Facebook still ‘secretly’ tracks your iPhone

by nwotnagromon 5/23/2021, 6:37 AMwith 256 comments

by phhon 5/23/2021, 8:30 AM

For once I'm surprised. Android has been stripping location from Exif when the app don't have location permission for more than a year now: https://developer.android.com/training/data-storage/shared/m...

by jefftkon 5/23/2021, 11:51 AM

This is an OS privacy bug, and isn't specific to Facebook. If an app does not have location permissions, it should not receive the geolocation portion of photos' EXIF metadata.

by motohagiographyon 5/23/2021, 2:32 PM

Beginning to think the reason security is so difficult is because ostensibly "good" companies do everything an attacker does and worse, but under the guise of EULAs.

Here's a thought experiement: If Facebook were malware, could you get rid of it?

by toddmoreyon 5/23/2021, 9:38 AM

Geez, even the author of this piece is "Founder/CEO of Digital Barriers, which develops advanced surveillance technologies for frontline security and defence agencies as well as commercial organizations in the US, Europe and Asia. The company is at the forefront of AI-based surveillance."

by h0ndon 5/23/2021, 12:50 PM

i use jailbreak to control my location better - i can more easily de/activate it and spoof my location.

Now, I noticed a weird behaviour. I am not sure if its a 'bug' due to jailbreak, or if it shows how apps can access location.

The setup is as follows: location services are completely deactivated system-wide. a spoof location is set.

This means, I am not able in any way to access/share my location, neither the real nor the spoofed one.

However, when someone shares a location with me, upon displaying it on a map, instead of the location shared the spoofed one will be displayed along the correct address of the shared location.

ok, i dont know how iOS manages location services. still it is not nice at all to see that somehow an app can access a location, even if its spoofed and by error.

regarding the article: you can tell your phone not to give fb any location data. but why would you take a picture with location data and upload it to facebook? its so obvious and straight-forward that the user simply undermines his own privacy.

by saoson 5/23/2021, 7:24 AM

Or just delete Facebook apps.

by freebujuon 5/23/2021, 8:24 AM

Yeah. This is not particularly a Facebook problem. And it certainly is not an iPhone exclusive one. I would be willing to bet my 2¢ that Apple photo backups store your photos with exif data. Should be trivially easy to strip this info and "track" you as well. Am not seeing anyone crying over this.

by spideymanson 5/23/2021, 4:50 PM

>“Facebook marketing is generally dominated by iOS,” one ad industry article laments, “it’s pretty safe to assume Facebook has lost at least half their data, arguably the most valuable half.”

That's surprising. Facebook has a global reach and can run on damn near anything with a screen. I'm surprised iOS makes up such disproportionate part of its revenue.

by mrunseenon 5/23/2021, 7:44 AM

A user can disable geo-tagging or the better(?) disable precise location in Settings.app > Privacy > Camera.

Like mentioned in the article, there a lot of EXIF strips in Appstore too but I’m not sure if a regular user would take the road of take photo > go to exif stripper > delete exif on photo > save the photo > go to facebook > upload to facebook

by andylynchon 5/23/2021, 10:40 AM

If you’re concerned about this, you can stop Facebook getting this data by sharing from the Photos app. It gives you the option to strip EXIF data in the share sheet.

by jack_rimintonon 5/23/2021, 9:54 AM

With all of the complexity of tracking technology, protocols and data laws I'm wondering whether these findings are also revelations to FB.

I'm not shilling for them but just wondering whether some of these results are a direct consequence of the nature of the systems rather than nefarious design

by thomon 5/23/2021, 7:51 AM

I wouldn’t know, still busy trying to fill out your cookie consent form.

by bobinyon 5/23/2021, 7:49 AM

A picture with messengers comparison is wrong: Telegram has 7 positions in Data Linked to You, not 3.

edit: grammar

by gigatexalon 5/23/2021, 8:32 AM

Forbes’s cookie pop up is ridiculous. They list all the ads trackers and it requires seemingly infinite scrolling.

I am fortunate to have been able to delete Facebook and Instagram from my phone but being in Europe I have to use WhatsApp.

by rdiddlyon 5/23/2021, 5:46 PM

I'll save you a lot of reading: They still read photo geotags.

by imgabeon 5/23/2021, 10:57 AM

Why on Earth would you install the Facebook app on your phone?

by intricatedetailon 5/23/2021, 9:13 AM

Why any privacy compromising options are not opt in by default? It should be a law if companies can't be bothered.

by villgaxon 5/23/2021, 3:06 PM

It'd be a joke if people really think Facebook doesn't tag you at an IP address level either.

by dw-im-hereon 5/23/2021, 7:41 AM

"""secretly"""

by apion 5/23/2021, 2:01 PM

Not if you don’t install any of their apps. I use it as a web site which is enough to post pics of kids for relatives, pretty much my only use for it.

by KaiserProon 5/23/2021, 7:22 AM

TL;DR: facebook stores exif data. however it strips it out for display to the public. This includes geodata. Its unclear what they do with it after, and how you have control over it.

Interesting nugget: the author repeats the lies that apple doesn't collect/store/index your data.

I think the scepticism of facebook is a good thing, however I really wish it would be applied equally to every big company. Especially when they so clearly abuse privacy like Apple and Google.

by forgingaheadon 5/23/2021, 10:07 AM

This is a clickbait article - the issue is not with Facebook, but with Apple iPhones where this data is stored as part of the image EXIF information.