Live data from Hacker News

"Localhost tracking" explained. It could cost Meta €32B

zeropartydata.es

71–80 of 286 posts

Re: "Localhost tracking" explained. It could cost Meta €32B

#71
You've rented a device that connects to a worldwide communications network built on a principle of numerically exact message routing between every device and use it to run numerically exact programs from service providers to access services that host and consolidate the particulars of your identity within their servers rather than your device, and you are amazed that the device can persistently track everything you do with the device?

What's the point of being Google or Apple except for precisely control of such central services?...

♪ Central Services, we do the work, you do the pleasure... ♪

"Have you considered your ducts?"

...And it just so happens that all the news you see is from the device and subject to this surveillance used to colonize your mind... Sounds democratic!

The old Politburo could only dream of such tools for maintenance of a compliant, obedient proletariat.

And with Central Services new "AI" you can get a brain implant to ensure your perfect conformity and access to the best paying jobs in the world, yours and your family's future will be secure. Be sure to invest in these securities, shop here, entertain and vacation there— leave the driving to us! Do it your way.

"A new life awaits you in the Offworld Colonies. A chance to begin again in a golden land of opportunity and adventure. So c'mon America..."

"...Every leap of civilization was built off the back of a disposable work force..."

Re: "Localhost tracking" explained. It could cost Meta €32B

#72

Earlier quoted context omitted.

Completely agree. My feeling is that corporate officers should bear the burden that the corporation as a person currently bears. I can only imagine how much better things would be in past experiences if the C-levels felt a personal need to actually know how the sausage is being made.

I can't fully agree because the way I see it, that is in a way scapegoating the company executives. Are they responsible? Probably, yes, they set the direction of the company and give the orders at the highest level. But we the engineers and designers are the ones actually implementing what is probably a fairly nebulous order at the highest levels into something concrete. They deign that there should be evil created,…

Do you also take personal responsibility for your company’s hiring practices, investment strategy, and marketing content? None of that would exist without you.

I think anyone would agree that there’s a level of flagrantly where individuals should feel culpability and make the right choices (“write software to prescribe poison to groups we don’t like”).

But something like this? Two apps establishing a comms channel? How many millions of times does this get done per year with no ill intent or effect? Is every engineer supposed to demand to know l of the use cases, and cross reference to other projects they’re not working on?

At some point it’s only fair to say that individuals should exercise their conscience when they have enough information, but it is not incumbent on every engineer to demand justification for every project. That’s where the decision makers who do have the time, resources, and chatter to know better should be taking at least legal responsibility.

Re: "Localhost tracking" explained. It could cost Meta €32B

#73

Earlier quoted context omitted.

> Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. They had people install a VPN app using enterprise certificate so it was never in the App Store and they monitored all the traffic that the VPN sent. Unlike this case, it required users to jump through a number of hoops/scary iOS warnings. Many still did, for a gift card or less.

> Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. That's what allowed them to know WhatsApp and Instagram were good acquisition targets. Incorrect. An Israeli startup (Onavo) had pivoted into selling data acquired from their VPN got acquired by Facebook. Importantly, they used statistics to estimate population prevalence which is how F…

Ahh, I knew about the Onavo acquisition history but I had had "context crunched" it down and skipped over the time when it was on the App Store before they rebranded it as (internally) "Project Atlas" and externally Facebook Research which was distributed through enterprise distribution. Thank you for the clarification.

Re: "Localhost tracking" explained. It could cost Meta €32B

#75

Earlier quoted context omitted.

> Companies have no soul. They are, by design, just chasing revenue. Everything else is just a risk to be factored. I disagree - companies are set up/run by people, and those people define company culture/ company culture reflects those people. Not all companies, even big ones, are the same. To make that concrete - if Mark Zuckerberg found out about the above activity and was appalled and sacked everyone involved tha…

> To make that concrete - if Mark Zuckerberg found out about the above activity and was appalled and sacked everyone involved that would send out a very strong signal. We know from another case that the opposite culture is true: when told to break the law and use copyrighted material, the engineers feel uneasy - they were not stupid and understood what they were going to do, and for a similar-in-nature-but-a-few-orde…

Exactly.

People made that decision.

Re: "Localhost tracking" explained. It could cost Meta €32B

#76

So I am seeing two issues here. 1. Android allows apps to open ports without permissions. And apps to communicate with each other without permissions. 2. The browsers allow random domains to access services on the localhost. Without notifying the user. We have seen vulnerabilities in the past accessing dev services running on localhost. Something should be done there.

I'd split that first list into two: 1a. Arbitrary apps can listen on ports without permissions. 1b. Arbitrary apps can access local ports without permissions. I've recently been experimenting with running the browser (on my desktop) in a network namespace precisely because of these reasons. Random websites shouldn't be able to access services running on localhost.

> I've recently been experimenting with running the browser (on my desktop) in a network namespace precisely because of these reasons.

Let me introduce you to https://www.qubes-os.org/.

Re: "Localhost tracking" explained. It could cost Meta €32B

#77

Every story like this has me thinking about two things: 1. Companies have no soul. They are, by design, just chasing revenue. Everything else is just a risk to be factored. 2. There are real humans at these companies who choose to take part in the business and design and engineering, etc. I don’t think these humans have no soul (though some won’t), and I don’t think they’re stupid (though some are). I think it’s just…

I think about this a lot …

I think the key aspect of a company with “soul” is humans directing the company rather than the company directing the humans.

I think the biggest inflection point where this flips is when companies “pivot”.

The human founders of a company should have a well-defined philosophical Vision of what it is they are building and who it is for. If this doesn’t work out, the business should be terminated.

It is the zombie husks of corporate organizations that have been repurposed to other ends by finance that are dangerous.

Re: "Localhost tracking" explained. It could cost Meta €32B

#78

Earlier quoted context omitted.

> Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. That's what allowed them to know WhatsApp and Instagram were good acquisition targets. Incorrect. An Israeli startup (Onavo) had pivoted into selling data acquired from their VPN got acquired by Facebook. Importantly, they used statistics to estimate population prevalence which is how F…

Ahh, I knew about the Onavo acquisition history but I had had "context crunched" it down and skipped over the time when it was on the App Store before they rebranded it as (internally) "Project Atlas" and externally Facebook Research which was distributed through enterprise distribution. Thank you for the clarification.

Yeah, they were different and happened at different times. I can kinda justify Onavo (personally I think that they could've been the Neilsen of mobile if they hadn't gotten acquired) but the whole enterprise cert thing was super, super shady.

Re: "Localhost tracking" explained. It could cost Meta €32B

#80

Very impressive but not surprising coming from Meta. They have an history of doing this kind of things. Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. That's what allowed them to know WhatsApp and Instagram were good acquisition targets. At this point, I think the race for Zuckerberg is, can Meta survive long enough for the next platf…

Companies have been trying to make AR/VR the next platform shift but I'm not super convinced that people actually want or desire this outside of a few niche games. To me it feels like it has about as much staying power as 3D glasses in movies.
Post reply on HN