Doing something like this should result in Meta and such being legally annihilated. But nothing will happen, as usual.
What's the crime?
Covert web-to-app tracking via localhost on Android
161–170 of 356 posts
Re: Covert web-to-app tracking via localhost on Android
#162Would an individual using this technique to collect information from someone else's computer possibly face prosecution under the Computer Fraud and Abuse act?
This only works if you control the code on both sides (ie. on the website being visited and an app running on the phone). It's not some sort of magic hack that allows you to exfiltrate arbitrary browser history. Therefore it's unclear how it can be construed as "hacking" in any meaningful way. As bad non-consensual tracking done by google/meta/whatever are, it's not covered under CFAA.
On the FB side, I can see a malicious user potentially poisoning a target site visitors’s ad profile or even social media algorithm with crafted cookies. Fill their feed with diaper ads or something.
Re: Covert web-to-app tracking via localhost on Android
#163Probably hard to do for many but the solution seems be not to have their apps installed. It’s crazy to me that people tolerate FB et al on their devices where you have absolutely no control over what they’re doing.
My healthcare provider recently yanked the mobile version of their portal website, and forces users to download their app. Personally, I see the security angle, but still feel like it’s a punch in the face and so I just went back to paper billing and using a PC for healthcare stuff. More of this is coming, I suspect.
Re: Covert web-to-app tracking via localhost on Android
#164Doing something like this should result in Meta and such being legally annihilated. But nothing will happen, as usual.
What's the crime?
Re: Covert web-to-app tracking via localhost on Android
#165Earlier quoted context omitted.
There are over 300M companies in the world. It seems only 2 companies did this. So look at the revenue models of the other 299,999,998 companies. Meta only started this less than a year ago, so look at their revenue model prior to that.
If I could pay for my groceries with my browsing habits I would. In fact, I bet most people would.
Re: Covert web-to-app tracking via localhost on Android
#166Earlier quoted context omitted.
Let it show "Use WebRTC?". If users don't understand, they click whatever. If the website really needs it to operate, it will explain why before requesting, just like apps do now. Always aim for a little more knowledgeable users than you think they are.
That feels pretty useless. You might as well do what happens today: enable it by default and allow knowledgable power users to disable it. If it's disabled, show a message to the user explaining why it's needed.
And why enable it by default, why not disable by default?
Also, sibling comments say iOS is already asking for the permission, why not just copy it?
Re: Covert web-to-app tracking via localhost on Android
#167If it were so, Google should be knowingly be allowing this to happen and be a co-conspirator. I mean, they surveil our devices as if it were their home. Impossible that they're not aware.
[0] https://netzpolitik-org.translate.goog/2025/databroker-files...
Re: Covert web-to-app tracking via localhost on Android
#168Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.
I am not sure which Meta apps open ports, but e.g. Samsung phones come with a bunch of Meta apps pre-shipped. IIRC just removing the Facebook app is is not enough, there is another service installed that is not visible as an app (com.facebook.services etc.), which you can only uninstall from the data partition with something like ADB/UAD. Or buy an iPhone or a Pixel.
Re: Covert web-to-app tracking via localhost on Android
#169Earlier quoted context omitted.
In the early days of the information revolution, when computers were new and being nerdy was still seen (almost universally) as a bad thing, a very high proportion of computer enthusiasts were people already on the fringes of society, for one reason or another. For a large number of them, hacking was a way to express their preexisting antiestablishment tendencies. For a lot of them, they were also your basic angsty a…
Thanks for your thoughts! How can we create more hackers? I think the fear of punishment has really put a damper on things but not sure how that can be avoided.
Re: Covert web-to-app tracking via localhost on Android
#170Earlier quoted context omitted.
As someone who works for a similar large org, it's just as likely that some low level programmer put it in without much thought, and then this got surfaces to higher up people who didn't know about it and told them to remove it immediately.
It seems incredibly unlikely a low level programmer could come up with this method then get the necessary code into both the tracking pixel served to third party sites and Meta's android apps without some higher ups knowing about it.