Live data from Hacker News

How Facebook tracks you on Android [video]

media.ccc.de

121–130 of 213 posts

Re: How Facebook tracks you on Android [video]

#122
post #112

Earlier quoted context omitted.

one thing that irks me is ppl blindly suggesting duckduckgo over google DDG is fucking horrible It doesn't work. I'm almost always going back to Google. There should be a service that searches Google for you behind 7 proxies.

That is searx. Self hosted and fully randomizing. I use it, and it works very well for general web searches Image search is subtly broken in the packaged releases tho, so you'll either have to hit up google image search or use the git version

nice find. that is exactly what I was looking for.

DDG at the end of the day are no more disposed to exposing their users at the behest of the gov than FAANG

Re: How Facebook tracks you on Android [video]

#123

I don't have a FB app on my phone, I have a FB account that has no posts. I look at it occasionally to track my "likes". Last week I was a conference in downtown Boston. I have no connection to the conference, I was there to meet my friend's daughter who lives oversees. While standing in line, people watching, I couldn't help but notice an extravagant fellow, I later discovered he was a an out of town PHD student the…

They use geolocation extensively.

You probably were in proximity long enough to have triggered something. You never know — your friends daughter may have been in the same line somewhere at the airport or a lounge as well.

I used to get this a lot as I’m 1-2 degrees of separation from some highish profile people. FB seems to adapt and move on to a different strategy over time.

Re: How Facebook tracks you on Android [video]

#124

Earlier quoted context omitted.

Thanks. Care to share a uMatrix setup that reports a non-unique fingerprint on https://panopticlick.eff.org ?

I think the point is not that the core domain can't fingerprint you, it is that 3rd party JavaScript is blocked by default, which makes those domains less likely to track you. Not impossible, just less likely. For example there is almost never any reason to allow Google Analytics JS.

Agreed. If you take the default uMatrix setup, change javascript to be disabled, then just whitelist as you go, you'll pass most of those tests and be pretty tracker-resistant.

My suspicion is that fingerprinting by the core domain will actually get worse since your browser behaves so differently from stock browsers (which is after all the point of uMatrix :-) ). The majority of trackers tho will be third party (such as Google analytics). Very few sites roll their own trackers because it's hard to get right, and some great ones like GA is free. For those that do, I'm not too worried anyway, but that's certainly just a personal thing.

Re: How Facebook tracks you on Android [video]

#125

Earlier quoted context omitted.

Disabling Javascript kills fingerprinting in the womb. Enable only for trusted sites as needed.

May as well just go buy physical newspapers and magazines then since few web sites today work without javascipt

That's funny, I consume an unhealthy amount of news via the web in a noscript browser having nothing whitelisted.

Re: How Facebook tracks you on Android [video]

#126

Earlier quoted context omitted.

May as well just go buy physical newspapers and magazines then since few web sites today work without javascipt

I've been blocking JS for the last 6 months or so and I've found it to be a greatly improved experience overall. I can enable at the click of a button JS for a website that fails to load properly but the majority of sites I view are fine without this. It was refreshing to learn that not as many websites as I suspected are JS abominations!

My experience exactly. Everyone said "don't do it, most sites need js!" but it isn't true. SPAs are certainly out there, but not nearly as common as you'd think (I most thank SEO for that since only recently would Google crawl a client-side rendered page). Will it be a seamless experience? No, definitely not, but I agree, overall it's an improvement.

Re: How Facebook tracks you on Android [video]

#127

Earlier quoted context omitted.

>When the revenue stream of the creator of Android fundamentally depends on being able to tie devices to identity and behaviour, it's highly unlikely this is going to happen. Well put. I’ve tried to explain to people that I prefer Apple’s upfrontness that they are there to sell me a device and it’s software for money. Unlike Android systems where I feel the lead is intentionally buried by telling me how “free” the so…

iOS apps have similar issues, actually. On the Android side, you can at least use free and auditable apps from the F-Droid repository, and buy your device from an OEM vendor which will let you unlock it and install google-free LineageOS. (More speculatively, the community is now working on replacing AOSP altogether with the usual Linux desktop stack, via PostmarketOS. Not usable right now, but it's progressing rather…

>On the Android side, you can at least use free and auditable apps from the F-Droid repository, and buy your device from an OEM vendor which will let you unlock it and install google-free LineageOS.

