TikTok tracks you across the web, even if you don’t use the app
consumerreports.org
consumerreports.org
It's hard to believe I have to say that after the many decades of people getting it drilled into their heads "Do not open random email attachments" but here we are in a dark future where everyone is going to say not automatically running untrusted code is stupid and not a real option. It is. And it works.
I keep bringing up that I don't want JS to execute random code, even if it's sandboxed, it's mostly unnecessary, and I always get the same sort of replies.
Everyone calls me out of touch, I'm downvoted to oblivion, everyone suggests that I'm a unique case and everyone wants JS, they say that they don't want fragmentation and want life to be easier for them.
I get it, their pay check literally depends on them using JS, it adds a lot of flexibility.
I'm going to make the additional, controversial, guess that most web-developers don't really know what they're doing either; I would surmise that they lean on frameworks and if those frameworks are ever under threat (from people like me requesting progressive enhancement) then they need to defend the frameworks to defend themselves.
I think the real answer to why this hasn't been toothfully patched yet is ads and the billions of dollars behind it. Not JS developers.
It's still very useful for people who want to run arbitrary code on your CPU. Both AMD and Intel have severe flaws, called "speculative execution CPU bugs", that can be exploited to extract credentials, encryption keys, session keys etc. from your computer - even information living in other applications or [hardware layer] VM's.
https://pagexray.fouanalytics.com/q/pathofexile.fandom.com%2...
Don't obfuscate your JS either if you can help it. If I'm not sure if I should be trusting your site I'll be looking over your JS to see what's doing, but I'm not spending more time than it takes to glance over it either.
a convenient user experience to me, is one that fails gracefully without JS. Displaying text/images shouldn't need JS at all. I'll accept that it won't be as fancy without it, and I won't hold it against you for having JS as a fancy default, but a site should still be mostly functional without JS. Content at least should remain accessible.
Let's say a website serves React from its own domain, so no 3rd party references are used (which in this case it'll be very easy for them to serve you a modified version of the framework), they'd rightfully want to save bandwidth and minimize it! Which means obfuscation as a byproduct.
I understand where you're coming from and I do a fair share of blocking myself, but I also see why things are the way they are if you want to develop an online product.
A dashboard may still work if you can just display the current data and add a note that because JS is disabled the page must be refreshed manually to pull updated values. You don't even have to throw in a refresh button since the browser's already got one. If I go to a website without JS enabled I expect things to take a bit more work on my part.
Minified JS is a problem I run into a lot. Most of the time though, I err on the side of caution and just move on. There's so many interesting things worthy of my attention that if the site full of inscrutable javascript is just a random article/blog post or something shared as a general "hey look at this cool/fun/impressive site" it can easily be abandoned for something less troublesome.
For sites I actually do need to access for some reason I can take the time to analyze it properly, but most of the time those kinds of sites are already familiar/trustworthy, and I've got other options too like firing up a less restricted browser in a VM.
I certainly don't expect developers to give up using JavaScript for the sake of the few users like me, but the better a site does at keeping content accessible without it the less likely I am to just move on to the next tab.
"The most simple things" absolutely do not require it. Simple things can be done in pure HTML. That's what the web has always fundamentally been about.
You should TRY building a site without JS. Just try it! You'll be amazed.
The “simple things” like displaying a document don’t need JS. Why does every knowledge base system is JS when they are literally just showing a document? Or discussion forums when you’re JS reading them?
The different form input elements do a lot of work for you, and are very platform-agnostic, unlike javascript, which will fail silently as soon as someone is on an out-of-date android/ios version.
Up voting is done via a link.
https://news.ycombinator.com/vote?id={id}&how=up&auth={auth}
But you're right about maps. They're extremely well suited to being viewed in a browser with javascript.
Here's a really obvious example: https://nextspaceflight.com/
Every single link on this page requires javascript to work, when they could be actually just proper href links.
Modern CSS can handle a lot on the visual side, and modern HTML allows you to do form validation, dynamic lazy-loading and resizing of images, dialogs, collapsible elements, etc without JavaScript.
