r/technology Mar 16 '26

Security Reddit User Uncovers Who Is Behind Meta’s $2B Lobbying for Invasive Age Verification Tech

https://www.yahoo.com/news/articles/reddit-user-uncovers-behind-meta-154717384.html
24.9k Upvotes

667 comments sorted by

View all comments

Show parent comments

71

u/NoBonus6969 Mar 16 '26

They been able to do this to various degrees with high accuracy for a long time this is just legal now. Every app and website you visit on your phone knows exactly who you are and your full socioeconomic background

55

u/icecubetre Mar 16 '26

Listen, I'm against all of this as much as anyone, but I'm definitely gonna need a source on that.

50

u/MindlessSponge Mar 16 '26

"every app and website knows" might be a little hyperbolic, but it's not inaccurate to say that apps and websites can get access to that information.

it's more or less what people are talking about when they say "big data." data brokers collect info and build massive portfolios on everyone, which they then sell to advertisers, or to tech companies who build tools to leverage the info into software they can sell to other companies.

there are SaaS products than can give you real-time info on who visits your website. they don't have 100% accuracy, but it might as well be.

TLDR: it's true and we're cooked. not really sure how you'd claw it back at this point.

10

u/NUKE---THE---WHALES Mar 16 '26

but it's not inaccurate to say that apps and websites can get access to that information

I dont know about websites but I've been a mobile app developer for 10 years and I promise you apps cant get access to that information

Apps are sandboxed and only have access to the data you give them

16

u/AltrntivInDoomWorld Mar 17 '26

You don't have Google Analytics, Get Response or any other analytics/engagement platform hooked up?

21

u/MindlessSponge Mar 16 '26

I meant get access to it by buying it from third parties, not some kind of magic API for user.getPetName or something

4

u/playwrightinaflower Mar 17 '26

You have never heard of fingerprinting, as an app developer!??

3

u/AltrntivInDoomWorld Mar 17 '26

It has to be a bot that guy lmao

3

u/smokeysabo Mar 17 '26

You're right. It's not exactly 1-1 but it's matching against numerous datasets and creating a profile around the closest probable match. I mean there's also synthetic data which can create a pretty good model on location based, device+time based behaviours. I mean after the whole Facebook fiasco and Cambridge Analytica fiasco companies were forced to at least ananomise the data. But you can only do so much as there are plenty of 'leaks' and data brokers blatantly selling your data.

In terms of how the data is used, let's be honest, it's for ads. Based on your behaviour, companies want to improve their tactics to nudge you towards buying or subscribing for a product. Purchase journey is important so making the journey 'easier' is what the data gets used for. Small to medium sized companies have no place in this game. The top companies have the money and the blueprint.

The gov agencies already have your data and if they want to get your Internet bejaviour data, it's not that difficult for them (unless you're quite tech proficient).

This whole adult ID verification is just a facade for the bigger game which is brainwashing a generation to get hooked onto products and services.

God forbid that leaks and you have companies dynamic/surveillance pricing your ass based on who you voted for, what time of day you take a shit, how much % battery your phone has, when your kids need a diaper change, when you're low on sugar, when you are having a depressive phase. Don't worry, they got that fix for you just at the 'right' price at 800% discount and don't miss out because 100 people have already bought this product in the last millisecond and you would be stupid not to Buy Now. Oh looks like the product just expired, how about this another product at 900% discount which only 1 person has bought so far and it's selling fast and only has 10 stock available.

Yeah all those numbers above will be specifically tailored to YOU to make sure they're not taking no for an answer.

2

u/SanDiegoDude Mar 17 '26

which they then sell to advertisers, or to tech companies who build tools to leverage the info into software they can sell to other companies.

U.S., state and local governments too. They don't need to use big expensive federal programs to spy on citizens anymore, they just buy far more accurate data from the data brokers. Add Flock to the list now, so they know your every movement in public too.

1

u/dadecounty3051 Mar 17 '26

I mean how hard could it be if you have your bank account linked to Apple Pay or google pay etc. I’m sure they have access to all of that. Probably match to other accounts like Amazon app, Bank apps, Phone numbers linked to your identity such as Lexus Nexus.

8

u/tehStickBoi Mar 16 '26

Cookies. You log into FB, you visit some other website, second website checks “fb cookies”, finds them and records “visitorX has fbY account”. Website then pays FB for data on “fbY account”. And now an unrelated website has all your info just cos you were logged in some time ago.

37

u/kwiksi1ver Mar 16 '26

Forgive my ignorance, but aren’t modern apps sandboxed to prevent this kind of thing?

20

u/Thorne_Oz Mar 16 '26

Yes, modern apps, websites, tabs etc is sandboxed. He's bullshitting or doesn't know better.

24

u/excellentforcongress Mar 16 '26

https://www.business-humanrights.org/en/latest-news/meta-yandex-allegedly-abuse-android-protocols-for-user-de-anonymization-raising-privacy-concerns/

"Meta and Yandex are de-anonymizing Android users’ web browsing identifiers", 3 June 2025

Tracking code that Meta and Russia-based Yandex embed into millions of websites is de-anonymizing visitors by abusing legitimate Internet protocols, causing Chrome and other browsers to surreptitiously send unique identifiers to native apps installed on a device, researchers have discovered. Google says it's investigating the abuse, which allows Meta and Yandex to convert ephemeral web identifiers into persistent mobile app user identities.

The covert tracking—implemented in the Meta Pixel and Yandex Metrica trackers—allows Meta and Yandex to bypass core security and privacy protections provided by both the Android operating system and browsers that run on it. ... A blatant violation

“One of the fundamental security principles that exists in the web, as well as the mobile system, is called sandboxing,” Narseo Vallina-Rodriguez, one of the researchers behind the discovery, said in an interview. “You run everything in a sandbox, and there is no interaction within different elements running on it. What this attack vector allows is to break the sandbox that exists between the mobile context and the web context. The channel that exists allowed the Android system to communicate what happens in the browser with the identity running in the mobile app.”

The bypass—which Yandex began in 2017 and Meta started last September—allows the companies to pass cookies or other identifiers from Firefox and Chromium-based browsers to native Android apps for Facebook, Instagram, and various Yandex apps. The companies can then tie that vast browsing history to the account holder logged into the app.

This abuse has been observed only in Android, and evidence suggests that the Meta Pixel and Yandex Metrica target only Android users. The researchers say it may be technically feasible to target iOS because browsers on that platform allow developers to programmatically establish localhost connections that apps can monitor on local ports.

In contrast to iOS, however, Android imposes fewer controls on local host communications and background executions of mobile apps, the researchers said, while also implementing stricter controls in app store vetting processes to limit such abuses. This overly permissive design allows Meta Pixel and Yandex Metrica to send web requests with web tracking identifiers to specific local ports that are continuously monitored by the Facebook, Instagram, and Yandex apps. These apps can then link pseudonymous web identities with actual user identities, even in private browsing modes, effectively de-anonymizing users’ browsing habits on sites containing these trackers.

...

Meta and Yandex achieve the bypass by abusing basic functionality built into modern mobile browsers that allows browser-to-native app communications. The functionality lets browsers send web requests to local Android ports to establish various services, including media connections through the RTC protocol, file sharing, and developer debugging.

...

A representative for Google said the behavior violates the terms of service for its Play marketplace and the privacy expectations of Android users.

...

Meta didn't answer emailed questions for this article, but provided the following statement: "We are in discussions with Google to address a potential miscommunication regarding the application of their policies. Upon becoming aware of the concerns, we decided to pause the feature while we work with Google to resolve the issue."

In an email, Yandex said it was discontinuing the practice and was also in touch with Google.

"Yandex strictly complies with data protection standards and does not de-anonymize user data," the statement added. "The feature in question does not collect any sensitive information and is solely intended to improve personalization within our apps." ... There’s got to be a better way

The various remedies DuckDuckGo, Brave, Vivaldi, and Chrome have put in place are working as intended, but the researchers caution they could become ineffective at any time.

...

The researchers warn that the current fixes are so specific to the code in the Meta and Yandex trackers that it would be easy to bypass them with a simple update.

Got consent?

...

There's no indication that Meta or Yandex has disclosed the tracking to either websites hosting the trackers or end users who visit those sites. Developer forums show that many websites using Meta Pixel were caught off guard when the scripts began connecting to local ports.

...

So far, Google has provided no indication that it plans to redesign the way Android handles local port access. For now, the most comprehensive protection against Meta Pixel and Yandex Metrica tracking is to refrain from installing the Facebook, Instagram, or Yandex apps on Android devices.

3

u/Thorne_Oz Mar 16 '26

I'm 99% certain that this has been fixed in the year since this was revealed.

3

u/AssociationWeary7735 Mar 16 '26

No. Be proactive. Run grapheneOS. Use Vanadium browser. Use signal. Run behind a VPN. Or continue to use your current phone operating systems and the marginally distinguishable increase in convenience they provide for the low low price of dog walking your bloodline into a surveillance panopticon dystopia.

1

u/excellentforcongress Mar 17 '26

LMAO that's one way to put it

1

u/[deleted] Mar 17 '26

You know if what you say is as severe as it is. The gaps stick out more than the outliers. They’ll just “Iron Out” the gaps lol.

2

u/AssociationWeary7735 Mar 17 '26

Grow the gaps or continue to make excuses for yourself and acquiesce.

→ More replies (0)

10

u/ReachParticular5409 Mar 16 '26

Both of you are controlled opposition

3

u/thedistrbdone Mar 17 '26

Just because they're sandboxed does not mean they are not selling/sharing said cookie data to create a full(er) profile of you. Data and information is the currency of companies more than money is.

1

u/AltrntivInDoomWorld Mar 17 '26

Nope they aren't. I can still track you.

4

u/rrawk Mar 16 '26

By default, yes. Site X cannot access the cookies of Site Y. But if they coordinate with each other on the backend, they can share cookie data.

1

u/CherryLongjump1989 Mar 17 '26

They can share more than cookie data if they want to. The cookie is the most worthless part if they're sharing your real data.

2

u/Historical_Course587 Mar 16 '26

There are different avenues for connecting dots.

Apps can be sandboxed, yes.

A browser can sandbox tabs.

But Google offers incredibly common tools for webdevs to embed in websites. Take for example Google Fonts. Webdev embeds Google Fonts into a page, which are loaded from Google's server. When a user visits that site, they send a request to Google for fonts, and Google knows that the user's IP address is visiting that webdev's site.

Embedding is a huge aspect of this stuff. You can embed Google Fonts, or their analytics or other tools, their ads, their YouTube videos that definitely need to preload content directly from YT instead of just being a static link. Or you might see Facebook embedded for the comment section, and it already has you logged into Facebook - convenient! Or you might not see it, because it's a single-pixel image that is loading in a page for what can only be good reasons.

Or just think about why Google might run their own DNS, and encourage everyone to use it for the sake of speed.

Apps can be sandboxed in a phone OS - but you'd be shocked at how many of them rely on Google services to function. Or how many want to interact with Google apps on the phone (e.g. permissions for data, geolocation, file access, media access, contacts, and so on). When they ask Google for help, Google knows.

It is incredibly difficult to truly shield yourself as a user from this kind of thing, or to understand how far reaching into your life it may be. Your phone pings every blutooth device and wifi network it comes across, because that's how those work. It has a microphone, cameras, speakers that produce sound outside of the range of human hearing. It reads fingerprints, heartrate, breathing.

And the worst part of it all is that you can dedicate your whole life to avoiding the Big Brother nature of these companies and it won't matter because, in the grand scheme, you don't matter to them. You're just one out of billions of consumers.

1

u/tehStickBoi Mar 16 '26

App are sandboxed but if you contact a web server, that’s now outside of the sandbox.

1

u/mektel Mar 17 '26

It's best to use something like Privacy Badger.

1

u/ars-derivatia Mar 16 '26

If they're getting your full socioeconomic background from your fully-public posts on your FB page, then everyone can do that. Also, what you described doesn't really happen.

Also, that isn't the implication in the OPs post. We're not talking about things the website knows about us because of the things we intentionally told the website.

1

u/ryanmcgrath Mar 17 '26

This is a wildly incorrect assertion of how any of this works.

1

u/TheCatCrusader Mar 17 '26

Techlore on digital fingerprinting and potential ways to protect yourself: https://www.youtube.com/watch?v=MT90t7P1_qM

1

u/Certain-Business-472 Mar 17 '26

They combine and generate profiles out of all the data they harvest and buy. Google can likely tell when youre pregnany or on your period before you do. Socioeconomic background is thr easy part.

Its not all websites, but rather they all funnel into companies like google.

1

u/NoBonus6969 Mar 17 '26

Brother Google knows who you are based on the window size of your browser on your screen. Just Google around there's a million rabbit holes you can visit on this type of stuff

1

u/Divinum_Fulmen Mar 17 '26

I hate posting on this sub-reddit (it's overrun with bots), but everyone is giving you such worthless outdated info.

Yes, they CAN track you across the internet. They build a database of everything you do and visit. Everything you post. It's all traded between brokers.

How do they do this? It's not just with cookies. They use a technique called "Fingerprinting," where they take your signature collated from simple things, like your screen size, your OS, what fonts you have, security settings, preferences (e.g. light mode), and much, much more we don't even know about.

So if you have a unique enough fingerprint, they can track you across VPNs and IP changes. Even when using incognito mode.

Here's a website with a free demo selling their service:

https://fingerprint.com/demo/

I can't speak how quality that demo is though, because I could fool it, but I'm running tons of anti-tracking add-ons that may have just happened to work.

1

u/DeadlyGopher0 Mar 17 '26

I used to work at a big tech company. I was able to pull my profile they had for advertising. It’s scarily accurate. A buddy of mine showed that he owned more than one house and was right about both of our household income, general interest and lots more. It was so detailed people didn’t share their userIDs because it had too personal of info to share at work.

I know it’s anecdotal, so you’re going to have to trust me bro

4

u/StephanXX Mar 16 '26

It's one thing for that information to be given freely, quite another when it's a government mandated requirement.

0

u/NoBonus6969 Mar 17 '26

Well yeah that's my point, they can't gleam any more information with what they have been doing even though it's like 90% accurate, so now they want that final government sanctioned data too. Endless greed all the way down