Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is this not utterly illegal in the EU, per GDPR? (Which was drafted to stop indiscriminate data acquisition on human subjects: I'm assuming that metadata about the core libraries on your phone, in conjunction with FB's user metadata, are trivially de-anonymizable.)


In general, I don't think this is going to collect any more identifiable data than just logging the phone model and Android build ID would; under almost all circumstances every build should correspond to exactly one set of system libraries, and they could match across upgrades just as easily with just the build metadata. Generally, every phone of the same model sold by the same carrier in the same country will have the exact same Android build with the exact same system libraries.

The main benefit that Facebook likely get out of this is that it helps them debug crashes on devices they don't have themselves.


How does this provide any more data for fingerprinting than just checking the model of the phone?


My previous phone got an OS patch every few months. You would get most of this by reading the phone model and Android version, but there's probably a smidge more information in the library versions


Harder to spoof, less likely to be faked, plus additional meta information.


For starters, I'm not convinced it would be harder to spoof that than the library information (which also seems pretty easy to spoof if not easier).

But even if that were the case, why would they spend this level of engineering effort just to be able to fingerprint people in that extremely rare case of having a spoofed phone model? Do you think that kind of customer would even be receptive to targeted ads in the first place? It just doesn't make sense to me.


Tracking value increases with rarity. Data is packaged and sold, not simply stored and empty cells can go for crazy money if the target is hot enough.

How much would you pay for Elons verified personal number?


Under which provision would this be illegal though? It's the operating system image Facebook can get by just buying the exact same model of phone the user owns. I'm having trouble finding under which definition of GDPR managed personal data does this fall over.

The only angle I see is copyright infringement for copying libraries owned by the phone manufacturer... but even that I'm not sure if it's really illegal in this case. Worth filing a complaint anyway I guess.


I would assume system libraries don't count as personally identifiable data (after all, millions of people have those same libraries), so the gdpr doesn't apply.


It's not metadata, is IS the binaries.


I'm pretty sure you can fingerprint a device by gathering data about the binaries (and versions thereof) installed on it. I'm pretty sure that Facebook also know whose instance of the FB app is running on the device in question. Ergo, the data can be deanonymized and gives them more insights into what their users are doing … including, oh, competing platforms and apps?

The traditional model of computer security assumes that there's one device (the computer) which may have multiple users, so the emphasis is on identifying the user to the device. But today, one user may have one or more computers (smartphones/tablets/laptops), so the emphasis is on linking devices to users and thereby tracking usage patterns across devices. Which lands it straight in GDPR territory.


> I'm pretty sure you can fingerprint a device by gathering data about the binaries

Actually, probably not. These libraries are the base system image, which is read-only, and typically will only identify which model of phone it is. It might identify you if you have a custom android build you've done yourself though.


Shit, there are dozens of us. Dozens


No I meant they're outright uploading binaries, not just metadata.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: