Do they actually do that? Because I'm not so sure that they do.
The preview sends a request to some server on a Facebook subdomain. I know because I was sniffing traffic on my phone without any Facebook app installed other than WhatsApp.
Did you see the content of that domain? It might be spam/phishing protection, which can be done in a privacy-preserving way (e.g. sending only a truncated hash of the link TLD to a server and downloading a larger set of blocked domains for local filtering).
At least on my Mac, I also only see connections to the URL domain, nothing to a Facebook subdomain.
> 7.5.1. Partner User Location. Any Partner Users that Partner Enlists or provides access to the Interoperable Messaging Services must be located and remain in the EEA. Without limiting Section 11 (Warranties), Partner represents and warrants that it will only (i) Enlist and (ii) enable access to the Interoperable Messaging Services by Partner Users that Partner independently validates are located in the European Eco…
And that they are reluctantly complying in bad faith in the most hostile way they found. Is this going to fly? Where do these 60 days come from for instance? How is it any useful and who is going to want to implement such interoperability under such terms? This reads like a lot of words to say Fuck You Europe to me. Well, feelings are mutual, at least we are on the same page, them and me.
Sounds less like "bad faith" and more like "I was hoping that Meta would cave and offer this to everyone, but turns out they don't have to do that because EU jurisdiction ends at EU borders"?
Gosh, all of this is so locked down. I've been waiting for this, and hoping I could "just" cook up some of my own code to use with WhatsApp, and/or integrate it with Pidgin or bridge to email or whatever. But the entire process is about as hostile as possible. For example "Partner shall have in place a dedicated security team" basically excludes most startups, or most smaller companies. It's not clear to me if this i…
You seem to be confusing interoperability with WA’s desires to make sure that e2e encryption isn’t broken. What’s the point of thinking that WhatsApp is e2ee if anyone can write their own end point? my friends and I use WhatsApp because we know the messages are secure. Imagine if every other group message had the “green bubble” equivalent experience if someone was using a custom client.
>What’s the point of thinking that WhatsApp is e2ee if anyone can write their own end point?
But even if you're using the official super secure endpoint, there's nothing preventing the user from taking a picture of the screen, which bypasses all protections.
Hey I can shed light on this. It’s the iCloud keychain. Disabling the keychain doesn’t delete existing entries. There is no way to modify the keychain on iOS (you can on Mac). Lots of apps store sign on data in the keychain for obvious reasons. It would be really great to have a keychain section in iOS’s settings, like Keychain Access on Mac. The dev can build in-app functionality to delete keys from the keychain, bu…
> Keychain storage doesn’t let FB track you It sure lets app developers identify me across app deletions and reinstalls! I'm also not sure why Apple has kept this loophole open for so long when they are otherwise so focused on making sure user tracking across reinstalls is so hard (e.g. by making APNs tokens change after a reinstall, which used to not be the case as well, restricting access to read the device MAC add…
You can theoretically do that, but that's against app store regulations. I'd imagine that logging out first, then deleting the app, should prevent the behavior because afterwards there's very little reason to have any sort of lingering keychain data. But at the end of the day, it's basically an honor system.
> These apps are free to download Yes but you aren’t truly free to choose which app you download. You have to use the one being used by the people you want to message. That is of strong benefit to incumbents.
Has there been meaningful innovation in messaging? I had free AIM on $3 T-Zones in 2006. So I see no downsides to just forcing interoperability.
Meta and Apple are paying for far more bandwidth than what AIM was moving around back then. Very high quality videos, audio, pictures, and gifs not to mention files and group video calls.
There's something really appalling that I discovered lately and I can't believe there isn't enough uproar about it. Every attempt to talk about this gets ignored or buried (maybe by people who want this ""feature"" to be kept quiet) so I will take every opportunity on existing discussions about Facebook to bring it up: Facebook (and TikTok) store tracking data on iOS that the user CANNOT SEE and CANNOT DELETE: • It s…
> Every attempt to talk about this gets ignored or buried (maybe by people who want this ""feature"" to be kept quiet) so I will take every opportunity on existing discussions about Facebook to bring it up: Or maybe this happens because it's completely off-topic here and has nothing what-so-ever to do with WhatsApp? Most of your other messages seem similarly off-topic: https://hn.algolia.com/?dateRange=all&page=0&pre…
It's less of a "question" and more of a "WHY THE FUCK is this even a thing???" and why aren't people giving FB/Apple hell for this??
There was a popular post just a few hours ago about Filezilla (whatever that is) containing adware in the default download.
This is a FAR more grave violation of privacy than anything so far — Tracking people ACROSS reinstalls AND MULTIPLE PHONES!
There's something really appalling that I discovered lately and I can't believe there isn't enough uproar about it. Every attempt to talk about this gets ignored or buried (maybe by people who want this ""feature"" to be kept quiet) so I will take every opportunity on existing discussions about Facebook to bring it up: Facebook (and TikTok) store tracking data on iOS that the user CANNOT SEE and CANNOT DELETE: • It s…
Hey I can shed light on this. It’s the iCloud keychain. Disabling the keychain doesn’t delete existing entries. There is no way to modify the keychain on iOS (you can on Mac). Lots of apps store sign on data in the keychain for obvious reasons. It would be really great to have a keychain section in iOS’s settings, like Keychain Access on Mac. The dev can build in-app functionality to delete keys from the keychain, bu…
> Keychain storage doesn’t let FB track you
Are you serious? They literally know my previous accounts even after I DELETE the app, WIPE the iPhone, and login to the same iCloud account on ANOTHER iPhone.
They do this by storing some data. They can store data about anything else. How can be sure if we can't even LOOK at that data?
I only caught this because of the visible symptoms they CHOSE to show us: The list of previous logins.
Wow this shows the DMA might really do some good. I'm impressed with EU regulation. Standardized chargers, ending roaming charges, GDPR, DMA. Definitly worth the side effects overall.
Side effects like horrendous cookie banners everywhere. I really like the DMA too
After gdpr you can pretty consistently get companies to delete their data about you, and often get a data export. Those alone seem worth the consent pop ups.