6 ms·
This is the overall process used by Meta as I understand it, taken from https://localmess.github.io/ https://localmess.github.io/: 1. User logged into FB or IG
by merek 1y ago
This is the overall process used by Meta as I understand it, taken from https://localmess.github.io/ https://localmess.github.io/:
1. User logged into FB or IG app. The app runs in background, and listens for incoming traffic on specific ports.
2. User visits website on the phone's browser, say something-embarassing.com, which happens to have a Meta Pixel embedded. From the article, Meta Pixel is embedded on over 5.8 million websites. Even in In-Cognito mode, they will still get tracked.
3. Website might ask for user's consent depending on location. The article doesn't elaborate, presumably this is the cookie banner that many people automatically accept to get on with their browsing?
4. > The Meta Pixel script sends the _fbp cookie (containing browsing info) to the native Instagram or Facebook app via WebRTC (STUN) SDP Munging.
You won't see this in your browser's dev tools.
5. Through the logged-in app, Meta can now associate the "anonymous" browser activity with the logged-in user. The app relays _fbp info and user id info to Meta's servers.
Also noteworthy:
> This web-to-app ID sharing method bypasses typical privacy protections such as clearing cookies, Incognito Mode and Android's permission controls. Worse, it opens the door for potentially malicious apps eavesdropping on users’ web activity.
> On or around May 17th, Meta Pixel added a new method to their script that sends the _fbp cookie using WebRTC TURN instead of STUN. The new TURN method avoids SDP Munging, which Chrome developers publicly announced to disable following our disclosure. As of June 2, 2025, we have not observed the Facebook or Instagram applications actively listening on these new ports.
- fluidcruft 1y agoNot totally following but it sounds like you are saying one of the things they have been doing involves abusing mandated GDPR cookie notices to secretly track people?
- gruez 1y ago>abusing mandated GDPR cookie notices to secretly track people? How does that even work? What can GDPR cookie notices can do that the typical tracker can't do?
- salawat 1y agoThe cookie preference pop-up is a cookie. To track your preference, they need a cookie. We legally mandated a cookie. They're using the cookie regardless. But no one will call them on it until a critical mass is reached to get cases in a sufficiently large number of jurisdictions to curtail the behavior.
- gnud 1y agoThe 'no to tracking' cookie doesn't need to be identifiable in any way.
- scott_w 1y agoWhich, on the face of it, sounds like a violation of the GDPR...
- fluidcruft 1y agoThe intent of these laws is just so obtuse and unclear! And beyond that complying is technically impossible to implement but you could only understand that if you were a rocket scientist PhD computer science wizkid making $$$$k in California which isn't that much in such a high cost of living area donchaknow. /sardonic
- threecheese 1y agoYes? The cookie in question is First Party, which means you’ve consented to permitting only that party to track you using it, and not permitting its use for wider behavioral tracking across websites. However, the locally hosted FB/Yandex listener receives all of these first party cookies, from all parties, and the OPs implication is (I think) that now these non-correlateable-by-consent first party cookies can be or are being used to track you across all sites that use them.
- threecheese 1y agoNot only did you only consent to the one party using it, but the browser has robust protections in place to ensure that these cookies are only usable by that party. This “hack” gets around the restriction completely, leveraging a local service to aggregate all the cookies across sites.
- salawat 1y agoThis is why things involving cookies for permission to do things were really poison pills. As long as there is a cookie to be tracked, any at all, you have the data exfil/tracking problem. Only thing that changes is where the aggregation happens.
- gnud 1y agoLuckily, GDPR isn't about cookies, it's about processing personal information. Doesn't matter if you use cookies, localstorage, or carrier pigeon. The older EU 'cookie directive' only mentions cookies as an example of storage in a footnote. The regulative is actually about any storage on the users computer. Marketers would like you to believe that the stupid banners are about cookies. They're not - they're about processing your personal information.
- microtonal 1y agoIANAL, but it's not GDPR-conformant consent in any way. Consent needs to be informed, unambiguous, and freely given to be valid and should be easy to reject. The only way for this to be valid would be a consent form with something like: Allow Meta tracking to connect the Facebook or Instagram app on your device to associate visits to this website with your Meta account. Yes/No (With No selected as a default.) I am pretty sure that this is a grave violation of the GDPR.
- jeroenhd 1y agoThat's probably already part of the consent form websites pop up listing 200 different trackers. If you permit data sharing with Facebook/IG/Meta in the consent form, you're consenting to tracking in general, not just cookie-based tracking. "No" doesn't even need to be selected as a default, as long as you don't use dark patterns. Making the user manually click yes or no is perfectly valid (as long as you don't make "yes" easier than "no", so if you add an "allow all" button there should be an equally prominent "deny all" button).
- codedokode 1y agoSo main application for WebRTC is de-anonymisation of users (for example getting their local IP address). Why it is not hidden behind permission I don't understand.
- afavour 1y agoThe main application for WebRTC is peer to peer data transfer. I think you can make the argument that it should be behind a permission prompt these days but it's difficult. What would the permission prompt actually say, in easy to understand layman's terms? "This web site would like to transfer data from your computer to another computer in a way that could potentially identify you"? How many users are going to be able to make an informed choice after reading that?
- codedokode 1y agoThe website wants to connect to another computer|another app on your computer. Most users probably will click "No" and this is a good choice.
- afavour 1y agoBut that says nothing about the danger of identifying you. > Most users probably will click "No" Strong disagree. When I'm loading google.com is my computer not connecting to another computer? From a layman's perspective this is the basis of the internet doing what it does. Not to mention, the vast majority of users say yes to pretty much any permission prompt you put in front of them.
- gruez 1y ago>The website wants to connect to another computer|another app on your computer. "website wants to connect to another computer" basically describes all websites. Do you really expect the average user to understand the difference? The exploit is also non-trivial either. SDP and TURN aren't privacy risks in and of themselves. They only pose risks when the server is set to localhost and with a cooperating app.
- consumer451 1y ago> something-embarassing.com, Depending on the country that you or your family lives in, this could be far worse than embarrassment.
- refulgentis 1y ago[flagged]
- 3abiton 1y agoA reminder that it's possible to use tools like XPL-EX to circumvent those attempts. Also ad blocking via adaway would do the trick here I assume, as it should block Meta Pixel tracking. Overall, awful approach.
- nuker 1y ago> 1. User logged into FB or IG app. The app runs in background, and listens for incoming traffic on specific ports. I happened to be immune, I disabled Background App Refresh in iOS settings. All app notifications still work, except WhatsApp :( https://forums.macrumors.com/threads/any-reason-to-use-background-app-refresh.2399867/ https://forums.macrumors.com/threads/any-reason-to-use-backg...
- tonyhart7 1y ago> except whatsapp > company checks out
- SideburnsOfDoom 1y ago> User logged into FB or IG app. The app runs in background So a takeaway is to avoid having Facebook or Instagram apps on your phone. I'm happy to continue to not have them. Any others? e.g. WhatsApp. Sadly, I find this one a necessary communication tool for family and business in certain countries.