Live data from Hacker News

How Facebook tracks you on Android [video]

media.ccc.de

161–170 of 213 posts

Re: How Facebook tracks you on Android [video]

#161
post #155

Whats a good, slim solution for a VPN I can setup on my host to filter these tracking sites? I already have OpenVPN set up, does it have filtering features that could help block this unwanted traffic?

You can also use PiHole in combination with OpenVPN. Works like a charm

Re: How Facebook tracks you on Android [video]

#162

Earlier quoted context omitted.

They use geolocation extensively. You probably were in proximity long enough to have triggered something. You never know — your friends daughter may have been in the same line somewhere at the airport or a lounge as well. I used to get this a lot as I’m 1-2 degrees of separation from some highish profile people. FB seems to adapt and move on to a different strategy over time.

I don't have the app on my phone so how do they use geolocation? Perhaps as this article describes?

Partners.

Perhaps there is some way to tell via other people’s devices that you are nearby.

Re: How Facebook tracks you on Android [video]

#163
post #24

Earlier quoted context omitted.

I know you're not disagreeing with me, but the issue you raise only distracts and lends ammo to the defenders of these prolific tracking mechanisms. It's the Nirvana fallacy. I'm sure there's a Google rep somewhere that will tell you that their "advertising ID" is better than the status quo on the web because the user can rotate it and, because it's reliable and easy for app devs to use, they are discouraged from bei…

Anybody suggesting technical solutions to this problem is completely misunderstanding the scale of it. The only acceptable answer is a legal/regulatory solution.

So honest question, how does a legal/regulatory solution protect users against illegal bad actors, foreign actors, or malicious projects and frameworks that are either Open Source or that aren't backed by a company?

I hear this argument brought up a lot, that the only thing that can fix this is regulations. I've always come at this from the opposite direction -- regulatory solutions are nice, and I'm not against them, but they're less useful than technological solutions because my gut instinct is regulations only cover a) law-abiding entities (and usually only corporations at that), who are b) competent enough not to mess up compliance in the first place.

The perspective I lean on by default is that even if you have good regulations in place, the problem isn't really solved until there's a widespread technical solution. So for example, it might be nice to have a law banning MITM attacks, but HTTPS is the superior solution that we really want. When we pass laws criminalizing stuff like hacking or tracking children, my perspective is we're just trying to buy time and localize the damage to the slightly less frequented parts of the Android app store while we fix the crappy permissions models and sandboxing on our core platforms.

Is there a secondary aspect to the regulatory solutions that I'm missing? Something that would go much, much farther and be much stricter than laws like GDPR? I don't mean it as an argument, I'd just be curious to hear someone with the regulation>infrastructure perspective elaborate more on what they're thinking about when they say that, because it's a perspective I don't have much experience with.

Re: How Facebook tracks you on Android [video]

#164
post #120

Earlier quoted context omitted.

> We have an existence proof with both Android and Windows - and less so with Macs but only because they aren’t as large of a target - with what happens when apps are given unfettered access to the hardware and privacy related information even with user permissions. What exactly happens? A ton of innovative apps can be made? Bunch of enterpreneurs can innovate and built new products without approval from a huge ameri…

The existence proof is both Windows and Android and all of the spyware, malware, ransomware, and privacy invasion apps. Yes, powerful tools can be abused....You're effectively ceding full control of EVERYTHING you do on your computing device to Google and Apple forever because you're afraid that powerful tool, drivers of innovation and progress, might hurt someone occasionally. You’re speaking as if this is hypotheti…

> The existence proof is both Windows and Android and all of the spyware, malware, ransomware, and privacy invasion apps.

But... the existence proof is also Windows and Android and the massive market share and staggering amount of innovation that's happened on those platforms.

You're forgetting that many of the capabilities that Apple eventually caved on and added to iOS came directly as a result of Android's "we'll let you do that" default motto. There was a period of time where you couldn't have custom keyboards on iOS. There was a period of time where 3rd party apps on iOS couldn't even multitask.

Don't get me wrong, Android's permission model needs serious work at this point. But the coin you're holding up has two sides on it. You're writing off a huge amount of innovation that has benefited everyone, Apple users included.

Platform power is a continuum -- there's no single right or wrong answer for everyone buying a device, which is why it's good to have multiple platforms with multiple philosophies.

Even if you don't care about that though, and you personally enjoy staying closer to the secure side of things, permissive platforms still benefit you as a user because they're testing grounds to find out which capabilities are beneficial enough to end-users to be worth back-porting to the more closed gardens. That's something we've seen repeatedly throughout the years with Android and iOS: both platforms feed on each other in different ways.

