Uncategorized

This is how Facebook and Instagram can spy on you

A former Google developer warns about the iOS apps from Facebook and Instagram. If the in-app browser is used here, extensive monitoring can take place. Even passwords and payment data could theoretically be tapped via the apps. Meta has already reacted, but dismisses it.

iOS: Expert warns about Facebook and Instagram

Former Google developer Felix Krause is sure that from the iOS apps of Facebook and Instagram a high security risk can go out. If users use the browser integrated in the apps – instead of Safari, Chrome or others – then Meta, as the operator of the two networks, can collect extensive data. WhatsApp, which also belongs to Meta, should not be affected.

The expert states that Instagram and Facebook without any user consent Inject JavaScript code into web pages. At least in theory, all actions performed by the user could be recorded and stored for later use. According to Krause, this also includes sensitive entries in forms such as passwords, credit card and telephone numbers and addresses.

Meta already has responded to the serious allegations while maintaining his innocence. Although there would be a JavaScript injection in the in-app browsers, this does not serve any evil purposes. For example, data should be collected so that users can fill out forms more quickly (source: Felix Krause). Among other things, it is also about “optimizing advertisements and other aspects of the user experience on Facebook”.

Here’s how you can make your Facebook account more secure:

Expert: Don’t use the in-app browser

Krause generally advises users not to use in-app browsers. However, this is not possible with the iOS apps Facebook and Instagram, as these links automatically open in your own mobile browser. Only after opening the link the desired website can be viewed in Safari, Chrome or another browser. Alternatively, Facebook and Instagram can also be deleted and the web versions called up instead.

Leave a Reply

Your email address will not be published. Required fields are marked *