I mean having done front-end and back-end. I gotta say, the way a SPA framework lets you re-use front-end code is probably why such frameworks are selling like hot cakes. I legit feel like someone needs to spec out a back-end layout that is generic and implementable in any language, but supports some of the concepts like containers and such.
If they sat down with real users, then they'd know that most people get very frustrated when web apps make their phones slow, which happens relatively often.
If they cared, they'd also be frustrated, because they have the background knowledge to understand just how unnecessary such poor user experiences are most of the time. I've seen simple mailing address forms slow phones down. That doesn't need to happen.
> I really really wish that I could convince Web Developers that not every website needs to be a web app.
I'd say it's more that not every website needs to be written in JavaScript from the bottom up. There are web apps that I use that are tasteful and reserved with their uses of JavaScript, if they even use it at all.
You don't need to make web apps using using dynamic code for every little thing, like even building static HTML elements with JavaScript.
And not everything needs to be a SPA, nor does everything need to be built using nine layers of frameworks and abstractions.
This actually pushed me to scrape some websites. I essentially reverse engineered the site and created my own custom client for them just to ensure only my code ever runs. I don't have time or energy to do this for every site though...
I do recall building completely JS free eCommerce applications and in all honesty they were lightening fast compared to todays SPAs and still just as complex as applications. But we can do much better for user experience of complex applications with a sprinkle of interactivity.
That is not products fault. Take some responsibility.
The key word is SEEM. I have no idea regarding all the contradictory news coming out of all the camps. I posted a question on StackOverflow with a significant bounty that expires in 5 hours and so far no one has even showed up to answer it:
https://stackoverflow.com/questions/73794780/what-exactly-do...
I mention it in a post above, but data brokers have existed for a decade, which don't really care about any of this. Your email/phone/credit card + purchase behavior for instance, is likely sent to 3rd parties (as md5/sha hashed values) It boils down to sample resolution and sample size. Javascript made it really easy for literally every website to collect browse behaviors. ITP makes the skill ceiling / investment to collect this data much higher.
I can think of only one: convincing websites to add a CNAME to point subdomains to their servers.
See here for Facebook, but I'd expect other providers to do the same.
https://developers.facebook.com/docs/marketing-api/conversio...
First of all, the subdomain can redirect to google.com and back, loading it in a first-party context, and then redirect to your main domain page. I guess Google here would be a “second party”. https://learn.microsoft.com/en-us/azure/active-directory/dev...
Second way is that subdomain can load an iframe from google.com and the iframe will send a postMessage to the enclosing page, which will send a request to the server to set a cookie.
As long as you logged in ONCE in google (let’s say in a popup, or maybe using ITP’s click-to-login) then it will store the session cookie this way. And after that it can meep a cookie around for 10 years and track this guy across all the subdomains where he signed in once.
The only way to defeat this is to 1) have all browsers standardize on a single user-agent that never changes going forwards and 2) per-origin VPNs so that the public IP seen by each origin is different.
Do you maybe have other content blocking extensions running at the same time as uBO that are causing 'clashes'?
I think out of the box with the default blacklist mode very few things are broken, but the trade-off there is that you're running way more code. I do imagine the default list would block this specific nonsense from tiktok, although I haven't verified that assumption.
I block all scripts initially with ubo and slowly allow what I need to make a site function (or just close tab on sites I deem unworthy of the effort). This is certainly more than you could expect from a normal user.
* This block of code ensures these UI elements are synched among each other. * This block of code sends this UI data to this server address.
Something that gives a rough & coarse data tracing dependency analysis of inputs and outputs. There may be techniques to defeat this but I think some general patterns would become established where web designs could begin to be shifted to compartmentalize different functionality to streamline such a tool being able to to pare off the insignificant and safe parts of JS and enable folks like yourself to zero in on the interesting and questionable parts.
https://www.gnu.org/software/librejs/
It is not terribly useful.
I just tried adding tiktok.com to "My filters", but it seems like ads.tiktok.com is still accessible with that rule -- how can I block all tiktok subdomains simultaneously?
