Although completely believable and in-line knowing Meta/Facebook’s history, is there any evidence to support this claim? I’m sure it’s, unfortunately, just as easily deployed to specific targets so it may be hard to replicate, but this is pretty huge.
Anyone have any links/sources?
EDIT:
Found the source post: https://mastodon.social/@protonmail/111699323585240444
and the article: https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018
TL;DR: ProtonMail might want to delete this before they get sued by Meta for defamation, because the original research does not say that about Meta, it says it about TikTok.
–
I found the same sources, but if you’ll notice, the article that ProtonMail linked to actually isn’t about that. It’s about a different and new Facebook thing that has iffy privacy settings as well.
It links to another Gizmodo article about it, buried deep in ONE paragraph.
The problem? That article is about TikTok and the things detailed about the javascript injected that’s keylogging is all related to TikTok.
When you click on a link in the Facebook or Instagram apps, the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing.
This paragraph from the article links to this article in question:
https://gizmodo.com/tiktok-keylogging-privacy-meta-1849433690
This article references Meta a few times but is mostly about TikTok. Then THAT article links to the original blog post:
He has info on TikTok and Instagram, and while Instagram is injecting javascript into an internal browser instead of the default system browser, it is not noted as capturing text including passwords.
Capturing text and passwords is only ascribed by the security research to TikTok and TikTok alone. Meta companies are using similar Js injection tactics, but they, according to the original research, do not include keylogging.
That lines up with everything I’ve read about TikTok being the worst of the spyware social media apps. Unfortunately most online discussion about that subject gets filled with “Whatabout America spying?” posts trying to normalize the acceptance of everybody doing it. The discussions should be about how TikTok is the worst AND Facebook is close on their tails for the race of spying. All of the spyware social media apps are a bad thing.
I’m always thinking about Chinese intellegency agency thinking 10 years ago: “How can we create a spyware that everyone will use so we can collect all the data we want without too much troubles?”. Then they looked at Facebook doing the same for profit and they understood that all they have to do is to create a well designed social media app and make it so trendy that people will be diverted enough to not think about the spying issue. And then they fucking nailed it, it worked so well, I’m impressed. The average people do happily through away their private life for a shot of well crafted trendy entertainment everyday. All the revelations about spying didn’t stop the growth one bit.
Whatabout America spying?
nobody’s trying to normalize that. Just calling out the blatant hypocrisy. These social media companies started in US long ago and it has more data than you can possibly imagine, People suddenly mad when a foreign company starts doing something nefarious is on brand for people who want to point fingers at everyone else but themselves.
Facebook started when https was very rare, browsers sent login authentication in plain text, internet explorer was still popular and they probably exploited way more vulnerabilities that Tiktok ever did. Facebook, Google, Twitter tracked users through share buttons on websites. Everyone installed multiple Internet explorer addons with nefarious permissions, malicious code without a single thought. Their owners are billionaires now, exploiting, tracking and selling your data to whoever pays best. It was all common knowledge.
Where were these concerns for a decade before tiktok even was a thought. If social media companies were held responsible for privacy of the users, when Facebook, twitter were gaining hold, Tiktok wouldn’t even be able to follow on their footsteps.
I don’t use Facebook anymore and never have used tiktok, but fuck all concern trolling once someone other takes your cake. You reap what you sow.
Stay mad tho
You make a good point worth considering. For all non-USians/non-Chinese out there, all those social media giants are foreign corporations belonging to foreign powers.
The spying part of it is bad for the spying, not for who’s doing it.
What the fuck are you talking about “Stay mad tho” ? It sounds like you agreed with what I said mostly. This shit is all bad, and that was my point.
Whatabout America spying?
nobody’s trying to normalize that
Objectively false, seeing how Snowden lives in Russia, Assange is actively drugged and tortured, and Chelsea Manning was brainwashed/threatened and became an active NATO spokesperson (and a DJ, but that is just for optics).
