Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

311–320 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#311

Earlier quoted context omitted.

Google gets no competitive advantage from removing third party cookies from chrome. The anticompetitive monopolistic tactic was the plan to replace third party cookies with FLoC/Privacy Sandbox/Topics AI, and THAT is what they were not prevented from doing. No one is trying to stop google from removing third party cookies. Google is just unwilling to remove them without introducing a new anticompetitive tracking tool…

> No one is trying to stop google from removing third party cookies. That's simply not true. As I already mentioned, the CMA presented a legal challenge which you can read about online. Please review the history, as it's been going on for years now. https://www.gov.uk/government/news/cma-to-have-key-oversight... https://www.marketing-beat.co.uk/2024/02/06/cma-cookies-goog...

The first link confirms exactly what I said above. They’re not preventing Google from removing third party cookies, they’re preventing Google from implementing ALTERNATIVES to third party cookies. The only reason Google is unwilling to straight up remove third party cookies is their business model.

  The CMA was concerned that, without regulatory oversight and scrutiny, Google’s alternatives could be developed and implemented in ways that impede competition in digital advertising markets. This would cause advertising spending to become even more concentrated on Google, harming consumers who ultimately pay for the cost of advertising. It would also undermine the ability of online publishers such as newspapers to generate revenue and continue to produce valuable content in the future.
The second link does contain the phrase “cannot proceed with third-party cookie deprecation”, but it’s simply obvious that it’s not about third party cookies per se. It’s all about Google’s (unnecessary, anticompetitive, anti-user, anti-privacy) replacements for third party cookies.

  … report on the implementation of Google’s Privacy Sandbox commitments, the regulator has said that although the tech giant is so far complying with its demands, there remain considerable areas of concerns …
  …
  That it must not “design, develop or use the Privacy Sandbox proposals in ways that reinforce the existing market position of its advertising products and services, including Google Ad Manager“
  …
  It must also address issues with specific Sandbox tools such as how its Topics API targeting alternative can harm smaller tech business, and clarify who will govern the Topics API taxonomy.

Re: Covert web-to-app tracking via localhost on Android

#312

Earlier quoted context omitted.

The person working on Arcan runs the browser on a separate machine via Remote Desktop with it set to wipe and re-image itself between sessions.

crazy

Yes but I kinda love it. Perfectly safe from any future Rowhammer type exploit.

Re: Covert web-to-app tracking via localhost on Android

#313
post #287

Earlier quoted context omitted.

It's already enough to just have plain ads. Like we have them on the streets, at the bus station, newspapers, etc. No tracking needed at all, just give out the message. If you need to target people to it in the context of the place or content you are showing it with. But you don't need to know anything about the user seeing the ad. Targeting by user doesn't work anyway.

> Targeting by user doesn't work anyway. How did you reach this conclusion? The main problem is that it works way better than traditional marketing medium. It's the reason Google and Facebook are so massive, why would publishers choose to pay them if it doesn't work?

By the same logic cigarettes are presumptively beneficial...

Re: Covert web-to-app tracking via localhost on Android

#315
post #246

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

The majority of internet users are either unwilling or unable to pay for content, and so far advertising has been the best business model to allow these users to access content without paying. Do you have a better suggestion?

I think that might be a rhetorical device bequeathed to you by the social media companies.

People of course do pay for things all the time. It’s just the social media folks found a way to make a lot more money than people would otherwise pay, through advertising. And in this situation, through illegal advertising.

The best thing we can all do is refuse to work for Meta. If good engineers did that, there would be no Meta. Problem solved. But it seems many engineers prefer it this way.

Re: Covert web-to-app tracking via localhost on Android

#316
post #287

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

It's already enough to just have plain ads. Like we have them on the streets, at the bus station, newspapers, etc. No tracking needed at all, just give out the message. If you need to target people to it in the context of the place or content you are showing it with. But you don't need to know anything about the user seeing the ad. Targeting by user doesn't work anyway.

Depending on the data you collect, targeting by user - unfortunately - works. If the granularity is not one user, it will be a hundred. If not, a thousand, and so on. I've seen apps run ads targeting a total of 5 cohorts(together holding a hundred million users), and I've seen companies run ads targeting 100s of cohorts with the same number of users. They all work better than no targeting at all.