8 years ago, I could very much target viewers (no click needed) who have bought XYZ using a credit card or on the attribution end, know you saw a specific ad and went into the store and bought it.
Javascript and browse behavior added much resolution to that.
Source: Am in the advertising industry and worked on accounts in the Fortune 5.
I access the www everyday using a browser that does not auto-load resources. It would be dishonest to claim it is not useful.
I recall a brief period of time in the early www where web pages could contain "Java applets" and the browser would prompt the user if they wanted to run the code.
Web developers have become so dependent on all this control they have been given over unsuspecting computer users, how would they react to removing/reducing any of these "features".
The "modern" web browser feels like a Trojan Horse.
More and more of our lives are conducted interacting through the web. The vast majority of the tooling is focused on eye candy.
What is given up completely if we leave javascript? Or, how can we lock down browsers to stop this nonsense without completely disabling it?
Auto-fetching took this to a new level. (I always disable this behaviour, either within the client or outside it.)
Going even further, HTTP/2 server push has IMO only highlighted the questionable nature of this behaviour. Its justification is "performance" but it still removes control from the client. Will push be removed from Chrome.
https://groups.google.com/a/chromium.org/g/blink-dev/c/K3rYL...
That doesn’t seem safe to me.
... cue the WHATWG cronies shreiking "but but but but you will BREAK THE WEB"
You need to take a step back and figure out what you're failing to understand before going into these "everyone is a fool" rants.
One of the reasons people don't understand the risks is the fact that, by design, these risks don't exist at the eye of the end user. No one knows, not even you, how many servers are being hit when you click on a link.
You're opening emails, you're clicking a link, and hundreds of requests are flying out of your browser right under your nose to God knows where. How many of them are requesting useless images you never saw? How many if them are reporting telemetry data on how you're using a website? You do not know. Why are you whining about other not knowing as well?
Privacy is a hard problem because everyone is using a system explicitly designed to transfer information around without any control or supervision. Up until now the best tool we have at our disposal is a set of laws that require companies to disclose and delete data they collect on us.
Blaming the end user for clicking links is victim blaming, and demonstrates a colossal amount of ignorance about the problem domain.
Yeah no, they didn't allow their advertisers to do that. I ended up getting permission to remove from the site when their pixel was found to be causing a performance impact for users. But without good monitoring for that they would have still been running, possibly for forever. I'm sure this is basically how they get to be everywhere.
> Use privacy-protecting browser extensions. You can add extensions to your browser that will do a lot to protect your privacy. One is Disconnect, made by the company that performed our TikTok investigation. The Disconnect extension shows you how websites are trying to track you and blocks a lot of that data collection. Privacy experts often recommend uBlock Origin, as well.
> Change your browser’s privacy settings. A lot of browsers have built-in controls you can use to block trackers, including cookies, pixels, and other technologies. Open your browser’s preferences or settings, and you’ll usually find the controls in the privacy section.
> Try a more private browser. Google Chrome collects a lot of data on behalf of Google. The Consumer Reports Security Planner recommends Firefox and Brave as more privacy-focused options.
Case closed when you use uBlock Origin preferably with Brave or Firefox. As an extra measure I disable JS Unless it's really needed, and surf in a private/incognito session to stop cookies building up.
I'm using it now, and it's IMO hands down *the absolute best extension I have ever used*.
uMatrix >> (uBO | noScript | privacy badger | cookie ninja | cookie autodelete | etc)
I use all of them along with vimium-ff and midnightlizard, but uMatrix is by far the best idea for managing what is run for better privacy and performance of browsing.
[0] https://www.ghacks.net/2020/09/20/umatrix-development-has-en...
[1] https://www.ghacks.net/2021/07/15/umatrix-has-an-unfixed-vul...
It's quite nice though. I have it set to disable any and all third party resources by default and from there it's generally fairly easy to permit the necessary things the first time I visit a site. And if it proves to be difficult I generally just decline to use that website at all.
Edit: After setting advanced mode, hit ctrl twice in the popup to get the green/gray/red filtering. https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
Rather than do this, you should install Cookie Autodelete. It simply clears all cookies when a site is closed, while incognito only clears when all incognito windows are closed.
