8 ms·
A particularly bad instance of link tracking I've found is in TikTok's link sharing feature. If you share a link from the TikTok app, it gives you a vm.tiktok.
by jacobajit 5y ago
A particularly bad instance of link tracking I've found is in TikTok's link sharing feature.
If you share a link from the TikTok app, it gives you a vm.tiktok.com/[xyz] link to send/post elsewhere. It gives you no indication that this isn't a generic link to the post, nor does it give you an option to expose the generic link to the post.
Instead, when you share that link and someone clicks on it and does not have the app, it opens with a header saying "[First Last] is on TikTok." On the other hand, once you do click on that link (if and only if you don't have the app installed), you get redirected to the static link to the video and finally obtain it.
This is an anti-pattern that enables further tracking and potentially unknowingly exposes user data when links are shared publicly. And there's no indication to the user that this is happening, since the link is structured as if it does not contain any tracking. Ie a tool like this wouldn't be able to "strip out" the tracking since it isn't tacked on in any way, but embedded as the generated link itself.
- fossuser 5y agoThat’s pretty bad. I think TikTok’s risks are higher than people think. It’s better to avoid it. https://stratechery.com/2020/the-tiktok-war/ https://stratechery.com/2020/the-tiktok-war/ Any company running out of mainland China is going to have serious privacy problems due to CCP influence and their need to comply with both local laws and the government’s interest in influencing public sentiment.
- calvinmorrison 5y agoAny company running out of mainland USA is going to have serious privacy problems due to USA influence and their need to comply with both local laws and the government’s interest in influencing public sentiment.
- fossuser 5y agoWhataboutism style arguments (which are always the knee-jerk reactions that show up) are wrong. I wrote about this at length here: https://zalberico.com/essay/2020/06/13/zoom-in-china.html https://zalberico.com/essay/2020/06/13/zoom-in-china.html and won’t rehash it again in the comments.
- imiric 5y agoIt's really frustrating how often whataboutism is used whenever China is criticized, particularly towards the US. Yes, we know other countries have similar issues, but we can't excuse the blatant wrongdoings of the CCP by pointing the finger elsewhere. It often feels like the work of bots or government shills anytime it happens, but good luck getting to the bottom of that.
- brabel 5y agoWhy is it frustrating when others point out that the most popular services, which are usually from the USA, also have the same kind of problem of being under the influence of the respective government, but nobody seems to be as worried about it? The criticism almost always comes up whenever a service provided by a Chinese company is mentioned in any context. China has shown no interest that I know of in spying on non-Chinese citizens, so I feel like it's probably less problematic to use a chinese service than an American one if your only worry is that someone is spying on you, specially considering how there's plenty of evidence of the USA spying on the whole bloody planet, including heads of state of allied countries, for f'sake... >It often feels like the work of bots or government shills Do you think I'm a bot because I disagree with you? Maybe you are the bot... how can we verify you're not? :D good luck getting to the bottom of that.
- shard 5y ago> China has shown no interest that I know of in spying on non-Chinese citizens I believe China has kept tabs on 2 groups of non-Chinese citizens: 1. foreign nationals within China borders, and 2. foreign nationals who are ethnically Chinese.
- deleted 5y ago[deleted]
- imiric 5y agoIt's frustrating because it's not the topic of conversation, and it only serves to derail it as we're doing now. If we're discussing the high cost of apples and someone brings up oranges, it doesn't change the fact that apples are expensive. > Do you think I'm a bot because I disagree with you? No, but a lazy comment doing s/China/USA/ certainly reads like it. And if you've seen some of the threads on Reddit or Twitter it becomes pretty clear some accounts search for any negative discussion about China and interject with whataboutism, which would be pretty easy to automate.
- ebruchez 5y agoIf you think the two are actually comparable in degree, you are seriously misled.
- wongarsu 5y agoYes, if you care about privacy both the large Chinese services and the large American services are bad. If you use Facebook or Instagram assume that the NSA has all your data, and that someone might try to manipulate you. If you use TikTok assume that China has all your data, and someone might try to manipulate you. You either choose your poison, or you stay on services that aren't in the limelight
- lurkerasdfh8 5y agoNot sure why you think those are exclusive. All companies mentioned have offices and comply with law on both regions.
