Live data from Hacker News

Instagram can track anything you do on any website in their in-app browser

krausefx.com

141–150 of 469 posts

Re: Instagram can track anything you do on any website in their in-app browser

#141
post #64
post #39

Earlier quoted context omitted.

webviews for clicking arbitrary links in apps like instagram or gmail are absurdly restrictive. i lose my context, cookies, and regular tools (bookmarks are gone, sharing often overridden, etc)

This is why https://developer.apple.com/documentation/safariservices/sfs... exists and why the blog post advocates for using it.

That was a great update, but still not a true browser. No tabs, no bookmarks. Why should the website be restricted to one tab? Just open Safari and be done with it.

Re: Instagram can track anything you do on any website in their in-app browser

#142

Please tell every newspaper to publish this so Apple puts a stop to this. I have no idea why they allow this. All apps should use Safari unless they’re a browser and this rated “18+”

Well I like when browsing reddit that when I open links they are sandboxed. The in-app browser in that case has an easy button to open to get to my normal safari if I want to.

Re: Instagram can track anything you do on any website in their in-app browser

#144
post #103

surprised this is at the top of HN. isn’t it obvious that every app does this? tiktok, snapchat, even linkedin all open links in their built-in browser and can track what you’re doing. click open in safari if you’re doing anything more than visiting a single page.

>isn’t it obvious that every app does this?

Not if you never have/ don't use them.

Re: Instagram can track anything you do on any website in their in-app browser

#145

Earlier quoted context omitted.

> this is the same company that just gave police DMs that aided in an abortion investigation They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.

I don't think the GP is saying that Meta should have ignored a lawful order. I think they're saying that they shouldn't have put themselves in the position of being able to render that information, and only have done so because it's profitable for them to do so.

It’s really painful to see all of these encryption holes in every product we use daily. Apple claims privacy, yet your whole phone sits unencrypted on their server ready to be served to anyone who asks (assuming you back up your phone to iCloud)

Re: Instagram can track anything you do on any website in their in-app browser

#146

Websites need cookie notices, but apps can track your full web usage (albeit within the in-app browser) without any such notice or opt in? Doesn't seem like this would be legal. Anyone know how this could be compliant in the EU? It's also frustrating that on an android device you can't simply disable in-app browsers globally.

The EU+UK e-privacy "cookie" rule applies to apps in the same way as anything else that's sending/receiving data over a public network (e.g. the Internet): all storage of information to, or reading of information from, the end-user device requires their free, informed and specific consent, unless it's a technical necessity for the service they requested, or certain limited (technical) purposes like load balancing. How strictly this is enforced by regulators has waxed and waned over time and from one country to another. Civil litigants, however, have had pretty good results in the courts (or just threatening litigation) - e.g. the Lloyd and Vidal-Hall cases against Google in the UK

Re: Instagram can track anything you do on any website in their in-app browser

#147
post #73
post #44

Earlier quoted context omitted.

Apps that use Safari View Controller cannot view the page - of course Facebook doesn't use SVC for this reason. While you're right that the Facebook/Instagram app can spy on links opened within the app, it can't plant cookies in your web browser - so those go both ways.

I thought Facebook/Instagram used a WebView for their in-app browser on both iOS and Android? Which means they can do anything they want, including exfiltrate your browsing.

GP a was referring to a specific “web view” implementation that offers an almost-complete browser implementation and security on iOS. Facebook does not use this but a regular WebView

Re: Instagram can track anything you do on any website in their in-app browser

#148

As a provider is it possible to defend against this with a Content Security Policy or does this mechanism override the site’s CSP?

External sources yes, preventing an app to inject inline HTML and JavaScript is tricky.

Re: Instagram can track anything you do on any website in their in-app browser

#149

Please tell every newspaper to publish this so Apple puts a stop to this. I have no idea why they allow this. All apps should use Safari unless they’re a browser and this rated “18+”

Well I like when browsing reddit that when I open links they are sandboxed. The in-app browser in that case has an easy button to open to get to my normal safari if I want to.

I’d much rather seen a system-wide “container” implementation a-la-Firefox instead. Safari is pretty good at this but not as good as Firefox. I really want my real-life accounts be segregated from the rest of the internet. Reddit should never be able to know what other sites I use.

Re: Instagram can track anything you do on any website in their in-app browser

#150

Earlier quoted context omitted.

I don't think the GP is saying that Meta should have ignored a lawful order. I think they're saying that they shouldn't have put themselves in the position of being able to render that information, and only have done so because it's profitable for them to do so.

It’s really painful to see all of these encryption holes in every product we use daily. Apple claims privacy, yet your whole phone sits unencrypted on their server ready to be served to anyone who asks (assuming you back up your phone to iCloud)

My understanding is that iCloud backups are encrypted[1].

[1]: https://support.apple.com/en-us/HT202303

Post reply on HN