How Facebook tracks you on Android [video]
media.ccc.de
media.ccc.de
The Android platform API should simply never allow apps to obtain global system identifiers (serial numbers, "advertising IDs", MACs, Wifi network info, EMEIs etc) in the first place. Perhaps even going as far as not providing a shared filesystem.
Mobile apps, despite platform API permission, and having some ability to protect their own data, are a lot closer to desktop programs than web apps in many regards.
EFF has had a proof of concept online for quite a while https://panopticlick.eff.org/
And HN users are probably even more vulnerable since we will have customized our software making it stand out.
On the other hand, among HN users you'll probably find a higher percentage of those who block JS by default and allow it only on selected websites. Most of these fingerprinting methods (and most web abuse in general) depends on JS being turned on.
Unless you're using a vanilla Tor Browser, you will probably stand out. And if you are, 'tptacek will tell you how it's a bad idea for other reasons.
I'm sure there's a Google rep somewhere that will tell you that their "advertising ID" is better than the status quo on the web because the user can rotate it and, because it's reliable and easy for app devs to use, they are discouraged from being more nefarious and sneaky in tracking users.
This is all a bloody distraction from the point: it should not be an acceptable norm for this tracking to happen and it should be as hard as possible to pull off without informed user consent.
The degree to which platforms are defensive against it is a different issue to whether or not they actively encourage it by design... which shouldn't even be open to debate.
Our world is starting to looka lot like that of the Space Merchants..
First, our computing devices do not protect our privacy and security sufficiently. It's a general problem, not limited or even particularly affecting Android. And you deal with general problems differently than with incidental ones. You don't tell people in an epidemic to "just go see a doctor."
Second, I do more sensitive computing in the browser on my computer than I do on my phone. It's the bigger issue.
Finally, the way we dealt with Internet worms and viruses was not by strongly stating how unacceptable infecting other people's computers is. We patched our software, kept it up to date, and even completely changed its design. Later shamed Microsoft into doing the same.
https://support.google.com/googleplay/android-developer/answ...
https://www.businessinsider.com/ifa-apples-iphone-tracking-i...
And the developer will pinky promise that they won’t abuse it....
The only acceptable answer is a legal/regulatory solution.
I hear this argument brought up a lot, that the only thing that can fix this is regulations. I've always come at this from the opposite direction -- regulatory solutions are nice, and I'm not against them, but they're less useful than technological solutions because my gut instinct is regulations only cover a) law-abiding entities (and usually only corporations at that), who are b) competent enough not to mess up compliance in the first place.
The perspective I lean on by default is that even if you have good regulations in place, the problem isn't really solved until there's a widespread technical solution. So for example, it might be nice to have a law banning MITM attacks, but HTTPS is the superior solution that we really want. When we pass laws criminalizing stuff like hacking or tracking children, my perspective is we're just trying to buy time and localize the damage to the slightly less frequented parts of the Android app store while we fix the crappy permissions models and sandboxing on our core platforms.
Is there a secondary aspect to the regulatory solutions that I'm missing? Something that would go much, much farther and be much stricter than laws like GDPR? I don't mean it as an argument, I'd just be curious to hear someone with the regulation>infrastructure perspective elaborate more on what they're thinking about when they say that, because it's a perspective I don't have much experience with.
I'm using a VPN + ublock origin + https everywhere + temporary containers + don't track me google + chameleon + canvas blocker + custom user.js (that disables e.g. webgl).
It's pretty good to address many tracking methods (e.g. cookies, IP) but fingerprinting is remarkably hard to prevent.
However, it comes with a fairly long list of downsides: less secure than Chrome, less secure than even Firefox it's based on because it's not updated as often and quickly, and you MITM yourself by default, and it's slow, it doesn't block ads... The price to pay is steep.
If you are a web developer or are familiar with web terminology like origins, domains, frames, XHR, etc on the web, and are willing to put in some time learning how to use it (15 mins for a seasoned web dev, maybe 30-60 mins otherwise) get uMatrix (https://github.com/gorhill/uMatrix). It will change your life! If not, use ScriptBlock on Chrome or NoScript on Firefox. Block all scripts (and if using uMatrix, cookies, XHR, and frames) by default and whitelist as you go for sites you trust (or want to use bad enough to potentially open yourself up for tracking).
My suspicion is that fingerprinting by the core domain will actually get worse since your browser behaves so differently from stock browsers (which is after all the point of uMatrix :-) ). The majority of trackers tho will be third party (such as Google analytics). Very few sites roll their own trackers because it's hard to get right, and some great ones like GA is free. For those that do, I'm not too worried anyway, but that's certainly just a personal thing.
JavaScript developers should ask themselves if they want JS to become the popup of the 2010s: initially well-intentioned, shamelessly abused, universally loathed, and ultimately killed.
I'm not saying you can't finger print, and like you pointed out it's easier on desktop. I'm only pointing out that panopticlick needs some work to be more accurate.
Of course. On the other hand, Google's global attitude is that user tracking is fine, their core business is based on that. So it would be hypocritical on their part if they decided to block user tracking on their devices.
You're just spreading unsupported fud. Actions speak louder than words and Google's actions for Android apps and APIs do not agree with your comments.
I’m sure there are applications that need unlimited access to your file system, read your text messages, and read your call logs.
How has that worked out for the privacy and security of Android users?
The fact that the application must request permission to see that data gets those applications extra scrutiny from not only the user but the app store and third party security researchers as well.
And even if “security researchers” do find an issue with an Android app, how does that information get disseminated to users? Even if Google decides to close the hole, Android doesn’t exactly have a great track record of getting updates to users.
A much better example is the massive XCodeGhost infection on the app store. Apple relies entirely on users for figuring out if things are misbehaving, while Android also has automated detection and the third party security ecosystem, as I pointed out in the comment you replied to.
> And even if “security researchers” do find an issue with an Android app, how does that information get disseminated to users?
By having the app removed from the store. Which Apple is unable to do because it doesn't allow third party security researchers to scrutinize its app store. This resulted in the massive XCodeGhost infection, which Apple couldn't fully remove from their store for weeks after.
> Even if Google decides to close the hole, Android doesn’t exactly have a great track record of getting updates to users.
The whole point is that it's not a hole. It's an app abusing an API. The correct thing to do is to simply remove the app from the store, which is exactly what happens.
XCodeGhost was first found by Alibaba - a third party.
Are you seriously claiming that our portable computers should lock us out from creating these kind of new application experiences permanently and give ONLY Google and Apple the ability to create them? You want innovation in use of our portable computers to be permanently owned and controlled by Google and Apple exclusively?
Come on, think for a while about what you're asking.
Your app on the phone wouldn’t need your Bluetooth ID (which is separate from the WiFi MAC ID). It would need the ID of the connecting device.
Any kind of mDNS and direct WiFi apps.
https://developer.apple.com/documentation/networkextension/n...
Are you seriously claiming that our portable computers should lock us out from creating these kind of new application experiences permanently and give ONLY Google and Apple the ability to create them? You want innovation in use of our portable computers to be permanently owned and controlled by Google and Apple exclusively?
We have an existence proof with both Android and Windows - and less so with Macs but only because they aren’t as large of a target - with what happens when apps are given unfettered access to the hardware and privacy related information even with user permissions. How often have we seen yet another privacy invasion from Facebook but only against Android users?
What exactly happens? A ton of innovative apps can be made? Bunch of enterpreneurs can innovate and built new products without approval from a huge american corporation?
Yes, powerful tools can be abused. But powerful use-cases require powerful tools. What you're defending is akin to saying we should cut out everyone's tongue to defend against people accidentally telling their personal information to strangers. It's NOT a proportional response. You're effectively ceding full control of EVERYTHING you do on your computing device to Google and Apple forever because you're afraid that powerful tool, drivers of innovation and progress, might hurt someone occasionally.
You can't have progress in a kindergarten - instead of demanding that large corporations babysit the public and tell them what to think, we NEED to make sure that people take responsibility for themselves. It's the only way you keep free market and freedom functioning.
