Live data from Hacker News

Instagram can track anything you do on any website in their in-app browser

krausefx.com

121–130 of 469 posts

Re: Instagram can track anything you do on any website in their in-app browser

#121
post #93

Earlier quoted context omitted.

Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…

> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.

Keep reading, you might be missing the point, the paragraph continues on after that sentence

Re: Instagram can track anything you do on any website in their in-app browser

#122
post #93

Earlier quoted context omitted.

Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…

Yes, but people love that, otherwise e.g. freemium and ad-driven games would not exist. Consumers have a payment-avoiding behaviour as a status quo.

This comes across as victim blaming.

Users are given the choice to accept risks that are buried on page 7 of privacy policies only a lawyer could understand the tricks in.

Services knowingly endangering unknowing users for money should be like cigarettes and be forced to say on the signup page in big bold text they can and will sell user data to anyone, including law enforcement.

Users largely think free services are like public libraries and do not default to expecting they are being exploited for money. Element, Wikipedia, and duckduckgo exist for free without selling user data so it is not a given that exploitation is always present in free services.

Re: Instagram can track anything you do on any website in their in-app browser

#124
post #93

Earlier quoted context omitted.

Remember this is the same company that just gave police DMs that aided in an abortion investigation. If those had been end to end encrypted that risk would not have existed, but they made a business decision to leave the application vulnerable to spying for profit reasons. That is a vulnerability, in the same way we call it a vulnerability when an entity man-in-the-middles a browser to spy on people. Personal user br…

Yes, but people love that, otherwise e.g. freemium and ad-driven games would not exist. Consumers have a payment-avoiding behaviour as a status quo.

This isn't a consumer choice issue. People love morphine too, it doesn't mean Amazon can sell it to them. If Apple enforced its own rules in this case, Facebook would just have to act like any other developer and find some revenue streams that comply with established privacy norms.

Re: Instagram can track anything you do on any website in their in-app browser

#125
post #47

I generally don't see any appeal to in-app browsers in the first place. They often have extremely broken navigation controls (i.e. attempting to swipe back to a previous page usually just returns back to the app), block the ability to navigate to a specific URL, content blockers don't work, don't allow opening "smart links" that would typically open in another app if opened from a normal browser, etc. From what I'm g…

I'm sure this has gotten better as people have become more used to smartphones, but I worked on a popular app for a big company a number of years ago, and we would send people out to Safari to open links. The number of customer service calls we got from people who couldn't figure out how to get back to the app after that was ASTOUNDING. We eventually gave in and did an in-app browser. Not only did it get rid of that category of call, but it also noticeably helped our key metrics because fewer people were leaving the app to never come back again.

I realize that doesn't address the appeal FOR USERS, but it is why we did it as developers.

Re: Instagram can track anything you do on any website in their in-app browser

#126
The battle for control continues. I started noticing this personally when using social media and took note of the fact that the browsing was still being done within the app when clicking on an external link.

The war on control of data continues on.

Re: Instagram can track anything you do on any website in their in-app browser

#127

No wonder. I recently opened a link on Instagram and the website's responsive elements were completely broken. Then I opened the link in Safari and it worked fine. Does this script injection break Apple's ToS? I thought Apple required Safari/Webkit for all in-app browsers? Zuckerberg has no shame. PS. I hate in-app browsers. They don't sync with my main browser states such as authenticated sessions.

It probably is still running Webkit underneath with some additional JavaScript to track everything

It would have to be. Apple's main bugbear seems to be anyone embedding Chrome or Firefox on iOS.

Re: Instagram can track anything you do on any website in their in-app browser

#128

Earlier quoted context omitted.

in 2015 i got an iphone for a job, then i made it my daily driver because i liked the restrictions. now my phones last four years instead of one

How is the walled garden allowing a phone to last for four years? Where you getting new phones because you polluted your non-walled garden device with so many bad apps that you chose to get a new device? Not really following your point, but maybe I am?

i was getting new phones mostly because my devices were getting bogged down by android updates and capabilities. the os allowed developers to do more and more things, and offered more and more customization, faster than the pace of hardware improvements supported, to the point i'd have to get a new phone if i wanted something both up-to-date and fast. if i kept a phone longer much longer than a year, i'd have to worry about software updates as well, OR replace the OS and deal with instability.

and i'm not talking about bad phones here — htc one s, nexus 4, nexus 5, nexus 5x. admittedly, degradation of shitty NAND is still a factor in higher-end android phones, so it's not all about the android ecosystem being a free-for-all

an iphone xr will still run everything fine, including the latest version of ios. hundreds of dollars saved and a whole set of problems avoided over the life of the phone. i only replace my phones when they're smashed to bits now

anecdote: someone in my family just had to replace their android phone because a software update caused the radio to stop working for calls. so the ecosystem issue is not just a userland thing

Re: Instagram can track anything you do on any website in their in-app browser

#129
post #103

surprised this is at the top of HN. isn’t it obvious that every app does this? tiktok, snapchat, even linkedin all open links in their built-in browser and can track what you’re doing. click open in safari if you’re doing anything more than visiting a single page.

It's not surprising, but it's not obvious.

Re: Instagram can track anything you do on any website in their in-app browser

#130
post #81

Earlier quoted context omitted.

Apple can just disallow in app browsers in the store policy. Require apps to call out to the default external browser.

The line is a bit blurry there. from a webview-based apps to just in-app browsers that opens when you tap a link in an app.

Sure but since the App Store is human review, they can tell the difference between a web view and an external website. Or just require the app to only call web views on their own domain or a whitelist of domains they submit with the app.
Post reply on HN