Live data from Hacker News

Covert web-to-app tracking via localhost on Android

localmess.github.io

351–356 of 356 posts

Re: Covert web-to-app tracking via localhost on Android

#352
post #123

Earlier quoted context omitted.

As someone who works for a similar large org, it's just as likely that some low level programmer put it in without much thought, and then this got surfaces to higher up people who didn't know about it and told them to remove it immediately.

It seems incredibly unlikely a low level programmer could come up with this method then get the necessary code into both the tracking pixel served to third party sites and Meta's android apps without some higher ups knowing about it.

Easier than you'd think.

Re: Covert web-to-app tracking via localhost on Android

#353

Earlier quoted context omitted.

Not only did you only consent to the one party using it, but the browser has robust protections in place to ensure that these cookies are only usable by that party. This “hack” gets around the restriction completely, leveraging a local service to aggregate all the cookies across sites.

This is why things involving cookies for permission to do things were really poison pills. As long as there is a cookie to be tracked, any at all , you have the data exfil/tracking problem. Only thing that changes is where the aggregation happens.

Luckily, GDPR isn't about cookies, it's about processing personal information. Doesn't matter if you use cookies, localstorage, or carrier pigeon.

The older EU 'cookie directive' only mentions cookies as an example of storage in a footnote. The regulative is actually about any storage on the users computer.

Marketers would like you to believe that the stupid banners are about cookies. They're not - they're about processing your personal information.

Re: Covert web-to-app tracking via localhost on Android

#354
post #77

Earlier quoted context omitted.

>abusing mandated GDPR cookie notices to secretly track people? How does that even work? What can GDPR cookie notices can do that the typical tracker can't do?

The cookie preference pop-up is a cookie. To track your preference, they need a cookie. We legally mandated a cookie. They're using the cookie regardless. But no one will call them on it until a critical mass is reached to get cases in a sufficiently large number of jurisdictions to curtail the behavior.

The 'no to tracking' cookie doesn't need to be identifiable in any way.

Re: Covert web-to-app tracking via localhost on Android

#356

I wish we could just ban advertising and tracking on the internet. I feel like so much crap these days has come out of it, all so that CEOs can afford an extra yacht

I don't think it has to go that far. I think there's a middle ground here that people would accept: show us ads, but make it a one-way firehose, like TV and billboards. If you need to advertise to pay for the site, put up all the banners you want. But don't try to single me out for a specific one. If it could pay for network TV there's no reason it can't pay for a website. (You could still do audience-level tracking,…

We have those one-way firehose online too. They're not mutually exclusive methods. Nothing short of legislation will stop the current norms.
Post reply on HN