Skip to content

Meta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars Technica

Technology
58 39 756
  • they still try that?

    i can't remember the last time i have seen one of those warnings.

    Google doesn't do global roll outs with their updates. The anti adblock stuff especially. They target only some % of randomly selected users to spread confusion online, and I would guess their hope is to frustrate people into disabling ad blockers on Youtube after reading a bunch of misinformation and placebo bad advice when looking for tech support.

  • So you got all your friends, family and coworkers and acquaintances using Signal?

    So you got all your friends, family and coworkers and acquaintances using Signal?

    Only the ones I like.

    Joking aside, yes. I've found that just letting a friend or relative ask exploratory "how bad can WhatsApp be?" questions for about five minutes gets them to start the switch to Signal.

    I can't take any credit, Meta decided to lean in hard on spying on people.

  • Fair warning: Last week one of my accounts was seemingly shadowbanned, and now gets "This content isn't available" on every video.

    Logging out plays videos, making a new brand account worked, etc. and no notification from youtube.

    You were shadowbanned for watching youtube in a web browser with adblock? Sounds excessive.

  • For those use Universal Android Debloater Or Canta with shizuku from android to install for the current user.

  • I prefer nightly because about:config is accessible unlike on the mainline version. Does Beta also allow that?

    Beta does and unlike nightly doesn't update every night.

    There's also Fennec on fdroid if you need something stable with about:config support.

  • I feel like that's all you need. You don't have their apps installed, so the problem is already solved. If you use uBlock Origin to block their trackers, the problem is solved. So you've solved it twice.

    Yes and no, I've treated the symptoms, but not the problem. All it takes is a trillion dollar company buying a new domain every once in a while to foil uBlock, and now that it's more known, anyone can create an an app that opens ports and listens for trackers.

    Would love it if Firefox would let me block all requests to localhost.

  • I know that people here generally like to shit on Brave, but it seems that the claim "Privacy by default" has held up in this context.

    Isn't that Proton's tagline?

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    laughs in adguard

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    Not surprising, it's always expected from tech corporations, where at the end of the day it's profit and favor with conservative politicians. If they're not trying to use information gathered on people to bad government looking to cut costs ("saving taxpayers' money") by removing minority beneficiaries, they love to shove content you don't even want.

    Why I never use my real name online.

  • Useless article, but at least they link the source: https://localmess.github.io/

    We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

    These native Android apps receive browsers' metadata, cookies and commands from the Meta Pixel and Yandex Metrica scripts embedded on thousands of web sites. These JavaScripts load on users' mobile browsers and silently connect with native apps running on the same device through localhost sockets. As native apps access programatically device identifiers like the Android Advertising ID (AAID) or handle user identities as in the case of Meta apps, this method effectively allows these organizations to link mobile browsing sessions and web cookies to user identities, hence de-anonymizing users' visiting sites embedding their scripts.

    📢 UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed.

    Thanks for the update, pitchforks down people. Let's go back to blindly trusting these anti consumer cabals.

  • Thanks for the update, pitchforks down people. Let's go back to blindly trusting these anti consumer cabals.

    I almost didn't copy the update because my focus was on the technical background. I did a double-check before submitting, if I caught the gist correctly, and decided that people would probably want to know that the report triggered that change.

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    Does anyone know if there's additional sandboxing of local ports happening for apps running in Private Space?

    E: Checked myself. Can access servers in Private Space from non-Private Space browsers and vice versa. So Facebook installed in Private Space is no bueno. Even if the time to transfer data is limited since Private Space is running for short periods of time, it's likely enough to pass a token while browsing some sites.

  • Google Keeps Making Smartphones Worse

    Technology technology
    202
    1
    765 Stimmen
    202 Beiträge
    3k Aufrufe
    jjlinux@lemmy.mlJ
    In all honesty, I have no idea. I didn't give the stock firmware enough time on my phone to check on anything other than the amount of tracking and the move to the system partition. As for the reason for putting them in this partition, I'm sold on the idea that it's to keep the levels of invasion as high as possible while removing the user's options to get rid of them.
  • YouTube is getting rid of its Trending page and Trending Now list

    Technology technology
    51
    194 Stimmen
    51 Beiträge
    820 Aufrufe
    I
    Oh no! All those pages i block by turning my youtube history off!
  • 678 Stimmen
    179 Beiträge
    4k Aufrufe
    D
    Thats what the firewall rules do too, don't allow internet connection if there's no vpn connection. Firewall is a system-wide solution that always works, while qbt config relies heavily on the application implementing interface binding properly. Which it doesn't fully btw.
  • 528 Stimmen
    123 Beiträge
    1k Aufrufe
    B
    I'm not saying to waste space... but when manufacturers start a pissing match among themselves and say that it's because it's what the customers want, we end up with shit. Why does anyone need a screen that curves around the edge of the phone? What purpose does this serve? Who actually asked for this? I would give up some of my screen area to have forward facing speakers. I want a thicker phone that has better battery life. I also want to be able to swap out my battery. Oh, and I don't want the entire thing encased in glass. If we're so concerned about phone size then they should stop designing them so that a case is required.
  • 76 Stimmen
    6 Beiträge
    70 Aufrufe
    etherphon@lemmy.worldE
    We all know how well not regulating social media has gone, why the fuck not let's just double down.
  • 1 Stimmen
    1 Beiträge
    18 Aufrufe
    Niemand hat geantwortet
  • Is Matrix cooked?

    Technology technology
    54
    101 Stimmen
    54 Beiträge
    422 Aufrufe
    W
    Didn't know it only applied to UWP apps on Windows. That does seem like a pretty big problem then. it is mostly for compatibility reasons. no win32 programs are equipped to handle such granular permissions and sandboxing, they are all made with the assumption that they have access to whatever they need (other than other users' resources and things that require elevation). if Microsoft would have made that limitation to every kind of software, that Windows version would have probably been a failure in popularity because lots of software would have broken. I think S editions of windows is how they tried to go in that direction, with a more drastic way of simply just dropping support for 3rd party win32 programs. I don't still have a Mac readily available to test with but afaik it is any application that uses Apple's packaging format. ok, so if you run linux or windows utils in a compatibility layer, they still have less of a limited access? by which I mean graphical utilities. just tried with firefox, for macos it wanted to give me an .iso file (???) if so, it seems apple is doing roughly the same as microsoft with uwp and the appx format, and linux with flatpak: it's a choice for the user
  • Google’s test turns search results into an AI-generated podcast

    Technology technology
    4
    1
    5 Stimmen
    4 Beiträge
    43 Aufrufe
    lupusblackfur@lemmy.worldL
    Oh, Google... Just eviler and eviler every day. Not only robbing creators of any monetization via clicking on links but now just blatantly stealing their content for an even more efficient theft model. FFS. I can't fucking wait to complete my de-googling project and get you the absolute fuck completely out of my life. I've developed a hatred for Google that actually rivals my hatred for Apple. ‍️