Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

321–330 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#321
post #246

Earlier quoted context omitted.

The majority of internet users are either unwilling or unable to pay for content, and so far advertising has been the best business model to allow these users to access content without paying. Do you have a better suggestion?

They are able, because in the end advertising is also paid by customers. The complications are: - Paying for services is very visible, whereas the payment for advertising is so indirect that you do not feel like you are paying for it. - The payments for advertising are not uniformly distributed, people with more disposable income most likely pay more of overall advertising. But subscriptions cannot make distinctions…

This!

It's a game. When a merchant signs up to an ad platform (or when the platform is in need of volume), they are given good ROI, and the merchant also plays along and treats it as "marketing expenditure". Eventually, the ROI dries up i.e the marketing has saturated and the merchant starts counting it as a cost and passes it onto the customer. I don't know if this is actually done, but it's also trivial for an ad platform to force merchants to continue ads by making them feel it's important: when they reduce their ad volume, just boost the ROI and visibility for their competitors (a competitor can be detected purely by shared ad space no need to do any separate tagging). Heck, this is probably what whatever optimization algorithm they are running will end up suggesting as it's a local minima in feature space.

And yes, instead of banning ads, which would be too wide a legal net to be feasible, banning tracking is better. However, even this is complicated. For example, N websites can have legitimate uses for N browser features. But it turns out any M of the N features can be used to uniquely identify you. Oops. What can you even do about that, legally speaking? Don't say permissions most people I know just click allow on all of them.

Re: Covert web-to-app tracking via localhost on Android

#322

Earlier quoted context omitted.

> What laws are you referring to other than Terms of Service which are entirely artificial constructs whisked into existence by service/platform providers? Which will, admittedly, be as draconian and onesided as the courts will allow. There are two main ones. The first is the CFAA, which by its terms would turn those ToS violations into a serious felony, if violations of the ToS means your access is "unauthorized". C…

Fair. I see your angle now. 100% with you. >Why isn't there a popular Android fork which runs all the same apps but provides a better permissions model or greater visibility into what apps are doing? Besides every possible attempt being DoA because Google is intent on monopolizing the space with their TOS and OEM terms? There isn't a fork because it can't be Android if you do that sort of thing, and if you tried to i…

> The will is there amongst people to support things, but the legal power edifice has constructed intentional info asymmetries in order to keep the majority of the population under some semblance of controlled behavior through the shaping of the legal landscape and incentive structures.

Exactly. We have bad laws and therefore bad outcomes. To get better outcomes we need better laws.

Re: Covert web-to-app tracking via localhost on Android

#323

Earlier quoted context omitted.

Yes? The cookie in question is First Party, which means you’ve consented to permitting only that party to track you using it, and not permitting its use for wider behavioral tracking across websites. However, the locally hosted FB/Yandex listener receives all of these first party cookies, from all parties, and the OPs implication is (I think) that now these non-correlateable-by-consent first party cookies can be or a…

Not only did you only consent to the one party using it, but the browser has robust protections in place to ensure that these cookies are only usable by that party. This “hack” gets around the restriction completely, leveraging a local service to aggregate all the cookies across sites.

This is why things involving cookies for permission to do things were really poison pills. As long as there is a cookie to be tracked, any at all, you have the data exfil/tracking problem. Only thing that changes is where the aggregation happens.

Re: Covert web-to-app tracking via localhost on Android

#324
post #77

Earlier quoted context omitted.

Not totally following but it sounds like you are saying one of the things they have been doing involves abusing mandated GDPR cookie notices to secretly track people?

>abusing mandated GDPR cookie notices to secretly track people? How does that even work? What can GDPR cookie notices can do that the typical tracker can't do?

The cookie preference pop-up is a cookie. To track your preference, they need a cookie. We legally mandated a cookie. They're using the cookie regardless. But no one will call them on it until a critical mass is reached to get cases in a sufficiently large number of jurisdictions to curtail the behavior.

