frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Meta pauses mobile port tracking tech on Android after researchers cry foul

https://www.theregister.com/2025/06/03/meta_pauses_android_tracking_tech/
131•coloneltcb•1d ago

Comments

gnabgib•1d ago
Discussion (251 points, 11 hours ago, 198 comments) https://news.ycombinator.com/item?id=44169115
JadeNB•1d ago
> "We are in discussions with Google to address a potential miscommunication regarding the application of their policies," a Meta spokesperson told The Register. "Upon becoming aware of the concerns, we decided to pause the feature while we work with Google to resolve the issue."

Ah, good, so it was all an innocent miscommunication, certainly not Meta hoovering up whatever they thought they could get away with.

ryandrake•1d ago
Not just a miscommunication... a potential miscommunication!
djhn•1d ago
A potential miscommunication about a feature that may have had unintended consequences.

No, wait, claims of intent are falsifiable in discovery.

9283409232•1d ago
This is a PR statement because they got caught with their hand in the cookie jar. Same company that makes shadow profiles for people who have never used their services.
thayne•1d ago
It seems to me like a non-localhost site making requests to localhost, or a link-local address should require a permission granted by the user.
SchemaLoad•1d ago
On MacOS and probably iOS it does. You get a popup that the application wants to access other devices on the network. Unfortunately it's not really clear to the user what this means and if the app is asking it for legitimate reasons or for spyware.
ycombinatrix•1d ago
I have seen this pop-up many times, and not once has it been for a legitimate reason. Every site worked just fine without the permission.
morkalork•1d ago
Seriously, what's even the point of having firewalls or NAT if you're going to let any external website just start opening up arbitrary connections to localhost? Is something embedded on the page for foobar.com any more trust worthy than a random IP trying to open a connection?
skybrian•1d ago
It’s not a meaningful permission. Even if they know what “localhost” means, most users have no idea which servers are running on localhost on each of their devices, so they don’t know the risks.

This needs to be higher level: “can website A connect to app B?”

thayne•22h ago
> Even if they know what “localhost” means, most users have no idea which servers are running on localhost on each of their devices, so they don’t know the risks.

It could be worded as something like "connect to applications running on your device". And yeah, users probably don't know what things that might be, but that is why it is a scary permission, and almost all websites don't need it, and if you really do need it, you should be able to explain to the user why you need to talk to a local process, and you probably also need the user to install specific software.

> This needs to be higher level: “can website A connect to app B?”

Unfortunately, on at least some OSes, this isn't really possible. You don't connect to an app, you connect to a port, and there isn't always a way to know what is on the other side. Especially if this is something on your local network, not localhost. You could ask about a specific host/port combination, but most users won't have any idea what that means.

mmastrac•1d ago
I haven't had Facebook or Instagram apps installed on anything but a burner phone for half a decade and I'm happy about that decision.

Unfortunately I can't get rid of WhatsApp, but I hope it was immune to this.

93po•1d ago
if you use a burner phone i would imagine three letter agencies can still figure out it's you really easily through metadata alone. if they can see all the numbers you call and text over years then they can probably piece together who you are pretty easily
ycombinatrix•1d ago
They are hiding from Facebook surveillance, they are not evading the NSA
IAmGraydon•1d ago
Being surprised about this is like hanging out with Jeffrey Dahmer and being surprised when he kills you and turns you into a lamp for his living room table. Privacy violation is not just something that happens at Meta. It is literally their business model. It's what they do. It therefore follows that they will do it in every possible way that they can get away with under the law, and possibly in some ways that they can't. If this is something that you dislike, the only sensible move is to close your account and delete the app.
philistine•1d ago
You’re mixing your serial killers. Dahmer didn’t make furniture, he intended to make a shrine he never quite finished.
udev4096•1d ago
It's also surprising how most of the new cs grads have little to no ethics for working at such dishonest corp
xk_id•1d ago
Exactly, and there’s no wording I can imagine coming from the manager who requested this, which wouldn’t make it sound like the plain abuse that it is. But the guys who obeyed the manager and implemented it didn’t care. The mentality of parasites.
sdk16420•1d ago
High 5 figure salaries can bribe ethics, especially if the engineers are on a Green card
ycombinatrix•1d ago
>Being surprised about this is like hanging out with Jeffrey Dahmer and being surprised when he kills

I have a choice between Google brand Dahmer & Apple brand Dahmer, what do I do?

chmod775•1d ago
Still the same Facebook from 2004, despite the name change.

It's nice they're giving us annual reminders they're still scumbags.

xk_id•1d ago
They literally pay engineers to come up with crazy grey hat techniques to monitor people’s online activity. And those scumbags are probably HN users. It’s sinister. I wonder about the wording used by the manager behind it. It probably sounded plain evil and nobody who worked on it cared. It makes you wonder what else those parasites do that we haven’t discovered yet.
dvfjsdhgfv•1d ago
I heard many excuses from some of them.

* If I don't do it, someone else will.

* Don't be naive, everybody is doing it.

* Well, one has to support one's family.

* C'mon, we're not actually hurting anyone. Did opening this port actually hurt you?

And so on.

leoh•1d ago
Concerning that Android allows this — there are worse folks than meta that would exploit this
isodev•1d ago
It seems a happy coincidence the exploit wasn’t that effective on iOS. There are legitimate reasons for all the technologies involved to exist, but thanks to Meta we can’t have nice things.
ycombinatrix•1d ago
This is by design. Why do you think we still don't have a per-app network toggle? Android is built & released by a surveillance company.
93po•1d ago
lmao at "a potential miscommunication regarding the application of their policies"

"Essentially, by opening localhost ports that allow their Android apps to receive tracking data, such as cookies and browser metadata, from scripts running in mobile browsers, Meta and Yandex are able to bypass common privacy safeguards like cookie clearing, Incognito Mode, and Android's app permission system."

completely bypassing all permission systems and using what is literally just a security vulnerability is definitely not a miscommunication of policies

Refreeze5224•23h ago
If I found an application by some random developer, whose purpose was completely unrelated, doing this, I would categorize it as malware, or spyware at the very least.

By Facebook does it, and it's a "miscommunication." I have personally considered them a surveillance, and therefore spyware company, for years. I hope more people will realize it. Especially all people right here on HN who work for Facebook, and Google as well. Please realize what you're doing is wrong, and damaging, and that you should work somewhere else doing something less objectively harmful.

Choosing the right Linux file system for your needs – and why ext4 is so popular

https://www.zdnet.com/article/how-to-choose-the-right-linux-file-system-for-your-needs-and-why-ext4-is-so-popular/
1•fork-bomber•1m ago•0 comments

Paging the Poetic Web

https://www.are.na/editorial/paging-the-poetic-web
2•hgv•2m ago•0 comments

Navigating AI Trust

https://embedsecurity.com/blog/navigating-the-ai-trust-journey/
1•gk1•2m ago•0 comments

Lessons learned from moving across countries with my family

https://viniciusgravina.wordpress.com/2025/06/05/lessons-moving-across-countries-with-a-family/
1•vgrocha•3m ago•0 comments

A Takedown of the Take It Down Act

https://blog.ericgoldman.org/archives/2025/06/a-takedown-of-the-take-it-down-act.htm
1•hn_acker•3m ago•0 comments

How Anthropic Teams use Claude Code [pdf]

https://www-cdn.anthropic.com/58284b19e702b49db9302d5b6f135ad8871e7658.pdf
1•mellosouls•4m ago•0 comments

Show HN: I made a search engine for the indieweb

https://indieseas.net/
1•dapoyo•9m ago•0 comments

UK's largest data centre campus proposed in North Lincolnshire

https://www.grimsbytelegraph.co.uk/news/local-news/ai-data-centre-campus-proposed-10221218
2•petercooper•11m ago•0 comments

VS Code extension marketplace wars: Cursor users hit roadblocks

https://devclass.com/2025/04/08/vs-code-extension-marketplace-wars-cursor-users-hit-roadblocks/
2•rmason•14m ago•0 comments

Timing the Momentum Factor Using Its Own Volatility

https://quantnook.blogspot.com/2025/06/timing-momentum-factor-using-its-own_5.html
1•Joltypark•15m ago•1 comments

