Everyone knows your location: tracking myself down through in-app ads

https://timsh.org/tracking-myself-down-through-in-app-ads/#privacy

How I tracked myself down using leaked location data in the in-app ads, and what I found along the way.

92 points · 12 comments · view on lemmy.world

12 Comments

adespoton@lemmy.ca · 26 pts · 309d (3 replies)

Am I the only person who doesn’t use apps with in-app ads?

Chais@sh.itjust.works · 6 pts · 309d

I avoid them if possible and block the ads if not.

Onomatopoeia@lemmy.cafe · 4 pts · 309d (1 reply)

Part of why I root is to block them using Ad-away.

Auli@lemmy.ca · 2 pts · 308d

I just block with custom DNS.

FauxLiving@lemmy.world · 18 pts · 309d

Great article. It should be noted that your web browser allows websites to do this with javascript.

Also, since this tracking isn't really trying to hide, people have compiled lists of the dns names of the destinations of these requests.

If you host a DNS server and you take that list and return NULL for everyone on the list. Then clients on your network who have ad tracking software will try to look up the destination to send your data and your DNS will tell them that there is nowhere to send the data and so the data isn't delivered. So, all of the smart TVs, game consoles, refrigerators, toasters and doorknobs which automatically send data but you cannot configure will fail because they use DNS also.

This sounds complicated to do, but I'm just describing Pi-hole (https://pi-hole.net/). It only takes a few minutes to setup the container and change your router's DHCP configuration in order to give out the address of the Pi-hole DNS server.

Assuming you're on Linux, which you are because you're a reader of a c/Privacy... right?

Tundra@sh.itjust.works · 9 pts · 309d

You can check an app for embedded trackers & get a list of permissions here:

https://reports.exodus-privacy.eu.org/en/

not_me@piefed.social · 4 pts · 309d (6 replies)
[ removed ]
DoctorPress@lemmy.zip · 10 pts · 309d (3 replies)
[ removed ]
girsaysdoom@sh.itjust.works · 3 pts · 309d

Google Play services likely does this too, so to actually protect yourself from this spyware you will need to use either microG or containerized Google Play services like how GrapheneOS has implemented.

not_me@piefed.social · 0 pts · 308d (1 reply)
[ removed ]
Auli@lemmy.ca · 1 pts · 308d

GrapheneOS is not magic.

PatrickYaa@feddit.org · 7 pts · 309d (1 reply)

Not everyone has a pixel.

FauxLiving@lemmy.world · 1 pts · 309d

Everyone will have a next phone though.

NanoooK@sh.itjust.works · 4 pts · 309d

Very interesting, but also scary.

Sunshine@lemmy.ca · 4 pts · 309d

Bad Android apps with ads: you’re the product mate.