6 ms·
Ask HN: So what happened to Facebook "localhost" tracking?
It was discussed a year ago.
https://news.ycombinator.com/item?id=44235467 https://news.ycombinator.com/item?id=44235467
- KomoD 4mo agoLooks like they stopped doing it https://localmess.github.io https://localmess.github.io > UPDATE: As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost. The code responsible for sending the _fbp cookie has been almost completely removed. Yandex has also stopped the practice we describe below.
- hulitu 4mo ago> almost
- mozvalentin 4mo agoChrome and Firefox have deployed / are deploying local-network-access which prompts the user when apps try this.
- Tade0 4mo agoI've seen it and at least in Chrome it seems to be treating all URLs which are based on an IP address as "local", regardless of the class of the address.
- kibwen 4mo agoI'd be inherently suspicious of any website in the wild attempting to contact a bare IP address. Aside from localhost, my default assumption would be that such a website is either trying to circumvent my hosts file (or circumvent my other DNS configuration, e.g. pi-hole or DNS-over-HTTPS), malware trying to reach a command-and-control server, or malware trying to circumvent my adblocker.
- shit_game 4mo agoI was just about to say that my question in regards to this was "what are web browsers doing about it?"
- pezgrande 4mo agoI guess that's why I am getting so many "Allow to find devices on your network" alerts. Good feature overall.
- SoftTalker 4mo agoOnly a good feature if users have a clue what that question means. Most will click "Yes" because they want to get on with whatever they want to do. Change it to something like "This website is trying to spy on your local devices, do you want to allow this?"
- dpoloncsak 4mo agoI honestly don't think the average Google Chrome user knows what a 'local' device is, and we should go something more ELI5 "This website wants to spy on every other device connected to your network" or something
- lukan 4mo agoSince I can see legitimate use case (complex web apps, one sharing data with another) - I would not use the word spying. But still make it clear what can happen. "Attention! This website wants to get access to other web apps running on this device, do you want to allow this?" And then a link explaining some more. But better words are surely possible.
- deleted 4mo ago[deleted]
- Aachen 4mo agoI need to turn on location access for all software on my system globally to read the battery status of a device over Bluetooth. These "could be used for" warnings are nice and all, but usually goes beyond what makes sense. Proposing that we need to press "be spied upon" just to view photos stored on your NAS is way out there I'm sorry if people don't know what "access local devices" means but actively lying to them about the mechanisms is not going to inform anyone
- crtasm 4mo agoI just discovered that MacOS was blocking Firefox from connecting to devices on my LAN - there's per-app toggle in system settings. Access to my router's web interface was not blocked (understandably) but this left me rather confused for a while.
- gh02t 4mo agoThis also got me on my partner's Macbook. For the longest time I couldn't figure out why I could access my local services on (Safari? I forget which one actually worked) but not on Firefox/Chrome.
- apitman 4mo agoAny idea if Safari is on board?
- applfanboysbgon 4mo ago> Meta must face a lawsuit alleging that it secretly tracked Android users' browsing activity on mobile websites that embedded Meta's analytics pixel, and linked that activity to users' identities, a federal judge ruled Monday. > The decision, issued by U.S. District Court Judge Rita Lin in San Francisco, grew out of a class-action complaint initially brought last June by California resident Devin Rose (and later joined by other Android users). > Rose alleged that between September 2024 and June 2025, Meta exploited Android's localhost -- a feature that allows software developers to test applications -- to connect users’ mobile web browsing to their Facebook and Instagram profiles. May 12, 2026
- gruez 4mo agodocket: https://www.courtlistener.com/docket/70448987/in-re-meta-android-privacy-litigation/ https://www.courtlistener.com/docket/70448987/in-re-meta-and...
- Retr0id 4mo agoNot at all to defend Meta but "a feature that allows software developers to test applications" is a dubious definition of localhost. I also can't come up with a better one.
