this post was submitted on 03 Jun 2025
503 points (100.0% liked)

Technology

70847 readers
4826 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. Android sandboxing, for instance, isolates processes to prevent them from interacting with the OS and any other app installed on the device, cutting off access to sensitive data or privileged system resources. Defenses such as state partitioning and storage partitioning, which are built into all major browsers, store site cookies and other data associated with a website in containers that are unique to every top-level website domain to ensure they're off-limits for every other site.

top 50 comments
sorted by: hot top controversial new old
[–] avidamoeba 2 points 6 hours ago* (last edited 6 hours ago)

Does anyone know if there's additional sandboxing of local ports happening for apps running in Private Space?

E: Checked myself. Can access servers in Private Space from non-Private Space browsers and vice versa. So Facebook installed in Private Space is no bueno. Even if the time to transfer data is limited since Private Space is running for short periods of time, it's likely enough to pass a token while browsing some sites.

[–] [email protected] 38 points 1 day ago (1 children)

Meta should be broken up and its leadership barred from working in tech (or politics)

[–] [email protected] 10 points 1 day ago* (last edited 1 day ago)

and its leadership barred ~~from working in tech (or politics)~~

[–] [email protected] 134 points 2 days ago (4 children)

Well, it's always been a cat and mouse game.

Just earlier today, I got a pop-up on YouTube about how they would block me after 3 videos because I use an ad blocker. Jump to now and everything is fine again. Thank you, uBlock Origin!

[–] [email protected] 1 points 2 hours ago

I've been on Librewolf for a couple of years and yt is nagging me about ad blockers not being allowed, suddenly. Are they going to black screen me again?

[–] [email protected] 46 points 2 days ago (3 children)

they still try that?

i can't remember the last time i have seen one of those warnings.

[–] cygnus 35 points 2 days ago (1 children)

I'm guessing you use Firefox? It's much better at evading that tracking.

[–] [email protected] 5 points 2 days ago

Nah I saw it on FF as well. Forcing an update on the "Quick Fixes" blocklist on uBlock Origin got rid of it.

[–] [email protected] 5 points 1 day ago

Google doesn't do global roll outs with their updates. The anti adblock stuff especially. They target only some % of randomly selected users to spread confusion online, and I would guess their hope is to frustrate people into disabling ad blockers on Youtube after reading a bunch of misinformation and placebo bad advice when looking for tech support.

[–] [email protected] 11 points 2 days ago

The business cycle dictates that companies try to re-implement bad ideas every six months to two years.

If the idea was good, they'd have implemented it and made their money. Only bad ideas are still ripe for exploitation and new economic growth, because you haven't had someone as smart as me to make them work right.

[–] [email protected] 21 points 2 days ago* (last edited 2 days ago) (1 children)

Fair warning: Last week one of my accounts was seemingly shadowbanned, and now gets "This content isn't available" on every video.

Logging out plays videos, making a new brand account worked, etc. and no notification from youtube.

[–] [email protected] 2 points 1 day ago

You were shadowbanned for watching youtube in a web browser with adblock? Sounds excessive.

load more comments (1 replies)
[–] [email protected] 64 points 2 days ago (1 children)

Useless article, but at least they link the source: https://localmess.github.io/

We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

These native Android apps receive browsers' metadata, cookies and commands from the Meta Pixel and Yandex Metrica scripts embedded on thousands of web sites. These JavaScripts load on users' mobile browsers and silently connect with native apps running on the same device through localhost sockets. As native apps access programatically device identifiers like the Android Advertising ID (AAID) or handle user identities as in the case of Meta apps, this method effectively allows these organizations to link mobile browsing sessions and web cookies to user identities, hence de-anonymizing users' visiting sites embedding their scripts.

📢 UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed.

[–] [email protected] 4 points 1 day ago (1 children)

Thanks for the update, pitchforks down people. Let's go back to blindly trusting these anti consumer cabals.

[–] [email protected] 2 points 1 day ago

I almost didn't copy the update because my focus was on the technical background. I did a double-check before submitting, if I caught the gist correctly, and decided that people would probably want to know that the report triggered that change.

[–] [email protected] 5 points 1 day ago* (last edited 1 day ago)

Not surprising, it's always expected from tech corporations, where at the end of the day it's profit and favor with conservative politicians. If they're not trying to use information gathered on people to bad government looking to cut costs ("saving taxpayers' money") by removing minority beneficiaries, they love to shove content you don't even want.

Why I never use my real name online.

[–] [email protected] 5 points 1 day ago

laughs in adguard

[–] [email protected] 23 points 2 days ago* (last edited 2 days ago) (2 children)

We found that browsers such as Chrome, Firefox and Edge are susceptible to this form of browsing history leakage in both default and private browsing modes. Brave browser was unaffected by this issue due to their blocklist and the blocking of requests to the localhost; and DuckDuckGo was only minimally affected due to missing domains in their blocklist.

