"If you're not paying for the product, you are the product" - anonymous. Why is this very news is not in the HN front page for considerable amount of time is beyond me. It has the right recipe for top HN post namely users deception, sandbox bypass, privacy or lack thereof, web browser, Meta, etc.
"If you're paying, you're still the product", so apparently other factors anon didn't mention are involved
"Localhost tracking" explained. It could cost Meta €32B
251–260 of 286 posts
Re: "Localhost tracking" explained. It could cost Meta €32B
#252That seemed unnecessarily sneaky and made me appreciate the sense of righteousness which I would have, if I were a SW dev @ FB at the time, to add such a technique to a world-tier app like FB.
Re: "Localhost tracking" explained. It could cost Meta €32B
#253Re: "Localhost tracking" explained. It could cost Meta €32B
#254This system was designed and implemented by engineers who committed code in a source control system with their name attached, and the changes were requested by product managers in tickets in the ticketing system with their name attached. Those engineers and product managers should be personally liable for an equivalent % of their annual salary as Facebook is liable for a % of its annual revenue.
How would the EU fine American engineers who live and are paid in America?
Re: "Localhost tracking" explained. It could cost Meta €32B
#255Earlier quoted context omitted.
The laws specify revenue, to avoid transfer pricing removing all fineable profits. Live by the sword, die by the sword I guess.
This isn’t live/die/sword. This is “low margin companies held to a higher standard than high margins companies”. It hurts Otto a lot more to lose 9 years of profit than it hurts Amazon to lose one quarter.
More generally, the whole point of getting absurdly large (and such to be covered by DMA etc) is precisely to extract more monopoly profits.
GDPR is different, in that one can easily imagine a low margin company getting hurt by this, but in that case they should invest in compliance, rather like these (mostly US) companies do for US laws.
Re: "Localhost tracking" explained. It could cost Meta €32B
#256Earlier quoted context omitted.
"Legal" is missing the point by a mile and is irrelevant.
ok, get the point of being enraged by the one thing while ignoring the same other 4 things that are above board and do the same thing
If an app does everything it "legally" could, it would have become malware long before. The principle of that argument is quite similar to that of poor mobile ecosystems we sadly are subjected to. Of course other factors were as important to create these "security" models.
I also think that this plainly isn't or wasn't legal in any jurisdiction because Twitter lacked informed consent if this particular case ever got in front of a judge.
That Twitter isn't the only guilty party is true, like we know from the article.
Re: "Localhost tracking" explained. It could cost Meta €32B
#257Earlier quoted context omitted.
Yes, but it should include everyone involved, from top to bottom. We won't get those data theft misfeatures if engineers refused to work on them out of personal liability.
I once bluntly refused to deploy an app to production because it was a finance system that handled billions of dollars and the personal data of a million children. The HTTPS certificates couldn’t be organised on time (don’t ask), so I simply refused to deploy it using HTTP only “just for now” (=years). The look of stunned shock on the project manager’s face is something I’ll never forget. He was apoplectic with mixed…
Re: "Localhost tracking" explained. It could cost Meta €32B
#258Very impressive but not surprising coming from Meta. They have an history of doing this kind of things. Back in the early 2010s, they found a way to spy on HTTPS traffic on the iOS App Store to monitor which apps were getting popular. That's what allowed them to know WhatsApp and Instagram were good acquisition targets. At this point, I think the race for Zuckerberg is, can Meta survive long enough for the next platf…
Re: "Localhost tracking" explained. It could cost Meta €32B
#259Remember in 2014 when the Android Twitter app started sending a list of all your installed applications back to Twitter? https://news.bloomberglaw.com/privacy-and-data-security/twit... Ever since then I refused to install native versions of apps that could be used in a browser. I don't use Facebook or Instagram so I don't know if that works anymore, and I recall testing that they were intentionally crippling Facebook…
this is still perfectly legal and allowed. every app can scan your apps and recently opened ones "for security". same for your contacts. whatsapp (only meta product i need to touch in our fleet) will do both at very fast intervals, and upload a contact list diff if it detect changes. the whole issue here was that meta bypassed the user matching on the web without paying google "cookie matching" price
I genuinely think that should be illegal.
Re: "Localhost tracking" explained. It could cost Meta €32B
#260Perhaps sanctions on those that buy and use the data would help?