Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

11–20 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#11

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

The question is how do you ban it, and then how do you prove that people are breaking those rules?

Re: Covert web-to-app tracking via localhost on Android

#12

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

The question is how do you ban it, and then how do you prove that people are breaking those rules?

https://news.ycombinator.com/item?id=43595269

Re: Covert web-to-app tracking via localhost on Android

#13
To me it's weird that they're willing to misuse browser APIs so blatantly for interprocess communication, when, as I understand it, server-side correlation using a combination of IP, battery level and screen dimensions probably already gets them 95% of the surveillance capability.

Re: Covert web-to-app tracking via localhost on Android

#14
post #5

This just reinforced the use of uMatrix. Governments should mandate browser vendors to implement any standards gorhill might come up with.

Unfortunately in modern web uMatrix is just incredibly annoying. Nearly every site breaks for various reasons and often allowing everything in uMatrix still doesn't fix the issue.

Card payments, especially with 3D secure that use iframes, are one of the biggest problems. This often leads to creating new order several times since allowing something + reloading loses the entire flow.

Captchas are also massive pain, probably because they can't fingerprint as well as normally?

Life after having disabled uMatrix completely has been better.

Re: Covert web-to-app tracking via localhost on Android

#15
post #7

"UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed." I'm surprised they're allowed to listen on UDP ports, IIRC this requires special permissions? > The Meta (Facebook) Pixel JavaScript, when loaded in an Android mobile web browser, transmits the first-party _fbp co…

Nothing quite like an instant panicked coverup to confirm guilt and intent.

Hopefully not too late to make it into the lawsuit. Assholes.

Re: Covert web-to-app tracking via localhost on Android

#16
post #9
post #5

This just reinforced the use of uMatrix. Governments should mandate browser vendors to implement any standards gorhill might come up with.

If only uMatrix was still developed/supported.

It still works very well. I'm using it on both Linux and Android. The UI is far better than its replacement inside uBO.

Re: Covert web-to-app tracking via localhost on Android

#17
post #8
post #6

Crap like this is why I haven't had the Facebook or Instagram apps installed for years. I still have accounts, but I only visit them via the browser.

[flagged]

I heard they arrested a serial bank-robber and he said this in court when they asked him why he did it.

Re: Covert web-to-app tracking via localhost on Android

#18

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

The question is how do you ban it, and then how do you prove that people are breaking those rules?

I know. It's wishful thinking that will never become a reality. I pray for a solarpunk future in the same way

Re: Covert web-to-app tracking via localhost on Android

#19
post #8
post #6

Crap like this is why I haven't had the Facebook or Instagram apps installed for years. I still have accounts, but I only visit them via the browser.

[flagged]

There are over 300M companies in the world. It seems only 2 companies did this. So look at the revenue models of the other 299,999,998 companies. Meta only started this less than a year ago, so look at their revenue model prior to that.

Re: Covert web-to-app tracking via localhost on Android

#20
post #8
post #6

Crap like this is why I haven't had the Facebook or Instagram apps installed for years. I still have accounts, but I only visit them via the browser.

[flagged]

Imagine a website not being a trojan horse, but directly serving non-targeted advertising to users at the same level as their content.

They could target it by tailoring it to content they're serving, just like I'd be ok with seeing an ad for a new car when I'm on a page reading about the properties of a given combustion engine.

Post reply on HN