple can do that their competitors cannot due to their business models. It's becoming more and more of a concern to customers and the law in many places. Even if you assume Apple are 100% self-serving, this is obviously a valuable differentiator for them to capitalise on.

Re: How Facebook tracks you on Android [video]

#109
The article focuses on FB, but identifies Google as a bigger tracker:

> “Previous research has shown how 42.55 percent of free apps on the Google Play store could share data with Facebook, making Facebook the second most prevalent third-party tracker after Google’s parent company Alphabet."

Re: How Facebook tracks you on Android [video]

#110
post #8

We're spoiled in the desktop browser by being able to clear history, cookies, local storage etc, or use a private browser session. There's also the importance of the "same origin policy". The Android platform API should simply never allow apps to obtain global system identifiers (serial numbers, "advertising IDs", MACs, Wifi network info, EMEIs etc) in the first place. Perhaps even going as far as not providing a sha…

I would say educated, not spoiled. if you so choose to not install apps (which are the same of, in the 90s, going to twocows or download.com, searching for idiot applications like "blockbuster" and installing them in your computer with full access to memory and disk) then you can buy an android phone, install firefox, install uBlock Origin, and only use those companies offerings via the browser.

granted, you will have to give up on netflix unless you want to install their DRM client, just like in the desktop.

Post reply on HN