this post was submitted on 04 Jan 2024
1007 points (95.0% liked)

Privacy

31914 readers
442 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] KLISHDFSDF@lemmy.ml 187 points 10 months ago* (last edited 10 months ago) (4 children)

Although completely believable and in-line knowing Meta/Facebook's history, is there any evidence to support this claim? I'm sure it's, unfortunately, just as easily deployed to specific targets so it may be hard to replicate, but this is pretty huge.

Anyone have any links/sources?

EDIT:

Found the source post: https://mastodon.social/@protonmail/111699323585240444

and the article: https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018

[–] SnotFlickerman@lemmy.blahaj.zone 204 points 10 months ago* (last edited 10 months ago) (3 children)

TL;DR: ProtonMail might want to delete this before they get sued by Meta for defamation, because the original research does not say that about Meta, it says it about TikTok.

--

I found the same sources, but if you'll notice, the article that ProtonMail linked to actually isn't about that. It's about a different and new Facebook thing that has iffy privacy settings as well.

It links to another Gizmodo article about it, buried deep in ONE paragraph.

The problem? That article is about TikTok and the things detailed about the javascript injected that's keylogging is all related to TikTok.

When you click on a link in the Facebook or Instagram apps, the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing.

This paragraph from the article links to this article in question:

https://gizmodo.com/tiktok-keylogging-privacy-meta-1849433690

This article references Meta a few times but is mostly about TikTok. Then THAT article links to the original blog post:

https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser

He has info on TikTok and Instagram, and while Instagram is injecting javascript into an internal browser instead of the default system browser, it is not noted as capturing text including passwords.

Capturing text and passwords is only ascribed by the security research to TikTok and TikTok alone. Meta companies are using similar Js injection tactics, but they, according to the original research, do not include keylogging.

[–] RaoulDook@lemmy.world 66 points 10 months ago (5 children)

That lines up with everything I've read about TikTok being the worst of the spyware social media apps. Unfortunately most online discussion about that subject gets filled with "Whatabout America spying?" posts trying to normalize the acceptance of everybody doing it. The discussions should be about how TikTok is the worst AND Facebook is close on their tails for the race of spying. All of the spyware social media apps are a bad thing.

[–] oce@jlai.lu 25 points 10 months ago* (last edited 10 months ago)

I'm always thinking about Chinese intellegency agency thinking 10 years ago: "How can we create a spyware that everyone will use so we can collect all the data we want without too much troubles?". Then they looked at Facebook doing the same for profit and they understood that all they have to do is to create a well designed social media app and make it so trendy that people will be diverted enough to not think about the spying issue. And then they fucking nailed it, it worked so well, I'm impressed. The average people do happily through away their private life for a shot of well crafted trendy entertainment everyday. All the revelations about spying didn't stop the growth one bit.

load more comments (4 replies)
[–] Venat0r@lemmy.world 17 points 10 months ago

They might not sue to avoid bringing more attention to it.

load more comments (1 replies)
[–] Shadow@lemmy.ca 25 points 10 months ago (1 children)
[–] Zeroc00l@sh.itjust.works 19 points 10 months ago (1 children)

I'm quite surprised Proton would use Gizmodo as a source. A quote from their articles first paragraph: "[as] Apple and Google beef up privacy".

I guess they mean all the tech companies try to block each other so that they collect all the data themselves...

[–] Shirasho@lemmings.world 10 points 10 months ago

I agree. Multiple apps bind to the keypress event to inject functionality. Binding to such event does not automatically imply nefarious intent.

load more comments (1 replies)
[–] Luci@lemmy.ca 79 points 10 months ago* (last edited 10 months ago) (1 children)

Some people in this thread are claiming the article doesn't mention Facebook.

I actually read the article. You're welcome.

When you click on a link in the Facebook or Instagram apps, the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing.

Edit: The article Proton got their info from.

[–] SnotFlickerman@lemmy.blahaj.zone 76 points 10 months ago (3 children)

https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser

Kraus makes very clear that while Meta apps are also injecting javascript, that he only has evidence of TikTok doing "keylogging" type activities. Both Gizmodo and ProtonMail are wrong in that regard.

It's like nobody has real media literacy anymore, even media organizations.

load more comments (3 replies)
[–] DingoBilly@lemmy.world 58 points 10 months ago (3 children)

Don't let your bias against Meta overcome critical thinking skills.

As others have mentioned this is just incorrect. I'm no fan of Meta but you are a moron if you think this is happening.

[–] CO_Chewie@sh.itjust.works 74 points 10 months ago (20 children)

Given this is the top comment it should be pointed out that while Proton was incorrect about this being Meta there is research out about TikTok doing this very thing.