- fossuser 5y agoOne big difference is in the US the companies are not required to manipulate content to serve USG interests. TikTok may downrank or censor HongKong videos because the government forces them to - the same does not happen at American companies. I think the 'assume they have all of your data' is paranoid (particularly for encrypted stuff like whatsapp), but people should probably more careful about this kind of thing than they are anyway. The US has laws and rules around access, you may not agree with them - but they are far and away better than the CCP's approach. The CCP is running concentration camps for a minority population of their own citizens, invading and taking over neighboring countries (HK with an eye towards Taiwan), and censoring pooh bear from the internet because of a light hearted comparison to Xi. The police call foreign students in the US to threaten them over their internet activity: https://www.vice.com/en/article/jgxdv7/chinese-police-are-video-calling-citizens-abroad-with-threats-not-to-criticize-beijing https://www.vice.com/en/article/jgxdv7/chinese-police-are-vi... The comparisons are not valid.
- leephillips 5y agoYou're right about Chinese government behavior. But “the same does not happen at American companies.” --- no, but they censor the internet in obedience to Pakistani demands.
- 5y ago
- madeofpalk 5y agoAs a non-american, we don't really have a choice of using a "native" social network that only has interference from our own government.
- fossuser 5y agoThat doesn’t make the two equivalent. Also, hopefully soon you will: https://urbit.org/ https://urbit.org/
- earthboundkid 5y agoLOL, if you don't like a social network run by communists or capitalists, try the one run by don't-call-them-fascists.
- bb010g 5y agoDigital land ownership! Just what the internet desperately needed. /s
- fossuser 5y agoThese knee-jerk responses are lame. - IDs stop the spam problem and give people control over something that keeps its reputation (and they're cheap). - Federated systems normally suck because administering the servers and keeping decentralized versions in sync is hard. Urbit's design fixes this. - Encrypted by default, ability to be as easy to run as FB (eventually, not right now). Peer to peer with the address space and key issues solved from first principles. - Stability over long time horizons due to design (goal being indefinite), the urbit abstraction layer doesn't change and state can always be recomputed - changing pieces are implemented via jets to communicate with whatever underlying OS is doing the normal stuff. It's a clever design and solves a lot of problems with modern computing, people often dismiss it out of hand because Yarvin's politics are stupid (he's no longer involved in the project and hasn't been for some time). Peter Thiel's Trump support was stupid too, but that doesn't mean he doesn't get a lot of other stuff right. https://urbit.org/blog/the-understanding-urbit-podcast/ https://urbit.org/blog/the-understanding-urbit-podcast/
- jtbayly 5y agoBut this can be solved, too, can’t it? It’s effectively a Bitly link. Just need to auto-expand to the final destination, right?
- black_puppydog 5y agoPiece of cake. I'm sure there's an app for that, which incidentally needs access to your location data... /s
- jtbayly 5y agoClearURLs is being discussed. It changes the URL you are visiting to remove tracking info. There are preexisting plugins that do the same thing with shortened URLs—unmasking them and thus untrackifying them. So mock and downvote all you want. I don't see why ClearURLs couldn't add this functionality. Edit: Or am I just being downvoted by people who don't want anybody to know that it's possible to stop this form of tracking?
- ronjouch 5y agoI fail to understand how you'd "unmask" a backend-obfuscated URL (where you just have an ID, and there's no way to get the target URL by just looking at the URL) without opening the URL, defeating the purpose of improving privacy we're discussing here. Or maybe you and OP don't care about the privacy part of the problem, and you just want to automate getting the "canonical" / "non-personal" one from the "masked" one?
- userbinator 5y agoWith websites, at least you can just copy the URL from the address bar and clean it. Of course, people are being slowly dumbed down by browser's (mostly Chrome, but Firefox seems to follow its stupid trends not long afterwards) attempts at removing or hiding the URL, which is no surprise when you realise that herding the userbase to use dedicated "share" buttons (complete with tracking) is one of the reasons they're doing that.
- DangerousPie 5y agoWhat's to stop a website to do the same thing with the URLs in your address bar?
- ryankrage77 5y agoThey absolutely do that, but when you copy-paste them to share elsewhere, you can manually strip all the tracking info out. For example, when I search Google for 'Hacker News', the URL I arrive at is "https://www.google.com/search?client=firefox-b-d&q=hacker+news https://www.google.com/search?client=firefox-b-d&q=hacker+ne...". If I want to send that to a friend, I would edit the link to be "https://www.google.com/search?q=hacker+news https://www.google.com/search?q=hacker+news". The dedicated share buttons will often give you a link generated on the fly, with all the tracking info on the back end. For example, if google was to do this (which they thankfully don't), the link might look like "google.com/?query=cce1602b-5af6-4d95-965b-e88450afc266", and in the database there would be all sorts of tracking info tied to it. I can't edit that URL to dissaciate from that information, so if I share it, they would know it was me who shared it, and not someone else visiting it on their own. Of course, companies can and do track you via less obvious means all the time, but this is just one small way you can foul a data point for them.