It's not a perfect replacement for UBO as the underlying filtering API isn't as powerful but it does a good enough job most of the time. It still uses the same filter lists as UBO (though again it's not able to make all rules work, due to API limitations).
The web views the filters don't apply to have different use-cases such as customizing/hiding the browser UI elements, injecting Javascript, etc. There are legitimate reasons to use it in some cases (in case you need to display server-side-rendered content as if it was native).
Of course, Apple could decide on a case-by-case basis and reject usages of the legacy web view when the new implementation is appropriate, but they won't just like they don't do anything for apps that lie on the "privacy nutrition labels" about the data they collect or various other breaches of the App Store guidelines.
I’m reading this using iCab Mobile on iOS, which is a browser apparently no-one on HN has ever heard of, as I need to mention it every time this tired old and inaccurate assertion is trotted-out again.
This browser allows you to define your own blocking lists, including filters for every conceivable combination of JS, CSS, cross-site, cookie-based and URL tracking.
So which part do you want to ban exactly?
[0] https://apps.apple.com/us/app/icab-mobile-web-browser/id3081...
ie. https://www.tiktok.com/t/ZTRmqkW4N
What seems like an inconspicuous and universal URL for a video actually sends a lot of advertising and tracing data back to TikTok’s servers about your friend/you.
And it's not even resource intensive to do something like this. It can all be done in a purely stateless manner by concatenating an internal ID with a counter and encrypting it to derive the URL that gets served to the user.
The moral of the story is, you should really download and share things yourself.
curl -I https://www.tiktok.com/t/ZTRmqkW4N
produces: HTTP/2 301
server: nginx
content-type: text/html; charset=utf-8
location: https://www.tiktok.com/@spencer.sebastian.yang/video/7149578560230034734?_t=8W9Y6CPjvbf&_r=1
Trim off the GET params (the bit after the ? in the URL) and you get <https://www.tiktok.com/@spencer.sebastian.yang/video/7149578...>. That appears to load in a browser for me.I did check to see if that resulting URL after the first redirect is also a redirect. It is not, but also returned an HTTP 403 response ('Forbidden'), when submitted without cookies that had been added.
On the other hand, I don't think most people consider a public IP address to be private or protected information. If you're interested in finding the "root" content URL, which lives on a TikTok domain, then you've already implicitly signaled that you accept them knowing your public IP address.
But that doesn't mean it's not protected by privacy legislation. Your plate or IP isn't secret, but tracking everywhere it goes still impacts privacy.
Of course I do hate it that the only way to make money on the web today is though ads and trackers. Of course I hate it to be monitored by sneaky pixels, even if I don't use the app. But the solution to the problem is quite simple: does my browser actually render and run the Javascript? If the answer is no (because the tracking script is either stopped by NoScript, or by uBlock, or by the DNS itself that resolves the tracking domain to 127.0.0.1), then I have no problem.
Let's stop whining of IT products tracking every single aspect of our digital lives: almost 30 years down the line, and the Internet hasn't yet figured out a way to make money other than ads and trackers, and it's not going to change any time soon. Instead, let's just make sure that the change happens faster: let's educate people to block all the trackers on all of their devices, so these companies are FORCED to come up with better ways of making money, or they just go burst.
As a practical matter, this means that while I can tell my mother to install uBlock Origin on her desktop browser, it isn't practical for me to tell her to root her phone and run Adaway on it.
Of course, most people use smartphones much more than they do PCs lately.
I use NextDNS (sort of "Pi-hole-as-a-Service"), which provides a "configuration profile […] that will make your device use NextDNS natively using the Encrypted DNS feature". I can't imagine it being any easier, really.
I suspect Apple will improve things in the future. Media/News companies have attempted to vilify Apple by saying they are 'getting into the ad business', however I suspect that Apple will (as usual) take a user centric approach with expanding their ad business. I am absolutely not the person to defend Apple 24/7, however their privacy practices have been great.
On iOS VPNs are a joke, and everything is a limited WebKit reskin.
Granted, it takes some technical skills to set up, but once it's set up other people can easily connect to the same VPN and have the same level of protection - my wife's and my mother's phones are also connected to the same VPN.
It's not great, but everyone is doing it so I wouldn't consider the fact that TikTok, one of the biggest social media platforms, does it too as news.
Here are a couple:
Apple News and Stocks: The topics and categories of the stories you read and the publications you follow, subscribe to, or turn on notifications from.
Advertising: Your interactions with ads delivered by Apple’s advertising platform.You can turn off Personalized Ads on your iOS or iPadOS device by going to Settings > Privacy & Security > Apple Advertising and tapping to turn off Personalized Ads. On Mac, go to System Settings > Privacy & Security > Privacy, click Apple Advertising, and deselect Personalized Ads. The Personalized Ads option may be unavailable if you are a minor, have a managed account, or are in a location where Apple does not deliver advertising to its apps.
Apple’s advertising platform does not track you, meaning that it does not link user or device data collected from our apps with user or device data collected from third parties for targeted advertising or advertising measurement purposes, and does not share user or device data with data brokers.
If so, I don't see any problem with that. The only customers accessing that page would be incoming ad clicks.
Without the pixel, the platform sees a click on their side. But if you wanted to pay for other conversions, eg a purchase, you'd need to send an event back (either via pixel or via API).
As an other example, if you wanted to retarget, you'd also need the pixel. Let's say you wanted to target users who added an item to their cart but never purchased, the pixel would fire a "added to cart" event.
Finally, if you want look-alike audiences, you'd want to pixel as many users as broadly across your site as possible. As an example of this last one, you might want to tell the ad platform to show your ad to people who seem to resemble people who have made purchases on your site. Having the pixel let's them build that list of users who purchased on your site, then try to target users who seem to have similar interests/location/browsing habits. The funny part about this is the platform might implicit learn to target your ad to people who have visited a competitor. But since you add the pixel too, they show the competitor ad to people who visit you. So the ad platform is really a weapons dealer here.
So Yea, you could decide to only use the pixel in a limited way, or not use it at all, but you'd miss out on better targeting, optimization, and reporting.
If you put the pixel on a lan
But I do it because ads are annoying -- I don't like how they look and I don't like how they slow down every experience. I...don't really care about the tracking aspect? As far as I can tell, nothing bad happens to people because some faceless entity is tracking all your browser history.
Is there some secret malice that I'm not aware of that I should be more concerned about? Near as I can tell all this vast tracking infrastructure is really only there to more precisely target me with ads and doesn't really do anything else.
As far as privacy goes, I'm much more weirded out by the fact that my property tax records are public. Or that cell providers have the ability to fairly accurately track my location if they want to. Facebook seems pretty benign compared against that.
If you want a credit and you are friends with people who don't pay back their debts you are also a risk for the bank and get a higher rate.
If you want an insurance and you are a extrem cyclists you won't get one.
If you open a shopping side and they know you can afford it, they mark up the price. (Udemy is ridiculously doing this)
Yes, this is death by a thousand paper cuts.
What could the Chinese Government do with the data? Lower or rise your social credit score? Stop you from visiting China. Throw you in Jail for watching Winnie Poo?
All the other tech giants were in the US and so we didn’t have to worried about this. At least if you weren't a terrorist or behaved like one. Now China has a totally different agenda.
Is it okay to be LGBTQ in China? What happeneds if you watch a TikTok with this theme?
Though sadly there are plenty of false positives here too...
The Udemy thing is interesting, but it's also (as far as I can tell) just doing stuff with first party cookies and region lookups. Nothing at all the level of sophistication that is being observed from Meta or Tiktok.
I'd love to hear stories of people who got screwed because of facebook or Google's broad web of surveillance, but as near as I can tell, nobody is actually being harmed.
But the most chilling quote is "we kill people based on metadata":
As NSA General Counsel Stewart Baker has said, “metadata absolutely tells you everything about somebody’s life. If you have enough metadata, you don’t really need content.” When I quoted Baker at a recent debate at Johns Hopkins University, my opponent, General Michael Hayden, former director of the NSA and the CIA, called Baker’s comment “absolutely correct,” and raised him one, asserting, “We kill people based on metadata.”