The privacy invasion by Western governments and corporations is astronomically normalised amongst the masses, and anyone who does not participate in the digital data rape rituals is a weirdo heretic.
They might not sue to avoid bringing more attention to it.
It might be better to archive.is and archive.org it.
I dug up this mastodon post and they cited this:
https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018
I agree. Multiple apps bind to the keypress event to inject functionality. Binding to such event does not automatically imply nefarious intent.
Yes, JavaScript injection tests come back with extra code when opened from within instagram.
Some people in this thread are claiming the article doesn’t mention Facebook.
I actually read the article. You’re welcome.
When you click on a link in the Facebook or Instagram apps, the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing.
Edit: The article Proton got their info from.
Kraus makes very clear that while Meta apps are also injecting javascript, that he only has evidence of TikTok doing “keylogging” type activities. Both Gizmodo and ProtonMail are wrong in that regard.
It’s like nobody has real media literacy anymore, even media organizations.
But I want to outrage at sensationalized headlines and tweets :( How can I do that if I actually read the articles?
It’s weird how ardently you defend Facebook. This post and one earlier where you insinuated Proton Mail is liable for libel is something a Meta employee would say to dissuade this kind of thinking. But the fact is the researcher, Kraus, confirmed that the logging script is present. Meta maliciously spies.
I just went looking for what you were talking about cause I was curious to know more, and from what I can tell, saying “Kraus confirmed the logging script is present” is a bit misleading- it implies that the logging script that logs keystrokes is present. Its possible I missed something but from what I could find, it looks like what he confirmed is that meta tracks interaction with the elements of pages, like selecting a text box, tapping/clicking on buttons, etc., but I didn’t see anything about keylogging. Thats still super creepy, and is obviously bad, but it doesn’t seem like the person you’re responding to is wrong to say that the findings of the security researcher have been misinterpreted here. And you’re not wrong that they’re absolutely maliciously spying (of course they are, maliciously spying, contributing to genocide in developing countries, and negatively manipulating peoples mental health for profit are meta’s bread and butter! 😀) but I do think it pays to be accurate when we criticize things, and to not mislead people.
But if we wanna criticize meta, may I interest you in: facilitating a horrifying genocide resulting in massive loss of life in Myanmar?
https://erinkissane.com/meta-in-myanmar-full-series
Edit: clarified a point, also added the link cause I needed to go find it
While they log a lot of things like all clicks made on the site and what elements you focus on, there was no keylogger script found in metas apps as of now.
Don’t get me wrong, that’s still a shitty thing to do, but it’s nowhere on the same level as a keylogger that even reads your passwords. If Meta wants to this can easily end in a defamation case against proton.
Don’t let your bias against Meta overcome critical thinking skills.
As others have mentioned this is just incorrect. I’m no fan of Meta but you are a moron if you think this is happening.
You’re a moron if you think only Meta is doing this. Teams on Windows is a keystroke logger and has been since launch. It records even mouse movements by microseconds in a plain txt file.
If you are using a mobile app, it’s a pretty good bet it’s logging every input.
Agreed, and who ever that still uses Facebook in 2024 really needs to get out and meet real ppl and get a life.
Fuck 500 virtual friends. I’ll trade that in a second for 1 real true friend IRL.
but then, you’d have to.
Maybe not keylogging but it’s pretty fucking bad still, it tracks basically everything else about how you navigate when using the integrated browser.
Given this is the top comment it should be pointed out that while Proton was incorrect about this being Meta there is research out about TikTok doing this very thing.
The way you’ve worded your comment makes it seem like this either can’t happen or isn’t happening and that simply isn’t the case.
I personally do not think I should care about the xenophobic witch hunting of Chinese companies like TikTok and Huawei, even though US feds have never presented any evidence against Huawei, and we know how fair the Congressional hearings were for TikTok.