Re: Covert web-to-app tracking via localhost on Android

#325
post #146
post #47

Earlier quoted context omitted.

In the early days of the information revolution, when computers were new and being nerdy was still seen (almost universally) as a bad thing, a very high proportion of computer enthusiasts were people already on the fringes of society, for one reason or another. For a large number of them, hacking was a way to express their preexisting antiestablishment tendencies. For a lot of them, they were also your basic angsty a…

Thanks for your thoughts! How can we create more hackers? I think the fear of punishment has really put a damper on things but not sure how that can be avoided.

Well, note that my conclusion is largely that we have not, in fact, decreased the number of hackers, nor their proportion within the general population—just their proportion within the computer-using population, and that only by adding a large number of non-hackers to that population. I'm skeptical that we can ever increase the proportion of the population that has the hacker mindset much higher than it is without some kind of overall cultural shift (something that's beyond our power to affect).

But it's also unquestionably true that it's much easier to be a "hacker", in the sense we think of from the 1960s-80s, in a time and field where the hardware and software is simpler, more open, and less obfuscated. As such, I think it's probably not helpful to long for those bygone days—especially the "simpler" part—which we are clearly never getting back until and unless we make a breakthrough that is just as revolutionary as the transistor and the microchip were (and I'm skeptical as to whether that's possible, both in terms of what physics allow ever, and in terms of the shape of the corporate landscape now and for the foreseeable future). Honestly, a lot of the things that were possible back then, a lot of the incentive to get into hacking, was stuff that's actually hugely dangerous or invasive. Instead, I think it's better to focus on what we can do to improve the latter two parts of that equation: more open, less obfuscated.

Personally, I would say that the way toward that is pushing for, creating, and working on more open protocols and open standards, and insisting that those be used to enable more interoperability in place of proprietary formats and integration only with other software and hardware from the same company.

Re: Covert web-to-app tracking via localhost on Android

#326

Earlier quoted context omitted.

Unauthorized access to a computer system. I'm sure if I connected to some port on a computer belonging to Meta without them wanting it, that would be the crime I would be charged with. But somehow if Meta connects to a port on my phone without me agreeing to it, it's not a crime?

Yes.. and that listening service is their software that you installed on your device... So caveat emptor.

Found the meta PM that thought of this idea

Re: Covert web-to-app tracking via localhost on Android

#328

Earlier quoted context omitted.

Samsung devices are loaded with malware and AI slop in general. I'd avoid them if you at all care about privacy. Since Google is still missing end to end encryption for cloud data, iOS seems like the only good choice currently.

iOS sends data to metrics.apple.com, metrics.icloud.com, iadsdk.apple.com, etc. a lot. They are much better than Samsung (who send data to Samsung and other parties), but I am not convinced they are much better than Google devices. It's more who you prefer sending your data to. In the end something like GrapheneOS is the only good choice. Has all the security features of Pixel (which is similar to iPhone) and the tra…

Not all metrics are equal. I don't really care if Apple collects anonomized data on which features are most used or collects crash reports. That's worlds away from using preinstalled apps to backdoor your phone to provide tracking scripts your details in incognito mode.

Re: Covert web-to-app tracking via localhost on Android

#329
post #117

Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.

> Not only our their websites painful which discourages use, websites are more sandboxed.

This isn't remotely true. It is pretty trivial for a well-resourced engineering organization to generate unique fingerprints of users with common browser features.

Re: Covert web-to-app tracking via localhost on Android

#330
post #117

Another reason not to install big tech's apps and only use their websites if you must. Not only our their websites painful which discourages use, websites are more sandboxed.

> Not only our their websites painful which discourages use, websites are more sandboxed. This isn't remotely true. It is pretty trivial for a well-resourced engineering organization to generate unique fingerprints of users with common browser features.

Wouldn't native apps be even worse in that regard, most of the time?
Post reply on HN