Live data from Hacker News

"Localhost tracking" explained. It could cost Meta €32B

zeropartydata.es

91–100 of 286 posts

Re: "Localhost tracking" explained. It could cost Meta €32B

#92
Remember in 2014 when the Android Twitter app started sending a list of all your installed applications back to Twitter? https://news.bloomberglaw.com/privacy-and-data-security/twit...

Ever since then I refused to install native versions of apps that could be used in a browser. I don't use Facebook or Instagram so I don't know if that works anymore, and I recall testing that they were intentionally crippling Facebook Messenger at one point.

Then the past decade of native apps requesting tons of permissions and users just clicking agree. Why should Facebook be able to read my Wi-Fi network or Bluetooth? Of course there is something shady going on. Beacons tracking people walking around brick and mortar stores. https://en.wikipedia.org/wiki/Facebook_Bluetooth_Beacon

Such a shame because native apps are so much more pleasant and performant to use than web apps.

Re: "Localhost tracking" explained. It could cost Meta €32B

#93

So I am seeing two issues here. 1. Android allows apps to open ports without permissions. And apps to communicate with each other without permissions. 2. The browsers allow random domains to access services on the localhost. Without notifying the user. We have seen vulnerabilities in the past accessing dev services running on localhost. Something should be done there.

Those are two technical issues, yes.

But even with those technical issues present, Facebook shouldn't have done this.

Re: "Localhost tracking" explained. It could cost Meta €32B

#94

Every story like this has me thinking about two things: 1. Companies have no soul. They are, by design, just chasing revenue. Everything else is just a risk to be factored. 2. There are real humans at these companies who choose to take part in the business and design and engineering, etc. I don’t think these humans have no soul (though some won’t), and I don’t think they’re stupid (though some are). I think it’s just…

> I don’t think these humans have no soul

They're sellouts and traitors.

Then there are people who will take to pondering what it means to be a sellout in a disingenuous manner. They act like it takes a haughty philosophy club to stroke their beards, reinvent paid labor from first principals and through motivated reasoning discovered "sellout" isn't that all that bad. And it turns out everyone sells out one way or another, so it's a wash what line of work you go into anyway.

Now those are the people who have no souls.

Re: "Localhost tracking" explained. It could cost Meta €32B

#95
post #90
post #81

What's funny is that the engineers who implemented this are probably one of us here on HN. I don't think Zuck implemented this himself

That's what they need AI for. It won't say no.

The engineers did not say no either though.

Re: "Localhost tracking" explained. It could cost Meta €32B

#96
post #85

Earlier quoted context omitted.

Companies have been trying to make AR/VR the next platform shift but I'm not super convinced that people actually want or desire this outside of a few niche games. To me it feels like it has about as much staying power as 3D glasses in movies.

The window of opportunity already closed for AR/VR. AI dealt the death blow.

What do you mean? AI will enable better AR/VR experiences, or AI will obsolete them?

Re: "Localhost tracking" explained. It could cost Meta €32B

#97

This is one of the reason you need to segregate your whole LAN. At the bare minimum, use VLANs to knock off these ruthless scanners. And obviously, this wouldn't be possible if you used a strong adblock list on whatever DNS you're running. They cannot touch the people who take proper measures. I also do not believe people who use Facebook really care about privacy. I am well aware of how mean this sounds but they ful…

> they fully deserve to be tracked

Absolutely not. The law is still the law. The fact that Meta is able to break the law via technical means doesn’t mean victims deserve to be victimized.

Just because someone is able to pick your lock at night doesn’t mean you deserve to be burglarized.

Re: "Localhost tracking" explained. It could cost Meta €32B

#99
post #12

Tldr because this article has way too much fillers to my taste (but I'm sure there are people out there that enjoy reading that kind of thing): The native Instagram and meta apps start a server listening on predefined ports when you launch said apps, they eventually run on the background as well. When you are on your browser, whether in private more, not logged, refused or disabled cookies, or anything else that migh…

Does anyone know how long was this going on, are we talking weeks, months or years?

Re: "Localhost tracking" explained. It could cost Meta €32B

#100

This is one of the reason you need to segregate your whole LAN. At the bare minimum, use VLANs to knock off these ruthless scanners. And obviously, this wouldn't be possible if you used a strong adblock list on whatever DNS you're running. They cannot touch the people who take proper measures. I also do not believe people who use Facebook really care about privacy. I am well aware of how mean this sounds but they ful…

> they fully deserve to be tracked Absolutely not. The law is still the law. The fact that Meta is able to break the law via technical means doesn’t mean victims deserve to be victimized. Just because someone is able to pick your lock at night doesn’t mean you deserve to be burglarized.

Get a better lock. If you don't care enough to not get lock picked, whose fault is it? The bar to avoid this form of tracking is not high at all. It's trivial for anyone who is willing to put some serious efforts in defending their privacy
Post reply on HN