- istumbler 4mo ago“A network interface which allows processes on the same internet host to communicate without the need for a network connection”
- Retr0id 4mo agoThere's a lot of layperson-unfriendly words in there! Iterating on that: "A feature that allows multiple programs on the same device to communicate without the need for an internet connection"
- FergusArgyll 4mo agoa pty fits that definition though
- woodrowbarlow 4mo agoi would love to have a software engineer's union, not so much to get better working conditions but to be able to say stuff like "i can't implement that unethical feature, it's against union rules and i'd lose my membership".
- absqueued 4mo agoTake a lead, let me sign up :)
- hasahmed 4mo agosame
- SoftTalker 4mo agoAnd this is why we don't have one. Someone else is expected to do the hard part.
- volkercraig 4mo agoStart one. Unions are worker owned. You could also join the IWW.
- actionfromafar 4mo agoUnions in the US are nerfed, by law.
- greyface- 4mo agoCollective bargaining is nerfed. Other structures remain viable and legal.
- actionfromafar 4mo agoExactly. Nerfed. Unions without collective bargaining is more like a social club.
- 4mo ago
- throwa356262 4mo agoOff topic: I wonder how hard it is to poison this type of data gathering?
- deleted 4mo ago[deleted]
- Aachen 4mo agoIs that a question?
- vorticalbox 4mo agoNot hard, one could build an application that listens on common software ports and simply returns 200 for every request it gets. Not sure how it would benefit you telling some website you run all the software.
- chris_explicare 4mo ago[dead]
- 1vuio0pswjnm7 4mo agoA timely question. Hopefully someone will share the recent Order and Third Amended Complaint Since that discussion in 2025 Rose v Meta was consolidated with some other privacy cases against Meta A first amended complaint was filed,^1 Google was added as a defendant Defendants motion to dismiss was denied A third amended complaint was filed on Monday Here are the PDFs 1. 1st amended complaint https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.84.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Meta motion to dismiss https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.101.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Google motion to dismiss https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.104.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Plaintiffs response https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.107.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Meta reply https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.110.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Google reply https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.113.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... Order (Payment required) https://pacer.login.uscourts.gov/csologin/login.jsf?pscCourtId=CANDC&appurl=https://ecf.cand.uscourts.gov/doc1/035027110772?caseid%3D450524 https://pacer.login.uscourts.gov/csologin/login.jsf?pscCourt... 2nd amended complaint (Payment required) https://pacer.login.uscourts.gov/csologin/login.jsf?pscCourtId=CANDC&appurl=https://ecf.cand.uscourts.gov/doc1/035027197826?caseid%3D450524 https://pacer.login.uscourts.gov/csologin/login.jsf?pscCourt...
- apitman 4mo agoI've recently been exploring options for allowing web apps to access LAN services. For example, a WebDAV server so you can watch local videos in the app without streaming them through a server. You can actually achieve a form of discovery if your service registers itself using mDNS for something like `service.local`. Browsers will allow direct navigation/redirection to `http://service.local http://service.local`, but they'll block any fetch/XHR requests due to mixed content rules, even if you have CORS configured. And of course you can't get a cert for `.local` domains. Newer things like Chrome's LNA[0] are actually really helpful, because (for now at least) if the user grants the permission, fetch/XHR will go through, but you'll get a bunch of mixed content warnings in the console. It seems like the only way to fully support this use case currently is with WebRTC, which is pretty sad. [0]: https://developer.chrome.com/blog/local-network-access https://developer.chrome.com/blog/local-network-access
- 0john 4mo agoThis actually inspired me recently to create Pal Pipe for Android- https://gitlab.com/not_john/palpipe https://gitlab.com/not_john/palpipe
- 1vuio0pswjnm7 4mo agoThe May 11, 2026 Order on defendants' Motion to Dismiss has now been uploaded to the Internet Archive https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.450524/gov.uscourts.cand.450524.120.0.pdf https://dn711508.ca.archive.org/0/items/gov.uscourts.cand.45... No claims were dismissed without leave to amend Defendants have failed to stop this litigation from going forward Expect a settlement before this moves into discovery The Court's understanding of "localhost" in this Order may be less than complete but if this litigation progresses further and experts are retained then that could change