Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

151–160 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#151
post #117

Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.

I am not sure which Meta apps open ports, but e.g. Samsung phones come with a bunch of Meta apps pre-shipped. IIRC just removing the Facebook app is is not enough, there is another service installed that is not visible as an app (com.facebook.services etc.), which you can only uninstall from the data partition with something like ADB/UAD.

Or buy an iPhone or a Pixel.

Re: Covert web-to-app tracking via localhost on Android

#152

Doing something like this should result in Meta and such being legally annihilated. But nothing will happen, as usual.

What's the crime?

Spying on users, connecting their real life identities to their browsing history without their consent or knowledge?

Re: Covert web-to-app tracking via localhost on Android

#153

Doing something like this should result in Meta and such being legally annihilated. But nothing will happen, as usual.

What's the crime?

Tracking users without their consent. This is a crime in the EU. It’s a crime that it’s not a crime in the US.

Re: Covert web-to-app tracking via localhost on Android

#154
post #81

Would an individual using this technique to collect information from someone else's computer possibly face prosecution under the Computer Fraud and Abuse act?

This only works if you control the code on both sides (ie. on the website being visited and an app running on the phone). It's not some sort of magic hack that allows you to exfiltrate arbitrary browser history. Therefore it's unclear how it can be construed as "hacking" in any meaningful way. As bad non-consensual tracking done by google/meta/whatever are, it's not covered under CFAA.

I agree it's not hacking, but the Computer Fraud and Abuse act seems to have a pretty broad definition of computer fraud and abuse. In particular, the technique seems like it might (emphasis mine) "knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value …". Would the other person have a reasonable belief that they didn't authorize access to information which their OS attempts to prevent access to?

I'm not a lawyer, so my question is genuine.

Re: Covert web-to-app tracking via localhost on Android

#155
post #117

Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.

I am not sure which Meta apps open ports, but e.g. Samsung phones come with a bunch of Meta apps pre-shipped. IIRC just removing the Facebook app is is not enough, there is another service installed that is not visible as an app (com.facebook.services etc.), which you can only uninstall from the data partition with something like ADB/UAD. Or buy an iPhone or a Pixel.

The Pixel "Private Space" feature should prevent Meta apps from running in the background. It also prevents you from getting notifications.

Re: Covert web-to-app tracking via localhost on Android

#156
post #147

Earlier quoted context omitted.

Eh. You can have a very comfortable career doing work that still lets you look at yourself in the mirror. You don’t have to choose to burn the world to pay the rent.

I agree with you but I also don’t. It’s a privilege to have the ability to choose which job you work.

Not in this case. If you’re qualified to get a job at a company who will pay you to sell out your neighbor, you’re qualified to get a job with a decent boss who’ll never ask you do to do this kind of thing, pays 90% as much, and is still many times the national average salary.

The alternatives are not doing evil vs starving. They’re getting paid well for doing evil, or getting paid well for doing good or at least neutral.

Re: Covert web-to-app tracking via localhost on Android

#157
post #31

This is the overall process used by Meta as I understand it, taken from https://localmess.github.io/ : 1. User logged into FB or IG app. The app runs in background, and listens for incoming traffic on specific ports. 2. User visits website on the phone's browser, say something-embarassing.com, which happens to have a Meta Pixel embedded. From the article, Meta Pixel is embedded on over 5.8 million websites. Even in I…

Not totally following but it sounds like you are saying one of the things they have been doing involves abusing mandated GDPR cookie notices to secretly track people?

Yes? The cookie in question is First Party, which means you’ve consented to permitting only that party to track you using it, and not permitting its use for wider behavioral tracking across websites.

However, the locally hosted FB/Yandex listener receives all of these first party cookies, from all parties, and the OPs implication is (I think) that now these non-correlateable-by-consent first party cookies can be or are being used to track you across all sites that use them.

Re: Covert web-to-app tracking via localhost on Android

#158

Earlier quoted context omitted.

Not totally following but it sounds like you are saying one of the things they have been doing involves abusing mandated GDPR cookie notices to secretly track people?

Yes? The cookie in question is First Party, which means you’ve consented to permitting only that party to track you using it, and not permitting its use for wider behavioral tracking across websites. However, the locally hosted FB/Yandex listener receives all of these first party cookies, from all parties, and the OPs implication is (I think) that now these non-correlateable-by-consent first party cookies can be or a…

Not only did you only consent to the one party using it, but the browser has robust protections in place to ensure that these cookies are only usable by that party. This “hack” gets around the restriction completely, leveraging a local service to aggregate all the cookies across sites.

Re: Covert web-to-app tracking via localhost on Android

#159

Earlier quoted context omitted.

The deprecation of third-party cookies, that all browsers were at one point on track to implement , was pretty much the most realistic first step to that. Which is why Google killed it last year by leveraging their control over Chrome. While not technically a crime, it was a disgusting, unethical market manipulation move that never really got the public outrage it deserved. Google execs’ initial support for it was al…

Most commenters on Hacker News hated Google’s plan and hoped it would fail. Were they wrong? It seems like damned-if-you-do, damned-if-you-don’t.

That stemmed from “dammit Google now every SaaS developer has to work nights to meet your arbitrary deadline”; here we’re caring more about the impact as consumers. It’s ok to think about things in two ways.

source: a developer who actually did have to do this (and did it, and now didn’t have to, but it’s done)

Re: Covert web-to-app tracking via localhost on Android

#160
post #147

Earlier quoted context omitted.

I agree with you but I also don’t. It’s a privilege to have the ability to choose which job you work.

Not in this case. If you’re qualified to get a job at a company who will pay you to sell out your neighbor, you’re qualified to get a job with a decent boss who’ll never ask you do to do this kind of thing, pays 90% as much, and is still many times the national average salary. The alternatives are not doing evil vs starving. They’re getting paid well for doing evil, or getting paid well for doing good or at least neu…

Ok you’ve convinced me!
Post reply on HN