21 ms·
Facebook still ‘secretly’ tracks your iPhone
- KaiserPro 5y agoTL;DR: facebook stores exif data. however it strips it out for display to the public. This includes geodata. Its unclear what they do with it after, and how you have control over it. Interesting nugget: the author repeats the lies that apple doesn't collect/store/index your data. I think the scepticism of facebook is a good thing, however I really wish it would be applied equally to every big company. Especially when they so clearly abuse privacy like Apple and Google.
- LucidLynx 5y ago> Interesting nugget: the author repeats the lies that apple doesn't collect/store/index your data. I did not saw this in the article... Can you elaborate on this like copy/pasting the line(s) from the article please?
- chrisandchris 5y ago> iOS 14.5 is also fairly new—the impact is still being assessed. And so we’ll need to wait and see what workarounds the data giants find to keep tracking our web and app activity. 6th paragraph. However, I‘m not sure whether Apple or Facebook is „the data giants“.
- mrunseen 5y agoApple is a data giant, that’s for sure but article talks mostly about location data which Apple has raw access to.
- KaiserPro 5y agothe image labelled "Privacy Labels - Facebook Vs Rivals @UKZak / Apple"
- deleted 5y ago[deleted]
- KaiserPro 5y agoThe reason why I say that image is a brazen lie is this: It says that there are only four things linked to you when you use imessage. one of those is "device id". It doesn't say thatit ties you to your icloud account. From that your location, passwords, icloud tabs, photos, purchases, etc, etc, etc are all indexable.
- ricardo81 5y agoI think one of his main points is that he explicitly indicated not to collect that data, and the FB app itself indicates that the functionality is 'switched off'. Also: "I suggested to them that this data is used for advertising purposes, and that this is “regardless of the privacy settings selected by the user within the Facebook/Instagram app on their phones.” Facebook told me it was fine to proceed with those assumptions." FB stance seems to be that the user has the option to strip EXIF data before uploading to FB. On the same token, can't strip your IP, guess that means a proxy.
- KaiserPro 5y ago> FB stance seems to be that the user has the option to strip EXIF data before uploading to FB. Which is pretty poor. I'd be interesting to see what twitter, tiktok and snap do with similar data. Although people seem pretty chilled with other companies doing it. We already know google indexes by location. That's how they do the real time busyness graphs.
- helsinkiandrew 5y ago> Its unclear what they do with it after The article states that FB all but confirmed that it is used for advertising purposes. > the author repeats the lies that apple doesn't collect/store/index your data. Where's the proof/evidence of this? Apps/OS have been found to leak/send some 'personal' data to Apple servers, but they say they don't track outside of apps (so app store ads use data from your app store usage etc), for them to do so without admitting it would be a huge commercial risk for very little gain (advertising revenue is still a small % of their total revenue).
- KaiserPro 5y ago> Apps/OS have been found to leak/send some 'personal' data to Apple servers, This isn't about leaks, its about actual design. The itracker system scans your local area for tags, and reports back their IDs and your location. This was rolled out without consent. By default apple collects "significant locations", which is then accessible to the itracker system ostensibly to warn you about tracking devices. We accept this because apple are "trusted". What if Apple are only trusted because they understand how to PR their way out of a bad narrative? By default all your photos are sent to icloud. They are indexed and processed to give you faces, locations and other (useful) metadata tools. In one of the OS upgrades, OSX uploaded all my passwords saved in my laptop keychain to icloud, without consent or warning. Not only that it shared them with my phone. My phone didn't at the time have a strong password set. Just imagine the sheer breathless indignity if facebook, tiktok, or similar tried just one of these actions. However apple(and google) has impunity to do all. That's my point, if we do care about privacy, then we need to apply the same level of criticism to _all_ companies.
- helsinkiandrew 5y ago> By default all your photos are sent to icloud Go into settings and turn off iCloud for photos, keychain and any other app you don't want it to work with. The difference of all of these things is that Apple is doing it to improve its apps for YOU, uploading photos from your phone to iCloud so you can see on other devices, or face recognition to group your photos, keychain copying is used across devices that you've enabled it for. FB is using the data to create targeted ads, Apple isn't. If you don't like Apples cloud processing of your photos or passwords turn it off. The data may be in Apples iCloud but is 'private' - it's probably as secure as your home or the phone in your pocket and at least as private as the information the phone companies have about your phone location.
- cookiengineer 5y ago> Interesting nugget: the author repeats the lies that apple doesn't collect/store/index your data. I always wonder why the bias is always against facebook and apple. As if people don't realize that all the privacy smoke and mirrors was just about being able to compete with the Ad Industry. Apple Ads now does the same, in a non-blockable manner. I mean, it clearly was about business tactics all along.
- tjpnz 5y ago>I think the scepticism of facebook is a good thing, however I really wish it would be applied equally to every big company. Especially when they so clearly abuse privacy like Apple and Google. The difference between Apple and Facebook is that Facebook's entire business model is built on abusing the privacy of it's users.
- KaiserPro 5y agoSo is google's, and all the ad tech companies, a bunch of medical tech companies, most of TV. But we don't give them as much introspection. but, apart from cambridge analytica, where actual data was leaked, what privacy abuses are unique to facebook? Its not like they drove around harvesting your wifi to geolocate you, or deliberately hid breaches to protect it's "good name", or sells your location data to any and everyone who asks is it? All big companies have done shitty things, but why do we let them off? shouldn't we hold them to account as well?
- saos 5y agoOr just delete Facebook apps.
- speedgoose 5y agoUnfortunately it's not that simple for everyone. I personally would lose contact with a lot of people if I delete Messenger or Whatsapp. On all my contacts, I have two on Signal, zero on Matrix.
- ignoramous 5y ago> I personally would lose contact with a lot of people if I delete Messenger or Whatsapp See Beeper (bridges to various chat apps based on Matrix.org): https://news.ycombinator.com/item?id=25848278 https://news.ycombinator.com/item?id=25848278
- speedgoose 5y agoWhat's the value of such a bridge if Facebook still gets my messages ? And this doesn't support video calls.
- soziawa 5y agoThis doesn't provide end-to-end-encryption for WhatsApp so I'd actually call this worse than just using WhatsApp in the first place. Facebook gets all the data and your messages are stored somewhere (either at Beeper or on your own server) as plaintext.
- ekianjo 5y agoYou think Facebook does not have access to Whatsapp messages ? Would be very surprised if thats not the case.
- ignoramous 5y agoOne's speculation, the other's a certainty? Good thing that Beeper lets you self-host their (AGPLd) bridges.
- dw-im-here 5y ago"""secretly"""
- mrunseen 5y agoA user can disable geo-tagging or the better(?) disable precise location in Settings.app > Privacy > Camera. Like mentioned in the article, there a lot of EXIF strips in Appstore too but I’m not sure if a regular user would take the road of take photo > go to exif stripper > delete exif on photo > save the photo > go to facebook > upload to facebook
- tjoff 5y agoThat is a very useful feature to have though - for personal use. As a privacy nut I always make sure it is turned on. Then again, I don't use facebook and I do strip exif if I want to upload a photo somewhere I don't want to share my location. (and I can do this with termux and the same tool I'd use this on my PC, just run exiftool -all= foo.jpg) I get that it is not a sensible solution for the average user. But the problem is not exif-tags. It is facebook and the current ad ecosystem. On android a file-picker that could optionally remove exif-data when a file is chosen seems like an easy workaround for the time being.
- ViViDboarder 5y agoiOS can do this out of the box when “sharing” a photo via the share sheet, but apps that you give photos access can bypass that sheet. Apple should update the photo permissions to allow enabling or disabling access to metadata as well.
- appplemac 5y agoMore specifically: Settings.app —> Privacy —> Location services —> Camera and turning off the “precise location” option for the Camera app that way. It would be ideal if there were an “EXIF data” toggle in the Camera section that could allow sharing pictures with apps but with all metadata removed.
- pjerem 5y agoIt exists : when the sharing panel appears, there is little blue « Options » (or maybe Settings in English) link on the top of the screen. There you can choose to share the picture without location.
- bobiny 5y agoA picture with messengers comparison is wrong: Telegram has 7 positions in Data Linked to You, not 3. edit: grammar
- thom 5y agoI wouldn’t know, still busy trying to fill out your cookie consent form.
- thih9 5y agoI'd love to see a detailed analysis / reverse engineering that targets how 'legitimate interest' settings really works in these forms. This form in particular pre-selects all 'legitimate interest' switches and requires me to click them all, one by one. Does it really change anything? What does it change? What if I left them selected? A quick look at their privacy policy [1] brings up: > Forbes may also process certain user information on the basis of the following legitimate interests, provided that such interests are not overridden by your privacy rights and interests: delivering and continuing to develop and improve the Site, learning from your behavior on the Site (e.g., analyzing traffic) to better serve you and other Site users, helping us modify or enhance the Site and its content, receiving insight as to what users do (and don’t) like about our Site or aspects thereof, and providing a stable, consistent, and secure user experience in connection with the Site. I understood this as 'unless your privacy rights and interests prohibit us, we'll process your data' (TINLA). Still, would be nice to know how do they check for an individual's privacy rights. [1]: https://www.forbes.com/privacy/english/#d91194a30610 https://www.forbes.com/privacy/english/#d91194a30610
- mnw21cam 5y agoYeah, it's a dark pattern, illegal under the GDPR, and I'd love to see a prosecution under it. It's making the entire consent form a farce, because they do not obey the "No, I do not give consent". You actually have to go through and say "Not only do I not give consent, but I also object to you doing it against my consent".
- freebuju 5y agoYeah. This is not particularly a Facebook problem. And it certainly is not an iPhone exclusive one. I would be willing to bet my 2¢ that Apple photo backups store your photos with exif data. Should be trivially easy to strip this info and "track" you as well. Am not seeing anyone crying over this.
- korla 5y agoI'm guessing here, but perhaps that is since apple revenue isn't ad-driven in the same sense Facebook is?
- freebuju 5y agoNone can be trusted. Doesn't matter what either party claims to sell/not sell. Google started off with "Do no evil" as a motto at some point in its history.
- wittyreference 5y ago“Do no evil” is idealism. “Don’t undermine our marketing to grab data assets that don’t align with our business model” is cold self-interest. I have much more faith in a company staying true to the latter. Not 100% faith, because their assessment of what business model to pursue can change, but it’s certainly not comparable in flakiness to corporate idealism.
- beagle3 5y agoApple revenue is not ad (or otherwise, location) driven today but that doesn’t mean it won’t be tomorrow. (Non ad location business: hazard profile based on where you hang out. Frequency of pub visits may impact your life insurance rates)
- philjohn 5y agoYet.
- shoto_io 5y agoI love the location data. I couldn’t live without on my iPhone / iCloud. It’s great for pulling up pictures of which you remember the place but not the time for example.
- phh 5y agoFor once I'm surprised. Android has been stripping location from Exif when the app don't have location permission for more than a year now: https://developer.android.com/training/data-storage/shared/media#media-location-permission https://developer.android.com/training/data-storage/shared/m...
- gigatexal 5y agoForbes’s cookie pop up is ridiculous. They list all the ads trackers and it requires seemingly infinite scrolling. I am fortunate to have been able to delete Facebook and Instagram from my phone but being in Europe I have to use WhatsApp.
- skinkestek 5y agoIt takes effort but I don't have to use WhatsApp anymore (last time was last year to speak to a Google employee I started talking with here on HN). I have contacts in UK, Scotland, Germany, Norway, Pakistan, India, South Africa and probably a few more. They all have installed Telegram by now. Of course I think we can do better than Telegram but at least I am not contributing to forcing everyone to give all their metadata to Facebook.
- randomhodler84 5y agoI wouldn’t be celebrating WA->Telegram as a great win, telegram is not encrypted end2end and stores the plaintext on their servers. So folks have switched from giving Zuck metadata, to giving Durov their messages.
- hansel_der 5y agoit stands to hope that telegram does not employ a seemingly endless list of advertising partners with 'legitimate interest'
- skinkestek 5y agoA couple of things: - back when I started moving groups WhatsApp wasn't E2E-encrypted - one of those (Zuck and Durov) is a known bad guy and it isn't Durov. The other might or might not be a bad guy, but if he is he is truly hiding it well for now. - also once I have managed to get people to understand that multiple messengers exist I hope much of the work is done already and the first groups have already been on Telegram so long that I might start to push them towards Matrix without triggering any bad feelings. (Yep, possible: the oldest one I've seen jumping from WhatsApp to Telegram with no issues at all must have been well over 80.)
- intricatedetail 5y agoWhy any privacy compromising options are not opt in by default? It should be a law if companies can't be bothered.
- sp332 5y agoIt's "opt-in" when you sign up for a Facebook account, install the app, etc.
- Nextgrid 5y agoThis would absolutely not comply with the GDPR. Under the GDPR, consent for non-essential data processing purposes should be granular, so people should be able to opt in selectively.
- Nextgrid 5y agoThe GDPR makes it opt-in, and this behavior is absolutely in breach of it. Two problems: * there's a lot of misinformation around the GDPR even in the tech community * some of this misinformation is most likely distributed intentionally, either to derail the GDPR itself or to continue profiting off nefarious things (marketing, etc) while pretending to comply and getting business via that (the majority of "GDPR compliance solutions" are absolutely not compliant, and yet companies pay for them) * some GDPR criticism is clearly in bad faith by vested interests who currently make a lot of money from breaching it (including on this community) * the regulators have been absolutely incompetent or unwilling to enforce it.
- toddmorey 5y agoGeez, even the author of this piece is "Founder/CEO of Digital Barriers, which develops advanced surveillance technologies for frontline security and defence agencies as well as commercial organizations in the US, Europe and Asia. The company is at the forefront of AI-based surveillance."
- codegladiator 5y agoHow can this person even be trusted ? or what are you implying?
- quickthrower2 5y agoPots and kettles
- dylan604 5y agoMore like goose and gander
- toddmorey 5y agoNo, just surprise... so much tracking & surveillance happening in tech it makes your head spin.
- jack_riminton 5y agoWith all of the complexity of tracking technology, protocols and data laws I'm wondering whether these findings are also revelations to FB. I'm not shilling for them but just wondering whether some of these results are a direct consequence of the nature of the systems rather than nefarious design
- nieve 5y agoSome set of developers wrote code to extract the location metadata and feed it to their tracking system for advertising purposes. How can that be just some emergent property? Actual human beings held meetings about it and worked long hours getting it done. It's hard to see your claim as not "shilling" for them.
- jack_riminton 5y agoOh no a person on the internet thinks bad of me
- theduder99 5y agowell it was a nice try mr zuckerberg
- jack_riminton 5y agoDon’t make me kick you off insta
- fsociety 5y agoThis is likely the truth, code blindly extracts metadata from the photos without being aware of the privacy permissions. Doesn’t excuse it but outlines that a developer can have good intent but bad outcomes.
- jack_riminton 5y agoExactly. FB have depleted any benefit-of-the-doubt but I never attribute to malice what can most accurately be explained by stupidity or complexity
- forgingahead 5y agoThis is a clickbait article - the issue is not with Facebook, but with Apple iPhones where this data is stored as part of the image EXIF information.
- andylynch 5y agoIf you’re concerned about this, you can stop Facebook getting this data by sharing from the Photos app. It gives you the option to strip EXIF data in the share sheet.
- deleted 5y ago[deleted]
- imgabe 5y agoWhy on Earth would you install the Facebook app on your phone?
- AussieWog93 5y agoIn all seriousness, Marketplace. It's absolutely amazing.
- quickthrower2 5y agoHandy way to keep in touch. WhatsApp wasn’t always p0wnd by Facebook.
- Ensorceled 5y agoMy large, extended family and many of my friends are all on Facebook, keeping update to date during COVID. Sharing baby photos and other life events, starting businesses as they lose their jobs, sharing grief and support as my uncle nears his end. But sure, let's continue to victim shame and blame here.
- 369 5y agoYou can do all of that on a computer.
- maest 5y agoYou can use Metal on Android. Won't give access to chat, annoyingly, so you mist still need Facebook Lite
- ViViDboarder 5y agoMaybe I’m just not as social as others, but when I stopped using Facebook I never really missed those things. If some life change happens for someone I’m not talking to regularly via other means anyway, not learning about it on Facebook doesn’t really impact me. And, for people I do talk to regularly, I hear about it the next time we connect on a call, text, or in person. I actually end up with more to talk about because I haven’t passively consumed information about them. When my grandmother passed due to COVID, my family called and texted each other and offered support in plenty of ways outside of Facebook, despite most of them being heavy users. Everyone’s situation is going to be different, but it may be be as impactful as you think to drop Facebook. It’s addictive to read about people’s updates all day but it may not actually add much to your life and you may find the connections you have with people instead more meaningful as I have.
- williesleg 5y agoEverything's tracked there kiddies.
- jefftk 5y agoThis is an OS privacy bug, and isn't specific to Facebook. If an app does not have location permissions, it should not receive the geolocation portion of photos' EXIF metadata.
- Taek 5y agoThis is also a Facebook problem. A responsible company would have disclosed a vulnerability instead of exploited it
- wartijn_ 5y agoWell of course, but we all know Facebook isn't a responsible company and Apple shouldn't assume that every app in its store is made by a responsible company.
- sammorrowdrums 5y agoThey're currently in court arguing about how they make users safer by curating the available software. Issues like this don't reflect well on that argument.
- zepto 5y agoThey reflect very well. Now that this vulnerability has been identified, they can fix it and solve the problem for their users.
- thebean11 5y agoThey could fix the problem regardless of whether the app was downloaded from the app store, a third party store, or just sideloaded, so I don't see what you're getting at.
- zepto 5y agoIt sounds like you are saying this issue is irrelevant to the App Store. So how can it reflect badly on their case? The way it reflects well, is to notice that this is a small hole in their privacy measures which can easily be fixed, and the only reason we are talking about it is that for the most part their privacy controls work well. I.e. it demonstrates their seriousness about privacy.
