Post AvZEfgbdaPhJ9txGvw by GrapheneOS@grapheneos.social
(DIR) More posts by GrapheneOS@grapheneos.social
(DIR) Post #Aul5Uam0HlQ9CQtauu by dangoodin@infosec.exchange
2025-06-03T14:19:36Z
2 likes, 3 repeats
Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/
(DIR) Post #AvZEeanJhydSqQtdhI by rzeta0@mastodon.social
2025-06-03T14:29:41Z
0 likes, 0 repeats
@neurovagrant @dangoodin @mysk @GrapheneOS I'm waiting to see what grapheneOs says to
(DIR) Post #AvZEebtjbbMaGcuHL6 by catsalad@infosec.exchange
2025-06-03T14:44:54Z
1 likes, 0 repeats
@rzeta0 @neurovagrant @dangoodin @mysk @GrapheneOS Not having Meta apps installed thwarts this tracking, but if one is installed it looks as if these exploits they use work.
(DIR) Post #AvZEffiKu1SgOO56jg by rzeta0@mastodon.social
2025-06-03T14:46:18Z
0 likes, 0 repeats
@catsalad @neurovagrant @dangoodin @mysk @GrapheneOS Thanks I don't have meta apps but I wonder if the browser might enabler others to take advantage via web-page embedded code that tried to do the same.(I'm no expert)
(DIR) Post #AvZEfgbdaPhJ9txGvw by GrapheneOS@grapheneos.social
2025-06-03T15:48:22Z
1 likes, 0 repeats
@rzeta0 @catsalad @neurovagrant @dangoodin @mysk Vanadium has peer-to-peer WebRTC disabled by default and only allows server-based WebRTC by default.We plan to make further improvements to address these things in a more general way including making the loopback network interface per-profile by default and splitting our Network permission to have the option to toggle loopback access separately.
(DIR) Post #AvZEfr7uTHSDmt8Bcm by GrapheneOS@grapheneos.social
2025-06-03T15:51:08Z
1 likes, 0 repeats
@neurovagrant Vanadium has peer-to-peer WebRTC disabled by default and only allows server-based WebRTC by default. This isn't the only privacy issue caused by peer-to-peer WebRTC.We plan to make further improvements to address these things in a more general way including making the loopback network interface per-profile by default and splitting our Network permission to have the option to toggle loopback access separately.