>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.
Instagram can track anything you do on any website in their in-app browser
111–120 of 469 posts
Re: Instagram can track anything you do on any website in their in-app browser
#112I hope Apple doesn't disable JS injection in WKWebViews in response to this. JS injection is the (only?) way to call native Swift methods from JS ie. bridging. I am not sure what the solution here is. Maybe only allow injection to sites you control (via apple association file).
Should only be allowed on domains one owns. Could be solved by DNS records or certificates.
Re: Instagram can track anything you do on any website in their in-app browser
#113Earlier quoted context omitted.
Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…
> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.
Re: Instagram can track anything you do on any website in their in-app browser
#114As a provider is it possible to defend against this with a Content Security Policy or does this mechanism override the site’s CSP?
Re: Instagram can track anything you do on any website in their in-app browser
#115I hope Apple doesn't disable JS injection in WKWebViews in response to this. JS injection is the (only?) way to call native Swift methods from JS ie. bridging. I am not sure what the solution here is. Maybe only allow injection to sites you control (via apple association file).
Apple can just disallow in app browsers in the store policy. Require apps to call out to the default external browser.
Re: Instagram can track anything you do on any website in their in-app browser
#116>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.
Re: Instagram can track anything you do on any website in their in-app browser
#117surprised this is at the top of HN. isn’t it obvious that every app does this? tiktok, snapchat, even linkedin all open links in their built-in browser and can track what you’re doing. click open in safari if you’re doing anything more than visiting a single page.
Re: Instagram can track anything you do on any website in their in-app browser
#118Earlier quoted context omitted.
> use the sites. Which are increasingly user hostile, if not down right impossible to view on mobile. Go try using Reddit or Twitter on your Mobile browser.
It is infuriating that I can't browse certain Reddit pages because they want me to "use the app so they know I'm over 18". I first ran into this in my current attempt to play through Dark Souls 3. It seems like the community there has a lot of good discussions about beating certain bosses, but for some reason, Reddit has decided that the content in that sub-reddit needs age verification and they wall it behind the ap…
Nothing's stopping you. There is no such message on old.reddit.com.
Re: Instagram can track anything you do on any website in their in-app browser
#119>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.
Re: Instagram can track anything you do on any website in their in-app browser
#120Earlier quoted context omitted.
Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…
> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.