73
submitted 2 days ago by Blaze@piefed.social to c/android@lemdro.id
top 13 comments
sorted by: hot top controversial new old
[-] limerod@reddthat.com 19 points 2 days ago* (last edited 2 days ago)

You are willingly giving away your data if you are not blocking trackers in your web browser and android apps.

I recommend Firefox +Ublock-origin for web browser and apps liker PersonalDNSFilter or Adguard android app if you can get a license for HTTPS filtering.

[-] Ulrich@feddit.org 6 points 2 days ago* (last edited 2 days ago)

I don't know that blocking trackers would solve this problem but it sounds like simply not installing the native apps would.

Meta and Yandex achieve the bypass by abusing basic functionality built into modern mobile browsers that allows browser-to-native app communications. The functionality lets browsers send web requests to local Android ports to establish various services, including media connections through the RTC protocol, file sharing, and developer debugging.

A conceptual diagram representing the exchange of identifiers between the web trackers running on the browser context and native Facebook, Instagram, and Yandex apps for Android. While the technical underpinnings differ, both Meta Pixel and Yandex Metrica are performing a “weird protocol misuse” to gain unvetted access that Android provides to localhost ports on the 127.0.0.1 IP address. Browsers access these ports without user notification. Facebook, Instagram, and Yandex native apps silently listen on those ports, copy identifiers in real time, and link them to the user logged into the app.

[-] swelter_spark@reddthat.com 4 points 2 days ago

I use Tracker Control + Invizible Pro + Ironfox.

[-] Turret3857@infosec.pub 3 points 2 days ago

IronFox + Pi-Hole*

[-] MaXimus421@lemmy.world 2 points 2 days ago

You're willingly giving your data away as soon as you buy a smartphone. Just using FF and UBO isn't doing anything to help that.

I'm baffled as to how you seem to believe these two things somehow are making your personal data untouchable. There is no reality that exists where you aren't giving up an enormous amount of personal data.

Those things only help make the web less annoying.

[-] limerod@reddthat.com 2 points 2 days ago

I'm not using any Meta or standard service to justify funneling any data from my side to them.

My setup blocks most trackers and ads than the average person. I do not even see ads on my phone be it a website or a native app. I reduce my reliance on google only to what's needed. Others do not get it unless needed. This reduces data collection to a high degree.

This loophole for example did not touch my phone since ads and trackers are already blocked to a high degree.

[-] MaXimus421@lemmy.world 3 points 2 days ago

Aaaaand...

You're still giving hoards of data away.

Until you realize how this is possible, you and me cannot have this conversation.

[-] limerod@reddthat.com 4 points 2 days ago

Well, I do need to exist a certain degree in this world/society by giving away from some data. I'm already an outcast in a way that I do not use popular social media apps/websites most people use.

I can stop more data collection by installing Linux, AOSP, GrapheneOS with bare minimum apps from fdroid.

I could've done that but would be making my life more difficult for little gain.

[-] MaXimus421@lemmy.world 2 points 2 days ago

Exactly. You get it.

Limiting the data being thrown out the window is doable. You'll see folks trying to "De-Google" which is understandable. But you're effectively changing the entire way you use the internet. So if that's something you're comfortable with, there's that.

[-] Zak@lemmy.world 1 points 1 day ago

This exploit involved Meta and Yandex apps running servers on your phone which Javascript embedded in trackers would communicate with. You'd have to both allow their trackers and have their apps installed to be affected.

[-] limerod@reddthat.com 1 points 1 day ago
[-] b_tr3e@feddit.org 2 points 2 days ago

Tsss... Firefox, NoScript, Ublock origin and Tracker control (via f-droid.org). Also actively cursing trackers' employees, their wives, children, houses and pets using tradited ancient Roman ban curses. (Yes, I am speaking Latin. And I do have a black cat.)

[-] swelter_spark@reddthat.com 2 points 2 days ago

I use Tracker Control + Invizible Pro + Ironfox.

this post was submitted on 03 Jun 2025
73 points (98.7% liked)

Android

19215 readers
177 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 2 years ago
MODERATORS