“Localhost tracking” explained. It could cost Meta 32 billion.
“Localhost tracking” explained. It could cost Meta 32 billion.
Teil 2 der Serie »Wegwerfnummern«: Prepaid-Karten für wenige Euro eignen sich ideal als Wegwerfnummer – ohne Abo, ohne App-Zwang. Doch Unterschiede bei Kosten und Komfort sind groß.
https://www.kuketz-blog.de/die-prepaid-klassiker-wegwerfnummern-teil-2/
Gibt es hier Schulen, Eltern, Schüler, die Quizlet einsetzen? Das ist keine gute Idee, weil: Die App überträgt schon beim Start ohne Interaktion Daten an Tracking- & Werbenetzwerke wie Google, Amazon, AppsFlyer, Braze & Co. – ohne Einwilligung. Besonders kritisch im Schulkontext. Datenschutz? Fehlanzeige.
Our kids are under surveillance: The hidden privacy crisis in Ed Tech
#DowningStreet ‘exploring plan for #digitalID cards’ | The Independent
The #ID card would be stored on a #smartphone and linked to government records, according to think tank proposals
#privacy #security #thinktank #uk #england #tracking #surveillance
Quizlet überträgt schon beim Start zahlreiche Daten an Drittanbieter – ohne Einwilligung. Datenschutzrechtlich höchst problematisch, besonders für Schulen.
Jetzt neu: Aufbereiteter Datenmitschnitt als HTML-Tabelle verfügbar.
Press Democrat: How to stop Walnut Creek Chamber of Commerce partner from cyber tracking you
"...“It’s just super creepy,” said a veteran technology editor.
Dan Goodin has been covering Silicon Valley’s internet security issues for two decades and if you ask him what he thinks about the Walnut Creek Chamber of Commerce’s plans to track the locations of visitors in town, he has this to say:
“It’s just super creepy.”
Arrivalist, the cyber location company partnering with the chamber of commerce, will be using data from cell towers, WiFi routers and “other means,” the company’s website says, to track the whereabouts of mobile devices from people coming into the East Bay city, for events, say, to hotels.
It doesn’t ask permission...."
(possible paywall, view in reader mode or archived versions)
https://www.pressdemocrat.com/article/news/walnut-creek-tracking-2/
Pi hole 6.1 ist da. Großes Update mit neuen Funktionen und besserer Leistung https://fosstopia.de/pi-hole-6-1-2/ #InternetOhneTracker #InternetOhneWerbung #PiHole #Tracking #Trackingschutz #Werbung
- Yandex has used this method since 2017.
- Meta started abusing localhost in late 2024 using HTTP, then upgraded to WebSockets and WebRTC. And disabled the behavior immediately after the public disclosure in June 2025.
#Meta et #Yandex désanonymisent les identifiants de navigation #Web des utilisateurs #Android
#Abuse permet à Meta et Yandex d'attacher des identifiants persistants aux historiques de navigation détaillés.
#DonnéesPersonnelles #Confidentialité #CyberSécurité #Tracking #Internet
3-Jun-2025
Research co-led by IMDEA Networks discovers a #privacy abuse involving #Meta and Yandex bridging persistent identifiers to browsing histories
Native #Android apps, such as #Facebook or #Instagram, silently listen on fixed local ports to receive web #tracking data from their web tracking solutions without user consent
https://www.eurekalert.org/news-releases/1086122 #science #technology
Disclosure: Covert Web-to-App Tracking via Localhost on Android
> We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users.
The Basics: Their apps are accessing the phone's local ports to send data to the companies outside of Android's app controls. Article included IOC's and TTP's
#android #meta #yandex #surveillance #tracking #privacy #facebook #instagram #scumbags
Meta & Yandex verknüpfen Web-Cookies mit App-IDs über localhost auf Android – domainübergreifendes Tracking trotz Schutzmechanismen möglich.
https://www.kuketz-blog.de/web-zu-app-tracking-wie-meta-yandex-android-nutzer-deanonymisieren/
#Meta is seriously concerning
Their apps open local ports on #Android, while their #tracking pixels, embedded in thousands of websites, connect to these ports and gather information about users. This effectively bypasses #privacy measures such as private browsing or clearing cookies, making users personally identifiable on websites that use those pixels.
Although it appears they have stopped this technique after it was uncovered, it still reveals Meta's true intentions, imho.
Meta (Facebook, Instagram) & Yandex nutzen lokale Ports auf Android-Geräten, um Browserdaten mit nativen Apps zu verknüpfen. Dieses „Web-to-App-ID-Sharing“ hebelt Inkognito-Modus, Cookie-Löschen & Berechtigungssysteme aus. Betroffen: Milliarden Nutzer. Meta hat das Verhalten nach Offenlegung gestoppt. Nach meiner Ansicht wäre hier die Höchststrafe fällig: 4 % vom Umsatz!
https://www.europesays.com/uk/155612/ “It Seems Like Science Fiction”: Researchers Unleash Breakthrough Tracking Technology Using Environmental DNA #bacteria #DNA #Environment #EnvironmentalDNA #Genetics #Pathogens #Science #Technology #tracking #UK #UnitedKingdom #UniversityOfFlorida #wildlife
"For now, the most comprehensive protection against Meta Pixel and Yandex Metrica tracking is to refrain from installing the Facebook, Instagram, or Yandex apps on Android devices."
That's exactly what I do.