Yes, powerful tools can be abused....You're effectively ceding full control of EVERYTHING you do on your computing device to Google and Apple forever because you're afraid that powerful tool, drivers of innovation and progress, might hurt someone occasionally.
You’re speaking as if this is hypothetical. Thirty plus years of PC use and 10 years of Android is proof that third party developers can’t be trusted and the platform providers have a responsibilty to keep third party providers in check. Given the trade off of inconveniencing a few geeks and not allowing third parties to read text messages, phone logs, etc. I think that’s a fair trade off.
I am a developer and have been for 20 years. But the platform providers should be catering to the users. I will install any random app on my iPhone. I don’t worry about whether the app comes from a trusted developer. I know because of the security model that the app can’t do too much damage.
we NEED to make sure that people take responsibility for themselves. It's the only way you keep free market and freedom functioning.
Again, how has that worked out so far for the vast number of PC and Android users?
It has been drilled into computer users heads not to download random apps from untrusted sources on their computers because of the potential for harm. The fact that the iOS App Store does enforce a sandbox actually gave app developers a larger market of people who would try random apps without having to trust the developer.
But most importantly, Android has been around for a decade. Where are all of the Android “entrepreneurs” that are getting rich because of their “innovative” apps that are possible because of its lax security model?
But... the existence proof is also Windows and Android and the massive market share and staggering amount of innovation that's happened on those platforms.
You're forgetting that many of the capabilities that Apple eventually caved on and added to iOS came directly as a result of Android's "we'll let you do that" default motto. There was a period of time where you couldn't have custom keyboards on iOS. There was a period of time where 3rd party apps on iOS couldn't even multitask.
Don't get me wrong, Android's permission model needs serious work at this point. But the coin you're holding up has two sides on it. You're writing off a huge amount of innovation that has benefited everyone, Apple users included.
Platform power is a continuum -- there's no single right or wrong answer for everyone buying a device, which is why it's good to have multiple platforms with multiple philosophies.
Even if you don't care about that though, and you personally enjoy staying closer to the secure side of things, permissive platforms still benefit you as a user because they're testing grounds to find out which capabilities are beneficial enough to end-users to be worth back-porting to the more closed gardens. That's something we've seen repeatedly throughout the years with Android and iOS: both platforms feed on each other in different ways.
The massive market share is because of cheap phones. The average selling price of an Android phone is a 3rd of an iPhone.
And where is this “massive innovation” that is leading to profit either by app makers making apps that can only be made on Android or by device makers? As the old saying goes - “if they are so smart, why aren’t they rich?” The whole Android ecosystem is a race to the unprofitable bottom.
The same can be said about Windows PC makers - thin margins and low profits. Not exactly what I would consider a “success”.
There was a period of time where you couldn't have custom keyboards on iOS. There was a period of time where 3rd party apps on iOS couldn't even multitask.
And when Apple did it, it did it more securely. You can’t just press a confirmation button, the user has to be purposeful and go into settings, the keyboard runs out of process, and even then by default the keyboard doesn’t have network access. The user has to go out of their way to go back into settings to give the keyboard network access and they get a huge warning. Also, when you enter a password, it changes back to the system keyboard.
As far as multitasking, again Apple was more thoughtful and limited multitasking in iOS 4 to not allow a third party app to drain the battery. Even now that they have opened it up more, the user can still granularly control what apps are allowed to run in the background.
There is huge difference between the thoughtfulness of how Apple implements features and how Google implements features.
The cheap phones are because Google allows 3rd-party OEMs to install Android on their own devices, even though that carries an extra risk of having an outdated phone, or a 3rd-party back door, or just a crappy experience that degrades the overall Android brand. It's the exact same thing we're talking about -- Apple doesn't do that because they think giving random device makers that much control is insecure and hurts their brand. It doesn't mean that Apple's approach is wrong. But I'm glad that both exist.
> And when Apple did it, it did it more securely.
This isn't an iOS vs Android contest. It doesn't matter who has the better implementation.
