Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

161–170 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#162
post #81

Would an individual using this technique to collect information from someone else's computer possibly face prosecution under the Computer Fraud and Abuse act?

This only works if you control the code on both sides (ie. on the website being visited and an app running on the phone). It's not some sort of magic hack that allows you to exfiltrate arbitrary browser history. Therefore it's unclear how it can be construed as "hacking" in any meaningful way. As bad non-consensual tracking done by google/meta/whatever are, it's not covered under CFAA.

The yandex one uses client/browser-side code to exfiltrate; it’s within the realm of possibility to abuse this, given a user visits a site under your control.

On the FB side, I can see a malicious user potentially poisoning a target site visitors’s ad profile or even social media algorithm with crafted cookies. Fill their feed with diaper ads or something.

Re: Covert web-to-app tracking via localhost on Android

#163

Probably hard to do for many but the solution seems be not to have their apps installed. It’s crazy to me that people tolerate FB et al on their devices where you have absolutely no control over what they’re doing.

I agree wrt Facebook, but there’s a long tail of useful apps-that-should-be-websites; 1 click for an app versus 45 seconds searching through tabs and re-logging in (etc) can be meaningful, especially when there are fifty of them.

My healthcare provider recently yanked the mobile version of their portal website, and forces users to download their app. Personally, I see the security angle, but still feel like it’s a punch in the face and so I just went back to paper billing and using a PC for healthcare stuff. More of this is coming, I suspect.

Re: Covert web-to-app tracking via localhost on Android

#164

Doing something like this should result in Meta and such being legally annihilated. But nothing will happen, as usual.

What's the crime?

Unauthorized access to a computer system. I'm sure if I connected to some port on a computer belonging to Meta without them wanting it, that would be the crime I would be charged with. But somehow if Meta connects to a port on my phone without me agreeing to it, it's not a crime?

Re: Covert web-to-app tracking via localhost on Android

#165
post #148
post #19

Earlier quoted context omitted.

There are over 300M companies in the world. It seems only 2 companies did this. So look at the revenue models of the other 299,999,998 companies. Meta only started this less than a year ago, so look at their revenue model prior to that.

If I could pay for my groceries with my browsing habits I would. In fact, I bet most people would.

More power to ‘em. And if Meta ever offers me the option to be compensated for my data they’re collected without my consent, I’d have that conversation with them.

Re: Covert web-to-app tracking via localhost on Android

#166
post #98
post #75

Earlier quoted context omitted.

Let it show "Use WebRTC?". If users don't understand, they click whatever. If the website really needs it to operate, it will explain why before requesting, just like apps do now. Always aim for a little more knowledgeable users than you think they are.

That feels pretty useless. You might as well do what happens today: enable it by default and allow knowledgable power users to disable it. If it's disabled, show a message to the user explaining why it's needed.

Today there's no way to disable it, I searched through my Firefox Mobile settings. So I'd say it's for very "power" users.

And why enable it by default, why not disable by default?

Also, sibling comments say iOS is already asking for the permission, why not just copy it?

Re: Covert web-to-app tracking via localhost on Android

#167
I wonder if companies like Wetter Online (from whom we know that they're selling the location data to brokers [0]) or ad service providers which offer libraries do the same.

If it were so, Google should be knowingly be allowing this to happen and be a co-conspirator. I mean, they surveil our devices as if it were their home. Impossible that they're not aware.

[0] https://netzpolitik-org.translate.goog/2025/databroker-files...

Re: Covert web-to-app tracking via localhost on Android

#168
post #117

Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.

I am not sure which Meta apps open ports, but e.g. Samsung phones come with a bunch of Meta apps pre-shipped. IIRC just removing the Facebook app is is not enough, there is another service installed that is not visible as an app (com.facebook.services etc.), which you can only uninstall from the data partition with something like ADB/UAD. Or buy an iPhone or a Pixel.

I tend to buy stock Android, e.g. Motorola moto g30, etc. It still has lots of Google stuff, but you can get rid of them, and I have a work profile specifically designed for Google-related stuff, and my personal profile is de-Googled as much as possible.

Re: Covert web-to-app tracking via localhost on Android

#169
post #146
post #47

Earlier quoted context omitted.

In the early days of the information revolution, when computers were new and being nerdy was still seen (almost universally) as a bad thing, a very high proportion of computer enthusiasts were people already on the fringes of society, for one reason or another. For a large number of them, hacking was a way to express their preexisting antiestablishment tendencies. For a lot of them, they were also your basic angsty a…

Thanks for your thoughts! How can we create more hackers? I think the fear of punishment has really put a damper on things but not sure how that can be avoided.

Hacking isn't about crime. It's about exploration. There are lots of people showing "the youths" how interesting it is to break a lock or go around it. Basically, any time you can make a system do something fun, helpful, or interesting that it wasn't intended to do, that's hacking. You can be 100% law abiding with no fear of punishment and still get the full experience.

Re: Covert web-to-app tracking via localhost on Android

#170
post #123

Earlier quoted context omitted.

As someone who works for a similar large org, it's just as likely that some low level programmer put it in without much thought, and then this got surfaces to higher up people who didn't know about it and told them to remove it immediately.

It seems incredibly unlikely a low level programmer could come up with this method then get the necessary code into both the tracking pixel served to third party sites and Meta's android apps without some higher ups knowing about it.

Or at the very least, a low level programmer not claiming credit for it during performance reviews which are reviewed by higher people.
Post reply on HN