Live data from Hacker News

Instagram can track anything you do on any website in their in-app browser

krausefx.com

111–120 of 469 posts

Re: Instagram can track anything you do on any website in their in-app browser

#111

>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.

[deleted]

Re: Instagram can track anything you do on any website in their in-app browser

#112

I hope Apple doesn't disable JS injection in WKWebViews in response to this. JS injection is the (only?) way to call native Swift methods from JS ie. bridging. I am not sure what the solution here is. Maybe only allow injection to sites you control (via apple association file).

Should only be allowed on domains one owns. Could be solved by DNS records or certificates.

Yup, apple association file is Apple's method of proving ownership to a domain.

Re: Instagram can track anything you do on any website in their in-app browser

#113
post #93

Earlier quoted context omitted.

Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…

> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.

I don't think the GP is saying that Meta should have ignored a lawful order. I think they're saying that they shouldn't have put themselves in the position of being able to render that information, and only have done so because it's profitable for them to do so.

Re: Instagram can track anything you do on any website in their in-app browser

#114

As a provider is it possible to defend against this with a Content Security Policy or does this mechanism override the site’s CSP?

MDN docs for Content Security Policy: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP (for anyone unfamiliar with that browser feature that should in theory disallow injection for websites you control).

Re: Instagram can track anything you do on any website in their in-app browser

#115
post #81

I hope Apple doesn't disable JS injection in WKWebViews in response to this. JS injection is the (only?) way to call native Swift methods from JS ie. bridging. I am not sure what the solution here is. Maybe only allow injection to sites you control (via apple association file).

Apple can just disallow in app browsers in the store policy. Require apps to call out to the default external browser.

The line is a bit blurry there. from a webview-based apps to just in-app browsers that opens when you tap a link in an app.

Re: Instagram can track anything you do on any website in their in-app browser

#116

>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.

It should be reported as a vulnerability. To Apple. Yes they made a decision for this as well but a decision can still be reported as a vulnerability.

Re: Instagram can track anything you do on any website in their in-app browser

#117
post #103

surprised this is at the top of HN. isn’t it obvious that every app does this? tiktok, snapchat, even linkedin all open links in their built-in browser and can track what you’re doing. click open in safari if you’re doing anything more than visiting a single page.

It’s not obvious but it is reasonable.

Re: Instagram can track anything you do on any website in their in-app browser

#118

Earlier quoted context omitted.

> use the sites. Which are increasingly user hostile, if not down right impossible to view on mobile. Go try using Reddit or Twitter on your Mobile browser.

It is infuriating that I can't browse certain Reddit pages because they want me to "use the app so they know I'm over 18". I first ran into this in my current attempt to play through Dark Souls 3. It seems like the community there has a lot of good discussions about beating certain bosses, but for some reason, Reddit has decided that the content in that sub-reddit needs age verification and they wall it behind the ap…

> It is infuriating that I can't browse certain Reddit pages because they want me to "use the app so they know I'm over 18".

Nothing's stopping you. There is no such message on old.reddit.com.

Re: Instagram can track anything you do on any website in their in-app browser

#119

>I’ve disclosed this issue with Meta through their Bug Bounty Program lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.

[deleted]

Re: Instagram can track anything you do on any website in their in-app browser

#120
post #93

Earlier quoted context omitted.

Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…

> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.

[deleted]
Post reply on HN