<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Holy shit this is detailed.]]></title><description><![CDATA[<p>Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?</p><p><a href="https://infosec.exchange/tags/privacy" rel="tag">#<span>privacy</span></a></p><p><a href="https://browsergate.eu/how-it-works/" rel="nofollow noopener"><span>https://</span><span>browsergate.eu/how-it-works/</span><span></span></a></p>]]></description><link>https://forum.fedi.dk/topic/81e3a2d5-7ba7-4800-8d99-89d671dcb6da/holy-shit-this-is-detailed.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 16:23:13 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/81e3a2d5-7ba7-4800-8d99-89d671dcb6da.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 02 Apr 2026 20:06:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:59:43 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@YurkshireLad" rel="nofollow noopener">@<span>YurkshireLad</span></a></span> no. Nearly any mobile app can do this and more.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337356554151632</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337356554151632</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:59:43 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:59:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/energisch_%40troet.cafe" rel="nofollow noopener">@<span>energisch_</span></a></span> I’m not a lawyer or European. But that blog makes a very strong argument that you’re right: it sure seems illegal by EU law.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337354445437435</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337354445437435</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:59:11 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:47:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> But this cannot be legal in Europe/EU!</p>]]></description><link>https://forum.fedi.dk/post/https://troet.cafe/users/energisch_/statuses/116337308425435078</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://troet.cafe/users/energisch_/statuses/116337308425435078</guid><dc:creator><![CDATA[energisch_@troet.cafe]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:47:29 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:43:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> I bet they’re not the only ones that scan your extensions.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/YurkshireLad/statuses/116337291897075957</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/YurkshireLad/statuses/116337291897075957</guid><dc:creator><![CDATA[yurkshirelad@mastodon.social]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:43:17 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:29:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> </p><p>for anyone who'd like a sense of their more common fingerprint, see here:</p><p><a href="https://amiunique.org/" rel="nofollow noopener"><span>https://</span><span>amiunique.org/</span><span></span></a></p><p>I wish this site had 4B entries and not 4M ...</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/joriki/statuses/116337238513751664</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/joriki/statuses/116337238513751664</guid><dc:creator><![CDATA[joriki@infosec.exchange]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:29:42 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:17:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/kitkat_blue%40mastodon.social" rel="nofollow noopener">@<span>kitkat_blue</span></a></span> Years ago I was working for a retailer in the UK who had only recently built their first mobile app on iOS. Like most apps of that era, it was little more than a webview and it didn't need much permisisons.</p><p>Like most developers, they had incorporated some analytics package that was reporting on users' interaction with the app. I'm fairly sure it was a binary library that they linked into their app. I don't think they got source code. I might be wrong.</p><p>I could see the telemetry going up in the analytics API calls. Which buttons, which pages, etc.</p><p>Then one day they launched an app feature "find a store near me." Now the app needed location permissions. If the user granted location permissions, the analytics library got access to location. Anything the app can do, the analytics library can do. And, sure enough, those analytics telemetry messages started to carry GPS coordinates from the user to this third party. My customer didn't make any change to their code. They didn't turn that on. They just asked for, and got, location permission from the end user for a legit purpose in the app.</p><p>I pointed it out, because this was a change in behavior that was not contemplated by their privacy policy. Heck, it's a change in behavior they didn't even know had happened! It wasn't in their code! So they quietly pushed out a small update to the policy that made it OK.</p><p>That was probably like 15-16 years ago.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337190078356106</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/paco/statuses/116337190078356106</guid><dc:creator><![CDATA[paco@infosec.exchange]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:17:23 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 21:03:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> </p><p>I'm more concerned with the fact that extensions *can* be detected this way. Web pages should not be able to detect the presence of extensions. If they can, that's a security vulnerability.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.sdf.org/users/argv_minus_one/statuses/116337135558580471</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.sdf.org/users/argv_minus_one/statuses/116337135558580471</guid><dc:creator><![CDATA[argv_minus_one@mastodon.sdf.org]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:03:31 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 20:55:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> </p><p>Kinda makes you wonder what all the other slimy digi-corpos are doing....  this is just one that's been caught after all.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/ap/users/115736792646413589/statuses/116337103693441147</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/ap/users/115736792646413589/statuses/116337103693441147</guid><dc:creator><![CDATA[kitkat_blue@mastodon.social]]></dc:creator><pubDate>Thu, 02 Apr 2026 20:55:25 GMT</pubDate></item><item><title><![CDATA[Reply to Holy shit this is detailed. on Thu, 02 Apr 2026 20:26:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/paco%40infosec.exchange">@<span>paco</span></a></span> i worked at major anti-virus company. not only i can believe it, i think it’s default   mode of all companies that came into contact with any sellable user data</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/cerny_kocky/statuses/116336991788423914</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/cerny_kocky/statuses/116336991788423914</guid><dc:creator><![CDATA[cerny_kocky@mastodon.social]]></dc:creator><pubDate>Thu, 02 Apr 2026 20:26:57 GMT</pubDate></item></channel></rss>