Can you link me example of this happening? Is there credible evidence that an ordinary citizen (like myself) is in more danger from state actors because of the information harvesting that large corporations engage in? I feel like if the government wants to track down and kill me they already have my address, cell phone records, etc. No need to contact Meta or Tiktok.
If they had no need for contacting Meta and Microsoft and Google, why did they do so?
How could would this put an ordinary citizen at risk? I don't know. All the data is run through an AI and if it labels you terrorist, who is to question it?
They sure kill a lot of people in Pakistan based on this data:
https://arstechnica.com/information-technology/2016/02/the-n...
(\.|^)tiktokcdn\.com$
-tiktokcdn-com.akamaized.net$
(\.|^)tiktokv\.com$
(\.|^)musical\.ly$
(\.|^)tiktok\.com$https://www.reddit.com/r/AppSecurity/comments/f422f3/tiktok_...
You're right most are doing the simplest things as most marketers do not have tech experience to understand the advanced methods. As more people try to prevent Javascript, you'll start to see more and more companies adopt these methods.
I visited several of the sites mentioned in TFA, and uBlock didn't show any connection requests being made to any tiktok-related URLs. Nor were there any unfamiliar websites commonly shared amongst these sites in case TikTok was using a proxy service to hide behind.
If you are running uBlock then you are probably blocking google tag manager that initiates these calls.
Apart from being a disgustingly deadly teenage trap it is a privacy leech at the same time. It's time people realized how useless and distracting these social media apps are, and that they are not really necessary for any functioning of the society. Real knowledge could come from reading books and sites like Wikipedia. Tiktok is good for nothing other than trapping tennagers to make them get viral by doing some really nasty/dangerous stuff.
They must be using a different name domain.
does anyone remember the comment or article that mentioned it? it seems like this tactic will be increasingly useful for companies whose revenue is entirely ad dependent. somewhat related, do any ad blocker extensions block POST/PUT but not GET?
I mean, I understand a random site doing this sh*t, but this is a gov agency, right? What the hell any ad tracking is doing there?
I have js disabled by default on my PC's and laptops. If I need (or want) to use a site that require js, I do so in a VM, and I use that VM only for one or a few related sites (like Hacker News and Slashdot). Each VM has different screen sizes and operating systems / Linux distributions. If I research a subject that is even slightly controversial, I use the Tor browser from a VM or Tails.
But mostly, I just ignore companies and organizations that don't know how to make a website work without js.
Personally, I dream of a future where 90% of content is delivered over RSS or similar and the middle man (bloated web pages) are cut out entirely.
It's a matter of principle. And once the VM's are created, they don't add much overhead.
There is nothing unique about TikTok's tracking implementations other than how much data they attempt to take in.
Side question: uBlock Origin + Brave should be enough for this type of tracking, right?
And you don't need UBlock with Brave, Nrave shields do the same thing while being faster(rust and integrated in the browser itself) and not being dependent on any extension updates.
There is a noticeable performance hit when using uBlock + shields.
127.0.0.1 analytics.tiktok.com
127.0.0.1 googletagmanager.comIt can be worded so that collecting any specific information pre and post-processed (to cover ML) about a person who is not a consenting user of your service allows individuals to sue for punitive damages and in exteme cases make it a felony.Any information, even anonymized information about individuals will be prohibited. However, if you use Google for example and agree to their ToS they can do whatever they want within reason, so long as the activity being tracked is related to the user explicitly interacting with a google service. So tracking cookies and all the weird shit they do is fine for their users, they just can't track users if the user visited hn.com and they did not explicitly consent to being tracked by google analytics, the hn.com admin can let you know it wants to allow the 3rd party service google to track you and get your consent.
This stuff is possible, I despise all the fatalism. Us, the people that understand this at any depth just need to agree on it and speak very loudly and convince our peers, being defeated and hoping politicians figure out tech some day is silly. That's why I am trying to discuss this here.