How can they even collect browsing history or biometric identifiers on Android? Isn't browser history stored in the browser's private storage space, or am I being naive here?
How can they even collect browsing history or biometric identifiers on Android? Isn't browser history stored in the browser's private storage space, or am I being naive here?
* Browsing history: If a user uses a WebView in your app, you can obtain the history of* that WebView instance.
Xiaomi phones let applications have access to the first (100?) bytes of each pcap line. [note: this is probably unintended, but their bug bounty programme didn't care].
* Keystroke patterns: You can track user keystrokes within your app. If you're a keyboard or accessibility provider, you can access keystrokes globally. I haven't used TikTok, but it's very unlikely that they do either of these, the UX to enable them is not pleasant because they're dangerous actions to take.
* Biometric identifiers: If a user takes a selfie, you have their iris/fingerprint/faceprint
What is pcap line?
The files are in: /storage/emulated/0/MIUI/debug_log/common/tcpdump if you have a phone to test.
To my limited understanding, the file on Xiaomi phones is a dump of all the packets that your router would see. If you're using HTTPS, it's probably leaking the sites, but it's mostly garbage.
[0] https://github.com/ankidroid/Anki-Android/blob/31cfbc914a746...
Now that you mentioned it tho, I'm not sure whether developer tools is showing me the ground truth, how does it give me 200 OK from cache without asking the remote whether the resource has changed? My memory agrees with you, something has changed in the matrix.
Biometric identifiers, I'm guessing mostly facial features: if you take a selfie/self-video with TikTok (which millions of people do) they can just take the data from there.