Re: How Facebook tracks you on Android [video]

#165

I seriously loathe the people hating on the web. On the web one can preview, debug, and block stuff at each application and network layer. Use Lynx, disable JS, install ad and tracking blockers, edit hosts file - you are the king. Want to see the true evil? Native Android and iOS applications, there doesn’t exist an alternative platform anymore. You think that app is free? Not even web-style in-app advertisements giv…

Anyone else feeling like there is a resurgence in web? Apps were the hot thing for a while, but now that major players have an app, they have figured out it matters little. I dont do my shopping on the Target App. I'm sure they are getting economic indicators that web on mobile is just as effective.

Yes, it's been happening for a while. Google and Mozilla have been pushing (sometimes rushing) for more capable web browsers while Apple actively protects the exclusivity of some functionalities of it's app store, to the detriment of Safari users, making them feel an even greater gap between websites and native apps.

Originally, smartphones were to be the new way of browsing the web but it turned out to be a new way for OS manufacturers to profit over third-party software because developers had to handcraft a way of accessing their data over the internet from the device given that web browsers were not up to the task of delivering fast, snappy experiences. Developers had to create native apps for the simplest services even if they didn't need the extra functionality and APIs like notifications, background updates or movement sensors.

Today, mostly because of the increase in mobile processing power, the difference between a website and an app for trivial tasks (notekeeping, calendar, ordering a product, whatevs) is innofensive and overall imperceptible, making websites a reliable way of providing functionality once again.

Browser updates and new APIs will increase the amount of possible trivial services you will be able to access from anything with a browser and up-to-date processing power.

Re: How Facebook tracks you on Android [video]

#166
post #127

Earlier quoted context omitted.

iOS apps have similar issues, actually. On the Android side, you can at least use free and auditable apps from the F-Droid repository, and buy your device from an OEM vendor which will let you unlock it and install google-free LineageOS. (More speculatively, the community is now working on replacing AOSP altogether with the usual Linux desktop stack, via PostmarketOS. Not usable right now, but it's progressing rather…

>On the Android side, you can at least use free and auditable apps from the F-Droid repository, and buy your device from an OEM vendor which will let you unlock it and install google-free LineageOS. Do you go audit every line of source code in the apps and OS you install? Do you then verify that the binary blobs you're installing were built from the same source? Do you somehow audit the source for the firmware on you…

Filtering apps by license is a great filter for intent. There are many reasons people write FLOSS licensed software for, but the fewest include wanting to get your data. For economically thinking professional data collectors who e.g. put some dancing pigs game out to get your contact data, the gaining access to a small population aren't worth the effort of open sourcing. F-Droid also has the concept of antifeatures, which upfront informs users about potentially unwanted behaviour like tracking.

Re: How Facebook tracks you on Android [video]

#168
post #26

I use Netguard ( https://github.com/M66B/NetGuard ) and block out access to Facebook's Graph API by every app on my phone. Works very well.

I found NoRoot Firewall to be a much more powerful app. It allows you to add global domain filters too. And for some reason the logging of apps which request internet access appears to be much more detailed.

Re: How Facebook tracks you on Android [video]

#169
post #8

We're spoiled in the desktop browser by being able to clear history, cookies, local storage etc, or use a private browser session. There's also the importance of the "same origin policy". The Android platform API should simply never allow apps to obtain global system identifiers (serial numbers, "advertising IDs", MACs, Wifi network info, EMEIs etc) in the first place. Perhaps even going as far as not providing a sha…

> The Android platform API should simply never allow apps to obtain global system identifiers (serial numbers, "advertising IDs", MACs, Wifi network info, EMEIs etc) in the first place. Perhaps even going as far as not providing a shared filesystem.

Well, that's a nice wish for Santa, but does anyone really expect such a policy from an advertising company like Google?

Re: How Facebook tracks you on Android [video]

#170

Earlier quoted context omitted.

> The Android platform API should simply never allow apps to obtain global system identifiers (serial numbers, "advertising IDs", MACs, Wifi network info, EMEIs etc) in the first place. Of course. On the other hand, Google's global attitude is that user tracking is fine, their core business is based on that. So it would be hypocritical on their part if they decided to block user tracking on their devices.

So it’s better not to buy your device based on a operating system created by an advertising company...

All smartphones are bad.
Post reply on HN