

How Companies Sidestep Protections to Spy on You
Jun 9, 2025
Discover how Meta and Yandex cleverly bypass Android's privacy protections while exploring the alarming sale of billions of stolen session cookies. Learn about Apple's extensive push notification data disclosures and what they mean for user privacy. Get insights into political updates impacting privacy laws globally, and find out if Signal is gearing up for paid subscription services. Plus, hear recommendations on how to protect yourself from invasive tracking with privacy-focused browsers and tools.
AI Snips
Chapters
Transcript
Episode notes
Browser-App Localhost Abuse De-Anonymizes Users
- Meta and Yandex convert ephemeral browser identifiers into persistent app identities by abusing localhost communication on Android.
- This lets them link web browsing to logged-in app accounts and de-anonymize users across sites.
Reduce Risk By Avoiding Native Apps
- Avoid installing Facebook, Instagram, or Yandex apps on Android to block this cross-context tracking.
- Use privacy browsers (Brave, DuckDuckGo) and layered DNS or tracker blockers to reduce leakage.
Blocklists Help But Are Always Reactive
- DNS and blocklist defenses are helpful but reactive and can be outpaced by new domains and techniques.
- Defense-in-depth is necessary because no single protection is perfect against evolving tracking methods.