Washington Post's Privacy Tip: Stop Using Chrome, Delete Meta Apps (and Yandex)

(tech.slashdot.org)

Comments

capyba 8 June 2025
I don’t know anyone that works at Meta, so I’m hoping that someone here could answer this for me-

What makes employees there feel good (or at least okay) about doing stuff like this? You're spying on people, no? Surveilling ordinary people, not enemy combatants or foreign militaries? Perhaps a friend of a friend or even a family member? This kind of thing is so creepy and disturbing to me, not that it’s anything new…

xnx 7 June 2025
Without the suggestion to install an adblocker, this is not credible advice.
xnx 7 June 2025
aucisson_masque 7 June 2025
What about the other app ? Now that this trick is known, either it’s completely fixed, including in system webview, or all the other usual spyware ,that the play store is full of, are going to use it to track their user.

Google still hasn’t fixed the issue of app being able to list all other installed app on your phone without requiring permission despite having been reported months ago. They didn’t even provide an answer.

I believe Google isn’t interested in Android user privacy in any way, even when it’s to their own benefit.

At this point either use iPhone, grapheneos or no phone at all.

klipklop 8 June 2025
Always funny how nearly universally Meta employees are quiet and never defend their companies practices..

The silence says a lot.

ajsnigrutin 7 June 2025
For most people in the west, using yandex and chinese alternatives would be better than local ones, because neither china nor russia has any auhority over you, while your local agencies do.
miohtama 8 June 2025
EMM_386 8 June 2025
If any software engineers out there are working on things like this I can only pray they STOP and think about why what they are doing. Implementing features by having to jump through hoops, just so that their employer can better spy on people and make more money.

That is so wrong, on so many levels ... I personally couldn't do it.

I hate this even more than NSO Group's Pegasys, which could easily get people killed. I'm ok with my reasoning, and I really hate that one as well.

Here, with Meta and Yandex, you see what you always see.

As soon as people catch on, they immediately remove it. But they will keep using it until that day comes.

For money, while trying to hide it from the users they are spying on.

It's greedy and evil and whoever in these companies think up these ideas should be let go. Immediately, in a perfect world.

Instead they'll just try another approach.

While everyone else has to clean up this latest one.

"Following public disclosure, Meta ceased using this method on June 3, 2025. Browser vendors like Chrome, Brave, Firefox, and DuckDuckGo have implemented or are developing mitigations, but a full resolution may require OS-level changes and stricter enforcement of platform policies to prevent further abuse."

m-localhost 7 June 2025
Zen Browser (FF) on Win and Firefox on iOS (for sync) works well for me. Edge for all M365 related stuff. Still use Chrome for web dev. Not sure what to move on in that regard...
JKCalhoun 8 June 2025
I like the succinctness of it. Reminded me of "Eat food, not too much, mostly plants" as Michael Pollan says about dieting.
sershe 10 June 2025
What I wonder is (from someone who has been in a room like that, not speculation), how do these decisions go down?

My other favorite example is un-disabling telemetry, resetting default browser, etc. Some PM or VP is in a meeting saying we are going to do this shady user hostile thing and everyone just nods? What is the amount and type of euphemisation?

I'd love to be a fly on the wall in one of these..

thadk 7 June 2025
Anyone have tips on how to avoid having the WhatsApp app on your phone?
meroes 7 June 2025
Hmm how can I use being forced to use Chrome for work, for me tax wise…

If I’m a contractor forced to use Chrome and mobile devices, can I deduct a separate work phone?

I really hate having it my iPhone, at least maybe I can claw something back this way?

jhbadger 7 June 2025
And stop using Alexa (of course Bezos' paper wouldn't say that!)
1vuio0pswjnm7 8 June 2025
keernan 7 June 2025
If we truly lived in a democracy which 'obeyed' the overwhelming will of the people, there would be laws with 'horrific' penalties for any effort to track devices or people online.
p0w3n3d 7 June 2025
I've noticed that recent Chrome version does not allow me to download the pdf I'm viewing. I had to open it in Firefox. The Chrome browser only allowed me to save it to drive (cloud)
ThinkBeat 7 June 2025
I dont yet understand this attack.

The WP article says:

"" Millions of websites contain a string of computer code from Meta that compiles your web activity. It might capture the income you report to the government, your application for a student loan and your online shopping. ""

If I read that correctly then they are capturing all https web content you access in clear text and uploads it all to Meta? Then Meta

I thought the exploit was used to track where you visited, not the full data of each webpage.

jgalt212 8 June 2025
> Know, too, that even if you don't have Meta apps on your phone, and even if you don't use Facebook or Instagram at all, Meta might still harvest information on your activity across the web.

A bit wishy washy. They are still tracking you, just not as effectively as before.

leereeves 7 June 2025
I hope people can get a "Stop Using Chrome" movement going, like we did with Internet Explorer long ago.
helph67 7 June 2025
Thirty months old but I'm guessing they haven't improved! https://www.techradar.com/news/nearly-half-of-all-online-tra...
ck2 7 June 2025
jeffbee 7 June 2025
It's sort of interesting that Brave was not affected by this because they already blocked the technique used by the Yandex app. I wonder if Brave devs were aware of that specific abuse, or if they just thought that localhost traffic was distasteful categorically.
egberts1 10 June 2025
All boils down to Chrome leveraging localhost for its location.
DidYaWipe 8 June 2025
Never used Chrome, and don't use Meta apps... and when I did, I did not give them any real information.

I'm disgusted by the number of people giving real personal information to these assholes. "Open"AI insisted that you give them a real, functioning phone number to use ChatGPT. No goddamned way.

gsky 8 June 2025
Gmail should be at the top of the list
dlachausse 7 June 2025
Safari reports that it blocked 16 trackers on WaPos home page. So it’s probably best to avoid them for privacy too.
cuncurrenzio 8 June 2025
There is a data pipe directly into the PNNL from Meta. Do your research!
righthand 8 June 2025
WaPo’s reputation so tarnished they have other outlets reporting for them? I don’t understand why a slashdot article has WaPo in the headline. Are they some authority on privacy?
cuncurren6zio 8 June 2025
There is a data pipe directly into the PNNL from Meta. Do your research!
TiredOfLife 7 June 2025
Washington Post also called Ukraines attack on russian bombers "dirty"
bn-l 7 June 2025
What is the alternative to chrome that doesn’t crash or is not noticeably slower?
NHQ 7 June 2025
Web browsers should become outmoded soon. It was fine for bootstrapping the web, but now to keep up a browser must emulate the operating system and more in a single app. This pressure is the centralizing factor in browser dominance. Ditch the features, drop the spy protocol (http), just get the files.
HocusLocus 8 June 2025
It's CREEPY to imagine the Internet is under a mandate to protect your privacy. Don't be CREEPY.

The EU cookie fiasco is just that. All of a sudden, your every day experience was derailed extremely in a way that 'broke' HTML standards and sites at first in hundreds of ways. All of a sudden sites that never did track users were forced to start tracking them -- in order to set the flag to suppress the harassing cookie warning. Ironically, they will remember your cookie settings if you 'sign up'. Meanwhile nothing became more secure or private. It was just a way for the EU to virtue signal out loud and be annoying. It throws the user into sitespace to navigate the site's own cookie settings. It's theater.

Meanwhile, advanced fingerprinting is, well uhm, advanced. If the EU cared about cookie privacy a better course of action would have been to see whether browsers were locked down with best anti-fingerprinting possible and local cookie dialogues... and certify the ones that were. Educate users, harass them one time.