Do you go audit every line of source code in the apps and OS you install? Do you then verify that the binary blobs you're installing were built from the same source? Do you somehow audit the source for the firmware on your device and verify that that is the firmware installed on your device? What about the hardware, do you audit it?

Re: How Facebook tracks you on Android [video]

#128
post #120

Earlier quoted context omitted.

For example any kind of Bluetooth companion app, including sensor readers, watch companion apps and pretty much anything there requires access to MAC to complete pairing. Your app on the phone wouldn’t need your Bluetooth ID (which is separate from the WiFi MAC ID). It would need the ID of the connecting device. Any kind of mDNS and direct WiFi apps. https://developer.apple.com/documentation/networkextension/n... Are…

> We have an existence proof with both Android and Windows - and less so with Macs but only because they aren’t as large of a target - with what happens when apps are given unfettered access to the hardware and privacy related information even with user permissions. What exactly happens? A ton of innovative apps can be made? Bunch of enterpreneurs can innovate and built new products without approval from a huge ameri…

The existence proof is both Windows and Android and all of the spyware, malware, ransomware, and privacy invasion apps.

Yes, powerful tools can be abused....You're effectively ceding full control of EVERYTHING you do on your computing device to Google and Apple forever because you're afraid that powerful tool, drivers of innovation and progress, might hurt someone occasionally.

You’re speaking as if this is hypothetical. Thirty plus years of PC use and 10 years of Android is proof that third party developers can’t be trusted and the platform providers have a responsibilty to keep third party providers in check. Given the trade off of inconveniencing a few geeks and not allowing third parties to read text messages, phone logs, etc. I think that’s a fair trade off.

I am a developer and have been for 20 years. But the platform providers should be catering to the users. I will install any random app on my iPhone. I don’t worry about whether the app comes from a trusted developer. I know because of the security model that the app can’t do too much damage.

we NEED to make sure that people take responsibility for themselves. It's the only way you keep free market and freedom functioning.

Again, how has that worked out so far for the vast number of PC and Android users?

It has been drilled into computer users heads not to download random apps from untrusted sources on their computers because of the potential for harm. The fact that the iOS App Store does enforce a sandbox actually gave app developers a larger market of people who would try random apps without having to trust the developer.

But most importantly, Android has been around for a decade. Where are all of the Android “entrepreneurs” that are getting rich because of their “innovative” apps that are possible because of its lax security model?

Re: How Facebook tracks you on Android [video]

#129
post #24

Earlier quoted context omitted.

I know you're not disagreeing with me, but the issue you raise only distracts and lends ammo to the defenders of these prolific tracking mechanisms. It's the Nirvana fallacy. I'm sure there's a Google rep somewhere that will tell you that their "advertising ID" is better than the status quo on the web because the user can rotate it and, because it's reliable and easy for app devs to use, they are discouraged from bei…

The Android advertising ID is exactly the same as the iOS IDFA. Both companies enforce policies on using those identifiers for apps published on their app stores. https://support.google.com/googleplay/android-developer/answ... https://www.businessinsider.com/ifa-apples-iphone-tracking-i...

You're responsible for ensuring your apps are in compliance with policies regarding its usage, as well as all Play policies.

And the developer will pinky promise that they won’t abuse it....

Re: How Facebook tracks you on Android [video]

#130
post #94

Earlier quoted context omitted.

Just speculating, but they might just need this information to combat bots actually. Think about it, they already know who you are because you are logged in with your account. They don’t need more info than that to run targeted ads.

> Just speculating, but they might just need this information to combat bots actually. That would be actually quite useful for fighting bots, but I doubt that is the reason. My guess would be just gathering telemetry to how how API is used, and what type of android devices are there (you know, like to know what you should support and test on).

My guess would be just gathering telemetry to how how API is used, and what type of android devices are there (you know, like to know what you should support and test on).

In the video it is shown that the information sent to Facebook is far more intrusive than that.

Post reply on HN