Covert web-to-app tracking via localhost on Android
localmess.github.io
Covert web-to-app tracking via localhost on Android
1–10 of 356 posts
Re: Covert web-to-app tracking via localhost on Android
#2Re: Covert web-to-app tracking via localhost on Android
#3>Google says it's investigating the abuse
That's a bit ironic, considering how they're using any side channel they could lay their hands on (e.g. Wi-Fi AP names) to track everyone. Basically every large app vendor with multiple apps does something similar to circumvent OS restrictions as well.
Re: Covert web-to-app tracking via localhost on Android
#4Re: Covert web-to-app tracking via localhost on Android
#5Re: Covert web-to-app tracking via localhost on Android
#6Re: Covert web-to-app tracking via localhost on Android
#7I'm surprised they're allowed to listen on UDP ports, IIRC this requires special permissions?
> The Meta (Facebook) Pixel JavaScript, when loaded in an Android mobile web browser, transmits the first-party _fbp cookie using WebRTC to UDP ports 12580–12585 to any app on the device that is listening on those ports.
Borders on criminal behavior.
Apparently this was a European team of researchers, which would mean that Meta very likely breached the GDPR and ePrivacy Directive. Let's hope this gets very expensive for Meta.
Re: Covert web-to-app tracking via localhost on Android
#8Crap like this is why I haven't had the Facebook or Instagram apps installed for years. I still have accounts, but I only visit them via the browser.
Re: Covert web-to-app tracking via localhost on Android
#9This just reinforced the use of uMatrix. Governments should mandate browser vendors to implement any standards gorhill might come up with.