Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Mysk馃嚚馃嚘馃嚛馃嚜
@mysk@mastodon.social  路  activity timestamp 3 weeks ago

We detailed this last year and we checked again today. Meta collects everything it needs to track users across apps, a practice strictly prohibited by Apple.

Stop using the native app. Use the web app.

#privacy #fingerprinting #iOS#PWA
More 馃憞

  • Copy link
  • Flag this post
  • Block
Mysk馃嚚馃嚘馃嚛馃嚜
@mysk@mastodon.social replied  路  activity timestamp 3 weeks ago

Link to our demo from last year. Apple's Required Reason API rules aren't being enforced - either they're ignoring it or they can't do it.

https://youtu.be/4ZPTjGG9t7s?feature=shared

  • Copy link
  • Flag this comment
  • Block
Mysk馃嚚馃嚘馃嚛馃嚜
@mysk@mastodon.social replied  路  activity timestamp 3 weeks ago

P.S.: The data collection is massive. We can't consistently simulate accounts that aren't based in the EU. Data collection isn't as massive for EU accounts. Our entire team is currently in the EU, which makes recording a demo capturing the massive data collection difficult. Our time is limited. It would be great if researchers outside the EU investigated this. We're happy to help.

  • Copy link
  • Flag this comment
  • Block
Mysk馃嚚馃嚘馃嚛馃嚜
@mysk@mastodon.social replied  路  activity timestamp 3 weeks ago

This article by @span 9to5Mac is spot on 馃憣

https://9to5mac.com/2025/08/21/meta-allegedly-bypassed-apple-privacy-measure-and-fired-employee-who-flagged-it/

  • Copy link
  • Flag this comment
  • Block
Mysk馃嚚馃嚘馃嚛馃嚜
@mysk@mastodon.social replied  路  activity timestamp 3 weeks ago

To investigate this, You need to connect your iPhone to a network where you can capture HTTPs traffic and decrypt it.
1- quit Instagram so it is not running in the background
2- Send yourself a DM or let someone comment on your posts
3- You get notifications and the app should wake up in the background and send the massive data
4- Capture the data, analyze it, redact it and publish it

You can do it with Proxyman.

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.0-rc.3.1 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login