While TikTok collects basic data, it never forces you to login other than for commenting (for obvious reasons) and similarly personal things, unlike Instagram. If you open an IG link in web browser, you cannot replay the video second time, and if you scroll the account’s posted images and videos, you will not be able to flick through a second time. And it is fair enough to see Western governments’ beloved support for the genocide of Palestinians (unlike the fake Uyghur narrative) and the ousting of Muslims from top positions across all of Western media, there exist open and transparent political and critical reasons to avoid Western media over non-Western media.
TikTok’s data collection is transparently compared to other social media outlets here (not going to trust fancy tech outlets or CNN/Fox). Tiktok is not even in the ballpark, simply by not needing an account or app to use it.
https://clario.co/blog/which-company-uses-most-data/
https://www.truepeoplesearch.com/insights/info-tech-companies-collecting-from-you
Edit: Edit: fuck you GrapheneOS, for almost 2 months now, they are mass downvoting my comments, and doing voting manipulation, also abusing federation
All this to say you’re fine with TikTok grabbing your passwords? Because you don’t want to be xenophobic? Weird line but you do you.
Can you tell me how TikTok is grabbing your passwords without an account, and outside of their app or website? I need an account for Facebook/Instagram, not TikTok.
Do you understand the difference between needing an account versus not needing one for a service? It is wider than the Grand Canyon. That is why I provided those links, and that is why it is critical to note the lack of personal identifier data grabbing with not needing an account. With one, you give phone number, contact book, IMEI, location data, email, some name or pseudonym et al. With the other, none.
Edit: since you have poked the bear, I will growl.
Facebook/Instagram data collection on a user is more than a TikTok user, even if there is an account on both services. On top of this, TikTok does not have tracking pixels, ad networks, CDN and other methods of tracking on other websites, unlike Facebook ecosystem. This allows Facebook ecosystem to correlate, interlink and form data clusters on users and IP addresses. Remember how Facebook ecosystem disallows accountless access? Or how they C&D’d Barinsta developer Austin Huang, citing they dislike anonymous access to Instagram?
This is precisely what makes TikTok objectively so harmless without an account, and even with an account, relatively far less harmful. It does not mean TikTok does not collect data, but the difference is too wide. These are the facts.
And your petty downvote makes it seem like this is too much to swallow.
Tiktok is Chinese spyware.
Facebook is American spyware.
Stop using them!
End of story.
When you grow older, you start to see 2+2 is always not 4. It can be 3 or 5 too.
I’ll bet I’m older than you.
Its pretty obvious isn’t it?
Holy shit, that should be illegal. I say should because I know there’s no way that it currently is.
Microsoft do the same with Windows and as far as I know, they haven’t got fined for it.
Do you have a source for that or you just making it up?
Its supposedly to learn typing habits. Heres how you turn it off.
It’s pretty hard to prove what anyone is doing with closed source code.
deleted by creator
Could be batched, could be encrypted, could be bundled with other data etc etc
Decompilers: Are we a joke to you?
I’d still agree with his statement. Subset of people who could even make the determination in available source code is small compared to total users, now reduce that set to people competent in reverse engineering. “pretty hard” is not a bad description imo
Multiple. I understand that many of you won’t believe or just don’t know about Microsoft’s spying, but that’s the reality. It can happen that I can have wrong with certain things (I’m only human, remember that), but Microsoft spying on you is the fact of why I now using Linux as my main operating system since 2015/2016.
- Disable Keylogger in Windows 11 to Stop Microsoft from Collecting Your Data
- Where does Windows 10 save Keyboard input?
- Windows 11 Keylogger: How to Detect & Disable it
- From a ex-employee at Microsoft: You won’t believe what happens when I turn off Windows 10 telemetry! - @Barnacules
- Microsoft’s own privacy policy page (hit “Learn more” under “Personal data we collect” and scroll down to the bullet list for “Interactions”)
There is a lot more proof out there, but I can’t think straight to be able to find them. So if you want to dig some more, by all means, do it.
To this day I don’t know what or why Google Chrome was using up all the processing power on my laptop while it was installed. As soon as I deleted Chrome, my 12gb laptop ran fine again.
It probably wasn’t keylogging but it was probably not updating itself 24/7 either.
