(I'm surprised a bit, i thought phones offer app isolation).
The only things that comes to mind is to correlate device ids from different apps if the apps use the same analytics/advertising networks.
Pls enlighten me...
(I'm surprised a bit, i thought phones offer app isolation).
The only things that comes to mind is to correlate device ids from different apps if the apps use the same analytics/advertising networks.
Pls enlighten me...
This, and also anything that uses "Sign in with Facebook". (That's one of several reasons I have for never using anything that requires signing in with Facebook or Google; if I can't create a username or enter an email address, I generally don't want to use it.)
They can tie all of this data neatly together using an identifier which Apple has to date provided as an opt-out service. Apple is now changing this to opt-in, so all these developers who have included APIs which are sneaking data out to the Google and Facebook will need to include a pop-up to get permissions to tie their data to the rest of Google and Facebook’s acquired knowledge about you.
If it's not obvious, these Facebook libraries are trojan malware, full stop. And, even though iOS apps are sandboxed, if 50% of a user's apps have the same Facebook library baked into them, it's not hard for Facebook to link all that data together to determine usage patterns across apps.
The reason why they're fighting with Apple now is that it used to be much easier for Facebook to obtain a device-unique identifier that each app could forward along to Facebook, giving them device-level usage data. Apple now sees the privacy flaws in device-unique ids, and has either started or plans to start rotating those device ids and making them unique at the app-level only, which reduces the resolution of its tracking from the device level to the network level.
A long time ago, device IDs were available to apps. But that changed because those are typically immutable and the user has no control on revealing a different one to apps. So the makers of the operating systems brought a new identifier (IDFA in Apple’s OSes) that can be controlled through settings. Even before the forthcoming iOS update, you could just turn off cross app tracking completely by turning on Settings->Privacy->Advertising->Limit Ad Tracking in previous versions. But this was off by default, meaning tracking was allowed unless disabled by the user. Now it’s an explicit prompt when an app asks for the IDFA. The IDFA can be used to uniquely identify and connect a user across apps.
Is this more due to FB dragnet network analytics that they can put enough data together that it doesn't matter if you isolate the app?
Exactly this.
This is probaly in the “/tmp” or similar directory and probably useful for the system as a whole to be readable (or probably /dev or /proc). It is not a big deal unless you are facebook and, for instance, want to know if your user watches foxnews or has the cnn app or whatever.
AFAIK just doing “ps” gives you a LOT of info on any unix env.