Aside from having uBlock Origin and not having any Meta/Yandex apps installed, anyone aware of additional Firefox settings that could help shut this nonsense down?

[–] [email protected] 10 points 2 days ago (1 children)

I know that people here generally like to shit on Brave, but it seems that the claim "Privacy by default" has held up in this context.

[–] [email protected] 1 points 1 day ago

Isn't that Proton's tagline?

[–] [email protected] 5 points 1 day ago* (last edited 1 day ago) (1 children)

I feel like that's all you need. You don't have their apps installed, so the problem is already solved. If you use uBlock Origin to block their trackers, the problem is solved. So you've solved it twice.

load more comments (1 replies)
[–] [email protected] 18 points 2 days ago (1 children)

De-anonymising Yandex

Me: Ha! Good thing I am not Russian!

De-anonymising Meta

Me: Damn..and it is hard for me to let go because my social circle use Meta-owned social media and couldn't care less about privacy....I am toast...

[–] [email protected] 16 points 1 day ago

I used to be in your situation and one day I just told everyone I was leaving and if they want to contact me they would have to use Signal. You can't change most people's minds and Meta knows it, that's how they keep their monopoly

[–] [email protected] 30 points 2 days ago (3 children)

I am assuming all of this trash is blocked by uBlock Origin?

[–] [email protected] 28 points 2 days ago (1 children)

Seems like it's transferred through a cookie and javascript, so in theory you can block it with ublock or noscript and the like, but a sure way to block is to not have meta apps installed on your phone (or not signed in).

[–] [email protected] 11 points 2 days ago (2 children)

I don't have any Meta apps installed. :)

[–] [email protected] 26 points 2 days ago (2 children)

That's the fun part. They come preinstalled!

[–] [email protected] 10 points 2 days ago (1 children)

some android phones go as far as come with an ununinstallable system app called "meta services" beyond the regular zucc apps.

[–] [email protected] 2 points 1 day ago

For those use Universal Android Debloater Or Canta with shizuku from android to install for the current user.

load more comments (1 replies)
[–] [email protected] 8 points 2 days ago (2 children)
[–] [email protected] 10 points 2 days ago (1 children)

I'd nail my foot to the floor before I installed WhatsApp.

[–] [email protected] 5 points 1 day ago (2 children)

So you got all your friends, family and coworkers and acquaintances using Signal?

[–] [email protected] 4 points 1 day ago* (last edited 1 day ago)

So you got all your friends, family and coworkers and acquaintances using Signal?

Only the ones I like.

Joking aside, yes. I've found that just letting a friend or relative ask exploratory "how bad can WhatsApp be?" questions for about five minutes gets them to start the switch to Signal.

I can't take any credit, Meta decided to lean in hard on spying on people.

[–] [email protected] 3 points 1 day ago

Most of the people I talk to regularly, yes. I also use Discord for less private stuff, less personal contacts, and for video chat when I play D&D. I text with my wife and one friend who I mostly discuss D&D with. Both of them have Signal if I needed to reach out to them privately or while abroad. For the record, I would like to get off Discord but audio and video quality are really important to me and I haven't found a good replacement yet.

I also have a seperate (company paid) phone for all work communications. There's ups and downs to that but it definitely contributes to my ability to be restrictive in what apps I put on my phone.

[–] [email protected] 3 points 2 days ago* (last edited 2 days ago)

Got me on that one! I forgot about WhatsApp.

For what it's worth I didn't have it logged in until last week when I needed to get in touch with someone.

I will need to log out.

[–] [email protected] 10 points 1 day ago

Check that "Filter lists > Privacy > Block outsider intrusion into LAN" is enabled and you should be fine

[–] [email protected] 6 points 2 days ago (1 children)

EasyPrivacy should block Meta and Yandex pixels by default. If you have the knowledge you can put uBO in "hard mode" which will block all 3p connections. It requires you to know which CDNs to allow or websites will be broken.

[–] [email protected] 3 points 2 days ago

I am aware of hardmode, I used to use NoScript.

It's a bit too much work these days.

[–] [email protected] 4 points 2 days ago (2 children)

Block all tracking scripts and use Firefox Nightly with ublock when possible.

[–] [email protected] 12 points 2 days ago (1 children)

Not sure about the "nightly" part (as opposed to beta or stable), but yes.

[–] [email protected] 2 points 1 day ago (1 children)

I prefer nightly because about:config is accessible unlike on the mainline version. Does Beta also allow that?

[–] [email protected] 3 points 1 day ago

Beta does and unlike nightly doesn't update every night.

There's also Fennec on fdroid if you need something stable with about:config support.

[–] [email protected] 4 points 2 days ago (6 children)

Using such a unique browser version is very de-anonymizing.

load more comments (6 replies)
load more comments
view more: next ›