Skip to content

Meta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars Technica

Technology
58 39 786
  • Fair warning: Last week one of my accounts was seemingly shadowbanned, and now gets "This content isn't available" on every video.

    Logging out plays videos, making a new brand account worked, etc. and no notification from youtube.

    You were shadowbanned for watching youtube in a web browser with adblock? Sounds excessive.

  • For those use Universal Android Debloater Or Canta with shizuku from android to install for the current user.

  • I prefer nightly because about:config is accessible unlike on the mainline version. Does Beta also allow that?

    Beta does and unlike nightly doesn't update every night.

    There's also Fennec on fdroid if you need something stable with about:config support.

  • I feel like that's all you need. You don't have their apps installed, so the problem is already solved. If you use uBlock Origin to block their trackers, the problem is solved. So you've solved it twice.

    Yes and no, I've treated the symptoms, but not the problem. All it takes is a trillion dollar company buying a new domain every once in a while to foil uBlock, and now that it's more known, anyone can create an an app that opens ports and listens for trackers.

    Would love it if Firefox would let me block all requests to localhost.

  • I know that people here generally like to shit on Brave, but it seems that the claim "Privacy by default" has held up in this context.

    Isn't that Proton's tagline?

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    laughs in adguard

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    Not surprising, it's always expected from tech corporations, where at the end of the day it's profit and favor with conservative politicians. If they're not trying to use information gathered on people to bad government looking to cut costs ("saving taxpayers' money") by removing minority beneficiaries, they love to shove content you don't even want.

    Why I never use my real name online.

  • Useless article, but at least they link the source: https://localmess.github.io/

    We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

    These native Android apps receive browsers' metadata, cookies and commands from the Meta Pixel and Yandex Metrica scripts embedded on thousands of web sites. These JavaScripts load on users' mobile browsers and silently connect with native apps running on the same device through localhost sockets. As native apps access programatically device identifiers like the Android Advertising ID (AAID) or handle user identities as in the case of Meta apps, this method effectively allows these organizations to link mobile browsing sessions and web cookies to user identities, hence de-anonymizing users' visiting sites embedding their scripts.

    📢 UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed.

    Thanks for the update, pitchforks down people. Let's go back to blindly trusting these anti consumer cabals.

  • Thanks for the update, pitchforks down people. Let's go back to blindly trusting these anti consumer cabals.

    I almost didn't copy the update because my focus was on the technical background. I did a double-check before submitting, if I caught the gist correctly, and decided that people would probably want to know that the report triggered that change.

  • Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

    The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

    Does anyone know if there's additional sandboxing of local ports happening for apps running in Private Space?

    E: Checked myself. Can access servers in Private Space from non-Private Space browsers and vice versa. So Facebook installed in Private Space is no bueno. Even if the time to transfer data is limited since Private Space is running for short periods of time, it's likely enough to pass a token while browsing some sites.

  • Cornell's world-first 'microwave brain' computes differently

    Technology technology
    10
    1
    92 Stimmen
    10 Beiträge
    19 Aufrufe
    Z
    Here's Cornell's own press release https://news.cornell.edu/stories/2025/08/researchers-build-first-microwave-brain-chip
  • 1k Stimmen
    137 Beiträge
    1k Aufrufe
    D
    Looks as if Visa Debit has about the same and slightly less fees than Visa Credit Cards. https://www.clearlypayments.com/blog/how-visa-debit-works-in-canada/ Looks like buying physical gift cards is the way to go...
  • The Age-Checked Internet Has Arrived

    Technology technology
    154
    1
    522 Stimmen
    154 Beiträge
    3k Aufrufe
    irmadlad@lemmy.worldI
    Governments like everything and everyone in their own little stack and in the government's self established status quo. When Paula Protester comes along with her LGBTQ++ agenda, governments don't like that. Paula Protester represents instability to the status quo established by the ruling class. Governments don't like instability. Governments like everyone sorted, coallated, and stapled, all in their respective stacks, so dissidents and social change advocates are viewed as adversaries and are not welcome. If it's genuuinely 'for the chirren' then it would seem to me that making parents be parents and take responsibility for their child's actions would go a very long way. However, we make laws with the lowest common denominator in mind. I don't want your children involved in adult activities online. However, just like any education program, the success is determined by parental involvement in their child's daily lives, and it starts at home. It's a lot easier to make government responsible for the child's developement, than actually requiring parents to be parents. I hear parents say 'I'm not technologically inclined.' Well, get there. The safety and well being of your child hangs in the balance. Take a class, read some of the millions of step by step tutorials that exist all over the internet. Ask some questions in forums. The possibilities are endless. Protecting your child is work, just like rasing them is work, and therein lies the issue.
  • 271 Stimmen
    41 Beiträge
    663 Aufrufe
    tonytins@pawb.socialT
    It was a failed attempt. I get that. You can drop it now.
  • www2025

    Technology technology
    1
    2
    1 Stimmen
    1 Beiträge
    25 Aufrufe
    Niemand hat geantwortet
  • getoffpocket.com, my guide to Pocket alternatives, just got a redesign

    Technology technology
    23
    84 Stimmen
    23 Beiträge
    300 Aufrufe
    B
    I've made some updates. There are many perspectives to view a guide like this. I hope there are some improvements to the self-hosting perspective. https://getoffpocket.com/
  • AI cheating surge pushes schools into chaos

    Technology technology
    25
    45 Stimmen
    25 Beiträge
    314 Aufrufe
    C
    Sorry for the late reply, I had to sit and think on this one for a little bit. I think there are would be a few things going on when it comes to designing a course to teach critical thinking, nuances, and originality; and they each have their own requirements. For critical thinking: The main goal is to provide students with a toolbelt for solving various problems. Then instilling the habit of always asking "does this match the expected outcome? What was I expecting?". So usually courses will be setup so students learn about a tool, practice using the tool, then have a culminating assignment on using all the tools. Ideally, the problems students face at the end require multiple tools to solve. Nuance mainly naturally comes with exposure to the material from a professional - The way a mechanical engineer may describe building a desk will probably differ greatly compared to a fantasy author. You can also explain definitions and industry standards; but thats really dry. So I try to teach nuances via definitions by mixing in the weird nuances as much as possible with jokes. Then for originality; I've realized I dont actually look for an original idea; but something creative. In a classroom setting, you're usually learning new things about a subject so a student's knowledge of that space is usually very limited. Thus, an idea that they've never heard about may be original to them, but common for an industry expert. For teaching originality creativity, I usually provide time to be creative & think, and provide open ended questions as prompts to explore ideas. My courses that require originality usually have it as a part of the culminating assignment at the end where they can apply their knowledge. I'll also add in time where students can come to me with preliminary ideas and I can provide feedback on whether or not it passes the creative threshold. Not all ideas are original, but I sometimes give a bit of slack if its creative enough. The amount of course overhauling to get around AI really depends on the material being taught. For example, in programming - you teach critical thinking by always testing your code, even with parameters that don't make sense. For example: Try to add 123 + "skibbidy", and see what the program does.
  • The silent force behind online echo chambers? Your Google search

    Technology technology
    21
    1
    170 Stimmen
    21 Beiträge
    338 Aufrufe
    silentknightowl@slrpnk.netS
    Same on all counts.