@YurkshireLad no. Nearly any mobile app can do this and more.
paco@infosec.exchange
Posts
-
Holy shit this is detailed. -
Holy shit this is detailed.@energisch_ I’m not a lawyer or European. But that blog makes a very strong argument that you’re right: it sure seems illegal by EU law.
-
Holy shit this is detailed.@kitkat_blue Years ago I was working for a retailer in the UK who had only recently built their first mobile app on iOS. Like most apps of that era, it was little more than a webview and it didn't need much permisisons.
Like most developers, they had incorporated some analytics package that was reporting on users' interaction with the app. I'm fairly sure it was a binary library that they linked into their app. I don't think they got source code. I might be wrong.
I could see the telemetry going up in the analytics API calls. Which buttons, which pages, etc.
Then one day they launched an app feature "find a store near me." Now the app needed location permissions. If the user granted location permissions, the analytics library got access to location. Anything the app can do, the analytics library can do. And, sure enough, those analytics telemetry messages started to carry GPS coordinates from the user to this third party. My customer didn't make any change to their code. They didn't turn that on. They just asked for, and got, location permission from the end user for a legit purpose in the app.
I pointed it out, because this was a change in behavior that was not contemplated by their privacy policy. Heck, it's a change in behavior they didn't even know had happened! It wasn't in their code! So they quietly pushed out a small update to the policy that made it OK.
That was probably like 15-16 years ago.
-
Holy shit this is detailed.Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?
The Attack: How it works
Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy. This page documents exactly how the system works, with line references and code excerpts from LinkedIn’s production JavaScript bundle.
BrowserGate (browsergate.eu)
-
Oh fudge.@strangefour Here comes Mothra:
#monsterdon -
Subject: Autistic ‘black and white’ thinking.@KatyElphinstone Being unambiguous is not “black and white” nor is it limiting. One can have a huge rainbow of clearly defined colours. Blue is not red, yellow is not green. But there are limitless colours. I suspect sometimes people mistake a strong desire for clarity to be a refusal to accept complexity. Sometimes it’s just a stubborn effort to understand or organise the complexity.
I love the phrase “pattern-seeking missile.”
-
THIS SUNDAY at 9PM Eastern (that's 1 am UTC) it's #MONSTERDON the weekly monster movie watch party!@CactuarJoe Sadly, it is not 1:00am UTC. It is 2:00am UTC. It's a 5-hour time difference. The UK and US do daylight savings time at different weeks, so there are some weeks when it's a 4 and some weeks when it's 6 hours. But for now, it is 5.
Anyways,
@steggy and I are in Dorset this weekend, so we are going to bed soon and setting an alarm to get up and watch! -
ARGH -
Few #monsterdon films have such a perfect final frame.Few #monsterdon films have such a perfect final frame.
It's just missing the WTF.
-
Folks it is now ONE HOUR until #MONSTERDON the weekly monster movie watch party.@CactuarJoe "Hello ladies and gentlemen."
-
Time for a #discord alternatives thread, for no particular reason.@mdiluz What do you meant “no web app” for mattermost? I just did a 3-way call tonight with 2 other folks using mattermost. I was using Firefox. I had video, audio, and screen sharing. They also have a mobile app.
-
Folks it is now about an hour until #Monsterdon the weekly monster movie watch party!@CactuarJoe This is the correct result. #mothra was 0% the worst #monsterdon
-
Here are the graphs!Here are the graphs!
A histogram showing posts per minute on Sunday, 18 Jan 2026. Each bar represents one minute. The event was 90.2 minutes long. There were 2022 posts during the event with an average of 22.41 posts per minute.
The busiest moment was at 50:00 from the start with 36 posts in that minute. The quietest moment was at 41:00 from the start with 12 posts in that minute. The yellow line is a 15-minute moving average.
The word cloud for Sunday, 18 Jan 2026. Words are larger the more frequently they appeared in posts. There were 7266 unique words posted, and the wordcloud shows the 200 most frequent. The top 10 most frequent words were: mothra: 756, mothradon: 383, mothra1961: 126, will: 79, time: 76, think: 69, giant: 61, island: 60, really: 55, tiny: 55,
These words were excluded from the word cloud:
movie, movies, film, films, watch, now, one, guy, got, going, good, well, see, know, monsterdondoublefeature, ack, mothra1962, marsattack, marsattacks, monstermiru, and the hashtag monsterdon. -
Folks it is now about an hour until #Monsterdon the weekly monster movie watch party!@CactuarJoe Is that a mouse in your trousers or are you just happy to see me?
#monsterdon -
My comments are littered with folks asking "why is it a problem if your blocklist is public on Bluesky?"@vkc I totally agree. I'm trying to be extra nice to the n00bs. If we want them to feel happy and welcome, then we need to do things that make them feel happy and welcome.
-
Stunt dude's face briefly comes into frame.Stunt dude's face briefly comes into frame. You can catch a bit of nose and a bit of hair.
#monsterdon -
Folks it is now about an hour until #MONSTERDON the weekly monster movie watch party.@CactuarJoe What do you think of buckets? Maybe give us 5 options?
- Top 20% best #monsterdon films, evar
- Next 20%
- Middle 20% of Monsterdon films
- Not quite the bottom 20%
- Bottom 20% of Monsterdon films
It's different from "stars" because someone could assign the same number of stars to every film. In this way we are thinking about what bucket it belongs in. Everything can't be in the top bucket.
Might be fun to let us rate old movies during a one-off, catch-up poll. Gives the field more info to work with.
-
New Peanuts movie dropped this holiday season.#monsterdonNew Peanuts movie dropped this holiday season.
#monsterdon -
Thanks for all the fun commentary everyone.Thanks for all the fun commentary everyone. See you next week
-
Folks it's about 45 minutes until #MONSTERDON the weekly monster movie watch party.@CactuarJoe I wonder if we could use a 2x2 grid scoring system. Good film to bad film, and fun to comment on to not fun to comment on. Some films were good (eg invasion of the body snatchers) and were not so much fun to comment on because they weren’t bad. And some are good bad, like Clash of the Titans, where they’re super fun to comment on. And others are bad bad like Invasion of the Star Creatures where there’s not much fun commenting.