Apple started from a perspective of "You don't need multitasking." Consumers widely said, "Yeah, we do. Those phones have it and we want it." Apple said, "fine, but we'll do it our way." Everybody won, because some people went out and did the experimental hacky thing, and Apple looked at them and said, "you know what, it has issues, but I guess that is worth supporting."
> And where is this “massive innovation” that is leading to profit either by app makers making apps that can only be made on Android or by device makers?
Innovation != profit. Otherwise, Open Source communities would be a lot richer. My metrics for user success are not primarily based on corporate profit margins, but the short answer to why people aren't getting rich on Android is because the app market as a whole on both iOS and Android is a race to the bottom. It just so happens that Android's bottom is slightly lower than Apple's is.
There certainly are apps on Android that can't exist on iOS though, if that's what you're getting at. Off the top of my head, the iOS equivalents of Tasker are way underpowered next to what's being offered on Android. 3rd-party non-Gecko web browsers still aren't supported on iOS, which actually does matter because the iOS browser engine is lagging on multiple web standards. Look backwards a little ways, and you have the swipe keyboard style, which started out as a 3rd-party app on Android and (I suspect) was a big part of Apple deciding to back-down on their 3rd-party keyboard restrictions. Go back even farther and you had 3rd-party tethering apps. On the OEM side, there are people who still swear by the Note series, and Apple seems pretty adamant that they're not interested in pursuing phone styluses. They're probably not gonna ever break on that, but I am about 65-75% sure that within 5-7 years Apple's gonna break down on touchscreen laptops; I feel like the convertible market is going to eventually be too big for them to ignore.
One big thing for me personally is that I use a file manager on Android to handle syncing -- I basically treat my phone like a USB drive. A really nice part of that is it's all web-based. I don't have anything installed on my computer, I can boot up essentially a local server from my phone and drag videos/music into or out of any app's data storage from any computer with a web browser. Even from other phones :)
Again, this doesn't mean that Android is better than iOS. It means iOS and Android serve different niches. If you like the iOS niche, that's great. Some people genuinely like the Android niche; they're not just buying Google phones because they're poor. The high-end Pixel phones sell.
In a thread about how Facebook invades users’ privacy because of lax security controls on Android, it does matter that one method of allowing third party keyboards is “secure” and the other isn’t.
Innovation != profit. Otherwise, Open Source communities would be a lot richer. This is like saying, "well if newspapers have such good reporting, why aren't they making money?" Because the app market as a whole on both iOS and Android is a race to the bottom. It just so happens that Android's bottom is slightly lower than Apple's is.
One of the posts in this thread was talking about “entrepreneurship” a Nd business opportunities that can’t exist because of Apple’s policy. If that were true, you should see a blossoming of business opportunities that exist on Android.
Go back even farther and you had 3rd-party tethering apps.
Tethering restrictions was the one thing that Apple did to cowtow to phone providers. Why would Apple care about third party tethering otherwise?
One big thing for me personally is that I use a file manager on Android to handle syncing -- I basically treat my phone like a USB drive. A really nice part of that is it's all web-based. I don't have anything installed on my computer, I can boot up essentially a local server from my phone and drag videos/music into or out of any app's data storage from any computer with a web browser. Even from other phones :
There are plenty of apps that do that with the iPhone. But, all of the cloud storage apps have web interfaces that you can copy files to and from.
The high-end Pixel phones sell.
Barely....
Estimates are that Google sells about 4 million phones in a year - the same number Apple sells in a week.
https://www.theverge.com/2018/2/13/17007104/google-pixel-tot...
And if Andy Rubin can’t convince people to buy high end Android phones - the Essentisl phone - who can?
...no. iOS doesn't have a user-accessible file browser. On Android, I can use my browser to access system files from any other application. Apps in iOS are sandboxed from the file system. I'm confused -- isn't that one of the things you like about iOS?
Maybe that's changed since the last time I used an iPhone? Did Apple break and add a system-wide file access permission recently? I don't see any iOS apps advertising that feature, but maybe I'm missing something.
The point I'm getting at is not whether or not iOS is more secure than Android. It's that the open app approach, while flawed for many reasons, allows developers to pursue innovative applications like weird keyboards that let you swipe instead of tap, and background apps that let you turn parts of your phone on and off when you walk into your house, and custom stylus-oriented devices that let you scrawl notes on your home screen while your phone's locked, and firewalls that let you monitor system-wide network requests and block ads, and homescreen widgets, and, yes, even network-level privileges that allowed 3rd-party OEMs and developers to add tethering regardless of what service providers wanted.
Some of these ended up being bad ideas, and some of them ended up being good ideas. And since then, some of the good ideas have gotten copied to iOS, with tweaks.
This is good for everyone. It's especially good for Apple users.
The point I'm getting at is you can't only focus on one part of this equation. Android is less secure than Apple because it's open. But it also, objectively, has a wider array of low and high-end devices and applications than iOS does. The same is true of Windows. Windows is insecure. But they also have Surface Books, which are cool. It's a trade-off.
When you talk about going wholesale down the "we control everything" approach, you are treating a multidimensional issue like it has exactly one right answer. It is in everyone's best interest to have multiple different systems trying out multiple different approaches.
> One of the posts in this thread was talking about “entrepreneurship”
Okay. But I'm not.
As far as generic files again the user chooses which files the app has access to outside of the sandbox via a standard file picker.
Besides the built in iCloud, if you install Dropbox, OneDrive, Google Drive, etc. you can choose any of those as destinations when you want to save or load a file from the standard file picker. They all just “storage providers”.
But if you want a local file storage solution that is accessible by all apps, you can install a storage provider for that too.
https://www.howtogeek.com/204010/how-to-get-an-android-style...
You can do SFTP etc.
> With iOS 8, your iPhone or iPad can now have a local file system like the one Android users have.
The evolution of file access on iOS is a perfect example of what I'm talking about. A rough feature that came out of Android's laissez faire permission model that was later tweaked and adopted by iOS after it proved useful and was demanded by users.
And I feel like this is still happening - to me the new Files app in iOS 11 is a pretty clear step towards unifying disparate storage solutions in a single interface, and opening up the Files app to third party integrations is another cautious shift towards Android's more permissive model. I would not honestly be surprised if at some point in the future Apple introduces a way to access some system files -- every desktop OS supports it, and the iPad is slowly positioning itself as a desktop replacement. But I dunno, it'll be interesting to see.
When you say, "oh, there's nothing innovative about this", you're glossing over that it took a heck of a long time to get file access at all in iOS, and that Apple is still evolving how file access works on its devices. Android served as a testing ground for that feature while Apple stood back and watched and thought about how they wanted to approach it. Which (again) is a process that's good for users on both platforms.
That’s kind of the point, the way that Apple allowed third party storage providers were done in a method that is still not “permissive”. Apps don’t have access to users files except for the files that the user chooses. If an app wants full access to their Dropbox or Google Drive storage, they still have to have a custom integration like VLC.
And every desktop OS has the potential for viruses and ransomware because of third party apps having access to system files and to what benefit?
When the revenue stream of the creator of Android fundamentally depends on being able to tie devices to identity and behaviour, it's highly unlikely this is going to happen. They can't also keep it only for themselves and block for others or they'll get unfair trade practices action on their backs.
Thr fact that Apple which could do this without significant adverse monetary impact but has chosen not to do so suggests they want to keep the possibility of re-entering the advertising business (or at least portray so to their shareholders)
Well put. I’ve tried to explain to people that I prefer Apple’s upfrontness that they are there to sell me a device and it’s software for money. Unlike Android systems where I feel the lead is intentionally buried by telling me how “free” the software is.
(More speculatively, the community is now working on replacing AOSP altogether with the usual Linux desktop stack, via PostmarketOS. Not usable right now, but it's progressing rather quickly, and may well be practically useful later in 2019.)
Which issues specifically?
So you're telling me that 2019 is the year of the Linux desktop... on mobile?
Do you go audit every line of source code in the apps and OS you install? Do you then verify that the binary blobs you're installing were built from the same source? Do you somehow audit the source for the firmware on your device and verify that that is the firmware installed on your device? What about the hardware, do you audit it?
Even worse, this 11 year old bug in the Linux kernel?
https://www.theregister.co.uk/2017/02/23/linux_kernel_gets_p...
They restrict access to most of the things listed above, giving randomised fakes where necessary. The advertising ID they do let apps access is unique to a publisher so they can't be tied together with behaviour from apps by other publishers, and it's trivially disabled/resettable by the end user (Settings > Privacy > Advertising > Limit Ad Tracking / Reset Advertising Identifier…). They improve things every year, e.g. Safari's intelligent tracking prevention.
I'm not really sure how you can arrive at the conclusion that Apple are holding back; they seem clearly committed to improving privacy as demonstrated by their continuous work in the area.
There's the identifierForVendor [0] which is unique to the publisher. This is pretty safe to use however you see fit (within reason).
Then there's the advertisingIdentifier [1], which is not unique, but can easily be permanently zeroed out by the user. Apple also have some fairly stringent rules about how it can be used [2], not to mention further rules about not identifying people surreptitiously [3]:
> 5.1.2 Data Use and Sharing
> (iii) Apps should not attempt to surreptitiously build a user profile based on collected data and may not attempt, facilitate, or encourage others to identify anonymous users or reconstruct user profiles based on data collected from Apple-provided APIs or any data that you say has been collected in an “anonymized,” “aggregated,” or otherwise non-identifiable way.
They ask you to explicitly confirm that you're following the advertising identifier rules in particular every single time you submit to the App Store.
[0] https://developer.apple.com/documentation/uikit/uidevice/162...
[1] https://developer.apple.com/documentation/adsupport/asidenti...
[2] https://support.appsflyer.com/hc/en-us/articles/207032086-Ap...
[3] https://developer.apple.com/app-store/review/guidelines/#dat...
Given the Apple phone was successfully hacked in the FBI case, I'm not sure why HN seems to think they are the bastion of privacy.
Given the other anti-consumer and anti-developer practices at Apple, I wouldn't trust them to protect privacy(today, and in the future when their stock price takes a hit).
I'm not saying that Apple products are 100% impenetrable against nation states; I'm pointing out that Apple are clearly putting serious effort into protecting user privacy.
I'm not sure why this is such a foreign concept to so many people. This is something Apple can do that their competitors cannot due to their business models. It's becoming more and more of a concern to customers and the law in many places. Even if you assume Apple are 100% self-serving, this is obviously a valuable differentiator for them to capitalise on.
It's contradictory in fact, because data monetizing companies prefer to control data not leak it, to keep the data's price high.
https://www.apple.com/business/site/docs/iOS_Security_Guide....
They still let apps give you a unique identifier through shared containers, those will only be deleted if you delete all apps that can access it. There is also some other container (I forgot the name) which will never be deleted unless you get a new device and don't restore any backups. You can see this kind of behaviour when you delete Instagram and they automatically fill out your username the next time you install it.
With Facebook owning WhatsApp, they are already able to give each iOS device a unique identifier. What is Apple going to do about it? Remove WhatsApp from the App Store?
I believe the other container you're talking about is the keychain. You can store small amounts of data in there (typically secure auth info) and it will persist even after app deletion. This is hardware encrypted by the Secure Enclave and can't be shared between publishers.
Apple have shown that they are willing to remove big social media apps from the App Store just a few weeks ago, with Tumblr.
Also, collecting information for use in WhatsApp and using it for a different purpose in Facebook is a DPA and GDPR violation:
https://www.theguardian.com/technology/2018/mar/14/whatsapp-...
granted, you will have to give up on netflix unless you want to install their DRM client, just like in the desktop.
[0]: https://forum.xda-developers.com/showthread.php?t=3034811
I'm just an ISV and have no evil intentions but I"m constantly having to defend myself against people saying I'm trying to track them too much.
I'm trying to track app version numbers, how often features are used, etc.
I've used user-agent's from the facebook app against a user for example(legit work :) ). It contains the phone version,app version and so much other detail that's a unique identifier.
Well, that's a nice wish for Santa, but does anyone really expect such a policy from an advertising company like Google?
Apps were the hot thing for a while, but now that major players have an app, they have figured out it matters little.
I dont do my shopping on the Target App. I'm sure they are getting economic indicators that web on mobile is just as effective.
Originally, smartphones were to be the new way of browsing the web but it turned out to be a new way for OS manufacturers to profit over third-party software because developers had to handcraft a way of accessing their data over the internet from the device given that web browsers were not up to the task of delivering fast, snappy experiences. Developers had to create native apps for the simplest services even if they didn't need the extra functionality and APIs like notifications, background updates or movement sensors.
Today, mostly because of the increase in mobile processing power, the difference between a website and an app for trivial tasks (notekeeping, calendar, ordering a product, whatevs) is innofensive and overall imperceptible, making websites a reliable way of providing functionality once again.
Browser updates and new APIs will increase the amount of possible trivial services you will be able to access from anything with a browser and up-to-date processing power.
It'll shift back over time. Mobile is not going away but there will be a resurgence of desktop usage in the form of the mobile devices being hooked up to dumb terminals or something of the sort, and privacy/usability initiatives will slowly trudge on.
It has fantastic benefits, particularly in the brief usage long tail category, but it's not an app platform. Stop trying to use it as something it just isn't. There's plenty of room here for both native and web.
The web is the most open and accessible platform we have. There's a powerful and fast layout engine. Scripting is open by default, and the client can at any time inspect, block, or modify those scripts to suit their needs.
The web is awesome for hackers.
The conference does provide a useful link to a privacy-centric page which catalogs some known facebook abuses:
https://privacyinternational.org/types-abuse/facebook
but there is no outline of this talk which summarizes the methods that facebook uses to spy on their users and the public.
Most negative news about Facebook is nonsense but this does seem to be pretty shady on Facebook's part.
Think about it, they already know who you are because you are logged in with your account.
They don’t need more info than that to run targeted ads.
That would be actually quite useful for fighting bots, but I doubt that is the reason.
My guess would be just gathering telemetry to how how API is used, and what type of android devices are there (you know, like to know what you should support and test on).
In the video it is shown that the information sent to Facebook is far more intrusive than that.
1. Facebook's "need" to prevent bots ought to be subservient to their need to acquire consent. GDPR requires such consent.
2. It seems quite likely that the persons giving this talk aren't on Facebook.
wait. is that how it really works? does the FB SDK these other apps use really require that?
I mean: what if I don't have a FB account? what if I don't have the FB app installed?
Apps are calling out to FB regardless of you having a [FB] account.
If you have root, using Xprivacy will annoy you by revealing the amount of data-mining that's happening across all apps.
I've seen this happening all the time using NetGuard (firewall which requires no root, made by the same dev behind Xprivacy). Most of the default apps on Samsung phones are constantly trying to call Facebook servers also.
If you have Android, you should not be using your phone without NetGuard installed - https://github.com/M66B/NetGuard
Android users enjoy bashing Google at every turn.
Just like I bash M$ despite loving windows 10 and Excel... (actually I've gotten better about this)
You probably were in proximity long enough to have triggered something. You never know — your friends daughter may have been in the same line somewhere at the airport or a lounge as well.
I used to get this a lot as I’m 1-2 degrees of separation from some highish profile people. FB seems to adapt and move on to a different strategy over time.
Or .. they have a database from mobile IP to rough location - or even, without knowing your exact location, perhaps both of you were using the same convention free WiFi, or the same Verizon proxy (or whatever), which would indicate close proximity even without giving the location directly.
Are you using iphone or android?
Perhaps there is some way to tell via other people’s devices that you are nearby.
Anyway, There are more paid tracking SDKs in the wild and probably more invasive than Facebook's.
For example, in Poland there is a service called Cluify which supposedly tracks millions of phones to then target ads at them. Although they're Google ads. In fact, they're a "proud partner of Google."
On the website https://cluify.com/ they mention using wifi but in sales pitches they boast inclusion in many popular apps. As their client you can geofence an area and buy ads directed at devices which frequent them.
I purged and fumigated most of these parasites from my phone. Going even as far as replacing the OS because LG thought the Facebook app should be an integral part of their distribution and not removable. Hopefully they at least charged Facebook dearly for it.
I had given up on buying new devices because of how restrictive and abusive phone manufacturers have become towards their customers. If adb can really do what you say it can, maybe I can finally upgrade my phone after all these years. Can you recommend an online article that goes over using `adb` like this? (especially for disabling locked apps)
I also block Wi-Fi and mobile data access wholesale for apps like virtual keyboards and most pre-loaded crapware that can't be uninstalled.
> If your app lists normal permissions in its manifest (that is, permissions that don't pose much risk to the user's privacy or the device's operation), the system automatically grants those permissions to your app.
But the app could use it to determine user's location (by scanning for WiFI access points identifiers) without any notification. So the user wouldn't realise that the app now knows their location.
You can see it in the docs [3]:
> Android 8.0 and Android 8.1:
> A successful call to WifiManager.getScanResults() requires any one of the following permissions:
> CHANGE_WIFI_STATE
So this issue was fixed only on Android 9, and had been working for years. Any application could secretly determine your location. That's the state of privacy protection on Android. It is difficult to believe that Google developers who are very smart people couldn't foresee it for years.
I googled a little and found a confirmation that this method was working: [4]
[1] https://developer.android.com/reference/android/Manifest.per...
[2] https://developer.android.com/guide/topics/permissions/overv...
[3] https://developer.android.com/guide/topics/connectivity/wifi...
[4] https://blog.trustlook.com/2015/06/02/how-apps-tracking-your...
“It’s difficult to get a man to understand something when his salary depends on him not understanding it”.
Cookies seem to be the majority of the aggregate identity/behavior data, which you can use various rules in the protocol to limit tracking to some extent.
I've found that opting out on a regular basis of the large adverts for a little extra peace of mind.
uBlock/uMatrix Origin, ghostery, duck.com, dns encryption, vpn, ip6.
removing old wireless access points from history/cache and disabling nfc, blutooth advertisement.
removing duplicate/shared passwords from your various authentication providers and using keypass or a secure password scheme that is easy to remember.
Log out manually of various applications such as facebook, google, microsoft, etc.
Contacts list. Clean em' up.
Keep your phone and hands sanitary at all times :)
DDG is fucking horrible
It doesn't work. I'm almost always going back to Google.
There should be a service that searches Google for you behind 7 proxies.
Image search is subtly broken in the packaged releases tho, so you'll either have to hit up google image search or use the git version
DDG at the end of the day are no more disposed to exposing their users at the behest of the gov than FAANG
Edit: Just wanted to say I'm not try to discount your experience, I just don't want to dissuade future people from trying out other search engines, when I think switching search engines is one of the biggest and easiest privacy wins a lot of people can do.
You'll need to ask about their data processors I think.
To get around that you just send everything every time.
> “Previous research has shown how 42.55 percent of free apps on the Google Play store could share data with Facebook, making Facebook the second most prevalent third-party tracker after Google’s parent company Alphabet."
Also, what happens if Facebook starts to introduce strong(er) incentives for app developers to share user data?
When the app attempts to connect to graph.facebook.com it gets NXDOMAIN.
Is it just about ease of implementation or are there legal implications? People have quoted the wiretap act to me but the argument doesn't make sense.
1. installing the Android dev SDK (complete with emulator images) on to your laptop
2. having a distinct emulator instance for each of your chosen profiles
m.facebook.com for the casual check, and mbasic.facebook.com for an admittely crippled but functional access to read the seldom chat message.
I'm happy that Fb Messenger is the tool of choice for 0,0% of people around here...
I get "0" Ads on my Android, also I'm a bit paranoid, I block every suspicious domain, only allowing Mobile/WiFi access to trusted apps.
Sadly this behaviour is easy to fingerprint.
I already have OpenVPN set up, does it have filtering features that could help block this unwanted traffic?