It probably wasn’t keylogging but it was probably not updating itself 24/7 either.
You’d be surprised at how shit Chrome’s autoupdate is.
There’s also no way that it’s happening. You can’t key log with JavaScript. There’s something called cross domain policies or xDomainPolicy which prevent certain types of code being run on one website by a different website.
Cross domain policies are enforced by the browser. If you’re using a third party app, guess what you’re using as a browser.
Want an easy example of this? Userscrips on Firefox. Install GreaseMonkey, and you can run whatever the hell you want on any webpage. Keylogging, mouse movements, clicks and navigations. Not hard, and impossible to really stop from the site itself, because no matter what you tell the browser to do, you essentially have to just hope the browser follows through.
If you’re using a third party app, guess what you’re using as a browser.
Yes if you are inside Facebook and while inside Facebook click a link to go somewhere else you are still in Facebook and they will keylog everything.
This is presented as if Facebook/Toktok can keylog everything.
“Don’t use in-app web browsers”
Somebody else is already pointed out that it’s already been debunked so no it wasn’t happening
And somebody else pointed out that that was debunked so yes it’s happening
Edit: the point I’m hopefully making is that you’re just kinda saying stuff and not even bothering to post a source.
I was responding to your claim of “not happening, impossible” with proof of it being possible, and actually fairly easy to implement.
But it’s not another website, it would be the web browser within the Facebook app, which could absolutely do that.
Except this is already being debunked see above
Except that this this has been debunked see below
Edit: the point I’m hopefully making is that you’re just kinda saying stuff and not even bothering to post a source.
My main goal on year 2018 was delete facebook. Unfortunately im still using whatsapp just because everyone uses it and i have no other place to talk with my friends and family.
I think (do correct if wrong!) the EU has approved an interoperability law for big tech companies? So it should be just a matter of time until you can switch messaging app and still be able to communicate with people on wa and big messaging apps
Ofc if all your friends all use whatsapp zuck will still be able to read all your messages and get your phone number via your contacts… so it’s only a partial solution. Still better than nothing tho.
Signal, bro.
Not popular enough. With Whatsapp you get to talk to pretty much everyone, from businesses to second hand sellers to your weird aunt that lives in the middle of the woods.
No one is important enough to justify using WhatsApp
Not everyone can live as a hermit to fulfil their Zucc-hate boner. Some of us have lives.
Then install signal and tell them you’re on there. Clearly you’re important enough for people to use signal, since you have a life
Riiight, because the corner shop will start using signal just for you…
SMS is still a thing. You need to put your foot down to make it happen.
Edit: May the Monty Python foot squish all downvoters into elderberry jam!
Nobody uses SMS in my country.
It still works though doesn’t it?
deleted by creator
But it comes with significant social drawbacks. I’m not sure if that’s really a hill worth dying on.
Is it worth having your credentials sold or stolen cuz people might think less of how they receive the same message in text form from you?
SMS is unencrypted
You say that as if WhatsApp is actually secure, as if Facebook haven’t filled it with backdoors. As if it wasn’t the vector for zero click access to Android phones in Pegasus. SMS could not do that (although iMessages did).
Holy shit, if you’re being targeted by nation states or other seriously motivated actors with Pegasus level spyware then they will get you. For everyone else, encrypted platforms like Signal or, yes, WhatsApp, are more secure than fucking SMS.
Facebook keylogs anything, even outside of FB in all pages with FB APIs (any page with an FB share button), if you don’t block it with an half a dozen extensions and scripts. For Example with
The source article from a security researcher Felix Krause:
If you’re still using the Facebook app in 2024 you deserve everything you get.
dont blame the victim.
Also, lots of sites embed the Meta Pixel. So to avoid it, you have to go into your cookie settings and block all of Meta’s domains and hope you don’t miss one. The internet was supposed to be a platform for all, by all…yet corporations have found a way to ruin the entire place.
Are you a victim when you walk into the BDSM club, sign the waivers, call safe words a conspiracy, and cry rape afterwards?