Infomaniak breaks rank and comes out in support of Swiss encryption law

https://www.tomsguide.com/computing/vpns/infomaniak-breaks-rank-and-comes-out-in-support-of-controversial-swiss-encryption-law
1•miles•15m ago•0 comments

Musk Says SpaceX to Decommission Dragon Spacecraft Immediately

https://www.bloomberg.com/news/articles/2025-06-05/musk-says-spacex-to-decommission-dragon-spacecraft-immediately-mbjtsokw
15•perihelions•16m ago•3 comments

Retreating to Safety

https://marco.org/2025/05/30/retreat
2•retskrad•20m ago•0 comments

Israel is falsely designating Gaza areas as empty in order to bomb them

https://www.972mag.com/israel-gaza-empty-neighborhoods-airstrikes/
13•Qem•21m ago•2 comments

Show HN: YouTubeGO – Free 8K downloader with scheduler

https://github.com/Efeckc17/YoutubeGO
1•toxi360•22m ago•0 comments

A wireless forehead e-tattoo for mental workload estimation

https://www.cell.com/device/fulltext/S2666-9986(25)00094-8
1•Metacelsus•23m ago•0 comments

Graphene thermal pad for AMD CPUs promises 17X better conductivity than paste

https://www.tomshardware.com/pc-components/thermal-paste/graphene-thermal-pad-for-amd-cpus-promises-17x-better-conductivity-than-thermal-paste-2x-improvement-over-thermal-grizzly
1•rbanffy•23m ago•0 comments

Mir: A lightweight JIT compiler based on MIR (Medium Internal Representation)

https://github.com/vnmakarov/mir
1•90s_dev•24m ago•0 comments

China Will Drop Great Firewall for Some Users to Boost Free-Trade Port Ambitions

https://www.scmp.com/tech/policy/article/3313224/chinas-hainan-offers-global-internet-access-some-boost-free-trade-port-ambitions
2•m463•25m ago•0 comments

What Was the Role of MS-DOS in Windows 95? (2007)

https://devblogs.microsoft.com/oldnewthing/20071224-00/?p=24063
2•rbanffy•28m ago•0 comments

Luke Marshall On Acquiring Baremetrics and setting his sights on $10M ARR

https://www.indiehackers.com/post/tech/acquiring-baremetrics-and-setting-his-sights-on-10m-arr-j4pRR51ReC22qypJ1mQb
2•wjgilmore•28m ago•0 comments

DR DOS: Revenge of CP/M

https://dfarq.homeip.net/dr-dos-revenge-of-cp-m/
1•rbanffy•28m ago•0 comments

Many of Dead Sea scrolls may be older than thought, experts say

https://www.theguardian.com/science/2025/jun/04/many-of-dead-sea-scrolls-may-be-older-that-thought-experts-say
1•amrrs•28m ago•0 comments

BlackRock to Eliminate About 300 Jobs in Second Cut This Year

https://www.bloomberg.com/news/articles/2025-06-05/blackrock-to-eliminate-about-300-jobs-in-second-cut-this-year
1•kamaraju•28m ago•0 comments

Ru and W isotope systematics in ocean island basalts reveals core leakage

https://www.nature.com/articles/s41586-025-09003-0
2•PaulHoule•28m ago•0 comments

Compounding Errors of LLM Agents

https://tushardadlani.com/the-compound-error-crisis-why-llm-agents-are-failing-like-broken-robots-and-why-computer-science-warned-us
3•tush726•31m ago•0 comments

Minions "secure" is vibe coded vaporware

https://github.com/HazyResearch/minions/issues/70
6•jsploit•32m ago•0 comments

Skribidi – Nimble bidirectional text stack for UIs

https://github.com/memononen/Skribidi
1•todsacerdoti•36m ago•0 comments

Lisp in your Excel sheet via lambda

https://spreadsheet.institute/lisp/
1•macmac•36m ago•0 comments

Kindle Store eInk manga bad formatting examples

https://github.com/ciromattia/kcc/wiki/Kindle-Store-bad-formatting
1•seam_carver•37m ago•0 comments