- h0nd 5y agoi use jailbreak to control my location better - i can more easily de/activate it and spoof my location. Now, I noticed a weird behaviour. I am not sure if its a 'bug' due to jailbreak, or if it shows how apps can access location. The setup is as follows: location services are completely deactivated system-wide. a spoof location is set. This means, I am not able in any way to access/share my location, neither the real nor the spoofed one. However, when someone shares a location with me, upon displaying it on a map, instead of the location shared the spoofed one will be displayed along the correct address of the shared location. ok, i dont know how iOS manages location services. still it is not nice at all to see that somehow an app can access a location, even if its spoofed and by error. regarding the article: you can tell your phone not to give fb any location data. but why would you take a picture with location data and upload it to facebook? its so obvious and straight-forward that the user simply undermines his own privacy.
- 369 5y agoI just turned off location services. I turn them back on for the rare times I use gps.
- jeromegv 5y agoIt's not obvious. You are uploading a photo to send to a friend, you don't know or expect that where this photo was taken is automatically used by Facebook to target you. Hell, most people wouldn't even know that the EXIF has the location.
- cj 5y agoI remember sending Apple Live photos to friends when "live" photos first came out. It wasn't 6+ months later that I realized audio was also embedded in live photos. I just never noticed because my phone is always on silent mode. The realization that I was sending audio clips to friends and family along with photos for months and month was... unnerving. It's a problem when tech becomes so complex that the average (or in my case, even the above average) tech user can't keep up.
- 5y ago
- api 5y agoNot if you don’t install any of their apps. I use it as a web site which is enough to post pics of kids for relatives, pretty much my only use for it.
- sp332 5y agoThat actually doesn't stop either of the tracking methods mentioned in the article. FB still gets your IP address and EXIF data that way.
- dylan604 5y agoYou have to specifiy any app to access Photos. By default, that access of through a non-Photos app should strip any location data. If this is not true, then I feel less tin hatty about my decision to not allow any apps access. I also feel that copying a photo from Photos should also strip location data.
- sp332 5y agoGP said they're not using the app. This is about uploading photos via the web browser.
- dylan604 5y agoSorry if my point wasn't clear enough. You have to allow the browser permission to access Photos too. If you are allowing a browser access to Photos, then it's a pretty good bet you are sharing the photo. Strip the location data.
- sp332 5y agoSure, but then it's less specific. Maybe I want to upload photos with EXIF to my Dropbox but without EXIF to Facebook. There's no way configure the OS or the browser that way.
- motohagiography 5y agoBeginning to think the reason security is so difficult is because ostensibly "good" companies do everything an attacker does and worse, but under the guise of EULAs. Here's a thought experiement: If Facebook were malware, could you get rid of it?
- cj 5y agoYes, but only if everyone else was convinced it was malware, too. "Facebook invades privacy" is still a minority opinion among their user base (whether we like it or not).
- motohagiography 5y agoNot sure you'd need everyone, it would be a product. Apple has been aiming to become that product, because I've said before that Apple is primarily a privacy company with a bunch of entertainment features. It also means that competing with Apple isn't about design, it's also mainly about providing privacy. Their whole recipe is the complementary packaging of the two orthogonal concepts of entertainment and privacy. I should start the next Apple.
- cvwright 5y agoWe should all work on starting the next Apples.
- frosted-flakes 5y agoApple is a hardware company that uses privacy as a selling feature. They don't sell privacy, they sell hardware.
- est31 5y agoLooking forward to 2060 when you can't participate in society any more unless you connect your brain to a cloud run by a facebook subsidiary, giving them access to all your thoughts, memories, etc. Everyone is connected to it. What's your problem?
- villgax 5y agoIt'd be a joke if people really think Facebook doesn't tag you at an IP address level either.
- spideymans 5y ago>“Facebook marketing is generally dominated by iOS,” one ad industry article laments, “it’s pretty safe to assume Facebook has lost at least half their data, arguably the most valuable half.” That's surprising. Facebook has a global reach and can run on damn near anything with a screen. I'm surprised iOS makes up such disproportionate part of its revenue.
- Nextgrid 5y agoThis would make sense if Facebook's business model was selling communications services to people, in which case people would just pay and indeed it wouldn't really matter whether they're running an iPhone or something else. The problem is that Facebook's business model is to sell out their userbase to the highest bidder, and the bids are significantly higher for iOS users who are considered good marks for ads compared to some generic feature-phone users.
- rdiddly 5y agoI'll save you a lot of reading: They still read photo geotags.