Edit: How about if you go back in after that?
There is information available to make an informed choice, but they don’t. Is there really no guilt?
This is my shocked Pikachu face. Jokes on them, I haven’t used Facebook since I deleted it with prejudice in 2007.
‘foresight’ is a gift provided to some folks who conceive things a little outside the norm, i suppose.
I use all social media in browser to give them less access to my device. I clear cache / cookies after use every time. Hopefully that gives them far less personal data.
If you’re an android user you might be very interested in the “Hermit” browser
https://play.google.com/store/apps/details?id=com.chimbori.hermitcrab
When I was using Facebook I used one of the third party apps - they’re basically a web browser that only browses Facebook, thereby isolating Facebook from any other internet traffic.
So they’re just actually pushing malware now?
Always has been.
The Facebook mobile webapp works just fine nowadays. Pretty sure it’s even possible to enable notifications in most web browsers. I still don’t get why people are willfully installing apps instead of just pinning web browser bookmarks.
No educational programs for smart phones?
I also only use the fb mobile web app, but for years they regularly break things, I assume it’s on purpose to get people to install their shady app
This is especially nefarious paired with their other practices. Many phones stock ROMs also ship with preinstalled bloatware including TikTok and Facebook crap.
I had to use Android developer tools (ADB powershell commands) to remove multiple facebook and tiktok packages from a friends new phone because they can’t be removed any other way. There was no “user visible” FB app but several packages were present and makes me think FB crap may run as “background” by default on several vendors stock ROMs. Irritating and deceiving to the consumer.
I also blacklist all their domains using PiHole so nothing on my home network can covertly back channel any data to their mothership. (Currently using Developer Dan’s lists from GitHub - the Facebook list alone has almost 30,000 hosts on it)
These big tech surveillance bros can get clapped.
Laughs in GrapheneOS
Yeah that’s what I daily drive. It is nice knowing there isn’t a bunch of bundled spyware on your device.
That’s why I set up 2FA on whatever account I can grab my hand on. It sucks that I cannot do it on every single one I have (e.g. some popular names like Spotify, last.fm, Bandcamp or Feedly do not support it, for example), but for every account that I do have, 2FA has become critical lately.
Does Google also do this with their in-app browser in their search app?
Just block off *.facebook.com in uBlock Origin rules on Firefox (not possible on Chrome) or in system HOSTS ruleset. Leave out the fbcdn.net domain as it only acts as a CDN for videos and images.
Edit: fuck you GrapheneOS, for almost 2 months now, they are mass downvoting my comments, and doing voting manipulation, also abusing federation
I’m curious, what does that have to do with GrapheneOS?
See https://lemmy.ml/comment/7103845
You can see my comment history for the past month and a half with consistent 4-7 downvotes, if you ignore 4-5 comments people generally hated.
You know, instance admins can find out who is downvoting and upvoting by checking the database. It doesn’t have to be a mystery if you stand up your own instance. You don’t even have to use it primarily, just get it federating your comments.
Self-hosting is a pain in the ass, and I do not have the time and dedication for it, as someone who has 100 other things in life. I am no longer even a terminally online person, I just come here to check on the state of Lemmy, put on some helpful comments, moderate privacy and technology communities, and go back to real world after dedicating 15-30 minutes a day to Lemmy.
netseer-ipaddr-assoc.xy.fbcdn.net looks to be tracking.
I see, they have started pulling this shit. Probably a good idea to disable third party scripts with uBlock Origin’s medium mode. Atleast that way they will not be able to run their malware JS.
I use hard mode generally, but that sounds like a good reason for people using uBO easy mode to level up.
This is about the web browser within Meta apps, uBlock on another browser won’t help.
Then the HOSTS ruleset will work. You can use NetGuard or Invizible Pro with your custom HOSTS ruleset on Android, and on laptop/desktop, it is easy no matter if you use Linux, Windows, MacOS, BSD or other OSes. No option for iPhones and iPads.