However what you're saying isn't completely wrong. I've also seen user targeting become a self-fulfilling prophecy. What happens is that it's championed by a high level executive as the panacea for improving revenue, implemented, and seen to not work. Now, as we all now, the C*O is Always Correct, so everything else around it is modified until the user-level targeting A/B test shows positive results. Usually this ends up in the product being tortured into an unusable mess.

Re: Covert web-to-app tracking via localhost on Android

#317

Earlier quoted context omitted.

Why not? How is this different than, say, location access, or microphone access? I want to be able to configure this per web site, and a permission prompt is a better interface than having an allow/deny list hidden in settings.

Because users understand what “microphone access” entails. “Use WebRTC?” means nothing to the average user.

Mobile apps require location permissions to use Bluetooth right now, even though that's a hard to understand situation for average people.

If a feature can be used to track people, you have to flag it off or else you are just contributing to the tech Big Brother apparatus.

Re: Covert web-to-app tracking via localhost on Android

#318
post #246

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

The majority of internet users are either unwilling or unable to pay for content, and so far advertising has been the best business model to allow these users to access content without paying. Do you have a better suggestion?

>The majority of internet users are either unwilling or unable to pay for content

Except for Spotify, News subscriptions, videogame subscriptions, video streaming services, duolingo, donations, gofundmes, piracy services!, clothing and food subscriptions! etc etc

People pay $10 for a new fortnite skin. You really pretending they won't pay for content?

People were willing to pay for stuff on the internet even when you could only do so by calling someone up and reading off your credit card number and just trusting a stranger.

Meanwhile, the norm until cable television for "free" things like news was that you either paid, or you went to the library to read it for free.

Maybe people could visit libraries more again.

Re: Covert web-to-app tracking via localhost on Android

#319

Earlier quoted context omitted.

What laws are you referring to other than Terms of Service which are entirely artificial constructs whisked into existence by service/platform providers? Which will, admittedly, be as draconian and onesided as the courts will allow. Agree on your first point at a practical level, but from the normative standpoint, it's unforgivable to cross those streams. At the point we're talking about with a service provider despe…

> What laws are you referring to other than Terms of Service which are entirely artificial constructs whisked into existence by service/platform providers? Which will, admittedly, be as draconian and onesided as the courts will allow. There are two main ones. The first is the CFAA, which by its terms would turn those ToS violations into a serious felony, if violations of the ToS means your access is "unauthorized". C…

Fair. I see your angle now. 100% with you.

>Why isn't there a popular Android fork which runs all the same apps but provides a better permissions model or greater visibility into what apps are doing?

Besides every possible attempt being DoA because Google is intent on monopolizing the space with their TOS and OEM terms? There isn't a fork because it can't be Android if you do that sort of thing, and if you tried to it'd be you vs. Google. Nevermind the bloody rats nest of intentional one-sided architecture decisions done to ensure the modern smartphone is first and foremost a consumption device instead of a usable and configurable tool, which includes things like regulations around the base and processor, lawful interception/MITM capability, and meddling, as you mentioned, in the name of DMCA 1201.

Though there's an even more subtle reason why, too, and it's the lack of accessible system developer documentation, capability to write custom firmware, and architecture documentation. It's all NDA locked IP, and completely blobbed.

The will is there amongst people to support things, but the legal power edifice has constructed intentional info asymmetries in order to keep the majority of the population under some semblance of controlled behavior through the shaping of the legal landscape and incentive structures.

Re: Covert web-to-app tracking via localhost on Android

#320
post #31

This is the overall process used by Meta as I understand it, taken from https://localmess.github.io/ : 1. User logged into FB or IG app. The app runs in background, and listens for incoming traffic on specific ports. 2. User visits website on the phone's browser, say something-embarassing.com, which happens to have a Meta Pixel embedded. From the article, Meta Pixel is embedded on over 5.8 million websites. Even in I…

> something-embarassing.com, Depending on the country that you or your family lives in, this could be far worse than embarrassment.

[flagged]
Post reply on HN