- Black101 5y ago> They absolutely do that, but when you copy-paste them to share elsewhere, you can manually strip all the tracking info out. If they create custom urls for everyone that look like https://website.com/uuid/ https://website.com/uuid/ and don't redirect you to the real url... it is not possible to strip anything unless you do some research to find another URL that redirects you to the same page. Not sure what that would do to your search engine rankings though...
- milofeynman 5y agoWhen twitter's snowflake was lengthened recently I was worried they might be doing this too. I'm afraid of the big ones moving to this. Spotify, instagram, twitter, etc
- ddorian43 5y agoWhere was it lengthed ?
- vagrantJin 5y agoThis is needlessly alarmist. A short video platform can hardly be expected to be a paragon of security and privacy. It has no utility whatsoever. I don't see where the concern comes from. A video of someone drinking coffee does not particularly invoke a point of concern. What may be the real concern is China and the fact that the app is tied to it. Thats more race/geo-politics/war-mongering issue than a privacy concern.
- oauea 5y agoYou can't be serious. If what the gp says is true, then tiktok leaks your full name to anyone you share a link to. I see your HN username, nor bio, mentions your full name. Perhaps you are comfortable sharing this with anyone you communicate with online, but I'm not.
- vagrantJin 5y agoWell, my grandmothers logic and wise advice still holds. You have a problem with it - don't use it. It's genius. Just like you wouldn't stand there listening to a drunk person complain about alcohol related health issues, I'm not about to entertain people complain about privacy when they have the agency and choice.
- kevinh 5y agoPeople don't know that they're sharing personal info when they're sharing the links. It's like spiking someone's drink and then blaming them for getting drunk.
- oauea 5y agoI don't. This is one of the many reasons why I never will. I don't see how that is relevant to the discussion, however. Say hi to your grandmother for me.
- joshstrange 5y agoYes, I regularly warn people on Reddit that their full name is being leaked in the TikTok link they shared. I have an iOS shortcut that expands the URL and chops off the gross tracking stuff so I can share links in private/public without exposing my TikTok "name" (I don't link any accounts and my name is made up).
- ehsankia 5y ago> I have an iOS shortcut that expands the URL and chops off the gross tracking stuff Ooo, that's pretty neat. I wonder if something similar can be achieved on Android. I usually manually paste it in chrome and copy the redirect, although I also enable desktop view to not get the mobile link.
- joshstrange 5y agoYou might want to look at some basic Android automation tools. I'm pretty sure I've seen some before but I don't know any off the top of my head. It was really simple to write the iOS Shortcut, all I did was: * Accept a URL as input * Expand the URL to the full link * Find the "?" in the new url and snip everything after and including it. Originally I looked for ".html?" but some TikTok links don't have the ".html" anymore so I had to switch to just "?". Tasker for Android [0] might be what you are looking for but I can't be sure. You might want to ask on the subreddit [1] for help or search there for something similar. [0] https://play.google.com/store/apps/details?id=net.dinglisch.android.taskerm&hl=en_US&gl=US https://play.google.com/store/apps/details?id=net.dinglisch.... [1] https://www.reddit.com/r/tasker/ https://www.reddit.com/r/tasker/
- ehsankia 5y agoI didn't realize iOS shortcuts were so powerful, that's awesome. I do believe tasker should be able to do it, thanks!
- space_fountain 5y agoA fun/weird result of this that the interface in the link is in the language of whoever generated the link not your browser’s language
- imiric 5y agoStack Overflow does something similar, and adds a user tracking ID to any shared link, though apparently it's possible to remove it without breaking the link[1]. I only noticed when I received a badge for how many times it was clicked, and even though it's not nefarious I'd still prefer it to be opt-in rather than done by default. [1]: https://meta.stackoverflow.com/q/277769 https://meta.stackoverflow.com/q/277769
- 1vuio0pswjnm7 5y agoAssuming any certificate pinning can be defeated, it is easy to manipulate URLs with a loopback-bound forward proxy. Would be great if someone provided example of one of these TikTok URLs so we could investigate.
- 3np 5y agoDiscord does something very similar
- Breza 5y agoVRBO is another egregious example. My friend asked what I thought about a house she was thinking of renting for a trip. VRBO wouldn't let me view the link on my phone unless I downloaded their app. I had her copy and paste the house's description which I then Googled to get to the right listing.