Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

1–10 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#3
Actual report: https://localmess.github.io/

>Google says it's investigating the abuse

That's a bit ironic, considering how they're using any side channel they could lay their hands on (e.g. Wi-Fi AP names) to track everyone. Basically every large app vendor with multiple apps does something similar to circumvent OS restrictions as well.

Re: Covert web-to-app tracking via localhost on Android

#7
"UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed."

I'm surprised they're allowed to listen on UDP ports, IIRC this requires special permissions?

> The Meta (Facebook) Pixel JavaScript, when loaded in an Android mobile web browser, transmits the first-party _fbp cookie using WebRTC to UDP ports 12580–12585 to any app on the device that is listening on those ports.

Borders on criminal behavior.

Apparently this was a European team of researchers, which would mean that Meta very likely breached the GDPR and ePrivacy Directive. Let's hope this gets very expensive for Meta.

Post reply on HN