Live data from Hacker News

"Localhost tracking" explained. It could cost Meta €32B

zeropartydata.es

11–20 of 286 posts

Re: "Localhost tracking" explained. It could cost Meta €32B

#11
Sounds like you're affected if you have either Facebook or Instagram app installed on an Android phone, you're signed into your account, and you don't have anything set up to block tracking pixels and the like (though that last part I'm not as sure of).

Getting through VPNs and incognito mode are the most egregious parts of this offense, though. I think some people are under the impression that's a way to act like you're in total privacy... but it's not. It's just an easy way to act like you're in a new browser session or coming from another location, mostly.

Re: "Localhost tracking" explained. It could cost Meta €32B

#12
Tldr because this article has way too much fillers to my taste (but I'm sure there are people out there that enjoy reading that kind of thing):

The native Instagram and meta apps start a server listening on predefined ports when you launch said apps, they eventually run on the background as well. When you are on your browser, whether in private more, not logged, refused or disabled cookies, or anything else that might make you feel like you are not being explicitly tracked, the browser will connect to the locally running servers through webrtc and send all tracking data to said servers from the browser.

The android sandboxing thing is basically about how Android isolates each app and should only allow communication through android intents that inform the user of such inter app communication, such as sharing photos and the like. In this case, the browser is communicating with Instagram and Facebook apps without letting the user know.

The legal infregement here is that this happens even when you refuse to be tracked, which is a violation of GDPR and another law mentioned in the article.

The 32B figure is a theoretical maximum (but they also mentioned 100B+ in the article, which confuses me).

Re: "Localhost tracking" explained. It could cost Meta €32B

#13
post #7

This is an incredibly scummy and devious implementation of user tracking. I think META shareholders should hold onto their hats with this one. @dang maybe add a $ to the 32B? I see B so often with AI Models that I think the currency symbol would be useful in this link title

Ditto on the 32B, especially since that's IIRC one of the llama model sizes!

Re: "Localhost tracking" explained. It could cost Meta €32B

#14
So I am seeing two issues here.

1. Android allows apps to open ports without permissions. And apps to communicate with each other without permissions.

2. The browsers allow random domains to access services on the localhost. Without notifying the user. We have seen vulnerabilities in the past accessing dev services running on localhost. Something should be done there.

Re: "Localhost tracking" explained. It could cost Meta €32B

#15
Very impressive but not surprising coming from Meta. They have an history of doing this kind of things.

Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. That's what allowed them to know WhatsApp and Instagram were good acquisition targets.

At this point, I think the race for Zuckerberg is, can Meta survive long enough for the next platform shift (AR or VR) where they will own one of the major platforms and won't need to abide by any reasonable rules before their "internet tentacles" that sustain the Ad Machine are cut off.

My bet is they will make it. Though I don't wish it, they're on track.

Re: "Localhost tracking" explained. It could cost Meta €32B

#16

Every story like this has me thinking about two things: 1. Companies have no soul. They are, by design, just chasing revenue. Everything else is just a risk to be factored. 2. There are real humans at these companies who choose to take part in the business and design and engineering, etc. I don’t think these humans have no soul (though some won’t), and I don’t think they’re stupid (though some are). I think it’s just…

Never underestimate the evil a human can perpetuate in the name of a paycheck.

Re: "Localhost tracking" explained. It could cost Meta €32B

#18
post #4

My prediction, facebook gets fined something like ~12 million euros, eu bureaucrats shake their hands, facebook finds a different way to do the same thing. Definitely not even close to 32B

The EU doesn’t play around in this realm. 1.2 billion fine for an earlier incident: https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fi...

1.2B is less than 1% of Meta's revenue in FY2024. Maximum fines for infractions like these should exist on a sliding scale, as some percentage of prior revenue.

Re: "Localhost tracking" explained. It could cost Meta €32B

#19
post #7

This is an incredibly scummy and devious implementation of user tracking. I think META shareholders should hold onto their hats with this one. @dang maybe add a $ to the 32B? I see B so often with AI Models that I think the currency symbol would be useful in this link title

It's 32B€

Re: "Localhost tracking" explained. It could cost Meta €32B

#20
The same European intellegentsia that is progressively forcing Apple to tear down the walled garden simultaneously fails to understand that this is exactly why they had it in the first place:

> You’re not affected if (and only if) . . . > You browse on desktop computers or use iOS (iPhones)

At the very least they should step back and allow companies to enforce safeguards because they clearly lack the understanding or foresight to do so effectively.

The simple way for the EU to beat Meta is to stop being so cheap: break the WhatsApp dependency by actually paying properly for something that has a decent UX and doesn't track you. If you aren't willing to do this you will be exploited over and over again. TANSTAAFL

Post reply on HN