The way you've worded your comment makes it seem like this either can't happen or isn't happening and that simply isn't the case.

load more comments (20 replies)
[–] scarilog@lemmy.world 9 points 10 months ago

Maybe not keylogging but it's pretty fucking bad still, it tracks basically everything else about how you navigate when using the integrated browser.

[–] ipkpjersi@lemmy.ml 46 points 10 months ago* (last edited 10 months ago) (21 children)

Holy shit, that should be illegal. I say should because I know there's no way that it currently is.

load more comments (21 replies)
[–] dez@lemmy.ml 38 points 10 months ago (15 children)

My main goal on year 2018 was delete facebook. Unfortunately im still using whatsapp just because everyone uses it and i have no other place to talk with my friends and family.

[–] where_am_i@sh.itjust.works 17 points 10 months ago (9 children)
[–] Crashumbc@lemmy.world 36 points 10 months ago (2 children)

To do what exactly? Talk to myself?

load more comments (2 replies)
load more comments (8 replies)
[–] pistachio@lemmy.ml 7 points 10 months ago* (last edited 10 months ago) (1 children)

I think (do correct if wrong!) the EU has approved an interoperability law for big tech companies? So it should be just a matter of time until you can switch messaging app and still be able to communicate with people on wa and big messaging apps

Ofc if all your friends all use whatsapp zuck will still be able to read all your messages and get your phone number via your contacts... so it's only a partial solution. Still better than nothing tho.

Edit https://bgr.com/tech/whatsapp-and-facebook-messenger-are-gatekeepers-in-the-eu-prepare-to-be-confused/

load more comments (1 replies)
load more comments (13 replies)
[–] IdiosyncraticIdiot@sh.itjust.works 38 points 10 months ago (1 children)

Simple solution: stop using meta products

[–] PlutoniumAcid@lemmy.world 8 points 10 months ago (3 children)

Tell that to 99% of Europe where every idiot is using whatsap and the few who don't are shunned. FML

load more comments (3 replies)
[–] joe_archer@lemmy.world 33 points 10 months ago (3 children)

If you're still using the Facebook app in 2024 you deserve everything you get.

[–] lseif@sopuli.xyz 50 points 10 months ago (4 children)
[–] reev@sh.itjust.works 12 points 10 months ago* (last edited 10 months ago) (2 children)

Are they still a victim if they've been yelled at for close to a decade that these kinds of things are the standard for Facebook/Meta? I've tried telling friends and family so damn often but they just don't care.

It's like giving someone you pass on the street your ID, walking away and thinking "man, I can't believe that guy has my ID". I'm with you if they really don't know, I'm sure many don't. But so many know fully well and just don't care.

If you ask me both are to blame. Meta is only in a position where they get away with this stuff because people are practically encouraging it.

load more comments (2 replies)
load more comments (3 replies)
load more comments (2 replies)
[–] Zerush@lemmy.ml 32 points 10 months ago

Facebook keylogs anything, even outside of FB in all pages with FB APIs (any page with an FB share button), if you don't block it with an half a dozen extensions and scripts. For Example with

[–] willington@lemmy.dbzer0.com 26 points 10 months ago* (last edited 10 months ago)
[–] cayslaconic0j@lemmy.ml 21 points 10 months ago (2 children)

I use all social media in browser to give them less access to my device. I clear cache / cookies after use every time. Hopefully that gives them far less personal data.

load more comments (2 replies)
[–] pedroapero@lemmy.ml 16 points 10 months ago (1 children)

The Facebook mobile webapp works just fine nowadays. Pretty sure it's even possible to enable notifications in most web browsers. I still don't get why people are willfully installing apps instead of just pinning web browser bookmarks.

load more comments (1 replies)
[–] mctoasterson@reddthat.com 8 points 10 months ago* (last edited 10 months ago) (2 children)

This is especially nefarious paired with their other practices. Many phones stock ROMs also ship with preinstalled bloatware including TikTok and Facebook crap.

I had to use Android developer tools (ADB powershell commands) to remove multiple facebook and tiktok packages from a friends new phone because they can't be removed any other way. There was no "user visible" FB app but several packages were present and makes me think FB crap may run as "background" by default on several vendors stock ROMs. Irritating and deceiving to the consumer.

I also blacklist all their domains using PiHole so nothing on my home network can covertly back channel any data to their mothership. (Currently using Developer Dan's lists from GitHub - the Facebook list alone has almost 30,000 hosts on it)

These big tech surveillance bros can get clapped.

load more comments (2 replies)
load more comments
view more: next ›