Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Holy shit this is detailed.

Holy shit this is detailed.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
privacy
10 Indlæg 7 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • paco@infosec.exchangeP This user is from outside of this forum
    paco@infosec.exchangeP This user is from outside of this forum
    paco@infosec.exchange
    wrote sidst redigeret af
    #1

    Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

    #privacy

    https://browsergate.eu/how-it-works/

    cerny_kocky@mastodon.socialC kitkat_blue@mastodon.socialK argv_minus_one@mastodon.sdf.orgA joriki@infosec.exchangeJ yurkshirelad@mastodon.socialY 6 Replies Last reply
    1
    0
    • paco@infosec.exchangeP paco@infosec.exchange

      Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

      #privacy

      https://browsergate.eu/how-it-works/

      cerny_kocky@mastodon.socialC This user is from outside of this forum
      cerny_kocky@mastodon.socialC This user is from outside of this forum
      cerny_kocky@mastodon.social
      wrote sidst redigeret af
      #2

      @paco i worked at major anti-virus company. not only i can believe it, i think it’s default mode of all companies that came into contact with any sellable user data

      1 Reply Last reply
      0
      • paco@infosec.exchangeP paco@infosec.exchange

        Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

        #privacy

        https://browsergate.eu/how-it-works/

        kitkat_blue@mastodon.socialK This user is from outside of this forum
        kitkat_blue@mastodon.socialK This user is from outside of this forum
        kitkat_blue@mastodon.social
        wrote sidst redigeret af
        #3

        @paco

        Kinda makes you wonder what all the other slimy digi-corpos are doing.... this is just one that's been caught after all.

        paco@infosec.exchangeP 1 Reply Last reply
        0
        • paco@infosec.exchangeP paco@infosec.exchange

          Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

          #privacy

          https://browsergate.eu/how-it-works/

          argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
          argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
          argv_minus_one@mastodon.sdf.org
          wrote sidst redigeret af
          #4

          @paco

          I'm more concerned with the fact that extensions *can* be detected this way. Web pages should not be able to detect the presence of extensions. If they can, that's a security vulnerability.

          1 Reply Last reply
          0
          • kitkat_blue@mastodon.socialK kitkat_blue@mastodon.social

            @paco

            Kinda makes you wonder what all the other slimy digi-corpos are doing.... this is just one that's been caught after all.

            paco@infosec.exchangeP This user is from outside of this forum
            paco@infosec.exchangeP This user is from outside of this forum
            paco@infosec.exchange
            wrote sidst redigeret af
            #5

            @kitkat_blue Years ago I was working for a retailer in the UK who had only recently built their first mobile app on iOS. Like most apps of that era, it was little more than a webview and it didn't need much permisisons.

            Like most developers, they had incorporated some analytics package that was reporting on users' interaction with the app. I'm fairly sure it was a binary library that they linked into their app. I don't think they got source code. I might be wrong.

            I could see the telemetry going up in the analytics API calls. Which buttons, which pages, etc.

            Then one day they launched an app feature "find a store near me." Now the app needed location permissions. If the user granted location permissions, the analytics library got access to location. Anything the app can do, the analytics library can do. And, sure enough, those analytics telemetry messages started to carry GPS coordinates from the user to this third party. My customer didn't make any change to their code. They didn't turn that on. They just asked for, and got, location permission from the end user for a legit purpose in the app.

            I pointed it out, because this was a change in behavior that was not contemplated by their privacy policy. Heck, it's a change in behavior they didn't even know had happened! It wasn't in their code! So they quietly pushed out a small update to the policy that made it OK.

            That was probably like 15-16 years ago.

            1 Reply Last reply
            0
            • paco@infosec.exchangeP paco@infosec.exchange

              Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

              #privacy

              https://browsergate.eu/how-it-works/

              joriki@infosec.exchangeJ This user is from outside of this forum
              joriki@infosec.exchangeJ This user is from outside of this forum
              joriki@infosec.exchange
              wrote sidst redigeret af
              #6

              @paco

              for anyone who'd like a sense of their more common fingerprint, see here:

              https://amiunique.org/

              I wish this site had 4B entries and not 4M ...

              1 Reply Last reply
              0
              • paco@infosec.exchangeP paco@infosec.exchange

                Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

                #privacy

                https://browsergate.eu/how-it-works/

                yurkshirelad@mastodon.socialY This user is from outside of this forum
                yurkshirelad@mastodon.socialY This user is from outside of this forum
                yurkshirelad@mastodon.social
                wrote sidst redigeret af
                #7

                @paco I bet they’re not the only ones that scan your extensions.

                paco@infosec.exchangeP 1 Reply Last reply
                0
                • paco@infosec.exchangeP paco@infosec.exchange

                  Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

                  #privacy

                  https://browsergate.eu/how-it-works/

                  energisch_@troet.cafeE This user is from outside of this forum
                  energisch_@troet.cafeE This user is from outside of this forum
                  energisch_@troet.cafe
                  wrote sidst redigeret af
                  #8

                  @paco But this cannot be legal in Europe/EU!

                  paco@infosec.exchangeP 1 Reply Last reply
                  0
                  • energisch_@troet.cafeE energisch_@troet.cafe

                    @paco But this cannot be legal in Europe/EU!

                    paco@infosec.exchangeP This user is from outside of this forum
                    paco@infosec.exchangeP This user is from outside of this forum
                    paco@infosec.exchange
                    wrote sidst redigeret af
                    #9

                    @energisch_ I’m not a lawyer or European. But that blog makes a very strong argument that you’re right: it sure seems illegal by EU law.

                    1 Reply Last reply
                    0
                    • yurkshirelad@mastodon.socialY yurkshirelad@mastodon.social

                      @paco I bet they’re not the only ones that scan your extensions.

                      paco@infosec.exchangeP This user is from outside of this forum
                      paco@infosec.exchangeP This user is from outside of this forum
                      paco@infosec.exchange
                      wrote sidst redigeret af
                      #10

                      @YurkshireLad no. Nearly any mobile app can do this and more.

                      1 Reply Last reply
                      0
                      • gambolputte@expressional.socialG gambolputte@expressional.social shared this topic
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper