Meta’s Pixel and Yandex’s Metrica Trackers Scoff At Android’s Sandbox

Source: Ars Technica Meta’s Pixel and Yandex’s Metrica Trackers Scoff At Android’s Sandbox

We’re Calling Spying De-anonymizing Now?

Two app companies with widespread penetration in the smartphone market, Meta and Yandex, have been caught breaking Android’s sandboxing and pass unique identifiers from your browser to their apps.  This behaviour violates the terms of service for the Google Play marketplace and should be of great concern for anyone with even a modicum of interest in their own privacy; it may well also breach the law in some counties.  Meta has suggested this is just a misunderstanding of those terms on their part, while Yandex hasn’t bothered to make any sort of response to Ars Technica’s inquiries.

The way the two companies break out of the sandbox is by constantly monitoring and sometimes sending traffic over certain ports which are open but not actively used when you browse to a website.  That allows the companies to determine which sites you are visiting and if you are signed into an app like Facebook or one of the many Yandex mobile apps, is able to send that data, along with a unique identifier to that app.  This completely defeats the protection that the Android sandbox offers, letting the companies track your every move on the web.  The researchers who discovered this behaviour also noticed the two companies are constantly working to improve their ability to escape the sandbox and you can get the details on the various ways they are doing so in this post.

The bypass—which Yandex began in 2017 and Meta started last September—allows the companies to pass cookies or other identifiers from Firefox and Chromium-based browsers to native Android apps for Facebook, Instagram, and various Yandex apps.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!